Privacy Policy
Simena Digital LLC · privacy@bardicnotes.app
Last updated: September 2, 2026
Bardic is a session-recording, transcription, and note-keeping app made by Simena Digital LLC ("we," "us," or "our"), a Wyoming limited liability company based in the United States. This policy explains what data we collect, why, and how we protect it.
1. Information You Provide
When you use Bardic, you may provide the following information:
- Account information: name and email address (via Apple Sign-In), used only to tie your subscription to your account so it can be restored on a new device.
- Your debrief: the audio you record after a session, or the text you type instead. See §3 for exactly where it goes and how long we keep it.
- Your campaign: the transcript of each debrief, the recaps Bardic writes from it, and the campaign index it builds — the people, places and threads that appear in your sessions, together with any corrections you make to them. These are stored on our servers so they are there when you sign in on another device.
- App preferences: your language, theme, and notification settings.
2. Information Collected Automatically
When you access Bardic, we automatically receive:
- IP address and user agent (standard HTTP request data)
- Session tokens for authentication
We use one operational SDK, which cannot read your recordings, transcripts, or notes:
- Sentry (crash reporting): if the app crashes or errors, a technical report (device model, OS version, app version, stack trace) is sent to Sentry so we can fix the bug. Reports are scrubbed before sending: no email addresses, no IP addresses, no session content.
We do not run ads in the app and we do not track you across other apps or websites.
3. How a debrief is processed
Bardic transcribes in the cloud, not on your phone. Recording a debrief sends it off your device. Here is the whole path, in order:
- You record a debrief on your phone, or type one instead. Your phone keeps its own copy of the audio, and deleting it there is up to you.
- The recording is uploaded to our servers over an encrypted connection (HTTPS, TLS 1.2+).
- We send it to Deepgram, our speech-to-text provider, which returns a transcript.
- Our copy of the audio is deleted as soon as Deepgram answers — whether the transcription succeeded or failed. We are a transcription pipe, not an audio archive. We keep no recording of your session.
- The transcript is stored on our servers, and is then sent to Anthropic, which writes your player and GM recaps and extracts the people, places and threads for your campaign index.
- The transcript, the recaps and the index stay on our servers so they are available when you sign in again or on another device.
A typed debrief skips steps 2 to 4 entirely: there is no audio, so nothing goes to Deepgram. The text still goes to Anthropic in step 5.
This means a debrief needs an internet connection. Bardic does not transcribe offline.
4. How We Use Your Information
We use your information to:
- Provide and maintain Bardic's recording, transcription, recap and campaign-index features
- Authenticate your account and keep it secure
- Restore your subscription on a new device via your Apple ID
- Deliver scheduled local notifications (a daily reminder and a weekly recap)
- Enforce subscription entitlements and prevent free-trial abuse
5. Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Apple | Authentication (Sign in with Apple) | Name, email |
| RevenueCat | Subscription management and entitlement enforcement | Anonymous user ID, purchase history, and — on iOS — the Apple Search Ads attribution token (Apple's own privacy-preserving attribution mechanism; no advertising identifier, no App Tracking Transparency prompt) |
| Sentry | Crash and error reporting | Technical crash reports (device model, OS version, stack trace) — scrubbed of email, IP address, and all session content |
| Deepgram | Speech-to-text: turning your recorded debrief into a transcript | The debrief audio itself. Sent for transcription and not retained by us afterwards (see §3). Not sent at all for a typed debrief. |
| Anthropic | Writing your player and GM recaps, and extracting the people, places and threads for your campaign index | The transcript text of your debrief, plus the current campaign index sent as context so names are spelled consistently. Never your audio, never your name or email. |
All third-party service providers listed above are contractually required to protect your data to a standard equivalent to or greater than described in this policy.
We do not sell your personal data, and we do not use your sessions to train anyone's model.
Your audio does leave your device, and we will not pretend otherwise: transcription happens in the cloud (§3). What we do promise is that we do not keep it — our copy is deleted as soon as our transcription provider answers.
Before your first debrief is sent, Bardic asks for your permission in the app and records your answer on our servers. You can withdraw it at any time in Settings → AI & Privacy; while it is withdrawn, no debrief is sent.
6. Data Storage and Security
Your account record — name, email, and subscription status — is stored on secure servers. Communication between the app and our servers uses HTTPS (TLS 1.2+), and authentication uses timing-safe token comparison to prevent timing attacks.
