App Store & GDPR / CCPA Compliant

Privacy Policy

Your privacy, confidential deal parameters, and voice data are held to the highest standard of security. Learn how DealCalm protects, isolates, and respects your information.

Effective Date & Last Updated: August 16, 2026

Our Uncompromising Privacy Commitments

No Public Model Training: Your negotiation voice recordings, deal numbers, and transcripts are never used to train public foundation models.
Ephemeral Audio Processing: Live microphone streams are processed in real-time memory with TLS 1.3 encryption.
Strict Tenant Isolation: User transcripts and counterparts are compartmentalized in isolated Firestore security boundaries.
Complete Deletion Rights: You can delete any recording, counterpart, or your entire account at any moment.

1. Introduction & Data Controller

DealCalm ("DealCalm", "we", "us", or "our") operates the DealCalm.com web application and the DealCalm mobile applications available on the Apple App Store and Google Play Store.

For the purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), DealCalm is the Data Controller responsible for your personal information.

Contact: DealCalm Team | Email: admin@dealcalm.com | Website: https://dealcalm.com

2. Information We Collect

We collect information strictly necessary to provide real-time negotiation coaching, AI roleplay simulation, and account management:

A. Account & Profile Information

When you create an account, we collect your email address, username/display name, preferred language, and avatar choice. If you sign in via Google or Apple OAuth, we receive authorized profile identifiers according to your provider permissions.

B. Live Audio & Voice Stream Data

During active practice sessions or roleplay drills, our app captures your microphone input (16kHz PCM audio). This audio is streamed over secure WebSockets (TLS) to perform real-time behavioral tactic detection (e.g. Mirroring, Labeling, Preemptive Objection Audits) and generate synthesized voice responses.

C. Negotiation Scenarios, Transcripts & Counterparts

Transcripts generated during sessions, performance scores, tactical feedback, and custom counterpart profiles (such as negotiation style, environment, and hidden leverage notes) created by you in your dashboard.

D. Subscription & Payment Data

In-app purchases and auto-renewable subscriptions are processed directly through the Apple App Store (In-App Purchases) or Google Play Store, managed via RevenueCat. DealCalm never receives or stores your credit card number or bank details.

E. Technical Diagnostics & Telemetry

Aggregated session duration, seconds consumed, network latency, device platform (iOS / Android / Web), and crash reports to maintain platform availability and performance.

3. How We Use Your Information

We use collected data solely for the following legitimate purposes:

  • Interactive Coaching & Roleplay: Delivering real-time conversational AI negotiation partners and HUD whisper cues.
  • Performance Analytics: Generating tactical debriefs, technique breakdown scores, and voice summary feedback.
  • Account & Quota Management: Enforcing monthly talk-time limits, active subscription tier entitlements, and cross-device synchronization.
  • Platform Security & Abuse Prevention: Guarding against unauthorized access, credential stuffing, and Denial of Service (DoS) attacks.

4. Third-Party AI Data Sharing & Infrastructure (Apple Guidelines 5.1.1(i) & 5.1.2(i))

In full compliance with global privacy regulations and App Store Guidelines 5.1.1(i) & 5.1.2(i), DealCalm explicitly discloses its third-party Artificial Intelligence data flows:

Google Gemini Live AI (Google LLC) Processing Details:
  • Data Transmitted: Spoken audio stream (16kHz PCM), real-time speech transcripts, and negotiation roleplay parameters.
  • Recipient Entity: Google LLC (Google Cloud Platform, Mountain View, CA, USA).
  • User Consent: Explicit consent is requested and obtained in-app prior to the initiation of any AI coaching session. Users may manage this permission in Settings.
  • Equivalent Protection & Non-Training: All transmissions use TLS 1.3 encryption. Google processes this data under enterprise Data Processing Addendum (DPA) terms solely for live inference. Audio and transcript data are never stored or used to train public foundation models.
ProviderPurposeData Handled
Google Cloud (GCP) & Gemini Live APIReal-time speech synthesis & conversational AI reasoningEphemeral audio streams & prompt context (Zero model training)
Firebase (Google LLC)Authentication & user-isolated Cloud Firestore databaseUser credentials, saved transcripts, counterpart records
Apple Inc. & Google LLCApp Store distribution & payment processingIn-app purchase receipts & subscription tokens
RevenueCatSubscription lifecycle & entitlement managementAnonymous App User IDs & purchase status

5. Data Retention, User Rights & Account Deletion

In full compliance with Apple App Store Guideline 5.1.1(v) and global privacy regulations (GDPR / CCPA):

Self-Service Data Deletion

You can delete individual negotiation recordings or custom counterparts at any time from within your dashboard. Deleted records are permanently removed from Firestore and cloud storage immediately.

Complete Account Deletion

You have the right to request the complete deletion of your account and all associated records. You can initiate this in the Settings page or by sending an email to admin@dealcalm.com. We will permanently purge all account identifiers, transcripts, and records within 30 days.

6. Children's Privacy (COPPA & GDPR-K)

DealCalm is intended for business professionals, corporate negotiators, and adult learners. We do not knowingly solicit or collect personal information from children under the age of 13 (or under 16 in the EEA). If we learn that personal data of a minor has been collected without parental consent, we will promptly delete that data.

7. Data Security & Storage Architecture

We implement industry-leading technical and organizational security controls:

  • Encryption in Transit: All HTTP and WebSocket communications use TLS 1.3 encryption.
  • Encryption at Rest: Cloud Firestore databases and Firebase Storage buckets use AES-256 encryption.
  • Access Control: Granular database security rules prevent cross-tenant data access. Mobile auth tokens are stored using hardware-backed secure storage (iOS Keychain / Android KeyStore).

8. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When material changes are made, we will notify you via an in-app banner or by updating the "Last Updated" date at the top of this page.

Contact Our Privacy Team

If you have questions, feedback, or requests regarding this Privacy Policy or your personal data, please contact us: