Privacy Policy

Last updated: July 26, 2026

This Privacy Policy is separate from our Terms & Conditions. Both documents apply to your use of Horse's Mouth.

1. Introduction

Horse's Mouth ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Service").

By using the Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

Information You Provide

  • Account information (name, email address, password)
  • Phone number linked to your account via the sync profile feature (stored as a permanent account credential, separate from the one-time OTP verification flow)
  • Phone numbers of people you invite to record stories
  • Audio recordings you create or that are shared with you
  • Story titles, descriptions, tags, collections, audio duration, file size in bytes, and storyteller name you provide
  • Payment information (processed securely through Apple In-App Purchases or Stripe)
  • Reports you file against other users or stories, including the reason and any additional details you provide

Information Collected Automatically

  • Device information (device type, operating system, device identifiers)
  • Usage data (features used, interactions with the Service)
  • Storage usage information
  • Subscription and purchase data (transaction history, subscription status, processed through Apple's App Store and RevenueCat)
  • Block relationships — when you block another user, both user IDs and the timestamp of the block are stored

Data Stored On Your Device

  • The mobile app stores an authentication sync token in your device's secure encrypted storage (via Expo SecureStore / iOS Secure Enclave). This token is used to authenticate your session without transmitting your password. No biometric data is stored — Face ID and Touch ID are handled entirely by your device's operating system.

Data Collected from Non-Account Holders (Guest Recorders)

  • If someone records a story via a web link without creating an account ("guest recorder"), their audio file, title, duration, and file size are stored on our servers and linked to the associated story request. No account is created, but the recording is retained as described in Section 11.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process payments and manage subscriptions
  • Store and organize your audio stories
  • Send SMS verification codes for account setup
  • Provide customer support
  • Review and act on user reports for moderation purposes
  • Manage block relationships between users to enforce privacy preferences
  • Improve and develop new features

4. Phone Number Verification (SMS)

Horse's Mouth sends one-time verification codes (OTP) via SMS to confirm your phone number during account setup. By entering your phone number and tapping "Verify," you explicitly consent to receive a one-time passcode via SMS from Horse's Mouth.

  • Message frequency: One-time verification codes only, sent when you request them. We do not send marketing messages, recurring notifications, story request messages, or any other unsolicited messages.
  • Message and data rates may apply depending on your mobile carrier and plan.
  • Your mobile phone number is never shared with third parties or affiliates for marketing or promotional purposes. Phone numbers are shared with Twilio solely to deliver the verification code you requested.
  • Reply STOP to any message to unsubscribe. Reply HELP for help.

For full details on SMS consent and opt-out, see our SMS Consent & Messaging Policy.

5. Contacts Access

The app may request access to your device's contact list (via the Expo Contacts SDK) to allow you to easily select a recipient for a story request. When you grant contacts access:

  • Contact data is read locally on your device only to display the contact picker within the app.
  • Only the phone number of the specific contact you select is stored as part of the story request record on our server.
  • Story request messages are sent directly from your device using your native Messages app — not through our servers or Twilio.
  • We do not upload, store, or sync your full contact list. No contact data other than the selected phone number leaves your device.
  • The Expo Contacts SDK processes contact data entirely on-device and does not transmit any data to Expo's servers.

6. Data Storage, Security & On-Device Storage

Your audio recordings and personal data are stored securely using industry-standard encryption and security practices. We use Cloudflare R2 for secure cloud storage of audio files and Neon (PostgreSQL) for all structured account, story, and social data.

Audio recordings can only be accessed by authorized users within the app. We do not share your recordings with third parties.

The mobile app stores an encrypted authentication token in your device's secure storage (Expo SecureStore, backed by the iOS Secure Enclave on supported devices). This token is used to maintain your session. It is stored only on your device and is not transmitted to any third party.

7. Third-Party Services & SDKs

We use the following third-party services and software development kits (SDKs) to operate the Service. Each third party is contractually or operationally required to provide protections for user data that are consistent with this Privacy Policy and applicable data protection laws. We only share the minimum data necessary for each service to function.

