Privacy Policy
Last updated: May 14, 2026
Who we are: Sasha+, operated by Alexander Tabachnik (sole proprietor), New Brunswick, Canada. Contact: support@sashaplus.app
What We Collect
- Account information — your email address, display name, and authentication details when you create an account. If you use Sign in with Apple or Sign in with Google, we receive your name and email from that platform to create your account.
- Recordings — video and audio you capture during sessions. Video is stored locally on your device. Audio is sent to our transcription service to generate a text transcript used for AI analysis.
- AI conversations — messages you send and receive in the assistant chat, including any voice input you provide.
- Subscription status — whether you have an active Pro subscription, managed through Apple.
- App usage data — in-app events such as feature interactions, session starts, and screen views, linked to your account after you log in, used to understand and improve the app.
- Device information — device model, iOS version, and app version, collected alongside usage events.
- Push notification token — a device identifier issued by iOS used to deliver push notifications to your device.
- Crash and diagnostic data — information about app crashes and errors, including device state at the time of the crash, linked to your account and used to diagnose and fix issues.
We do not collect: precise or coarse location, contacts, health or medical records, payment card information, or any other sensitive categories not listed above.
How We Use It
- To provide and operate the app's features.
- To generate AI-powered feedback from your sessions.
- To manage your account and subscription.
- To send push notifications related to your subscription (such as trial reminders).
- To understand how the app is used, diagnose crashes, and improve it over time.
Ads and Data Sharing
No ads. We do not sell or share your personal information for cross-context behavioural advertising or targeted advertising of any kind.
Service Providers
We use a small number of third-party service providers to operate the app. We share only what each service needs to function:
- Cloud infrastructure and authentication — stores your account profile, subscription status, and push notification token.
- AI response generation — receives text summaries and transcripts of your sessions to generate responses. Raw video is never sent to this provider.
- Audio transcription — receives audio from your sessions to produce a text transcript used for AI analysis.
- Subscription and billing management — manages your in-app subscription via Apple. Receives a pseudonymous account identifier to verify your entitlement and deliver subscription-related notifications.
- Product analytics — receives in-app usage events and device metadata to help us understand and improve the app.
- Apple— Sign in with Apple authentication, in-app purchase processing, push notification delivery, and speech recognition for voice input. When you use voice input, Apple's Speech Recognition framework processes your audio; this may occur on-device or on Apple's servers depending on your device and iOS version.
- Google — optional Sign in with Google authentication. We receive a Google-generated identifier and your email address solely to verify your identity.
- Crash reporting — receives crash logs and diagnostic data linked to your account identifier to help us identify and fix technical issues.
Each provider processes data in accordance with their own privacy policy.
AI Assistant
Audio from your sessions is sent to our transcription service. The resulting transcript, along with a text summary of your session and any messages you type or speak in the assistant chat, is sent to our AI provider to generate a response. Raw video files are never sent to any external provider. We do not use your content to train AI models.
Account Deletion and Authentication Tokens
When you delete your account, all associated data is permanently removed from our systems. If you used Sign in with Apple, we retain an Apple-issued authorization token in your account record solely to perform server-side revocation with Apple at the time of deletion, as required by Apple's guidelines. This token is deleted as part of the account deletion process.
Data Retention
- Video recordings — stored locally on your device until you delete them.
- Transcripts and AI conversations — until you delete your account.
- Account information — until you delete your account.
- Subscription records— as required by Apple's receipt verification process.
- Usage and analytics data— subject to our analytics provider's standard retention periods.
You can delete your account at any time from within the app (Profile → Delete Account), which permanently removes your account and associated data from our systems.
Your Choices
- Delete your account: in-app via Profile → Delete Account, or email support@sashaplus.app.
- Opt out of AI features: do not submit content to them. Deleting your account removes all stored content.
- Push notifications: disable at any time in iOS Settings → Notifications → Sasha+.
International Transfers
Your data may be processed or stored in Canada, the United States, or other countries where our service providers operate. By using the app, you consent to these transfers.
GDPR / UK-GDPR
If you are in the EU or UK, you have the right to access, correct, delete, port, and object to or restrict processing of your personal data. Our lawful bases for processing are contract performance and legitimate interests. Contact support@sashaplus.app to exercise any of these rights. We respond within 30 days.
CCPA / CPRA (California)
We do not “sell” or “share” personal information as defined by the CPRA. California residents may request access to or deletion of their data by emailing support@sashaplus.app.
Children
Sasha+ is intended for users 13 and older. We do not knowingly collect personal information from children under 13. If we learn a child under 13 has created an account, we will delete their data promptly. Contact support@sashaplus.app if you believe this has occurred.
Security
We use industry-standard security measures including TLS encryption in transit and encryption at rest. No system is completely secure and we cannot guarantee absolute security.
Changes
We may update this policy from time to time. When we do, we will update the date at the top of this page. Continued use after changes constitutes acceptance.