Privacy Policy for CatchFrase

Effective Date: June 27, 2026 Last Updated: August 3, 2026

Alex Yao ("we," "our," or "us") built CatchFrase as a free-to-start app with an optional subscription (CatchFrase Plus). This Privacy Policy explains how we collect, use, and protect your information when you use the CatchFrase app or visit our website, catchfrase.com.

By using CatchFrase, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the app.

Version note: CatchFrase 1.2 and 1.2.1 do not ask for App Tracking Transparency permission and do not use Tenjin. The OneSignal, Layers, PostHog, Tenjin, and consented-attribution terms below apply only to CatchFrase 1.2.2 and later. Tenjin does not connect unless you allow tracking through Apple's system prompt.


1. Information We Collect

Information You Provide Directly

Information Collected Automatically

Information We Do NOT Collect


2. How We Use Your Information

We use the information we collect only to:

We do not use your information to sell data, build advertising profiles, or make automated decisions that significantly affect you.


3. How We Share Your Information

We do not sell, rent, or trade your personal information.

To identify the object in a photo, the app sends that photo to a third-party AI service (see Section 4). The app also sends the usage, subscription, crash, performance, messaging, and consented-attribution data described in Section 1 to the service providers that handle each job. We share information only in these limited circumstances:


4. Third-Party Services

To turn a photo into a vocabulary card, CatchFrase transmits the captured image to the following services:

Service Purpose Privacy Policy
Google (Gemini API) Identifies the object in your photo and generates the vocabulary card https://policies.google.com/privacy
Cloudflare (Workers) Securely routes the request between the app and the AI service, and stores the anonymous usage events described in Section 1 https://www.cloudflare.com/privacypolicy/
RevenueCat Manages subscription status for CatchFrase Plus (receipt validation tied to a random app identifier) https://www.revenuecat.com/privacy/
fal (SAM segmentation) Only when an on-device cutout fails and you tap to fix it: the photo is sent once so the object can be separated from its background. It is processed for that request and not kept https://fal.ai/privacy
Apple (Speech Recognition) Recognizes your voice during pronunciation practice. This happens on your device when your device supports it, and otherwise by Apple's speech recognition service. Audio is never stored and never reaches CatchFrase's servers https://www.apple.com/legal/privacy/
Sentry Receives a report when the app crashes: the error, where in the code it happened, your device model, operating system version and app version, plus an identifier Sentry generates for the installation. It carries no photos, no audio and no vocabulary you have collected https://sentry.io/privacy/
OneSignal Delivers push notifications and in-app messages, and records message delivery and interaction data under a random subscription or user identifier https://onesignal.com/privacy_policy
Layers Receives product-use, purchase, crash, and performance analytics under random app and device identifiers. Its advertising storage and ad user data stay off https://layers.com/privacy/
PostHog Receives named product-use events under a random identifier and derives coarse country and region from the connection. It discards the source IP address. Person profiles, screen capture, session replay, surveys, push handling, and crash reporting are off https://posthog.com/privacy
Tenjin Measures which posts and ads led to installs and paid subscriptions. It connects only after you allow tracking through Apple's system prompt https://tenjin.com/privacy/

The photo is transmitted over an encrypted (HTTPS) connection solely to generate your vocabulary card. We do not store the photo on our own servers. Your photo and the resulting card are saved on your device only.

Apple's on-device features used by CatchFrase — object cutout (Vision) and text-to-speech (AVSpeechSynthesizer) — run entirely on your device and do not transmit your data to us or any third party.


5. Our Website (catchfrase.com)

This section applies to the catchfrase.com website only, not the app.


6. Data Retention


7. Data Security

We implement reasonable technical measures to protect your information, including:

No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we take commercially reasonable steps to protect your data.


8. Your Rights

Because CatchFrase stores your collected data on your device and does not maintain an account or server-side copy, you can exercise most data rights directly:

For any other request regarding personal information, contact us at alex@alexyao.me. We will respond within 30 days.

For European Union / EEA Residents (GDPR)

For California Residents (CCPA)

To exercise your CCPA rights, contact us at alex@alexyao.me.

For Indian Residents (DPDP)


9. Children's Privacy

CatchFrase is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at alex@alexyao.me and we will delete it promptly.


10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will update the "Last Updated" date above and post the updated policy at our published privacy URL. Your continued use of CatchFrase after changes are posted constitutes acceptance of the updated Privacy Policy.


11. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, contact us at: