Privacy
CaveSpeak Privacy Policy
Effective July 19, 2026 · Operated by Master of AI LLC
This policy explains how CaveSpeak handles information in its iOS app, membership verification, safety reports, support, and App Store billing.
Information we handle
Account and identity
- A randomly generated device identifier for an automatically created trial account.
- Your Sign in with Apple identifier and, if Apple supplies them, your verified email and name.
- The verified Google email returned when you use Google sign-in.
- If you explicitly link FatherPhi benefits, the shared Master of AI identity service handles Discord authorization, the Discord account binding, managed-role verification outcome, entitlement tier, and verification timestamps. CaveSpeak receives only its scoped entitlement result, not your Discord messages or role list.
Prompts, reports, and support
Text prompts and recent context are sent to CaveSpeak and an AI provider to generate a response. When a question may require current, recent, location-dependent, or uncertain information, the AI provider may select web search and return source attribution. Durable iOS chat history remains on your device, and operational logs are designed not to contain raw chat content or search terms. For typed app and Home Screen widget questions, CaveSpeak temporarily stores bounded recent context and the answer for up to 24 hours so work can finish if you leave the app. Completion notifications use generic text and contain neither the question nor the answer.
When the structured answer planner determines that a request needs nearby results, CaveSpeak may ask for while-in-use location permission. If you allow it, the app requests one approximate location, rounds it before transmission, and uses it only for that answer. CaveSpeak does not monitor location in the background. If you decline, you can provide a city or ZIP code instead.
If you report an AI response, CaveSpeak stores the selected response and a short conversation snapshot for human investigation. Support requests contain the details you choose to provide. In-app refund-review intake is not enabled in version 1.
Voice
CaveSpeak uses Apple speech frameworks. CaveSpeak does not intentionally store raw microphone audio or send it to CaveSpeak servers. Depending on device support, settings, language, and availability, Apple may process recognition on-device or through Apple services. The transcript is handled like typed text.
Usage, security, and billing
We process answer counts, entitlement state, request timing, error categories, IP-derived rate-limit keys, and similar data to operate and protect the service. If you allow answer notifications, we store an APNs device token associated with your CaveSpeak account. For App Store billing, we receive signed transaction identifiers, product, price/currency metadata, coverage dates, subscription state, offer state, and revocation/refund state. Apple processes payment credentials; CaveSpeak does not receive or store full card numbers.
How we use information
- Authenticate accounts, synchronize entitlements, and meter introductory-trial and subscription allowances.
- Generate and deliver AI responses.
- Finish typed questions after the app backgrounds and notify you when the answer is ready.
- Use an approximate, request-scoped location to answer a nearby-results question when you authorize it.
- Verify an eligible FatherPhi membership through an explicit Discord link and provide the associated CaveSpeak benefit.
- Investigate safety reports, enforce our Terms, and prevent abuse or fraud.
- Respond to privacy, support, and refund-review requests.
Providers and sharing
Providers may include Apple for sign-in, speech services, device functionality, push-notification delivery, and StoreKit billing; Google for verified identity and, when selected by the AI provider, Search grounding; Discord and the shared Master of AI identity service when you explicitly link FatherPhi benefits; a configurable AI provider such as Google Gemini, Anthropic, or an OpenAI-compatible provider; Vercel; and Google Cloud. We disclose only what a provider needs for its function and may disclose information when required by law or needed to protect people or the service.
Retention
- On-device chat remains until you delete it, delete the CaveSpeak account, or remove the app and its data.
- Typed answer-job content and any approximate location attached to it expire within 24 hours by default and are not retained as CaveSpeak conversation or location history. Streaming voice location is held only for the active request. A reported snapshot is retained up to 180 days by default, then its content is removed while limited decision/security metadata may remain.
- APNs device tokens remain while notifications and the account are active; invalid tokens are disabled, and account deletion removes active tokens and pending answer jobs.
- Account and entitlement identifiers remain while active, then are deleted or deidentified except limited transaction, safety, fraud-prevention, or legal records.
- Billing/refund records may remain for applicable tax, accounting, dispute, and provider-reconciliation periods.
Your choices and deletion
You choose Google or Apple to establish a durable CaveSpeak account before subscribing. FatherPhi benefits are separate and optional: you choose whether to connect Discord in onboarding or Settings. The shared identity service verifies exact managed roles in the Masters of AI Discord server and returns only CaveSpeak's entitlement outcome. Ordinary Apple/Google sign-in and matching email addresses do not grant the benefit. After a successful link, server-side reverification normally occurs without asking you to authorize Discord again.
CaveSpeak asks for notification permission when you first submit a typed question. You can decline or disable notifications in iOS Settings and still retrieve pending answers by opening the app. Completion alerts are suppressed while CaveSpeak is foregrounded.
CaveSpeak asks for while-in-use location only after a question actually needs nearby results. You can decline and provide a city or ZIP code instead, or disable location later in iOS Settings. CaveSpeak does not request background location access.
Use Settings → Account → Delete CaveSpeak Account to delete the CaveSpeak profile, its client-scoped shared-identity binding and pending CaveSpeak authorization state, and local chat data. The shared Apple/Google identity, Discord proof, and accounts in other Master of AI services remain so CaveSpeak does not silently erase unrelated app data. If you used Sign in with Apple, follow the displayed Apple Account settings path after deletion to revoke CaveSpeak's Apple authorization. Email us to request access, correction, portability, or deletion across every Master of AI service or of a retained record.
Deleting an account does not automatically cancel Apple billing; manage App Store subscriptions through Apple.
Security, children, and international processing
We use encrypted transport, scoped credentials, rate limits, access controls, database isolation, and least-privilege connections. No system is completely secure; do not submit secrets or highly sensitive information to an AI chat.
CaveSpeak is not directed to children under 13. Providers may process information in the United States and other countries under appropriate contractual and technical safeguards.
Contact and changes
We may update this policy as CaveSpeak changes. We will change the effective date and provide additional notice when legally required.