Shower Talk is a voice journal. You speak, it transcribes what you said, and it uses language models to turn that into summaries, themes and charts. That means your recordings and their transcripts leave your phone. This page says exactly where they go.
It is written against what the software actually does. Where the honest answer is worse than the reassuring one, the honest answer is here.
Shower Talk is operated by Poppby Corporation. For anything below, write to support@showertalk.app.
What we collect
Your email address and password. Needed to make an account. Passwords are stored by our authentication provider as salted hashes; nobody at Poppby can read yours.
Your recordings. Audio you record in the app.
Your transcripts and everything derived from them — summaries, themes, emotion scores, extracted activities and thoughts, goals you write, and your conversations with the in-app assistant.
Names and quotes about other people. When you talk about someone, the app stores their name, any aliases it learns, a sentiment score, and short verbatim quotes from what you said. See “People who are not you” below, because this is the part most worth understanding.
A small amount of usage data — which screens you open, whether onboarding completed, whether a recording succeeded. Keyed to an account number, never to your email.
Crash reports when the app fails.
Subscription records — what you bought, when it renews, and the country your store account is in. We never see your card.
What happens to a recording
- You record. The audio is written to your phone.
- The audio is uploaded to our storage so it can be transcribed. It has to leave the phone: transcription runs on a paid third-party service, and calling that service directly from the app would mean shipping a key inside the app that anyone could extract and spend.
- Our transcription provider fetches the file over a short-lived signed link and returns text.
- Our copy of the audio is deleted once your phone confirms it still holds its own copy. Not when the transcript arrives — when your device confirms. Those are different moments and only one of them is the truth.
The failure case, stated plainly. If an entry fails, stalls before it is transcribed, or comes from a device that never confirms, our copy of that audio is kept indefinitely. The deletion job refuses to remove a file it cannot prove you still have, because the alternative is deleting your only copy. You can remove any of it yourself by deleting the entry or your account.
If you subscribe to Cloud audio backup, we keep the server copy on purpose — that is the entire product — until you delete the entry, turn the add-on off, or delete your account.
Transcripts and insights are not on that clock. Nothing automatically deletes them. They stay until you delete the entry or your account.
Who processes your data
Everyone below is a processor acting on our instructions. Nobody here is sold your data, and none of these providers is permitted to train models on it under the terms we use them on.
| Processor | What it receives | Why |
|---|---|---|
| Supabase | everything: account, audio, transcripts, insights, chat | hosting and database |
ElevenLabs (elevenlabs) | your recording | speech to text |
Deepgram (deepgram) | your recording | speech to text, alternate provider |
Together AI (together) | your recording, or transcript text | speech to text and model routing |
Anthropic (anthropic) | your transcript | analysis, summaries, the assistant |
OpenAI (openai) | your transcript | analysis and search embeddings |
Moonshot (moonshot) | transcript text | alternate analysis model |
DeepSeek (deepseek) | transcript text | alternate analysis model |
PostHog (posthog) | account number, screen names, feature events | product analytics, hosted in the EU |
Sentry (sentry) | crash reports, account number | crash reporting |
Superwall (superwall) | account number, purchase events | subscriptions and paywalls |
Apple APNs (apns) | device notification token | delivering notifications |
Google FCM (fcm) | device notification token | delivering notifications |
Amazon SES (ses) | your email address | sending email you asked for |
| Expo | app version requests when the app checks for an update | app delivery |
| Apple, Google | your purchase | payment |
Several transcription and analysis providers are listed because the app can be pointed at any of them and the choice is configuration rather than code. We list what it is able to use, not only what it happens to use today, so this page cannot quietly go out of date.
People who are not you
This deserves its own section because it is the least obvious thing the app does.
When you talk about someone — a partner, a manager, a friend — Shower Talk stores their name, other names you use for them, a sentiment score, and short verbatim quotes of what you said about them. That information is included in the text sent to our analysis providers.
Those people are not Shower Talk users. They did not agree to any of this. Two consequences worth being clear about:
- You are the one deciding to record it. Please think about that the way you would think about writing it in a paper diary that lives in someone else’s building.
- If someone contacts us asking what Shower Talk holds about them, we have no way to find them — their name only exists inside your private journal, which we will not search or hand over except where the law actually compels it.
Deleting an entry removes the quotes it contributed. Deleting a person removes that person’s record.
Notifications
Shower Talk sends notifications about your own journal — reminders, and word when an entry has finished processing. To do that:
- Your device gives us a notification token, which we store and send to Apple or Google to deliver the message. It identifies a device installation, not you. Signing out deletes it. If you simply uninstall, Apple or Google tell us the token is dead the next time we try to use it, and we stop sending to it and keep a record that we did.
- Notifications you choose to receive by email are delivered through Amazon SES, which therefore handles your email address.
You control what you get, per kind and per channel, in the app. Turning everything off stops the sending; it does not delete your account.
Analytics, and what it deliberately does not record
Product analytics runs on PostHog, hosted in the European Union, and is scoped tightly on purpose:
- You are identified by an account number, never your email.
- Session replay is off. We never record your screen.
- Screen names have their identifiers stripped before they are sent — we log that you opened an entry, never which entry. A dated log of which parts of your own journal you reread is exactly the thing that should not exist in a third-party system.
- No transcript, recording, person, or insight is ever sent to analytics.
Crash reports go to Sentry with an account number and your subscription state. Personally identifying data is switched off at the SDK.
Advertising
None. Shower Talk contains no advertising SDK, does not use the advertising identifier, and does not track you across other apps or websites.
Deleting your account
In the app: Profile → Delete account. It removes your recordings from storage first, then deletes the account, and everything attached to it — entries, transcripts, insights, people, chats, goals — is deleted with it. There is no undo.
Full instructions, including how to ask if you no longer have the app installed, are at https://showertalk.app/delete-account.
Two limits, stated rather than glossed.
- Audio already on your phone stays on your phone until you delete the app.
- Deleting your account does not automatically reach into our analytics, crash reporting or subscription providers to erase their copies. Those hold an account number and coarse events, not your journal. If you want them purged too, email us and we will do it by hand.
There is currently no way to export your data. We would rather say so than imply a button that does not exist. Ask us and we will get you your transcripts.
Your rights
Depending on where you live you may have the right to access, correct, export, delete, or restrict the processing of your personal data, and to complain to a data protection authority. Email support@showertalk.app and we will answer. We do not sell personal information and we do not share it for cross-context behavioural advertising.
We keep your data for as long as your account exists. Data is processed in the United States and the European Union.
Children
Shower Talk is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will remove it.
Changes
If this policy changes in a way that affects what we do with your data, we will say so in the app rather than only editing this page. The date at the top is the last substantive change.