Sapien Privacy Policy
This Privacy Policy explains how Sapien (“Sapien”, “we”, “us”) collects, uses, and shares information when you use our mobile application, website, and related services (collectively, the “Service”).
If you do not agree with this Privacy Policy, do not use the Service.
1) Who We Are
Sapien is operated by Sapien Group, Inc. ("Company").
Contact: support@sapienapp.io
2) Information We Collect
A. Information you provide
- Account information: email address and authentication identifiers (for sign-in).
- Profile information: username and optional profile details (e.g., name, bio, profile photo).
- Content you create: photos, videos, text posts (“Thoughts”), captions, and any metadata you attach.
- Social graph information: who you connect with (e.g., Inner Circle / Outer Circle), follow requests, blocks, and related actions.
- Communications: messages you send to support (and any attachments you include).
B. Information collected automatically
- Device and app information: device model, OS version, language, app version/build, and similar technical signals.
- Log and diagnostics data: crash reports and performance data, as available on your device/OS.
- Push notification tokens: if you enable notifications, we store a device token to deliver notifications.
C. Payments and subscriptions (Shield)
If you purchase a subscription (“Shield”) through Apple In‑App Purchase:
- Apple processes payment information. We do not receive your full payment card details.
- We may receive purchase/subscription status (e.g., whether a subscription is active) to unlock features.
D. Identity verification
If identity verification is enabled in the Service:
- Your session is assigned to Didit or Stripe Identity. During our staged provider transition, Stripe remains available for in-flight and rollback sessions. The disclosure shown before capture identifies your provider.
- A Didit flow is designed to process an identity document, selfie or face video, passive liveness, a 1:1 comparison between your face and document portrait, and a 1:N duplicate-face search intended to prevent one person from verifying multiple accounts. Depending on configuration, Didit may also process document details, legal name, date of birth, address, country or nationality, and device or anti-fraud signals.
- Stripe may process identity documents, selfies, biometric information, and related verification signals for sessions assigned to Stripe.
- The intended contract structure is for Sapien to act as controller/business and for Didit and Stripe to act as processors/service providers under approved terms. The Didit role is not treated as legally complete until the DPA and legal review are approved. Sapien makes the final access, duplicate, and manual-review decision; provider approval alone does not verify a Sapien account.
- Before Didit capture, we require a separate disclosure and affirmative consent covering document verification, liveness, 1:1 face match, 1:N duplicate search, the approved retention approach, and the deletion or withdrawal path.
- Sapien is designed not to store raw identity-document images, selfies, liveness media, provider media URLs, face templates, or complete provider decision payloads. We may store legal name, normalized status and reason, provider/session/workflow/consent/audit references, timestamps, and keyed non-plaintext identity fingerprints used to prevent duplicate accounts.
Didit launch status: live Didit processing is blocked until Sapien's owner and legal/security reviewers approve the provider contract and data-processing terms, subprocessors, transfers and data residency, security materials, biometric-consent language, retention duration, and deletion behavior. Stripe remains available for rollback while those gates or later rollout exit criteria remain open.
3) How We Use Information
We use information to:
- Provide the Service: create accounts, enable posting, show your content, and deliver core features like the feed, profile, and circle features.
- Safety and integrity: prevent spam, fraud, and abuse; enforce policies; troubleshoot issues.
- Operate and improve: monitor performance, debug crashes, and improve reliability.
- Communicate with you: respond to support requests and send important service notices.
- Billing and verification: manage subscriptions and verification-gated features, where applicable.
4) How We Share Information
We may share information:
- With other users, based on your settings. Your content and profile may be visible to other users according to your circle/visibility settings.
- With service providers that help us operate the Service (for example): Supabase (hosting, database, authentication, file storage), Apple (In‑App Purchase, Sign in with Apple, push notification delivery), Didit (identity-document, liveness, face-match, and duplicate-search processing only after the live-processing gates above are approved), Stripe (identity verification for assigned, in-flight, or rollback sessions), OpenAI (content moderation for posts and comments), xAI (voice‑to‑text transcription when you use voice input), and other vendors we use for infrastructure and security.
- For legal and safety reasons: to comply with law, respond to lawful requests, or protect rights, safety, and integrity.
- In connection with a business transfer: merger, acquisition, or sale of assets.
We do not sell your personal information.
Voice Transcription
When you use the voice‑to‑text feature in the post composer or messages, audio is transmitted to xAI for transcription only and is not retained by xAI for model training.
Content Moderation
Posts and comments are screened by OpenAI's moderation API before publication. For text posts, captions, and comments, the text is sent. For image or video posts, a short-lived signed image or poster URL may also be sent so visual content can be screened. We do not send your account identifiers.
5) Data Retention
We keep information only as long as needed to provide the Service and for legitimate business purposes.
- Expiring posts: content with a set expiration may be removed from the Service after it expires.
- Deleted content: when you delete content or your account, we remove it from active systems, though some information may remain in backups for a limited period.
- Identity-provider records: provider deletion can be asynchronous or logical before final retention deletion. A request may first hide a session and quarantine media while decision, audit, extracted-data, backup, duplicate-index, or blocklist records remain for the configured retention period or as legally permitted. Provider acceptance is not a promise of immediate physical erasure.
- Sapien duplicate-prevention records: Sapien may need to retain keyed identity fingerprints and minimal duplicate/manual-review history after provider media is deleted so account deletion cannot reset the one-human-one-account rule. The fields, duration, access controls, and deletion exceptions for this local branch require owner and legal approval before live Didit processing. These keyed values are not raw documents or face images, but remain protected personal information.
Didit's retention is not yet approved for live Sapien traffic. Before live use, we will configure either the shortest approved provider retention paired with measured local keyed-dedup coverage, or a specifically approved longer-lived biometric duplicate index with a defined purpose and duration. The selected approach must appear in the pre-capture disclosure. Until then, live Didit processing remains disabled.
6) Your Choices and Rights
Depending on where you live, you may have rights to access, correct, or delete your information.
In all cases, you can:
- Update your profile information in the app.
- Delete posts you created (where supported).
- Request account deletion (where supported).
- Decline a new Didit capture or withdraw consent before a new capture begins. Withdrawal does not necessarily erase processing already completed or records retained for integrity, legal, fraud-prevention, or dispute purposes.
- Ask us to submit applicable identity-provider deletion requests. Provider deletion may remain pending through logical-deletion and retention processing.
- Contact us at support@sapienapp.io with privacy questions or requests.
7) Security
We use reasonable administrative, technical, and physical safeguards designed to protect information. No system is 100% secure, and we cannot guarantee absolute security.
8) Children’s Privacy
Sapien is not intended for children under 16. We do not knowingly collect personal information from children below the applicable minimum age.
9) International Transfers
Your information may be processed in countries other than your own. These countries may have different data protection laws.
10) Changes to This Policy
We may update this Privacy Policy from time to time. We will update the “Last Updated” date and, where required, provide additional notice.
11) Contact Us
Email: support@sapienapp.io
Mailing address: 1209 Orange Street, Wilmington, DE 19801