yaplab
Privacy Policy
Last updated: 26 September 2026
yaplab is an iOS app for planning, recording and editing short-form videos. This policy explains what the app does with your data. It is written to be read, not to be skimmed past — the short version is that your recordings, scripts and projects stay on your iPhone, and the only data that leaves the device is what is needed to run a feature you asked for.
We run no user accounts, no analytics or tracking SDKs, and no advertising. We do not sell or rent your data, and we do not store your videos, audio, scripts or Instagram content on any server we control.
1. Data stored on your device
The following is created and kept locally on your iPhone, in the app's own storage or in the iOS Keychain. It is not uploaded to us:
- Video recordings, audio takes and rendered exports
- Ideas, scripts, teleprompter drafts, transcripts and caption timings
- Content plans, notes and reusable snippets
- Your OpenAI API key (iOS Keychain)
- Your Instagram access token, if you connect Instagram (iOS Keychain)
Deleting the app from your iPhone removes this data. See Data deletion.
2. Camera, video and face data
yaplab records video of you speaking, so recordings naturally show your face. We want to be exact about what that does and does not mean.
yaplab does not collect face data. The app performs no face detection, face recognition, face tracking or facial analysis of any kind. It does not create, derive, store or transmit a faceprint, face template, face mesh, face landmarks or any other biometric identifier, and it cannot identify anyone from a recording. It does not use ARKit, the Vision framework or any face-related API, and it never sends video frames off the device.
What the camera produces. A recording is an ordinary video file — picture and sound — written to the app's own storage on your iPhone. It is used only to let you watch your takes, edit them, add captions and export the result. It stays on the device. It is never uploaded to us, never sent to OpenAI, and never shared with anyone, unless you yourself export it to your photo library or hand it to another app through the iOS share sheet.
Cinematic mode. On iPhones that support it, you can record in Cinematic mode for a shallow depth-of-field look. In that mode iOS itself — not yaplab — separates the subject from the background and writes a depth (disparity) track and focus metadata into the same video file. yaplab only asks iOS to enable the mode and later asks Apple's Cinematic framework to render the blur for playback and export. The app never receives or inspects face geometry, and the depth data is part of your video file on your device: it is not biometric identification, it is not sent anywhere, and it is deleted with the recording.
Retention and deletion. Recordings, and any depth data inside them, are kept on your device until you delete the take, reset the app under Profile → Reset all data, or delete the app. There is no server-side copy to delete, and no retention period on our side, because we never receive them.
What does leave the device from a recording is the audio only: yaplab extracts the audio track to a small 16 kHz mono file and sends that to OpenAI for transcription, once you have granted the permission described in the next section. The picture never leaves.
3. Data sent to third parties
OpenAI — the AI features
yaplab's AI features — transcription, scriptwriting, titles, hooks and coaching — are provided by OpenAI, L.L.C. (United States). They do not run on your device, so using them means sending OpenAI the content they work on.
Nothing is sent to OpenAI until you allow it. The first time an AI feature would send anything, the app shows a disclosure naming exactly what would be sent, to whom and by which route, and asks for your permission. If you decline, no AI request is made — recording, the teleprompter, takes, the fix-a-line editor and export all keep working. You can withdraw permission at any time under Profile → Data & Privacy, and from that moment nothing further is sent.
What is sent, and why:
| Data | How it is collected | Why it is sent |
|---|---|---|
| Audio from your recordings (the audio track only — never the video file) | Recorded by you in the app, with the microphone permission you granted | Speech-to-text transcription, so your words become editable text and timed captions |
| Idea notes, transcripts and script text | Written or dictated by you in the app | Generating and refining scripts, titles, hooks, on-screen text and coaching feedback |
| A compact summary of your own Instagram posts (captions, view and share counts, dates) | Read from the Meta Graph API for your own account, only if you connected Instagram | So content suggestions can build on which of your own posts performed well |
How it reaches OpenAI. There are two routes, and the app tells you which one you are on:
- Included allowance. Your first 25 AI actions are relayed through our own backend, which holds our OpenAI key server-side and forwards the request to OpenAI. The relay is stateless: it stores no copy of your audio or text, and keeps no database.
- Your own API key. Once you add an OpenAI API key in the app, requests go directly from your device to OpenAI, billed to your own OpenAI account. Your key is kept in the iOS Keychain and never reaches our servers.
OpenAI processes this data as our processor (included allowance) or as your own provider (your key), under OpenAI's privacy policy and the OpenAI API terms. We have satisfied ourselves that this provides protection equivalent to the standard set out in this policy: API data is not used to train OpenAI's models, is retained by OpenAI for up to 30 days for abuse monitoring and then deleted, and transfers out of the EU/EEA are covered by the Standard Contractual Clauses in OpenAI's data processing addendum. OpenAI does not receive any name, email address or account identifier from yaplab, because the app has no accounts.
Meta / Instagram — optional
Connecting Instagram is optional; the rest of the app works without it. If you connect, you log in with Instagram (or, if you prefer, through Facebook) and grant access to your own Instagram professional account. The app then reads, on your device:
- Your professional account's profile basics (and, only if you log in through Facebook, the list of Facebook Pages you manage, to find the linked Instagram account)
- Your own published media (captions, thumbnails, permalinks, timestamps, like and comment counts)
- Insights for your own posts and account (for example views and shares)
- Comments on your own posts, where that permission has been granted
This data is fetched from Meta's Instagram APIs straight to your device and stored there. We use it only to show you your own statistics inside the app and, if you have allowed AI use, to inform the AI suggestions described above. We do not share it with anyone else, and we do not keep a copy on our servers. You can disconnect at any time in the app under Settings, which deletes the stored token.
Our backend
yaplab uses a small stateless backend at talking-head-lemon.vercel.app for three
things. It has no database and stores no user content.
| Endpoint | What it does | What it keeps |
|---|---|---|
| AI relay (included allowance only) | Forwards a transcription or text request to OpenAI using our own OpenAI key, so the key never has to ship inside the app, and passes OpenAI's answer straight back. Used only while you are on the included allowance and only after you have allowed AI use; once you add your own OpenAI key the app bypasses it entirely. | Nothing — the audio and text are held in memory for the length of the request and are never written to disk or to any database |
| Instagram token exchange | Swaps the Instagram or Facebook login code for a long-lived token, so the Meta app secret stays off the device. The token is passed straight back to your app. | Nothing |
| Error alerts | If an AI or network call fails, the app may send the error message, HTTP status code, app version, build number, bundle identifier and a short technical context, which is emailed to the developer so the bug can be fixed. Rate-limited to one report per error type per 15 minutes. | Nothing beyond the alert email |
Error reports do not contain your videos, audio, scripts or Instagram content. Requests are served by Vercel, whose infrastructure logs may briefly retain standard request metadata such as IP address; email delivery is handled by Resend.
Apple
The app uses Apple's speech recognition to follow your script while you practise, and Apple's photo library API to save a finished video when you ask it to. This is handled by iOS under Apple's privacy policy. yaplab requests add-only access to your photo library and cannot read your existing photos.
4. Permissions the app asks for
- Camera — to record video
- Microphone — to record audio
- Speech recognition — to follow your script during practice and time captions
- Photos (add only) — to save a finished export
- Notifications — optional reminders you enable yourself
Each can be revoked at any time in iOS Settings. Separately from these, sending content to OpenAI requires the in-app permission described in section 3, which you grant when first asked and can withdraw at any time under Profile → Data & Privacy.
5. Legal basis and purpose
We process the limited data described above to provide the features you request (performance of a contract) and, for error reports, to keep the app working (legitimate interest). Sending your audio and text to OpenAI rests on the separate permission you give in the app (consent), which you can withdraw at any time under Profile → Data & Privacy without affecting anything processed before you withdrew it. Instagram data is used only for the purposes described in section 3 and is never used for advertising, profiling of other people, or resale.
6. Retention
Content stays on your device until you delete it or delete the app. Your Instagram token is kept until you disconnect, or until it expires (60 days, renewed while you keep using the feature). Our backend retains nothing; content passed through the AI relay exists only for the duration of the request. OpenAI retains API data for up to 30 days for abuse monitoring, then deletes it. Error alert emails are kept by the developer only as long as needed to fix the underlying bug.
7. Your rights
Because your data lives on your device, you control it directly: you can view, edit and delete everything in the app. For anything else — access, correction, erasure, objection, or a complaint — write to calle@plan8.se. EU/EEA users may also lodge a complaint with their national data protection authority.
8. Children
yaplab is not directed at children under 13, and we do not knowingly process their data.
9. Changes
If this policy changes materially, the updated version will be published here with a new date.
10. Data controller and contact
The controller for the limited processing described above is:
Carl Stenqvist AB
Swedish company registration number 556706-9280
Heleneborgsgatan 3, 117 31 Stockholm, Sweden
Email: calle@plan8.se
yaplab is developed and published by Carl Stenqvist AB. Write to the address above with any question about this policy or about your data.