Privacy Policy
Parley — iOS app. Effective 8 August 2026.
Parley helps you prepare for a difficult conversation. You describe a situation, Parley returns a Brief: an opening line, likely pushback and responses, and a Pocket Card.
This policy describes exactly what leaves your device, who receives it, and how long they keep it. It is written against the shipping code, not against an intention.
There are no accounts and no login. Parley never asks for your name, your email address, or a password, and it has no way to link what you write to your identity.
1. What stays on your device
Everything Parley remembers is stored locally on your iPhone using Apple's SwiftData, in the app's own container. There is no Parley server that holds your content, and no Parley-operated database of situations, Briefs, or the people you describe.
Stored locally, and only locally:
- Your situations and the drafts you were part-way through writing
- Generated Briefs, including edits you make to the opening line
- People you create, including the aliases you give them
- Patterns Parley infers about how your conversations tend to go
- Debriefs — how the conversation actually went
- Your appearance preference, your onboarding answers, and scheduled reminders
Because this data lives on your device, it is covered by your device passcode and encryption, and it is included in your iPhone backups (iCloud or local) if you have backups turned on. Parley does not read or upload your backups.
2. What leaves your device, and why
To generate a Brief, Parley must send the relevant text to an AI model. Requests travel over HTTPS to a Cloudflare Worker operated by the developer, which forwards them to xAI through Cloudflare AI Gateway.
Sent for processing:
| What | When |
|---|---|
| Your situation text | When you generate a Brief |
| Your answers to clarifying questions | When you answer them |
| Voice recordings of your situation | When you use voice intake (see §4) |
| Aliases and context about the person | When the Brief needs it |
| Existing pattern evidence | When Parley personalises a Brief |
| A Brief section you ask to regenerate | When you tap regenerate |
| Your debrief text | When you complete a debrief |
| A random, app-generated identifier | With every request, for rate limiting |
Parley does not send your device's advertising identifier, your contacts, your location, your photos, or your calendar. It has no access to them.
3. Who processes your data
xAI — the AI provider. Models: grok-4.5 for generation, xai/grok-stt for voice
transcription. xAI receives the content listed in §2 in order to produce a result.
Retention, stated plainly. xAI may retain API inputs and outputs for up to 30 days for abuse auditing, and does not use API content to train its models. Parley does not promise that your content is deleted the instant it is processed, because that is not what the provider's policy guarantees. This is the same trade-off stated during onboarding and in Settings.
Cloudflare — operates the Worker and the AI Gateway that carry the request. The
Gateway is configured so that request and response payload logging is off
(cf-aig-collect-log-payload: false), caching is disabled (TTL 0, and every request
also sends cf-aig-skip-cache: true). The Worker itself logs no request bodies — only
error type names and coarse operational lines. Cloudflare processes the traffic as a
transport and infrastructure provider.
PostHog (EU region, eu.i.posthog.com) — product analytics. PostHog receives named
events about how the app is used, such as onboarding_step_viewed, brief_generated,
debrief_completed, and paywall_viewed, with fixed-choice or numeric properties: which
step, which input mode, how many clarifying questions, which Brief section. No
user-authored content is sent to PostHog — no situation text, no transcript, no Brief
text, no alias, no debrief text. Automatic screen-view capture and automatic error capture
are both switched off, precisely because those payloads can carry text you wrote.
RevenueCat — subscription status only, keyed to the same random app-generated identifier. No email, no name, no account.
Apple — processes every payment. Parley never sees or receives your card details, billing address, or Apple ID.
That is the complete list. Parley uses no advertising SDKs, does no cross-app or cross-company tracking, and sells nothing to anyone.
4. Voice recordings
If you speak your situation instead of typing it, Parley records short audio segments (roughly six seconds each) into your device's temporary directory, sends each segment for transcription, and deletes the file as soon as that segment has been transcribed — and also deletes any pending segments if recording stops or fails. The audio is not kept on your device and is not stored by Parley. The resulting transcript is treated like any text you typed: kept locally, sent for generation as described in §2. The 30-day provider retention window in §3 applies to the audio while it is being transcribed.
Microphone access is requested only when you first choose voice intake, and you can refuse it and type instead.
5. Legal basis (EEA/UK)
Where the GDPR applies, the developer processes generation requests to perform the contract you enter into by using Parley, and uses legitimate interests for the abuse-prevention limits that keep the service running. Optional product analytics are processed only with your consent, requested during onboarding and withdrawable at any time in Settings. Since there is no account, there is no named profile held about you.
6. Your choices and your rights
Usage analytics. Analytics are off until you explicitly enable them during onboarding or in Settings → Usage analytics. Your choice is saved on your device. You can withdraw consent at any time by turning the toggle off; this stops future collection and does not affect Brief generation or your subscription.
Delete everything. Settings → Delete Everything permanently removes, from your device: every conversation, Brief, Person, Pattern, draft, and debrief; all pending and delivered notifications; your onboarding answers; and the random app-generated identifier used with the Worker, RevenueCat, and PostHog (the analytics identity is reset at the same time). Parley then returns to onboarding. Your chosen appearance setting is the one preference this does not clear.
Two things Delete Everything cannot do, because they are not the app's to delete:
- It does not cancel an active subscription. Cancel that in Settings → your Apple ID → Subscriptions, or via Manage subscription in Parley.
- It does not reach back and delete content already sent to xAI within the abuse-auditing window described in §3.
Deleting the app removes the local database with it.
Requests. Because there is no account, the developer usually holds nothing that identifies you and so cannot look you up. If you believe data about you was processed and you want to exercise a right of access, correction, deletion, restriction, objection, or portability, email parley@nbarwicki.com and include the random identifier if you still have the app installed. You may also complain to your local data protection authority.
7. Children
Parley is not directed at children and is not intended for anyone under 13 (or the minimum age in your country). It does not knowingly collect data from children.
8. Security
All traffic is HTTPS. The Worker authenticates every request using Apple's App Attest, so only genuine installations of Parley can reach it, and it enforces per-device and global rate limits. No API keys for AI providers are shipped inside the app.
9. International transfers
xAI, Cloudflare, RevenueCat, and Apple may process data outside your country, including in the United States, under the transfer mechanisms in their own agreements. PostHog analytics are hosted in the EU.
10. Changes
Material changes to this policy will be reflected here with a new effective date, and where the change is significant it will be surfaced in the app.
11. Contact
Nikolas Barwicki — parley@nbarwicki.com
See also: Terms of Use · Support
