Offcuff — Privacy Policy
Last updated: 2026-09-27
Casa Pivote ("we", "us") provides the Offcuff application ("the App"). This policy explains how we handle your information.
1. The short version — your device holds the primary copy
Offcuff asks you to type in things that actually happened to you, so what you enter can be sensitive. The App is built around that:
- Signing in is optional. Everything in the App works without it. We do not collect your name, email address, phone number, or a password — including when you do sign in (Section 7-b).
- Your scripts, notes, and records live on your device as the primary copy. Our server is a place your rehearsal passes through, not where it lives.
- Our server holds the text you enter only while a rehearsal is being processed, and for up to 72 hours afterwards. After that the text is deleted from our server and only counters — which contain none of your text — remain.
- There is one exception. If you sign in and turn Backup on (so your records can be restored when you change phones), we hold a copy of them. Yours to switch on or off — see Section 7-b.
- We show no third-party advertising and do no tracking for advertising purposes (we do not carry out "tracking" as defined by Apple's App Tracking Transparency framework). No third-party analytics SDK is embedded in the App.
2. Information we collect
- An anonymous identifier: a UUID the App generates per device. It is not linked to your name or to any information that identifies you.
- What you type: the situation you want to practice, your lines during a rehearsal, the intentions and constraints you select, and your scene partner's setup (the name you use for them and their character). This is sent to our server and to the AI processors in Section 5 as needed to run the rehearsal. If you sign in and turn Backup on, a copy of your records — including this text — is also held on our server (Section 7-b).
- Subscription status: whether a subscription is active and which plan. Obtained through purchase verification data issued by Apple or Google. We do not receive your name or payment details.
- Usage and technical information: rehearsal starts and completions, number of exchanges, how many elements you met, elapsed time, which AI model handled the request and its token counts, error types, and which screens you reached. These consist only of event names, numbers, and category values; they contain none of the text you entered.
- A sign-in identifier (only if you sign in): an identifier issued by Apple or Google that uniquely represents you to us. We request it in a configuration that gives us no name and no email address.
- Device integrity results: to prevent circumvention of the free allowance, results from Apple DeviceCheck / App Attest and Google Play Integrity (a boolean result and a minimal flag recording whether the free allowance has been used).
3. Information we do not collect
In providing the App's features, we do not collect:
- Name, email address, phone number, postal address, date of birth
- Location, contacts, photos, calendar
- Audio recordings (see Section 4)
- Advertising identifiers (IDFA / Advertising ID), or any information for third-party behavioural tracking
The one exception is when you write to us. If you choose to email contact@offcuff.app, your email address and your message reach us — that is something you send, not something the App takes from your device. When you open a support draft from inside the App, what it fills in is your anonymous ID, the app version, your OS and its version, and your interface language, and you can edit or delete any of it before sending.
4. Speaking and read-aloud
When you speak your line, transcription happens on your device (on-device speech recognition). The audio itself never leaves your device. Only the resulting text — which you can review and edit — is sent.
Your partner's lines are read aloud using external speech synthesis services (Cartesia for Japanese, Inworld for English). Only your partner's lines are sent for this purpose — nothing you type is sent. Because your partner's lines are generated in response to what you write, they may indirectly reflect its content. If the Japanese service is unavailable, the English service is used instead, and if that is also unavailable, the app automatically falls back to your device's own speech synthesis.
5. Processors (including transfers outside your country)
We use the following providers to process and store data on our instructions:
| Provider | Role | Location |
|---|---|---|
| Anthropic PBC | AI processing (generating notes, screening what you type, building scenes) | United States |
| OpenAI OpCo, LLC | AI processing (generating partner replies, interludes, and model lines) | United States |
| Fly.io, Inc. | Application server hosting | United States (servers located in the Japan region) |
| Neon, Inc. | Database hosting | United States (database located in the Singapore region) |
| Cartesia AI, Inc. | Speech synthesis for reading your partner's lines aloud (Japanese) | United States |
| Theai, Inc. (dba Inworld) | Speech synthesis for reading your partner's lines aloud (English, and Japanese as a backup) | United States |
| Apple Inc. / Google LLC | App distribution, in-app purchase processing, device integrity checks | United States and elsewhere |
| Tigris Data, Inc. | Storing Backup copies | United States (regions are chosen by the provider's distributed placement) |
About the data sent to Anthropic (based on that company's published information as we verified it on 2026-08-12):
- Inputs and outputs sent through the API are not used to train AI models by default.
- Anthropic automatically deletes them within 30 days. If content is flagged as a suspected violation of that company's usage policy, it may be retained longer (per its published policy, up to two years).
- We do not have a zero-data-retention agreement in place, so the temporary retention described above does apply.
If we change or add a processor, we will update this policy. We do not sell your information.
6. Purposes
- Providing the App's features (running rehearsals, generating notes, managing your records, providing the sharing features)
- Managing free and fair-use allowances and preventing circumvention of them
- Restoring your records when you change or reinstall on a new device (only if you turned Backup on — Section 7-b)
- Improving the service and diagnosing faults (based on aggregates that contain none of your text)
- Responding to enquiries
We will give notice, and obtain consent where required, before using your information for any other purpose.
