Orate

Privacy

Your scripts never
leave your phone.

Not as a promise we could quietly change — there is no account, no sign-in and no server of ours for them to be sent to. Everything below describes what the app actually does, and each claim is something you can check.

Last updated 26 September 2026

The short version

Four things can leave, and you control all four.

Everything Orate sends, and what has to be true first.
What Only if Where it goes
Crash reports and errors Unless you turn Share anonymous diagnostics off — or, in the UK and Europe, only once you turn it on Firebase Crashlytics
Which screens and buttons were used Unless you turn Share anonymous diagnostics off — or, in the UK and Europe, only once you turn it on Google Analytics for Firebase, and PostHog
A notification address for this install You allow notifications Firebase Cloud Messaging
Your answer if you use the feedback sheet, and anything you type with it You answer it and press Send Firebase Realtime Database
A one-off attribution token, on iPhone only You have diagnostics on, and only to learn whether an Apple Search Ads campaign brought you here Apple
Nothing else — —

Refuse all three and the app still works completely: the prompter, recording, saving to your gallery and every setting are unaffected. None of them is a condition of using Orate.

What stays

Your writing and your video.

Scripts

Everything you write or paste stays in Orate's own storage on the device. It is never uploaded, never included in a crash report, and never attached to an analytics event.

That last one is enforced rather than intended: the internal type an event can carry is a closed set of strings, numbers and true/false flags chosen from a fixed list, so there is no code path by which a script, a filename or anything you typed could become part of one.

Recordings

Video and audio stay in Orate's own storage until you save or share them yourself. Saving copies a file to your photo library or gallery; sharing hands it to whichever app you pick. Neither passes through us.

Everything you set

Text size, reading window, pace, mirroring, appearance, language and recording quality are stored on the device only. There is nothing to sync because there is no account to sync to.

It works with the network off

Writing, prompting, recording, saving and sharing all work in airplane mode. If Orate ever appears to need a connection for one of those, that is a bug.

The two switches

Separate, because they are different questions.

Share anonymous diagnostics — on unless you turn it off, and off until you turn it on in the UK and Europe

In Settings. It covers two things together, because both are measurement and neither is something you asked for: crash reports, and a record of which screens and controls were used.

The events are things like “a recording started”, “a take was saved”, “the upgrade screen was opened”. They carry the app version, the platform, the interface language, the device model, whether the install has Pro and which plan if so, what you said you were filming if you answered that question during setup, and on Android where the install came from if a link said so — and nothing else. The same handful are also set once as a profile rather than repeated on every event, which is the same facts and not more of them.

Where it starts depends on where you are. In the UK, the European Economic Area and Switzerland it starts off, and nothing is collected until you turn it on. Everywhere else it starts on and you can turn it off. That is the law being different in those places rather than us thinking about you differently: there, measurement needs your permission first. We read your device's region setting to tell, which is a setting and not your location — nothing about where you are is collected or sent to work this out.

Turning it off stops collection at the source, not just in our own code: the underlying analytics and crash libraries are switched off in the app's own configuration files, before any of our code runs, and only this switch turns them on.

Notifications — only if you allow them

Orate asks after your first recording, never at launch. Most of what it sends is local and never leaves the device: a reminder you set yourself, an export finishing, a warning that storage is nearly full.

Allowing notifications also registers this install with Google's notification service, which issues an address for it. That address is what makes an occasional announcement possible. It identifies the installation, not you, and there is nothing on our side to join it to.

Revoke permission and the address is deleted rather than left behind. On Android you can also mute announcements on their own and keep your reminders, because they are separate notification channels.

Feedback — only what you answer, and never who you are

Once, after you make your first script, Orate asks whether it is working for you. Two buttons, and an optional box to say more. Nothing is sent unless you answer it and press Send, which is why it sits behind neither of the switches above — answering is the permission, and hiding it behind the diagnostics switch would mean somebody who declined measurement could not tell us the app was broken.

What arrives is your answer, the words you typed if you typed any, the app and OS version, your device model, the language the app is in, whether you have Premium, and how many scripts and videos you have. That is the whole list. Nothing in it identifies you — no account, no install code, nothing that joins your answer to anything else, including to the analytics above. Your scripts and your recordings are never attached.

The honest consequence: we cannot reply to feedback sent this way, and we cannot find your answer again to delete it, because there is nothing in it to look you up by. If you want a reply, use the feedback option in Settings, which opens an email you send yourself.

That email is a draft in your own mail app, and nothing goes until you press Send there. Below the space to write, it lists what we would otherwise have to ask: the app and OS version, your device model and language, whether you have Premium and which plan, how many scripts and videos you have, what your camera can record and what it is set to, free storage, whether the phone is hot or saving battery, your screen size, and on Android how you installed the app and your mobile carrier. If diagnostics are on, it also carries a Support ID — the anonymous code your diagnostics are filed under, so we can look at what happened on your phone. It is only there when diagnostics are on, and you can delete it, or any other line, before you send. Your scripts and recordings are never attached.

What announcements are segmented by

Two things, both of which your device declares for itself: your app language, and whether this install has Pro. Nothing is uploaded to make that work, and there is no list of devices anywhere — a message is addressed to a group, not to anyone in particular.

Never

Things Orate does not do.

No account, and no identity

There is no sign-up, no login and no profile. We never set a user identifier with any third party, and we never tell any of them who you are. Each service holds its own per-installation id — and because there is no account and no server of ours, there is nowhere those ids could be joined together or to a person.

