This Privacy Policy (the "Policy") describes the manner in which People Make Things, Inc., the operator of the Cupie mobile application (the "App") and the website located at cupie.app together with its associated subdomains (collectively, the "Website," and together with the App, the "Service") (such operator being referred to herein as the "Company," "we," "us," or "our") collects, receives, records, organizes, structures, stores, adapts, alters, retrieves, consults, uses, discloses, transmits, disseminates, aligns, combines, restricts, erases, or otherwise processes information that relates to an identified or identifiable natural person ("Personal Data"). This Policy is intended to satisfy, among other instruments, the transparency and notice obligations arising under Regulation (EU) 2016/679 (the "General Data Protection Regulation" or "GDPR"), the United Kingdom General Data Protection Regulation as incorporated into United Kingdom domestic law (the "UK GDPR"), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA"), and other applicable data protection and privacy laws, in each case to the extent such laws are applicable to the processing activities described herein. By accessing, downloading, installing, registering for, or otherwise using the Service, you acknowledge that you have read and understood this Policy in its entirety.
The purpose of this Policy is to provide a comprehensive, detailed, and exhaustive account of the categories of Personal Data that may be collected through your interaction with the Service, the purposes for which such Personal Data may be processed, the legal bases relied upon in respect of such processing where applicable, the categories of recipients to whom such Personal Data may be disclosed, the periods for which such Personal Data may be retained, the safeguards applied to international transfers of such Personal Data, and the rights that you may be entitled to exercise in relation to such Personal Data. This Policy applies to all individuals who interact with the Service in any capacity, including, without limitation, registered account holders, the partners with whom such account holders are paired within the App, prospective users who browse the Website, and any individual whose Personal Data is otherwise processed in connection with the operation, maintenance, improvement, or commercialization of the Service. This Policy should be read in conjunction with any supplementary or product-specific privacy notices, just-in-time disclosures, or consent prompts that we may present to you from time to time within the App, each of which forms part of, and is incorporated by reference into, this Policy.
For the purposes of this Policy, the following terms shall have the meanings ascribed to them below, and cognate expressions shall be construed accordingly. The term "Personal Data" means any information relating to an identified or identifiable natural person. The term "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means. The term "Controller" means the natural or legal person that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, and for the purposes of this Policy the Controller is the Company. The term "Processor" and the term "Sub-Processor" mean a natural or legal person that Processes Personal Data on behalf of the Controller. The term "Call Content" means, collectively, the microphone audio captured during a voice or video call conducted through the App, the textual transcripts derived from such audio, and the analytical outputs, metrics, classifications, characterizations, and other derived data generated from such transcripts. The term "Insights" means the analytical outputs presented to users following a call, as further described in Section 5.4. Headings are included for convenience only and shall not affect the interpretation of this Policy.
In the course of providing the Service, we may collect, generate, derive, infer, or otherwise come to Process the following non-exhaustive categories and sub-categories of Personal Data. The precise categories of Personal Data Processed in respect of any particular individual will depend upon the manner in which that individual interacts with the Service and the features of the Service that that individual elects to use.
When you create an account, we collect and Process the authentication identifier associated with the sign-in method that you elect to use, which may comprise an electronic mail address (in the case of sign-in mediated by Google or Apple), a telephone number together with a one-time verification code transmitted to that telephone number (in the case of telephone-based sign-in), and the unique account identifiers assigned to you by the relevant identity provider, including, as applicable, the Google account identifier and the Apple user identifier. We additionally generate and assign to your account a unique internal identifier for the purpose of distinguishing your account from other accounts within our systems. Where the identity provider makes available to us, and you have not restricted the disclosure of, your given name, family name, or both, we may collect and Process such name information.
We collect and Process the display name that you provide for presentation to yourself and to the partner with whom you are paired, the preferred language or locale setting that you select or that is inferred from your device configuration for the purpose of localizing the Service, and, where you elect to upload one, a profile photograph or avatar image, which is stored in our cloud object storage infrastructure. We additionally Process metadata associated with your profile, including timestamps recording when certain profile fields were last modified, for the purpose of enforcing reasonable rate limits on the alteration of such fields.
The App is designed to be used by two individuals who are paired together as a couple. To facilitate such pairing, we generate a short alphanumeric pairing code and associate it with your account; when your prospective partner enters that pairing code, we establish a bidirectional association between the two accounts and Process the resulting linkage as Personal Data relating to both individuals. As a consequence of pairing, certain Personal Data relating to you, including your display name and the Insights derived from calls in which you participate, becomes accessible to your paired partner, and certain Personal Data relating to your partner becomes accessible to you.
