Privacy Policy
What Advocate does
Advocate is a personal career journaling tool. You write short notes about your work ("moments"), and the app uses AI to reflect on them, cluster them into stories, and assemble them into a running performance review with citations back to what you wrote.
What we collect
- Account info: your email address, used to sign you in with a one-time code or an account password through Supabase.
- Voice and images: audio you choose to record is streamed to Deepgram for transcription. Advocate stores the resulting text, not an audio recording. A review-rubric photo you choose to upload is sent to Anthropic to extract the framework.
- Purchase information: subscription product, purchase/renewal status, and app account identifiers are used to manage access. Apple processes payment; Advocate does not receive your full payment-card details.
- Content you write: journal entries/moments, AI-generated summaries and reflections of them, competency/review sections and claims, story clusters, and any "compose" or "ask" conversations you have with the assistant.
- Profile fields: your role, review period dates, promotion goal/timeline, and an optional voice sample (used so generated text sounds like you, not like a template).
- Evidence health: a score (and its history) reflecting how well-supported your review sections currently are.
- Push notification token: if you enable notifications, a device token used to deliver them.
Who we share it with
We don't sell your data or run ads. We use a small number of processors to run the app:
- Anthropic (Claude): the text you write, plus your competency framework, is sent to Claude to generate reflections, clusters, and synthesized review claims. Anthropic's API does not train its models on API inputs by default.
- Deepgram: receives audio and relevant vocabulary, such as work-area names, to transcribe speech.
- RevenueCat: receives app account identifiers and Apple purchase information to validate subscriptions and restore access.
- Voyage AI: summaries of your moments are sent to generate embeddings (used for search/retrieval — matching new entries to the right section).
- Supabase: hosts our database, file storage, and authentication. Your data is stored in a Postgres database with row-level security, scoped so only you can read your own rows through the app. Authorized backend services process these records to provide features.
- Vercel: hosts the app and its backend functions.
- PostHog: product analytics. We only send event names, counts, and enum values (e.g. "capture_started", "section_locked") tied to your profile ID — never the text of your entries, reflections, or claims. Session recording is off.
- Apple Push Notification service: used to deliver notifications to your device, if enabled.
Your choice about AI processing
Before Advocate sends content to its AI providers, the app explains what will be shared and why. You choose whether to start a voice or typed entry. If you don't, you can still read saved work, export your data, or delete your account. Please check generated text before using it.
How long we keep it
We keep your data for as long as your account exists, so the review can keep building over time. Deleting your account removes your records from the live app database. Copies may remain temporarily in backups or service-provider logs under their retention policies; deletion does not cancel an Apple subscription. Manage subscriptions in your App Store account settings.
Your rights
- Export: from You, "Download all my data" gives you a JSON file of everything tied to your account — entries, threads, sections, and profile fields.
- Delete: from You, "Delete my account" permanently deletes your entries, threads, stories, review sections, and account. This cannot be undone.
Children
Advocate is not directed at children under 13, and we don't knowingly collect data from anyone under 13.