On your device, Bardic stores data using:
- AsyncStorage: preferences, your onboarding profile, and app settings
- expo-sqlite: your recordings library — session metadata, transcripts, and notes
- expo-secure-store: authentication tokens (encrypted by the OS keychain)
7. Data Retention and Deletion
Your account record is retained as long as your account is active. You can delete your account at any time from Settings within the app. Deletion is soft-applied immediately — your active session is ended and your Apple refresh token is revoked — and finalized after 30 days. During this 30-day grace window you may restore the account by signing in again with the same Apple ID. After 30 days, your account record is permanently and irreversibly removed from our servers.
Deleting your account removes your transcripts, recaps and campaign index from our servers. Your phone's own copies of your recordings are separate and are yours to manage: delete a debrief from the app to remove its local audio, or delete the app to remove all of it at once. We hold no audio to delete — ours is already gone (§3).
Data held by third-party services (e.g. RevenueCat purchase records, Apple account data) is subject to those services' own retention policies.
8. International Data Transfers
Bardic is operated from the United States. If you are located outside the United States, the data we hold — your account information, your debrief transcripts, your recaps and your campaign index (see §1) — is processed in the United States, protected by Standard Contractual Clauses (SCCs) or equivalent safeguards where required by GDPR and UK GDPR. Your debrief audio is processed in the same way while it is being transcribed, and is then deleted (see §3).
9. Legal Basis for Processing (GDPR / UK GDPR)
If you are in the European Economic Area or the United Kingdom, we process your personal data under the following legal bases:
- Contract performance: to provide the Bardic service you signed up for, including account management and subscription entitlement.
- Consent: for optional features that require your explicit opt-in, including microphone access for recording and local notifications.
- Legitimate interest: for service security and fraud prevention (e.g., preventing abuse of the free trial).
You may withdraw consent for consent-based processing at any time by disabling the relevant feature or contacting us at privacy@bardicnotes.app.
10. Your Rights Under GDPR / UK GDPR
If you are in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:
- Access: request a copy of the data we hold about you
- Rectification: correct inaccurate personal data
- Erasure: delete your account and all associated data
- Portability: receive your data in a machine-readable format
- Restriction: limit how we process your data
- Object: object to processing of your data
- Withdraw consent: withdraw consent at any time where processing is based on consent
- Lodge a complaint: file a complaint with your local data protection authority if you believe your data has been mishandled
To exercise any of these rights, email us at privacy@bardicnotes.app. You can also delete your account directly in the app under Settings. We will respond to requests within 30 days.
11. Notifications
Bardic uses local notifications only — a daily reminder and a weekly recap, both fully optional. No push notification tokens are sent to our servers. All notification scheduling happens on your device.
12. Microphone
Bardic requests microphone access only to record sessions. Recording begins only when you start it, and continues — including while the app is in the background or the phone is locked — until you stop it. Audio is saved to your device in one-minute segments as you record, so an interruption costs at most a moment, never the whole session. The recording is then uploaded for transcription, and our copy is deleted once that finishes — see §3, which describes the whole path.
13. Children's Privacy
Bardic is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at privacy@bardicnotes.app and we will delete it promptly.
14. Your Rights by Jurisdiction
In addition to the GDPR and UK GDPR rights described above, the following rights may apply based on your location:
United States (California — CCPA/CPRA): California residents have the right to know what personal information we collect, request its deletion, and opt out of the sale of personal information. We do not sell your personal information. To exercise your rights, contact us at privacy@bardicnotes.app.
Canada (PIPEDA): Canadian users have the right to access, correct, and request deletion of their personal data. We only collect personal information for purposes that a reasonable person would consider appropriate. Contact us at privacy@bardicnotes.app to exercise your rights.
Australia (Privacy Act 1988): Australian users may access and correct their personal data under the Australian Privacy Principles. If you believe we have breached the APPs, you may lodge a complaint with us at privacy@bardicnotes.app or with the Office of the Australian Information Commissioner (OAIC).
Japan (APPI): Japanese users have the right to request disclosure, correction, and deletion of their personal data. We handle personal information in accordance with the Act on the Protection of Personal Information. Contact us at privacy@bardicnotes.app.
South Korea (PIPA): Korean users have the right to access, correct, delete, and suspend processing of their personal data under the Personal Information Protection Act. Contact us at privacy@bardicnotes.app to exercise your rights.
For all jurisdictions: regardless of where you are located, you can delete your account and all associated data at any time from Settings within the app.
15. Changes to This Policy
We may update this privacy policy from time to time. If we make material changes, we will notify you through the app or by email. The "Last updated" date at the top of this page indicates when the policy was last revised.
16. Contact Us
If you have questions, concerns, or requests regarding this privacy policy or your personal data, contact us at:
Simena Digital LLC
1021 E Lincolnway, Suite 9026
Cheyenne, WY 82001, United States
Email: privacy@bardicnotes.app