When you conduct a voice or video call through the App with recording enabled for both participants, we collect, generate, and process Call Content as described in Section 5. If either participant has disabled recording, the shared call is not recorded or sent for transcription or AI analysis. Call Content includes the microphone audio of each participant, the textual transcript derived from that audio (including the words spoken, the attribution of utterances to individual participants, and the temporal positioning of utterances within the call), and the Insights derived from that transcript. We additionally Process metadata relating to each call, including the identifiers of the participants, the timestamps marking the commencement and conclusion of the call and of individual recording segments, the type of the call, the status and outcome of the call, the durations and storage references of recording segments, and records of in-call interactions such as the dismissal or selection of conversational prompt cards presented during the call.
Where you elect to purchase a subscription or other paid feature, we Process data relating to the status and lifecycle of that subscription, including the date and time at which the subscription was first activated, the date and time of the most recent renewal, the date and time of any cancellation, the date and time of any expiration, and a flag indicating whether the subscription is presently active. Such subscription transactions are processed by the operator of the relevant mobile application distribution platform (namely the Apple App Store or Google Play) and their associated payment services. We do not collect, receive, store, or otherwise Process your payment card number, your bank account details, or any equivalent financial instrument data, all of which are handled exclusively by the aforementioned platform operators.
We collect and Process technical data relating to the device and software environment through which you access the Service, including your IP address and device time-zone setting, which we use to estimate whether you are located in the United States for the purposes of Section 6.1; the operating system and operating system version of your device, the model designation of your device, the unique token issued by the applicable push-notification transport for the purpose of delivering notifications to your device, a counter reflecting the number of undelivered or unread notifications, and diagnostic data relating to crashes, errors, exceptions, and performance characteristics of the App, which diagnostic data may include stack traces, the internal identifier associated with your account, and the version of the App in use at the time of the relevant event.
Where you communicate with us, including by means of electronic mail directed to our support address, we Process the contents of such communications together with any Personal Data that you elect to include therein, for the purposes of responding to your inquiry, providing support, and maintaining a record of our correspondence.
By reason of the inherently interpersonal nature of the Service, Personal Data that you provide or generate may relate not only to you but also to your paired partner and, to the extent that the substance of your calls references third parties, to other identifiable individuals. You acknowledge and agree that you bear responsibility for ensuring that you have an appropriate basis for any Personal Data relating to other individuals that you introduce into the Service.
We collect your declaration during onboarding that you are at least 18 years old and records of relevant notices, Terms acceptance, recording choices, and other required consents. Age declarations and IP/time-zone signals are indicators, not guarantees, of age or physical location. We use these records to apply Section 6.1, honor your choices, and demonstrate compliance.
If you choose to use the distance feature of the Service, and only after you grant the App permission to access the location services of your device, we collect the approximate location of your device. We request approximate rather than precise location and we reduce the coordinates to a precision of approximately one kilometer before they leave your device. We collect them while the App is open and, if you allow location access at all times (“Always” on iOS, “Allow all the time” on Android), occasionally in the background, including when the App is closed, so that the distance shown to you and your paired partner and on your home screen widget stays up to date. If you allow location access only while the App is in use, we do not collect location in the background. We store only the most recent such location for your account and do not keep a location history. We use it solely to calculate the approximate distance between you and your paired partner. Your paired partner receives only that distance, and never your location. You may change or withdraw the permission at any time in the settings of your device; if you withdraw it entirely, we delete the stored location the next time you open the App.
We collect Personal Data from the following sources: directly from you, when you provide it in the course of registering for, configuring, or using the Service; automatically, by means of the operation of the App and the Website, including the capture of Call Content and the collection of device and diagnostic data; from your paired partner, to the extent that your partner generates Personal Data that relates to you, including by participating in calls with you; and from third-party service providers, including identity providers that authenticate your sign-in and application stores that report the status of your subscription.
Recording is enabled by default, and either participant can turn it off in Settings for the whole shared call (Section 5.1). When recording is on, your call audio is sent to a speech-to-text provider during the call to produce a transcript, and that transcript together with participants’ first names is sent to an AI model provider to generate your Insights. The providers we currently use are listed in Section 7; they process this data on our behalf and are contractually prohibited from training their own models on it. We may also use call audio and transcripts ourselves to develop our products and services, as described in Section 6.1. Video is never recorded.