  • Apple App Store / StoreKit — For processing in-app subscription purchases. Apple receives your Apple ID and payment information to complete transactions. Apple's privacy policy: apple.com/legal/privacy
  • RevenueCat — For managing in-app subscriptions and purchase verification. RevenueCat receives device identifiers, purchase/transaction history, subscription status, and app usage data. This data is used solely to process, verify, and manage your subscriptions. Privacy policy: revenuecat.com/privacy
  • Stripe — For processing web-based subscription payments. Stripe receives your email address and payment card details to complete transactions securely. Privacy policy: stripe.com/privacy
  • Twilio — For sending one-time verification codes (OTP) via SMS during account setup. Twilio receives your phone number and the verification code solely for delivering the SMS you requested. Twilio is not used for story requests, reminders, or any other messaging. Privacy policy: twilio.com/legal/privacy
  • Cloudflare (R2) — For secure cloud storage of audio recordings. Cloudflare receives and stores your audio files. No personally identifiable information is shared with Cloudflare beyond the file data. Privacy policy: cloudflare.com/privacypolicy
  • Neon (PostgreSQL Database) — For securely storing account information, story metadata, request records, and subscription data. Neon hosts our database infrastructure and adheres to SOC 2 compliance standards. Privacy policy: neon.tech/privacy-policy
  • Expo SDK (Contacts, Notifications) — Expo provides development tools and SDKs for building the mobile application. The Expo Contacts SDK processes contact data entirely on your device and does not transmit data to Expo's servers. The Expo Notifications SDK is used for local on-device notifications (e.g., reminders). No personal data is transmitted to Expo's servers for either of these features. Privacy policy: expo.dev/privacy
  • Resend — For sending transactional emails such as password reset links and account verification emails. Resend receives only your email address and the email content necessary to deliver the message. No other personal data is shared with Resend. Privacy policy: resend.com/legal/privacy-policy

All third-party services listed above are required to provide protections for your personal data that are consistent with this Privacy Policy. We conduct periodic reviews to ensure these services maintain adequate data protection standards.

8. Data We Do NOT Collect

We want to be transparent about the limits of our data collection. Horse's Mouth does not:

  • Sell, rent, or trade your personal information to any third party
  • Use third-party advertising networks or serve ads within the app
  • Collect or track your precise geographic location (GPS)
  • Access your camera or photo library (the app is audio-only)
  • Use tracking technologies such as advertising identifiers (IDFA) for cross-app tracking
  • Collect browsing history, search history, or activity outside of the app
  • Collect biometric data (Face ID / Touch ID authentication is handled entirely by your device's operating system and no biometric data is transmitted to us)
  • Upload, store, or sync your full contact list — only the phone number you explicitly select is transmitted

9. Advertising & Analytics

Horse's Mouth does not display advertisements and does not integrate with any advertising networks or demand-side platforms. We do not use third-party analytics SDKs (such as Google Analytics, Firebase Analytics, Mixpanel, or Amplitude) to track user behavior.

We may collect basic, anonymized usage metrics (such as feature usage counts and error rates) solely to improve the Service. These metrics cannot be used to identify individual users.

10. Admin Access to User Data

Horse's Mouth operates an internal admin panel that authorized staff use for moderation, customer support, and operational purposes. Through this panel, authorized team members may access:

  • User account information (name, email, phone number, subscription status)
  • Story metadata (titles, descriptions, file sizes, storyteller names)
  • Request records and request history
  • Storage usage data
  • Reports filed by or about users

Access to the admin panel is restricted to authorized personnel and protected by authentication. Admin access is used only for legitimate operational purposes — including safety, moderation, and resolving support requests — and is not used to listen to audio recordings without legal compulsion or explicit user consent.

11. Data Retention & Deletion

We retain your audio recordings and account data for as long as your account is active. If you delete your account:

  • Your personal data, audio recordings you own, story metadata, tags, collections, and request history will be permanently deleted within 30 days.
  • Audio files stored on Cloudflare R2 will be removed.
  • Subscription data managed by RevenueCat and Apple will be disassociated from your account.
  • Stories shared with others: If you recorded a story and shared it to another user's library, that story may remain accessible to the recipient after your account is deleted. The audio file and metadata may be retained to preserve the recipient's access. To request removal, contact us before deleting your account.
  • Guest recordings: Audio submitted by non-account holders (guest recorders) may be retained for as long as the receiving account holder's account is active, or until the story is deleted by the account holder. Guests may request removal by contacting us at headhorse@horsesmouthapp.com.
  • Report records: Reports you filed or that were filed about you may be retained beyond the 30-day window for safety and legal compliance purposes.
  • We may retain anonymized, aggregated data that cannot be used to identify you for analytical purposes.
  • Data required to be retained for legal, regulatory, or compliance purposes will be kept for the minimum period required by law.

12. Your Rights & How to Exercise Them

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your account and all associated data
  • Export your data upon request
  • Revoke consent for data processing at any time by deleting your account or contacting us
  • Opt out of SMS messages by replying STOP to any message

To exercise any of these rights, you can:

We will respond to all valid requests within 30 days.

13. Children's Privacy

The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided us with personal information, we will delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us at: