skip to content
babbl3
privacytermssupport

legal

Privacy Policy

Effective September 16, 2026

This policy explains what babbl3 processes, why it is needed, and the controls available to you.

What babbl3 processes

  • Account information used by identity and authentication services to sign you in, including your email address and account identifier.
  • Your generated or chosen username, display name, avatar emoji, optional profile photo, and any optional date of birth or gender you choose to save. Your date of birth and gender are visible only to you and are not used for matching, personalization, analytics, or age gating.
  • Voice recordings you choose to send, complete transcripts created on supported devices and submitted to babbl3 when you send, generated babbl3 text and audio, and message metadata.
  • Chat membership, per-note babbl3 Code state, emoji reactions, blocks, reports, deletion requests, and notification details you enable.
  • A device installation identifier and push token when you enable notifications.
  • Sanitized production JavaScript crash and error reports needed to find bugs, including a safe error category, feature and operation, source-code locations, and app/build/platform version. Anonymous transcription health attempts also report start and outcome, attempt kind, chat or thread surface, coarse latency, cancellation reason, safe error category, and app/build/platform/OS version. These diagnostics exclude audio, transcripts, message text, codes, invitation tokens, names, usernames, emails, account, device, chat, thread, draft, and contact identifiers, storage paths, credentials, and raw error messages.
  • Only after you choose Share analytics in the account prompt or turn Product analytics on in Settings, coarse production events for app, invitation, chat, voice-note, and message-action outcomes, linked to an app account identifier. Analytics excludes audio, transcripts, message text, codes, invitation tokens, names, usernames, emails, contact identifiers, storage paths, and raw errors.

Voice notes and Voice AI

After a recording is finalized, supported devices transcribe it on the device. On-device transcription is separate from Voice AI. babbl3 uploads each voice note you send to private, access-controlled cloud object storage and may submit the complete transcript to a private, access-controlled cloud database.

When Voice AI is on and you choose babbl3 speech, babbl3 sends generated babbl3 text, not the original recording or transcript, to ElevenLabs to create stock-voice audio.

If on-device transcription is unavailable, you can still send the original without a transcript, but the babbl3 option is unavailable for that draft. Turning Voice AI off stops new stock-voice generation by ElevenLabs, not on-device transcription.

Submitted transcripts remain in the private, access-controlled cloud database until deletion under babbl3's product rules. When notifications are enabled, babbl3 may include up to 120 characters of recipient-visible Original transcript or invented babbl3 text in message and thread-reply notifications sent through the push delivery service. Missing or unsafe previews use generic text. Transcripts are not placed in public message rows, live data updates, or operational logs. babbl3 does not send old recordings to another speech provider to create missing transcripts.

babbl3 applies its phrase filter to the transcript submitted by the app. Because the server cannot prove that client-produced text matches the audio, this is a best-effort check, not verification of the recording itself.

On-device chat cache

While you are signed in, current versions keep an account-scoped SQLite copy of the authorized conversation directory and, for warmed main chats and opened threads, the newest message page and selected transcripts on your device. This lets a known cached chat or thread open while babbl3 refreshes it from the server. The read cache contains no voice audio and cannot queue sends or other offline actions. Each account has one bounded directory snapshot. Its ordinary timeline cache keeps the newest 64 rows and up to 32 MiB of serialized content; rows older than 30 days by cached timestamp are removed during cache maintenance. Reporting leaves the message and its authorized transcript in the cache. Relocking clears the affected Original transcript copy. Block, chat deletion, membership or access loss, account deletion, sign-out, or account switch clears the applicable timeline and directory data after the connected device learns of the change. An offline device may keep cached content until its next successful authorization sync.

Profile photos

Profile photos are optional. babbl3 asks for photo-library access only when you choose a photo, crops and re-encodes the selection as a 512-pixel JPEG, and uploads only the copy you approve. Your library original stays on your device.

The approved copy is stored in private cloud object storage. Short-lived read access is issued only after babbl3 confirms that the requester is you or someone with whom you share an eligible chat.