When both participants have recording enabled, their microphone audio is captured and stored as described in this Policy. Recording may be organized as separate participant audio segments. You can turn recording off in the App under Settings → Advanced (the setting is currently labelled “Help improve Cupie with your calls”). If either participant has turned it off, the shared call is not recorded and is not transmitted to our speech-to-text or AI model providers. Unrecorded calls remain available, but do not generate transcripts or new audio-based Insights and are not used for the purposes described in Section 6.1. A change to this setting applies to calls that start after the change is made.
This setting does not remove audio transport necessary to connect an unrecorded call between participants. It stops the additional recording and AI-processing paths described here.
For a recorded call, audio is transmitted to our speech-to-text provider while the call is taking place, rather than only after the call has been stored. Recorded audio may also be submitted for transcription after the call has ended. The provider processes the audio to produce a written transcript. The transcript may include spoken words, speaker attribution, timing, and language information and is stored in our cloud infrastructure subject to Section 10.
The transcript, together with participants’ first names, is submitted to an AI model provider, in some cases through a routing service, to generate Insights. The providers currently used are listed in Section 7. Some analytical outputs may be computed within our systems. Insights are stored with the relevant call record.
The Insights generated from your Call Content may include, without limitation: quantitative speaking statistics, including per-participant word counts, proportions of speaking time, measures of silence, and comparative percentile rankings; enumerations of the words most frequently uttered by each participant; selections of purportedly humorous or otherwise notable quotations attributed to each participant together with their temporal context; characterizations of each participant's personality, including trait-based mappings and narrative summaries; quantifications of conversational interruptions, including counts and a timeline of individual interruption events attributed to individual participants; relationship-oriented metrics, including assessments described in terms such as emotional intelligence, alignment of expressed affection, mutual respect, compatibility, and mutual understanding, in each case expressed as a score together with a comparative percentile ranking; and classifications described in terms of favorable and unfavorable behavioral indicators attributed to each participant. You acknowledge that such Insights constitute inferences and characterizations derived by automated means and may relate to intimate aspects of your conduct, disposition, and relationship.
Recording and AI-processing disclosures are provided through onboarding and these linked policies. There is not a separate consent screen before each call. Each participant acts on their own behalf when accepting the Terms and selecting whether recording remains enabled. You can disable recording in Settings before making or joining a call. Each participant’s choice applies to the whole shared call, and the resulting Insights from recorded calls are accessible to both participants.
Do not include someone in a recorded conversation without their knowledge and consent. We remain responsible for meeting our own legal obligations; user acceptance of the Terms or responsibility for others does not replace recording consent or other disclosures required by applicable law. Where additional notice or consent is required, we obtain it before the affected recording or processing occurs.
Call Content, comprising audio recordings, transcripts, and Insights, is stored within cloud infrastructure operated by our hosting and storage service providers, which infrastructure may be located in, and accessible from, jurisdictions outside your country of residence, including the United States.
We Process Personal Data for the following purposes and, where the GDPR or the UK GDPR is applicable, in reliance upon the following legal bases. We Process identity, account, profile, partner, and Call Content data for the purpose of providing the Service to you, including the core functionality of conducting calls and generating Insights, in reliance upon the necessity of such Processing for the performance of a contract to which you are party. We Process approximate location data for the purpose of showing you and your paired partner the approximate distance between you, in reliance upon your consent, which you give through the location permission of your device and may withdraw at any time. We Process device, technical, and diagnostic data, and we Process Personal Data for the purposes of securing the Service, preventing fraud and abuse, diagnosing and remedying defects, and improving the Service, in reliance upon our legitimate interests in operating, securing, and improving a reliable Service, save where such interests are overridden by your interests or fundamental rights and freedoms. We Process Personal Data to the extent necessary for the purpose of complying with legal obligations to which we are subject, in reliance upon the necessity of such Processing for compliance with a legal obligation. Where we rely upon your consent in respect of any particular Processing activity, you may withdraw that consent at any time, without affecting the lawfulness of Processing carried out prior to such withdrawal. We additionally Process Call Content for the purposes described in Section 6.1, which applies only to calls in which both participants were located in the United States.
Purpose. In addition to the purposes described in Section 6, we may use Call Content — namely call audio recordings and the transcripts derived from them — to improve our products and services and to develop new products, services, and features, including products and services other than Cupie. This may include the development, training, testing, evaluation, and improvement of artificial-intelligence and machine-learning models, including models designed to better understand natural spoken conversation. We carry out this work ourselves. Service providers may assist us only on our behalf, under contractual confidentiality, security, and use restrictions, and may not use Call Content to train their own models. We do not sell Call Content, and we do not use it to identify people by voice or to create voiceprints for identity verification.