No tracking, and no advertising

No advertising identifier is read, no data is shared with advertisers or data brokers, and nothing is used to follow you across other apps or websites. There are no ads in Orate. This is why iOS never shows you an app-tracking prompt for it: there is nothing to ask about.

Nothing is sold

We do not sell or rent anything about you to anyone. There is no data to sell.

No payment details

Purchases are handled entirely by the App Store or Google Play. We never see your card, your address or your store account, and there is no receipt server here — Orate asks the store whether this install has Pro and gets back yes or no.

Details

Who else is involved, and for how long.

Service providers

Google, through Firebase, provides crash reporting, analytics, notification delivery, and the database feedback is stored in. They process that data on our behalf and receive nothing else.

PostHog receives the same usage events as the analytics above, and only those — the same list, behind the same switch, with the same things left out. We use two because they answer different questions well, not because either gets more. Google does see slightly more, and it is not a different kind of thing: its software records the first open and the start of each session by itself and gives us no way to stop it, and two events are sent to it under a second name as well so its own reports can count them. Same events, same list above. Their servers are in the United States. While diagnostics are off the app does not start their software at all — not a switched-off copy of it, none of it — so an install that turns diagnostics off, or that has not yet turned them on in the UK and Europe, sends them nothing and is not known to them.

Apple also answers one question, on iPhone only: whether an Apple Search Ads campaign is what brought you here. The app hands Apple a token Apple itself issued, once per install, and keeps only the campaign number that comes back — not the keyword, not the ad, not the country. It happens only while diagnostics are on, there is no advertising identifier involved and no tracking permission prompt, because this is Apple asking about its own ads rather than anyone following you between apps.

Apple and Google also process purchases as the stores you bought through, under their own privacy policies rather than this one.

Vercel hosts this website and counts its page views, Google Analytics records where visits to it came from, and Ahrefs measures which searches and links bring them. All three are the site rather than the app, and they are the next answer below.

This website, as opposed to the app

Everything above describes the app. This site counts page views, through Vercel Web Analytics: the page you opened, the link you arrived from, a rough country and city, and your device type, browser and operating system. It sets no cookies and stores nothing on your device, and it cannot see anything you type.

The theme switch in the header remembers a choice of Light or Dark in your browser’s local storage, so the next page opens the same way. It is written only when you press one of them, clearing this site’s data in your browser removes it, and it is never sent anywhere — it is a setting, not an identifier. Until you press either, the site follows your device.

This site does ask about cookies, and the app never will. If you accept the banner, PostHog sets a cookie so we can tell whether the same person came back — which is the only way to know whether a visit here turned into an install. Decline, or simply ignore it, and PostHog is never loaded: no script is requested, so there is nothing to opt out of afterwards. The site still counts visits either way.

Visitors are counted by a hash of the request that Vercel discards after 24 hours, so there is no identifier to follow you with and nothing that outlives a day. None of it reaches the app, and none of the app's switches apply to it.

The site also uses Google Analytics, which tells us where visits came from — a search, a link, a post somewhere — and which of the two store buttons gets clicked. Until you accept the banner it runs without cookies: every kind of storage is refused, nothing is written to your device, and no identifier is kept for you. Accepting lets it keep one, for the same reason PostHog does. The advertising categories stay refused whatever you choose — there are no ads here and nothing to build an audience for.

Ahrefs Web Analytics counts visits alongside the backlink and keyword data we already read there. It records the page, the referring site, a rough country, your device and browser, and which links on the page get clicked. It sets no cookies and does not fingerprint your browser, which is why it sits outside the choice the banner offers.

Vercel and Ahrefs are not part of that choice, because neither sets a cookie whatever you press. We ask about the two that do, and not about the two that don't.

If your browser sends Do Not Track or Global Privacy Control, neither the Google Analytics script nor the cookie banner is loaded at all — you have already answered the question it would ask, and asking again would be hoping for a different answer. Neither signal is legally binding in most places, which is rather the point of honouring it.

Vercel and Ahrefs count the visit either way, and it is worth saying so rather than letting the paragraph above imply otherwise. Neither can be asked not to: their scripts have no such setting, and the only way to honour the signal would be to not load them at all, which would leave the site with no way to tell whether anything written here is read. Neither one sets a cookie or builds an identifier, so what they keep is a count of pages and where visits came from — not a record of a person.

How long anything is kept

Crash reports and analytics events expire on Firebase's own retention schedule. Turning the diagnostics switch off stops any further collection immediately. The notification address is deleted when you revoke permission, and expires by itself if the app is removed. Feedback is kept while it is useful to us and cannot be deleted on request, because nothing in it says who sent it — the same absence that makes it anonymous makes it unfindable.

Your choices, and how to use them

Turn off Share anonymous diagnostics in Settings to stop analytics and crash reporting. Revoke notification permission in your phone's settings to delete the notification address. The feedback sheet is asked once and never again; closing it without answering sends nothing. Delete the app to remove everything held on the device, including every script and recording — those are on the device, so uninstalling is what deletes them, and it cannot be undone.

If you want to ask us anything about the above, or make a request about data held about an install, write to contact@planifyapps.com. Please say which platform you are on. Bear in mind that with no account we have no way to identify which records are yours, which is a limit of having collected so little rather than a refusal.

Children

Orate is a general-purpose tool and is not directed at children. It collects nothing that could identify anyone of any age.

Changes to this page

If what the app sends ever changes, this page changes in the same release rather than afterwards, and the date at the top moves. The store listings carry their own summaries of the same facts, and all three are kept in step deliberately.