yaplab
Privacy Policy
Last updated: 2 September 2026
yaplab is an iOS app for planning, recording and editing short-form videos. This policy explains what the app does with your data. It is written to be read, not to be skimmed past — the short version is that your recordings, scripts and projects stay on your iPhone, and the only data that leaves the device is what is needed to run a feature you asked for.
We run no user accounts, no analytics or tracking SDKs, and no advertising. We do not sell or rent your data, and we do not store your videos, audio, scripts or Instagram content on any server we control.
1. Data stored on your device
The following is created and kept locally on your iPhone, in the app's own storage or in the iOS Keychain. It is not uploaded to us:
- Video recordings, audio takes and rendered exports
- Ideas, scripts, teleprompter drafts, transcripts and caption timings
- Content plans, notes and reusable snippets
- Your OpenAI API key (iOS Keychain)
- Your Instagram access token, if you connect Instagram (iOS Keychain)
Deleting the app from your iPhone removes this data. See Data deletion.
2. Data sent to third parties
OpenAI — using your own API key
yaplab's AI features run on an OpenAI API key that you supply and that is billed to you. When you use those features, the app sends the relevant content directly from your device to OpenAI:
- Audio recordings, for transcription
- Ideas, transcripts and script text, for generating and refining scripts, titles and on-screen text suggestions
- If you have connected Instagram: a compact summary of your own posts' performance (captions, view and share counts, dates) so the app can suggest what to make next
Your key never reaches our servers. OpenAI's handling of this data is governed by OpenAI's privacy policy and the terms of your own OpenAI account. If you do not enter a key, no AI feature runs and nothing is sent to OpenAI.
Meta / Instagram — optional
Connecting Instagram is optional; the rest of the app works without it. If you connect, you log in through Facebook and grant access to your own Instagram professional account. The app then reads, on your device:
- Your professional account's profile basics and the list of Facebook Pages you manage
- Your own published media (captions, thumbnails, permalinks, timestamps, like and comment counts)
- Insights for your own posts and account (for example views and shares)
- Comments on your own posts, where that permission has been granted
This data is fetched from the Meta Graph API straight to your device and stored there. We use it only to show you your own statistics inside the app and, as described above, to inform AI suggestions made with your own OpenAI key. We do not share it with anyone else, and we do not keep a copy on our servers. You can disconnect at any time in the app under Settings, which deletes the stored token.
Our backend
yaplab uses a small stateless backend at talking-head-lemon.vercel.app for two
things. It has no database and stores no user content.
| Endpoint | What it does | What it keeps |
|---|---|---|
| Instagram token exchange | Swaps the Facebook login code for a long-lived token, so the Meta app secret stays off the device. The token is passed straight back to your app. | Nothing |
| Error alerts | If an AI or network call fails, the app may send the error message, HTTP status code, app version, build number, bundle identifier and a short technical context, which is emailed to the developer so the bug can be fixed. Rate-limited to one report per error type per 15 minutes. | Nothing beyond the alert email |
Error reports do not contain your videos, audio, scripts or Instagram content. Requests are served by Vercel, whose infrastructure logs may briefly retain standard request metadata such as IP address; email delivery is handled by Resend.
Apple
The app uses Apple's speech recognition to follow your script while you practise, and Apple's photo library API to save a finished video when you ask it to. This is handled by iOS under Apple's privacy policy. yaplab requests add-only access to your photo library and cannot read your existing photos.
3. Permissions the app asks for
- Camera — to record video
- Microphone — to record audio
- Speech recognition — to follow your script during practice and time captions
- Photos (add only) — to save a finished export
- Notifications — optional reminders you enable yourself
Each can be revoked at any time in iOS Settings.
4. Legal basis and purpose
We process the limited data described above to provide the features you request (performance of a contract) and, for error reports, to keep the app working (legitimate interest). Instagram data is used only for the purposes described in section 2 and is never used for advertising, profiling of other people, or resale.
5. Retention
Content stays on your device until you delete it or delete the app. Your Instagram token is kept until you disconnect, or until it expires (60 days, renewed while you keep using the feature). Our backend retains nothing. Error alert emails are kept by the developer only as long as needed to fix the underlying bug.
6. Your rights
Because your data lives on your device, you control it directly: you can view, edit and delete everything in the app. For anything else — access, correction, erasure, objection, or a complaint — write to calle@plan8.se. EU/EEA users may also lodge a complaint with their national data protection authority.
7. Children
yaplab is not directed at children under 13, and we do not knowingly process their data.
8. Changes
If this policy changes materially, the updated version will be published here with a new date.
9. Data controller and contact
The controller for the limited processing described above is:
Carl Stenqvist AB
Swedish company registration number 556706-9280
Heleneborgsgatan 3, 117 31 Stockholm, Sweden
Email: calle@plan8.se
yaplab is developed and published by Carl Stenqvist AB. Write to the address above with any question about this policy or about your data.