Shower Talk

Privacy policy

Last updated 31 August 2026

Shower Talk is a voice journal. You speak, it transcribes what you said, and it uses language models to turn that into summaries, themes and charts. That means your recordings and their transcripts leave your phone. This page says exactly where they go.

It is written against what the software actually does. Where the honest answer is worse than the reassuring one, the honest answer is here.

Shower Talk is operated by Poppby Corporation. For anything below, write to support@showertalk.app.

What we collect

Your email address and password. Needed to make an account. Passwords are stored by our authentication provider as salted hashes; nobody at Poppby can read yours.

Your recordings. Audio you record in the app.

Your transcripts and everything derived from them — summaries, themes, emotion scores, extracted activities and thoughts, goals you write, and your conversations with the in-app assistant.

Names and quotes about other people. When you talk about someone, the app stores their name, any aliases it learns, a sentiment score, and short verbatim quotes from what you said. See “People who are not you” below, because this is the part most worth understanding.

A small amount of usage data — which screens you open, whether onboarding completed, whether a recording succeeded. Keyed to an account number, never to your email.

Crash reports when the app fails.

Subscription records — what you bought, when it renews, and the country your store account is in. We never see your card.

What happens to a recording

  1. You record. The audio is written to your phone.
  2. The audio is uploaded to our storage so it can be transcribed. It has to leave the phone: transcription runs on a paid third-party service, and calling that service directly from the app would mean shipping a key inside the app that anyone could extract and spend.
  3. Our transcription provider fetches the file over a short-lived signed link and returns text.
  4. Our copy of the audio is deleted once your phone confirms it still holds its own copy. Not when the transcript arrives — when your device confirms. Those are different moments and only one of them is the truth.

The failure case, stated plainly. If an entry fails, stalls before it is transcribed, or comes from a device that never confirms, our copy of that audio is kept indefinitely. The deletion job refuses to remove a file it cannot prove you still have, because the alternative is deleting your only copy. You can remove any of it yourself by deleting the entry or your account.

If you subscribe to Cloud audio backup, we keep the server copy on purpose — that is the entire product — until you delete the entry, turn the add-on off, or delete your account.

Transcripts and insights are not on that clock. Nothing automatically deletes them. They stay until you delete the entry or your account.

Who processes your data

Everyone below is a processor acting on our instructions. Nobody here is sold your data, and none of these providers is permitted to train models on it under the terms we use them on.

ProcessorWhat it receivesWhy
Supabaseeverything: account, audio, transcripts, insights, chathosting and database
ElevenLabs (elevenlabs)your recordingspeech to text
Deepgram (deepgram)your recordingspeech to text, alternate provider
Together AI (together)your recording, or transcript textspeech to text and model routing
Anthropic (anthropic)your transcriptanalysis, summaries, the assistant
OpenAI (openai)your transcriptanalysis and search embeddings
Moonshot (moonshot)transcript textalternate analysis model
DeepSeek (deepseek)transcript textalternate analysis model
PostHog (posthog)account number, screen names, feature eventsproduct analytics, hosted in the EU
Sentry (sentry)crash reports, account numbercrash reporting
Superwall (superwall)account number, purchase eventssubscriptions and paywalls
Apple APNs (apns)device notification tokendelivering notifications
Google FCM (fcm)device notification tokendelivering notifications
Amazon SES (ses)your email addresssending email you asked for
Expoapp version requests when the app checks for an updateapp delivery
Apple, Googleyour purchasepayment

Several transcription and analysis providers are listed because the app can be pointed at any of them and the choice is configuration rather than code. We list what it is able to use, not only what it happens to use today, so this page cannot quietly go out of date.

People who are not you

This deserves its own section because it is the least obvious thing the app does.

When you talk about someone — a partner, a manager, a friend — Shower Talk stores their name, other names you use for them, a sentiment score, and short verbatim quotes of what you said about them. That information is included in the text sent to our analysis providers.

Those people are not Shower Talk users. They did not agree to any of this. Two consequences worth being clear about:

  • You are the one deciding to record it. Please think about that the way you would think about writing it in a paper diary that lives in someone else’s building.
  • If someone contacts us asking what Shower Talk holds about them, we have no way to find them — their name only exists inside your private journal, which we will not search or hand over except where the law actually compels it.

Deleting an entry removes the quotes it contributed. Deleting a person removes that person’s record.

Notifications

Shower Talk sends notifications about your own journal — reminders, and word when an entry has finished processing. To do that:

  • Your device gives us a notification token, which we store and send to Apple or Google to deliver the message. It identifies a device installation, not you. Signing out deletes it. If you simply uninstall, Apple or Google tell us the token is dead the next time we try to use it, and we stop sending to it and keep a record that we did.
  • Notifications you choose to receive by email are delivered through Amazon SES, which therefore handles your email address.

You control what you get, per kind and per channel, in the app. Turning everything off stops the sending; it does not delete your account.

Analytics, and what it deliberately does not record

Product analytics runs on PostHog, hosted in the European Union, and is scoped tightly on purpose:

  • You are identified by an account number, never your email.
  • Session replay is off. We never record your screen.
  • Screen names have their identifiers stripped before they are sent — we log that you opened an entry, never which entry. A dated log of which parts of your own journal you reread is exactly the thing that should not exist in a third-party system.
  • No transcript, recording, person, or insight is ever sent to analytics.

Crash reports go to Sentry with an account number and your subscription state. Personally identifying data is switched off at the SDK.

Advertising

None. Shower Talk contains no advertising SDK, does not use the advertising identifier, and does not track you across other apps or websites.

Deleting your account

In the app: Profile → Delete account. It removes your recordings from storage first, then deletes the account, and everything attached to it — entries, transcripts, insights, people, chats, goals — is deleted with it. There is no undo.

Full instructions, including how to ask if you no longer have the app installed, are at https://showertalk.app/delete-account.

Two limits, stated rather than glossed.

  • Audio already on your phone stays on your phone until you delete the app.
  • Deleting your account does not automatically reach into our analytics, crash reporting or subscription providers to erase their copies. Those hold an account number and coarse events, not your journal. If you want them purged too, email us and we will do it by hand.

There is currently no way to export your data. We would rather say so than imply a button that does not exist. Ask us and we will get you your transcripts.

Your rights

Depending on where you live you may have the right to access, correct, export, delete, or restrict the processing of your personal data, and to complain to a data protection authority. Email support@showertalk.app and we will answer. We do not sell personal information and we do not share it for cross-context behavioural advertising.

We keep your data for as long as your account exists. Data is processed in the United States and the European Union.

Children

Shower Talk is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will remove it.

Changes

If this policy changes in a way that affects what we do with your data, we will say so in the app rather than only editing this page. The date at the top is the last substantive change.