7. Retention
| Data | Retention |
|---|---|
| The text you enter (situation, lines, scripts, notes) | Server: while processing, and for up to 72 hours afterwards, then deleted (for Backup copies see Section 7-b). Device: until you delete it |
| Backup copies of your records | 12 months from the date they were last backed up, then deleted automatically (Section 7-b) |
| Allowance counters and subscription status (no text) | Stored against the anonymous identifier until you delete your data |
| Usage and technical information | As long as needed for aggregation and fault diagnosis |
| Public share links | Expire 90 days after creation. You can delete them at any time |
| Upcoming rehearsals and how it went in real life | On your device only — never sent to our server (reminders are local notifications) |
| Any assessment that you may be in distress | Not recorded. Support contacts are shown on screen; no assessment is stored or transmitted |
| Support emails you send us | As long as needed to answer you and to stop the same problem recurring. Held in our email inbox, not on our server |
Our server logs and usage records do not contain the text you enter. This is enforced as a design constraint and verified continuously by automated tests.
7-b. Signing in, and Backup — holding a copy so you can restore it
Backup keeps a copy of the records of people who sign in on our server, so you can carry them to a new phone.
Signing in is optional. Everything in the App works without it. If you do not sign in, your records live only on your device — and a move that does not go through your operating system's own backup will not carry them across.
How you sign in, and what we receive
You sign in with either an Apple or a Google account — your choice.
- All we receive and store is the identifier Apple or Google issues.
- We request it in a configuration that gives us no name and no email address. We never handle a password.
- Signing in links to the records you already built anonymously. Your free allowance and rehearsal counts stay on the anonymous identifier, as before.
What we hold
A copy of the rehearsal records on your device: your scripts, notes, scene records, keepers, the regulars you have met, the name you like to be called, and your rehearsal counts. This includes the text you entered — the situations you described and the lines you said.
What we do not hold: scheduled reminders, device settings such as read-aloud and display, and a rehearsal in progress.
What carries across
- Sign in with the same account on a new device and your records come back.
- Records held against an Apple sign-in cannot be carried across to a Google sign-in, or the other way round. Signing back in on the same side brings them back.
Retention and deletion
- Copies are deleted automatically 12 months after the date they were last backed up. We give no individual warning first — we hold no email address, so we have no way to reach you.
- Turning Backup off in Settings deletes the copy we hold.
- You can delete your account from "Delete all data" in Settings. This removes both the sign-in link and the copy we hold (Section 10).
Security, and one thing we want to be straight about
Backup copies are encrypted at rest, but we hold the decryption key. We are therefore technically able to read them. We do not read them — but this is not a system that makes it impossible for us to.
If that is not something you want, do not sign in. Everything in the App still works, and your records stay on your device and in your operating system's own backup (iCloud Backup or Android's backup service).
8. Other people in what you type
The situations you practice may involve people around you — a manager, a friend, a family member. In the field for their name, we recommend a nickname or initials rather than a real name. Please do not enter third-party personal or confidential information unnecessarily.
9. Sharing features
A public link you create through a sharing feature (a redacted script, a before/after card, a callout) can be viewed by anyone who has the link. What is shared is limited to the prompt, the listener setting, the score, and a redacted script — the text you entered is not reproduced verbatim. Please consider who you share links with.
10. Deleting your data
| Action | Result |
|---|---|
| Delete a single script | Removed from your device (no copy older than 72 hours exists on our server; if Backup is on, the next backup removes it from the copy too) |
| Turn Backup off | Deletes the copy we hold (Section 7-b) |
| Delete your account | Available from "Delete all data" in Settings. Removes both the sign-in link and the copy we hold |
| "Delete all data" in Settings | Erases data on your device and deletes the records held against your anonymous identifier on our server (your rehearsal and performance counts, the link to your subscription, any share links you created, and anything still inside the retention window). If you are signed in on that device, the copy we hold is deleted too — see the note below — and this is subject to the exception below |
| Delete the App | Your device data is removed by the operating system. A record against the anonymous identifier, containing no text, remains on our server. A Backup copy remains, so that you can restore it on a new device — it is deleted automatically on the schedule in Section 7-b |
A note about Backup copies: a copy belongs to the sign-in, not to a device. So if you have since signed in on a newer device, running "Delete all data" on the older one will not delete the copy — by then it belongs to the sign-in on the newer device. To delete it, run "Delete all data" on the device you are currently signed in on. This is deliberate: it stops a phone you gave away or sold from erasing the records of whoever had it before.
One exception: the minimal records needed to enforce usage limits are not erased on request. Specifically: whether the free allowance tied to your anonymous identifier has been used, and how many times you used the App on which dates. None of what you typed is included — that is erased. If these could be erased, the deletion control would itself become a procedure for resetting your free allowance and your daily limits. Where we use Apple's DeviceCheck for the same purpose, we treat that flag the same way.
11. Children
The App is not intended for children under 13. We do not knowingly collect personal information from children under 13.
12. Security
We use TLS for data in transit, encrypt Backup copies at rest, keep AI service credentials on the server only, exclude your text from logs and usage records, and delete data automatically once the retention period ends.
13. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of information about you. Contact us at the address below. Because we hold no name or email address, we will need the anonymous identifier shown in the App's settings screen in order to locate the data your request concerns — this is true whether or not you have signed in.
14. Changes
If we revise this policy, we will announce it on this page and in the App. Material changes will be announced before they take effect.
15. Provider and contact
- Provider: Casa Pivote (sole proprietorship, Japan)
- Address: Shibuya Dogenzaka Tokyu Bldg. 2F-C, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo 150-0043, Japan
- Contact: contact@offcuff.app