Pretake

Privacy policy

What Pretake keeps, what it sends, and what it never has.

Last updated

In short

1. Who is responsible

Pretake is operated by an individual based in Frankfurt am Main, Germany ("we", "us"). We are the controller for the processing described here. For anything about your data, write to privacy@getpretake.com.

This policy is governed by German law and the EU General Data Protection Regulation (GDPR).

2. No accounts, no identity

There is no sign-up. The first time the app runs it asks our server for an install token; that request carries nothing about you, and the token it gets back is random. It is the only thing the server uses to tell one install from another.

We do not collect your name, email address, phone number, device identifier, advertising identifier or location. The app contains no analytics SDK and no third-party trackers, and it does not use your IP address to work out where you are.

If you pick the person you want to rehearse with from your contacts, iOS shows its own picker outside the app. Pretake never asks for permission to read your contacts and never sees your address book; it receives the one name you tapped and nothing else — no number, no email address, no identifier.

3. What stays on your phone

DataWhat happens to it
A chat export (for example a WhatsApp export)Read on your phone, then deleted the moment the messages have been parsed.
ScreenshotsThe text is recognised on your phone using Apple's on-device Vision framework, then the images are deleted. They are never uploaded. The app does not read your photo library beyond the images you hand it.
A screen recordingSampled and text-recognised on your phone, then deleted. Never uploaded.
The reconstructed conversationStored on your phone, in the app's own database. Sent with each reply request (section 4) and never stored by the server. Deleted when you delete that person.
Notes on the older part of a long conversationStored on your phone next to the conversation (section 5). Deleted with it.
Your age checkOnly the fact that it passed, and when. Your date of birth is never stored.
Your install token and subscription stateStored on your phone so the app can talk to the server.

4. What is sent to the server, and what it keeps

Two different things leave your phone, and the difference between them is the whole design.

Stored on the server, against your token

All of this is encrypted at rest. Each install gets its own 256-bit key; message content, display names, relationships and style profiles are encrypted with AES-256-GCM under that key, and the token itself is stored only as a hash. A copy of the database contains none of it in readable form, and there is no password to reset because there is no account.

Sent, but not stored

The imported conversation. To reply as someone, the AI model has to have read them. So each time you send a message, the conversation goes with it: to our server, and on to the model provider (section 6). The server holds it for the length of one reply, uses it to build the request, and writes none of it to any table. Restart the server or copy its database and there is nothing of it to find. The only lasting copy is the one on your phone, and deleting that person deletes it.

Before it leaves, URLs, email addresses and phone numbers are replaced on your phone, and the same rule runs again on the server before the text reaches the model provider. The same identifiers are stripped from the style profile before it is uploaded, and the server refuses a profile that still contains one.

Each request is bounded: at most 4,000 messages, trimmed to 200,000 characters, keeping the most recent.

5. Long conversations

For a long conversation, not all of it travels with each reply. The most recent 40,000 characters go as they are. Everything before that is read by the AI model once, when you import, and turned into notes — who is who, what has happened, what keeps coming up, and a couple of dozen of the person's own messages copied exactly. From then on the notes travel in place of the older messages.

The notes are the same kind of data as the conversation and are handled the same way: written on your phone's request, stored on your phone next to the conversation, sent with each reply, never stored by the server, and deleted with the person. The only difference is quantity: the older messages reach the model provider once, at import, rather than with every reply.

6. The AI model provider

Replies are written by a large language model, not on your phone. Our server sends the request through OpenRouter, configured to route only to model providers that do not retain the request and do not train on it. Today the model is Google's Gemini. Both process the request only to produce the reply.

This means the redacted conversation — and, for a long conversation, the notes described in section 5 — reaches OpenRouter and the model provider for the length of each request. This is the one place your import goes beyond your phone and our server, and it is what makes the simulation able to sound like the person at all.

Our server and database are in Frankfurt, Germany, in the EU. Generating a reply involves processing outside the EU/EEA. Where it does, we rely on the safeguards in Chapter V of the GDPR, such as the European Commission's adequacy decisions or standard contractual clauses.

A message that trips the app's crisis rules is screened on your phone first and is never sent inside a request that asks the simulation to react to it; the app answers in its own voice instead.

7. No training

Nothing you import or write is used to train any model — not by us, and our routing forbids the model provider from doing so. We do not use it for analytics, for personalisation across users, or for advertising. It is used to provide the app, and for nothing else.

8. The person whose messages you import

The person you rehearse with did not agree to any of this and cannot be asked from inside the app. That fact shaped the design, and it comes with obligations for you (see the terms).

If you believe someone has imported a conversation with you, you can write to us at privacy@getpretake.com. Be aware of the limit: because nothing on the server is tied to an identity, we cannot search for conversations involving you. The reliable way to have one removed is for the person who imported it to delete it, which erases it from their phone and from our server.

9. Subscriptions

Pretake Unlimited is billed by Apple through the App Store. Pretake never sees your payment details; Apple's privacy policy governs the purchase.

To confirm that a subscription is active, the app sends our server a receipt signed by Apple. The server keeps the transaction identifier and the expiry date against your token. Apple also sends our server App Store Server Notifications — signed messages about renewals, expiries and refunds — so that access ends when a subscription does. They identify the transaction and the kind of event, not you.

A subscription is tied to one active install. Restoring it on a new phone moves it there and the previous install returns to the free tier.

10. Crash reports

The app and the server can send crash reports (through Sentry) if crash reporting is turned on in the version you are using. When it is, it is configured to send no IP address, no identity, no record of what you typed or which screens you visited, no session replays, and no request contents — only the technical trace of the crash. Crash data is not linked to you.

11. How long we keep it

Until you delete it. Data on the server lives for as long as your install holds it; there is currently no automatic expiry. Deleting a person, or everything, removes it as described in section 12.

12. Deleting

Deleting one person removes their style profile, every branch of the conversation, the imported conversation and the import record — on your phone first, then on the server, where one cascading delete takes the rest.

"Delete everything" in Settings asks the server to erase everything held under your token first, while the token still exists, and only then clears your phone and forgets the token. The order matters: the token is also the key to everything encrypted under it, so what is left behind is erased, not merely unreachable. If the server cannot be reached, the app tells you so rather than reporting a deletion that did not happen.

13. Age

Pretake is for adults. The app asks for your date of birth to check that you are 18 or over, and does not store it — only that the check passed, and when. We do not knowingly process data about anyone under 18.

14. Your rights

Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. You also have the right to lodge a complaint with a data protection supervisory authority — in our case the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), or the authority where you live.

Because nothing on the server is tied to an identity, we cannot match an email from you to any data. The app itself is the tool for exercising these rights: each person's page shows what was imported and what was kept, and Settings deletes everything. If you need help, write to privacy@getpretake.com.

We process your data to provide the app you asked for (Art. 6(1)(b) GDPR). Safety screening, crash reporting and the prevention of misuse rest on our legitimate interest in running the service safely (Art. 6(1)(f) GDPR). Processing the messages of the person you imported, in order to provide the rehearsal, rests on the legitimate interests of you and of us, subject to the safeguards in section 8 (Art. 6(1)(f) GDPR).

16. Changes

If this policy changes, the new version is published here with a new date at the top. Changes that matter will also be pointed out in the app.

17. Contact

privacy@getpretake.com