Privacy Policy for CatchFrase
Effective Date: June 27, 2026 Last Updated: August 3, 2026
Alex Yao ("we," "our," or "us") built CatchFrase as a free-to-start app with an optional subscription (CatchFrase Plus). This Privacy Policy explains how we collect, use, and protect your information when you use the CatchFrase app or visit our website, catchfrase.com.
By using CatchFrase, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the app.
Version note: CatchFrase 1.2 and 1.2.1 do not ask for App Tracking Transparency permission and do not use Tenjin. The OneSignal, Layers, PostHog, Tenjin, and consented-attribution terms below apply only to CatchFrase 1.2.2 and later. Tenjin does not connect unless you allow tracking through Apple's system prompt.
1. Information We Collect
Information You Provide Directly
- Photos you capture. When you point your camera at an object to collect it, the app captures that photo so it can identify the object and create a vocabulary card. See Section 3 and Section 4 for how this photo is processed.
- Support requests. If you contact us for support, we collect your email address and the content of your message.
Information Collected Automatically
- Anonymous usage analytics. The app sends us anonymous usage events (for example: the app was opened, a catch was made, a review was completed) together with a random install identifier generated on your device. These events contain no name, no email, no photos, no precise location, and no advertising identifier, and we cannot reasonably use them to identify you. We use them only to understand which features are used and to improve the app.
- Subscription status. If you subscribe to CatchFrase Plus, your payment is processed by Apple. We receive subscription-status information (such as whether a subscription is active) through our subscription-management provider, RevenueCat, tied to a random app identifier — not to your name or Apple ID.
- Crash reports. If the app crashes, a report is sent to our crash-reporting provider, Sentry, so we can find and fix the fault. It contains the error, where in the code it happened, your device model, operating system version and app version, and an identifier Sentry generates for the installation. It contains no name, no email, no photos, no audio and none of the words you have collected. We use these reports only to fix faults.
- Messaging data. In the version that adds OneSignal, the app sends a random subscription or user identifier, device and app details, notification permission and delivery state, and interactions with notifications or in-app messages. We use this data to deliver and measure those messages. It is not tied to a CatchFrase account because the app has no accounts.
- Product and performance analytics. In the version that adds Layers, the app sends a random install or device identifier, app version, operating system, device model, locale, time zone, product interactions, purchase and subscription events, crash details, and app performance data. Layers receives analytics data only. CatchFrase keeps Layers advertising storage, advertising user data, and ad personalization off.
- Anonymous product analytics. In CatchFrase 1.2.2 and later, PostHog receives a random identifier, app and device details, the named product events described above, and coarse country and region derived from the connection. PostHog discards the source IP address after deriving that coarse location. CatchFrase does not send PostHog names, email addresses, photos, audio, collected words, or the advertising identifier. PostHog person profiles, screen capture, session replay, surveys, push handling, and crash reporting are off.
- Advertising attribution after consent. In the version that adds Tenjin, the app asks for Apple's App Tracking Transparency permission after onboarding. If you allow it, Tenjin may receive the advertising identifier, vendor identifier, IP address, device and app details, Apple Ads attribution, selected product events, and paid subscription events so we can measure which posts and ads led to installs and purchases. If you decline, Tenjin does not connect and does not receive those events.
Information We Do NOT Collect
- We do not require you to create an account, and we do not collect your name, email, or login credentials to use the app.
- We do not show ads, sell personal information, or build advertising profiles.
- We do not send data to Tenjin for advertising measurement unless you first allow tracking through Apple's system prompt.
- We do not collect your precise location or GPS coordinates. PostHog derives coarse country and region for analytics and discards the source IP address.
- Your collected words, cards, and captures are stored only on your device and are not synced to our servers or any cloud account.
2. How We Use Your Information
We use the information we collect only to:
- Identify the object in your photo and generate a vocabulary card (word, pronunciation, and example sentences) in your chosen language
- Store your collected cards locally on your device so you can review them
- Understand aggregate feature usage (via the anonymous events above) so we can improve the app
- Deliver push notifications and in-app messages, and measure whether they worked
- Measure which posts and ads led to installs and paid subscriptions, but only after you allow tracking
- Validate your subscription and unlock CatchFrase Plus features if you subscribe
- Respond to your support requests
We do not use your information to sell data, build advertising profiles, or make automated decisions that significantly affect you.
3. How We Share Your Information
We do not sell, rent, or trade your personal information.
To identify the object in a photo, the app sends that photo to a third-party AI service (see Section 4). The app also sends the usage, subscription, crash, performance, messaging, and consented-attribution data described in Section 1 to the service providers that handle each job. We share information only in these limited circumstances:
- Service providers. We use the third-party services listed in Section 4. Each receives only the data needed for the purpose listed there.
- Legal requirements. We may disclose information if required by law, regulation, legal process, or government request.
- Safety. We may disclose information to protect the safety, rights, or property of Alex Yao, our users, or the public.