De-identification. Before Call Content is used for the purposes described in this Section 6.1, we apply de-identification measures designed to separate that content from certain potentially identifying information. These measures include the removal of account identifiers, profile names, and associated call metadata, and the application of automated redaction designed to remove names and similar directly identifying details spoken during a call. These measures are designed to reduce the likelihood that Call Content can be associated with a particular individual, but no de-identification method is perfect.
United States only. This Section 6.1 applies only to calls for which we determine that both participants were located in the United States when the call took place. We make that determination using signals such as IP address and device time-zone settings. Calls for which we cannot make that determination are not used for these purposes.
Your choice. If you are a user of the Service in the United States, you may opt out of the use of your Call Content for the purposes described in this Section 6.1 at any time by turning off the setting described in Section 5.1 (Settings → Advanced). This is currently the same setting that controls recording, so turning it off also stops transcription and new audio-based Insights for your shared calls. Because calls involve two participants, if either participant has turned the setting off, Call Content from that call is not used for these purposes. Your opt-out applies to Call Content generated after you opt out.
Timing. This Section 6.1 applies to Call Content generated on or after 17 September 2026 and after both participants have been given notice of this use. Call Content generated before then is used for these purposes only if both participants separately and specifically agree.
Deletion. If you ask us to delete your call data (Section 10), the Call Content linked to your account is deleted and is not used for these purposes from then on. Call Content that has already been de-identified is no longer linked to your account, and we may be unable to identify or remove it. Opting out or deleting data does not reverse development or training that has already been completed.
We use the following providers to operate Cupie and process data on our behalf for the stated purposes, subject to contractual confidentiality, security, data-protection and restricted-use obligations:
Providers receiving call audio, transcripts or associated request data are contractually prohibited from using the data for their own model training.
We do not sell your Personal Data, and we do not share your Personal Data for purposes of cross-context behavioral advertising. We do not sell or license call audio or transcripts to third parties for their own model training. Service providers that handle this data must act on our behalf and may not use it for their own independent model training. We may disclose Personal Data to the service providers and underlying model/serving providers described in Section 7; to your paired partner, to the extent inherent in the operation of the Service; to professional advisers, auditors, and insurers; to a successor entity in connection with a merger, acquisition, reorganization, or sale of assets; and to governmental authorities, courts, or other third parties where we believe in good faith that such disclosure is necessary to comply with a legal obligation, to respond to lawful requests, or to protect the rights, property, or safety of the Company, our users, or others.
The service providers described in Section 7 may Process Personal Data in jurisdictions other than your jurisdiction of residence, including the United States. Where we transfer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction that has not been the subject of an adequacy decision, we rely upon appropriate safeguards for such transfers, which may include the Standard Contractual Clauses approved by the European Commission and, as applicable, the United Kingdom International Data Transfer Addendum.
Call audio and transcripts. We retain recorded call audio and transcripts for as long as reasonably necessary for the purposes described in this Policy, including generating Insights and, where Section 6.1 applies, developing our products and services. Retention depends on the purpose for which the data was collected, continuing account and feature needs, sensitivity, user choices, deletion requests, and applicable legal obligations. We periodically review the data we hold and delete it when it is no longer needed for a permitted purpose, subject to applicable legal retention requirements.
Previously collected recordings. Recordings made before the date set out in Section 6.1 remain stored for the purposes disclosed when they were collected. Retaining a recording does not by itself make it available for the purposes described in Section 6.1.
Insights. We retain the Insights shown in your account until account deletion, unless you request earlier deletion or applicable law requires it. Profile, account, pairing and other information is retained only for as long as needed to operate your account, fulfill disclosed purposes and meet applicable legal obligations.
Approximate location. We retain only the most recent approximate location for your account. We delete it when you withdraw the location permission, as described in Section 3.10, and when you delete your account. The distance calculated for you and your paired partner is deleted when you disconnect from your partner or when either account is deleted.
Account deletion. You may delete your account at any time using the account-deletion function in the App’s settings. Deleting your account removes your account and profile data and the transcripts and Insights associated with it, and ends the pairing. Audio recordings of past calls are not automatically deleted by the account-deletion function. To have them deleted, or to request deletion of call data without deleting your account, contact support@cupie.app, and we will give effect to your request subject to any overriding legal retention obligation. Section 6.1 explains how deletion affects Call Content that has already been de-identified.
