1. Who is responsible
DevPhrase is an English technical-interview speaking practice service operated by Zhao Heng, an individual developer based in mainland China. This policy applies to the DevPhrase mobile app, its training service, and this website. You can contact us at support@devphrase.com.
2. Who may use DevPhrase
DevPhrase is for adults aged 18 or older and is not directed to children. We do not offer a parental-consent path. The app may use an available platform age-eligibility signal before access. We do not store a date of birth, age, or age range for that check.
3. Information we process
We process information needed to provide and protect the service. The categories can include:
- account information, including your recoverable email address, account identifier, and authentication-session information;
- the audio answer you choose to record, along with audio file type, size, and duration;
- the practice question, role and job context, training and interface language, attempt number, and Retry relationship;
- a transcript created while your answer is processed;
- structured feedback, scores, completion status, timestamps, and error information associated with a training record;
- limited service-operation information, such as IP address, user agent, request identifier, route, response status, timing, and byte count; and
- the email address, message, and any information you choose to send when contacting support.
4. Why we process information
We use this information to create and secure your account; provide recording, transcription, feedback, history, and Retry features; diagnose and prevent misuse or service failures; process deletion requests; and answer support messages. We do not sell personal information, share it for cross-context behavioral advertising, or use it to serve advertisements.
5. Audio, transcripts, and feedback
When you choose to train, the app records your answer in temporary storage on your device and uploads it to the DevPhrase backend hosted on Railway. The backend uses the audio temporarily to provide transcription and feedback. It attempts to remove its temporary audio copy after processing, cancellation, failure, record deletion, or account deletion; a background cleanup process also handles inactive files. Cleanup can be delayed by a system or storage failure, so we do not promise an exact deletion time.
The backend sends the audio to OpenAI for transcription. It then sends the transient transcript and relevant training context to OpenAI to generate structured feedback. Under the current service configuration, we request that OpenAI not store Responses API application state for feedback. OpenAI may otherwise process information under its own data controls, including abuse-monitoring retention where applicable.
We do not store original audio in Supabase. Under the current configuration, the transcript is processed to provide the training result but is not persisted with the training record. Supabase stores the account identifier and the training context, Retry relationship, audio metadata, status, timestamps, structured feedback, scores, and error information needed to provide history.
6. Service providers and international processing
We use service providers to operate DevPhrase: Supabase for authentication and the training database, Railway for the backend, OpenAI for transcription and feedback, and Namecheap Private Email for support messages. These providers process information for the services they provide to us. Because the operator is in mainland China, the initial app market is the United States, and providers may operate in other regions, information may be processed in China, the United States, and other locations where the relevant provider operates. We do not represent that all information stays in one country or that international transfers are risk-free.
A separate optional AI helper may be used only from the backend for synthetic or sufficiently deidentified question material. The app does not contain that helper's code, SDK, endpoint, or key. It is not permitted to receive real user audio, transcripts, answers, feedback, account data, or other real user content unless the service is separately reviewed before that use.
7. Retention and deletion
Training records remain available until you delete your account. We do not currently apply an automatic expiry to training history. Original server audio is temporary as described above, and transcripts are not persisted in the training database under the current configuration. Support messages are manually deleted 12 months after a support matter is closed, unless a limited, documented legal, security, fraud, or dispute need requires otherwise.
Operational logs are retained under the current Railway Hobby plan for up to seven days. Provider-level logs and backups are managed under the applicable provider's retention processes and can remain temporarily after data is removed from active service records. We do not maintain a separate long-term account-deletion record containing training content.
You can start account deletion in the app. When remote deletion is confirmed, the account and associated training records are removed and the app clears its local session, onboarding state, and training state. See Delete Account for the process and its status handling.
8. Website data and cookies
This website does not use analytics, advertising, or tracking scripts, and it does not intentionally set nonessential cookies. The service that delivers a page may process ordinary request information, such as IP address and browser information, to deliver and secure the page.
9. Security
We use reasonable technical and organizational measures designed to protect information, including authenticated access controls, row-level database controls, bounded uploads, and temporary-audio cleanup. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Your choices and rights
Depending on applicable law, you may have rights to request access to, correction of, deletion of, or information about personal information we process. You may also ask questions about this policy or our processing. To make a request, email support@devphrase.com. We may need reasonable information to verify the request and protect another person's account. Do not email passwords, one-time codes, complete authentication tokens, API keys, sensitive recordings, or a full transcript.
Nothing in this policy limits rights or remedies that cannot be waived under applicable United States federal or state law.
11. Changes and contact
We may update this policy when the service or its data practices change. We will post the updated version here and revise the last-updated date. Questions may be sent to support@devphrase.com.