Technology services

babbl3 requires every service provider that receives user data, including ElevenLabs, to provide the same or equivalent protection described in this policy and required by applicable platform rules. External services process data under their own terms and retention practices. babbl3 does not promise zero third-party retention.

  • Identity and authentication services handle account creation and sign-in.
  • Third-party services provide the managed database, server compute, and private object storage used for chats, transcripts, audio, and optional profile photos.
  • On-device speech technology transcribes finalized recordings on supported devices.
  • ElevenLabs receives generated babbl3 text and creates stock-voice babbl3 audio only while Voice AI is on. It does not receive original recordings or transcripts.
  • A push delivery service processes notification titles and recipient-visible previews when you enable notifications.
  • Resend processes transactional account-deletion completion emails. Recovery prevents a completion email from being prepared. At final deletion, babbl3 encrypts the current verified sign-in email and keeps that encrypted copy for no longer than seven days while attempting delivery. It erases the copy sooner when Resend accepts the email or delivery becomes terminal. These emails contain no marketing and use no open or click tracking.
  • An operational diagnostics service processes the sanitized production JavaScript crash, error, and anonymous transcription health reports described above. This reporting is separate from optional product analytics.
  • A product analytics service processes the coarse production analytics described above only after you opt in. Screen recording, session replay, broad interaction capture, and development or test analytics are disabled.

Security and babbl3 Codes

Messages are not end-to-end encrypted. A babbl3 Code is a playful access switch that lets the other participant request the retained original for one selected babbl3 voice note. It does not unlock the rest of the chat and is not encryption or a security guarantee.

babbl3 and the technology services it uses may process message content to operate the app. babbl3 support may access a reported original voice note to review a safety report.

Retention and deletion

Delivered messages, private transcripts, reactions, and stored audio remain available until they are deleted under babbl3's product rules. A sender can delete selected voice notes for both participants, and a chat creator can permanently delete a chat for all participants. A non-creator can permanently delete their own access to a joined chat.

Deleted content becomes inaccessible in the app immediately. babbl3-controlled physical copies, replaced or removed profile photos, and failed or abandoned processing artifacts are purged within 24 hours. The service that processes sanitized production JavaScript diagnostics and opted-in product analytics currently specifies one year of event retention on its free plan. Non-content deletion receipts are kept for 90 days. Safety reports and bounded moderation audit metadata are retained for up to 30 days.

Requesting account deletion locks the account immediately and begins a 30-day recovery period. After that period, babbl3 deletes the sign-in identity, optional personal details, clears the username, de-identifies the profile, and makes authored messages, stored audio, and the active profile photo inaccessible. babbl3-controlled physical copies are purged within 24 hours. When a verified sign-in address is available, babbl3 attempts to send a completion email only after that purge finishes. For an account connected through Sign in with Apple or Google, babbl3 attempts to revoke that sign-in authorization before deleting the sign-in identity. If babbl3 cannot retrieve a token to revoke, you can remove babbl3 from your Apple Account or Google Account linked-app settings, as applicable. Copies held by external services may remain under their policies or legal requirements.

Your choices and tracking

Settings lets you add, change, or remove your optional date of birth, gender, and profile photo; turn Voice AI off or on; turn Product analytics off or on; manage notifications; block people; open archived chats; delete chats; request account deletion; and open this policy. Turning Voice AI off stops new stock-voice generation by ElevenLabs. It does not stop on-device transcription on supported devices. Turning Product analytics off immediately stops new analytics events from that account on this device. It does not stop essential sanitized crash, error, or anonymous transcription health reports. During the account-deletion recovery period, sign in and choose Recover account to cancel deletion.

babbl3 shares data only with the technology services above as needed to operate the app, or when required by law. babbl3 does not sell personal data and does not use data for cross-app advertising tracking. Sanitized operational diagnostics are used to find production crashes, failed actions, and interrupted transcription attempts. Optional product analytics is used only to understand whether core product flows work.

Contact

Questions or privacy requests can be sent to chris@babbl3.com.