Copies and backups. We apply deletion to relevant copies and direct service providers to do the same. Residual backup copies that cannot immediately be erased are removed through scheduled backup rotation and are not used for the purposes described in Section 6.1. Data held solely under a specific legal retention requirement is used only for that requirement. We may retain minimal records of notices, choices, and deletion actions as needed to honor your choices, demonstrate compliance, and meet legal obligations.
We implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, including the encryption of Personal Data in transit and the storage of Personal Data with established cloud-infrastructure providers. Notwithstanding the foregoing, no method of transmission over the internet and no method of electronic storage is perfectly secure, and we are therefore unable to guarantee the absolute security of Personal Data.
Subject to the conditions and limitations prescribed by applicable law, you may have the right to request access to the Personal Data that we Process concerning you, to request the rectification of inaccurate Personal Data, to request the erasure of your Personal Data, and to request that we provide you with a copy of certain of your Personal Data. If you are a user of the Service in the United States, you may additionally opt out of the use of your Call Content for the purposes described in Section 6.1 at any time, using the in-app setting described in that Section. You may contact support@cupie.app for help exercising these rights.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may additionally have the right to restrict our Processing of your Personal Data, the right to object to Processing carried out in reliance upon our legitimate interests, the right to data portability, the right to withdraw consent where Processing is based upon consent, and the right to lodge a complaint with a supervisory authority, in particular in the Member State or country of your habitual residence, place of work, or place of the alleged infringement.
If you are a resident of the State of California, you may have the right to know the categories and specific pieces of Personal Data we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties to whom Personal Data is disclosed; the right to request deletion of your Personal Data; the right to correct inaccurate Personal Data; and the right not to receive discriminatory treatment for the exercise of your rights. We do not sell or share Personal Data within the meaning of the CCPA.
You may exercise the rights described in this Section 12 by submitting a request to the contact address set out in Section 19. We may be required to verify your identity before giving effect to your request. You may be entitled to use an authorized agent to submit a request on your behalf, subject to our verification of the agent's authority.
Call audio, transcripts, and Insights may reveal sensitive information, such as information about health, sex life, sexual orientation, beliefs, or other intimate matters, and may be sensitive personal information under applicable law. We process this information to provide Cupie’s features, including Insights, and, subject to the de-identification measures and choices described in Section 6.1, for the purposes described in that Section. Where applicable law requires additional consent or restrictions for sensitive information, we obtain that consent or exclude the information from those purposes. We do not use this information to infer sensitive characteristics about you for advertising. We do not treat your use of Cupie, by itself, as consent to processing for which applicable law requires a separate consent.
The generation of Insights involves the automated analysis of your Call Content and the production of inferences, characterizations, and profiles concerning you and your relationship, as described in Section 5.4. Such automated analysis is undertaken for the purpose of providing the analytical features of the Service and does not produce legal effects concerning you or similarly significantly affect you. The Insights are provided for informational and entertainment purposes and ought not to be relied upon as professional advice of any kind.
The Service is intended for, and may be used only by, individuals who are at least eighteen (18) years of age. The Service is not directed to children, and we do not knowingly collect Personal Data from any individual under the age of eighteen. If we become aware that we have collected Personal Data from an individual under the age of eighteen, we will take reasonable steps to delete such Personal Data.
The Website does not deploy advertising cookies, analytics cookies, or third-party tracking technologies. A funnel subdomain associated with the Website performs a device-aware redirection to the appropriate application distribution platform by reference to the user-agent string transmitted by your browser; such redirection is performed transiently and the user-agent string is not retained for this purpose. The analytics and crash-reporting functionality described elsewhere in this Policy pertains to the App rather than to the Website.
The Service may contain links to, or interoperate with, third-party websites, applications, or services that are not operated or controlled by us. This Policy does not apply to such third-party websites, applications, or services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any such third party.
We may update this Policy from time to time. We will update the “Last updated” date and provide notice of material changes within the App or by other appropriate means before the changes take effect. The notice will explain the material changes, including any new use of call audio or transcripts for AI model training, and how to exercise available choices. We will obtain consent where required by applicable law. Continued use of the Service after an update does not waive your privacy rights or authorize retroactive use of older calls for new purposes. Section 6.1 describes when Call Content generated before an update may be used for the purposes described in that Section.
People Make Things, Inc. is the operator of Cupie and the Controller responsible for the processing described in this Policy. Contact us at:
2261 Market Street, STE 35679
San Francisco, CA 94114, United States of America
Electronic mail: support@cupie.app
This Policy, and any non-contractual obligations arising out of or in connection with it, are governed by the laws of the State of California, United States of America, without regard to its conflict-of-laws principles, save to the extent that the mandatory data protection laws of your jurisdiction of residence apply.