4. Third-Party Services
To turn a photo into a vocabulary card, CatchFrase transmits the captured image to the following services:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google (Gemini API) | Identifies the object in your photo and generates the vocabulary card | https://policies.google.com/privacy |
| Cloudflare (Workers) | Securely routes the request between the app and the AI service, and stores the anonymous usage events described in Section 1 | https://www.cloudflare.com/privacypolicy/ |
| RevenueCat | Manages subscription status for CatchFrase Plus (receipt validation tied to a random app identifier) | https://www.revenuecat.com/privacy/ |
| fal (SAM segmentation) | Only when an on-device cutout fails and you tap to fix it: the photo is sent once so the object can be separated from its background. It is processed for that request and not kept | https://fal.ai/privacy |
| Apple (Speech Recognition) | Recognizes your voice during pronunciation practice. This happens on your device when your device supports it, and otherwise by Apple's speech recognition service. Audio is never stored and never reaches CatchFrase's servers | https://www.apple.com/legal/privacy/ |
| Sentry | Receives a report when the app crashes: the error, where in the code it happened, your device model, operating system version and app version, plus an identifier Sentry generates for the installation. It carries no photos, no audio and no vocabulary you have collected | https://sentry.io/privacy/ |
| OneSignal | Delivers push notifications and in-app messages, and records message delivery and interaction data under a random subscription or user identifier | https://onesignal.com/privacy_policy |
| Layers | Receives product-use, purchase, crash, and performance analytics under random app and device identifiers. Its advertising storage and ad user data stay off | https://layers.com/privacy/ |
| PostHog | Receives named product-use events under a random identifier and derives coarse country and region from the connection. It discards the source IP address. Person profiles, screen capture, session replay, surveys, push handling, and crash reporting are off | https://posthog.com/privacy |
| Tenjin | Measures which posts and ads led to installs and paid subscriptions. It connects only after you allow tracking through Apple's system prompt | https://tenjin.com/privacy/ |
The photo is transmitted over an encrypted (HTTPS) connection solely to generate your vocabulary card. We do not store the photo on our own servers. Your photo and the resulting card are saved on your device only.
Apple's on-device features used by CatchFrase — object cutout (Vision) and text-to-speech (AVSpeechSynthesizer) — run entirely on your device and do not transmit your data to us or any third party.
5. Our Website (catchfrase.com)
This section applies to the catchfrase.com website only, not the app.
- First-party analytics. The website sends us anonymous page-visit events. Each event contains the page event name, an optional referral code from the link you clicked (for example a teacher's invite link), and the hostname of the referring website — nothing else. These events use no cookies and contain no personal information.
- Microsoft Clarity. We use Microsoft Clarity to understand how visitors use the website through heatmaps and session replays (how pages are scrolled, moved through, and clicked). Clarity uses cookies and similar technologies to do this. The data is processed by Microsoft as described in the Microsoft Privacy Statement. Clarity runs on the website only — it is not part of the app and never sees anything you do in the app.
6. Data Retention
- On-device data (cards, captures, settings): Retained on your device until you delete the app or clear its data. Deleting the app removes this data.
- Photos sent for identification: Transmitted only to generate a card, or to redo a cutout you asked to fix, and not stored on our servers. Any handling by Google, Cloudflare or fal is governed by their respective privacy policies (Section 4).
- Anonymous usage events (app and website): Stored in aggregate form on our analytics infrastructure for a limited period and then expire automatically. They are never joined with any identity, because none is collected.
- Website session data (Microsoft Clarity): Retained by Microsoft according to the Microsoft Privacy Statement (Section 5).
- Crash reports: Retained by Sentry for a limited period and then deleted automatically. They hold no identity to join them to (Section 4).
- Messaging, product analytics, performance, and consented attribution: Retained by OneSignal, Layers, PostHog, and Tenjin under their policies and our service settings. These services use random app or device identifiers rather than a CatchFrase account.
- Support requests: Retained for as long as needed to resolve your request.
7. Data Security
We implement reasonable technical measures to protect your information, including:
- Encryption in transit (TLS/HTTPS) for all network communications
- On-device storage protected by the operating system's standard app data protections
- Limiting the data sent off-device to the information described in this policy
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we take commercially reasonable steps to protect your data.
8. Your Rights
Because CatchFrase stores your collected data on your device and does not maintain an account or server-side copy, you can exercise most data rights directly:
- Access / Export: Your cards and captures live on your device within the app.
- Deletion: Delete individual items in the app, or delete the app to remove all on-device data.
- Tracking choice: You can deny the tracking request or change it later in iOS Settings. Tenjin does not connect when tracking permission is denied.
- Notification choice: You can change notification permission in iOS Settings at any time.
For any other request regarding personal information, contact us at alex@alexyao.me. We will respond within 30 days.
For European Union / EEA Residents (GDPR)
- Data controller: Alex Yao, alex@alexyao.me
- Lawful basis for processing: We process the photo you capture to perform the service you requested (creating a vocabulary card) — Article 6(1)(b), performance of a contract, and your consent when you choose to capture a photo.
- Your rights: access, rectification, erasure, restriction, objection, and data portability. You also have the right to lodge a complaint with your local Data Protection Authority.
- International transfers: The AI services in Section 4 may process your photo on servers outside the EEA. Where this occurs, appropriate safeguards (such as Standard Contractual Clauses) apply under those providers' terms.
For California Residents (CCPA)
- Right to know / delete: You may request the categories and specific pieces of personal information we have collected, or request deletion.
- No sale of data: We do not sell or share your personal information for cross-context behavioral advertising.
- Non-discrimination: We will not discriminate against you for exercising your rights.
To exercise your CCPA rights, contact us at alex@alexyao.me.
For Indian Residents (DPDP)
- Data fiduciary: Alex Yao, alex@alexyao.me
- Purpose & consent: Your photo is processed, with your consent, only to generate a vocabulary card.
- Your rights: access, correction, erasure, grievance redressal, and the right to nominate a representative. To file a grievance, contact us at alex@alexyao.me.
9. Children's Privacy
CatchFrase is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at alex@alexyao.me and we will delete it promptly.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will update the "Last Updated" date above and post the updated policy at our published privacy URL. Your continued use of CatchFrase after changes are posted constitutes acceptance of the updated Privacy Policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
- Email: alex@alexyao.me
- Developer: Alex Yao
- Mailing address: 777 Brickell Ave, Ste 500, PMB 97954, Miami, FL 33131-2803, United States