Debatable is a voice-first adversarial-argument trainer. To make that work, we collect the minimum we need: a sign-in identity (if you sign in), optional private matching preferences you choose to provide, the debate rounds you generate, and the technical signals every web app collects. We don't sell your data and we don't run ad trackers. Audio from AI Voice Rounds is streamed peer-to-peer to OpenAI's Realtime API and is not stored on our servers. Ordinary live human video rooms are not recorded unless every seated participant accepts the recording and public-replay scope. Tournament rooms are recorded as a condition of participation. Registration, check-in, and room entry disclose that rule; the round stays closed until every assigned person acknowledges it. Preliminary footage is private by default. When capture runs, the room shows a recording indicator the whole time. You can also debate without your camera: Avatar mode replaces your video with an animated mask rendered on your own device, and the underlying camera frames are never transmitted or stored. If you sign in, we may send you a handful of account emails, every one of which has a one-click unsubscribe. We may license an anonymized corpus of debate rounds to AI research organizations, but only for accounts that opt in via profile settings and confirm they are 18 or older; it is off by default. See §7 for the full terms.
Debatable ("we", "us", "our") operates the web app at itsdebatable.com. The service is run by an independent developer based in the United States. The contact address for privacy questions, data-access requests, and deletion requests is hello@itsdebatable.com.
If you sign in, we receive your Google account email address and display name via Google OAuth (handled by Firebase Authentication). We do not see, store, or transmit your Google password. We use this to identify your account across sessions, attribute usage against your free or paid quota, and let you save rounds to your profile.
You can use the app anonymously without signing in. In that case we have no identifier for you beyond a randomly generated session ID held in your browser and the technical signals listed below. Anonymous voice-round transcripts and ratings may be stored under that random session ID so we can improve judging and model quality; they are not saved to a profile, linked to an email, or included in the licensed research corpus.
If you upload a profile picture, your browser crops it to a square and re-encodes it as a JPEG before sending it to Debatable. We store that picture with Netlify and show it anywhere your public identity appears, including profiles, match cards, rounds, ballots, and leaderboards. A profile picture is public, so do not upload an image you do not want other people to see. You can use a built avatar or one of the supplied pictures instead. Uploaded pictures are deleted when you delete your account.
The live Match Desk lets you optionally say where you lean on four issue areas: economic policy, immigration, online political speech, and democratic reform. Each question includes a “Not my topic” choice, and you can skip the whole setup. Answers are saved on your device as you continue or reach sign-in. Entering the queue after sign-in saves and uses those answers for matchmaking.
We store the answers in a server-only profile tied to your account. We use them to rank eligible people when you ask for a viewpoint clash and to generate a motion from an issue where both people gave opposing answers. Our AI provider receives only a general description of that disagreement. It receives no names, account identifiers, private notes, or indication of which person selected which answer. If generation is unavailable or its output fails our checks, we use a reviewed motion instead. Your positions are not written to the public matchmaking queue, shown to your opponent, given to the judge, placed in analytics, used for advertising, or included in the research corpus. Both people see the same motion when they enter the room and can change it through the existing motion negotiation. The answers that led to it remain private. The temporary generation description is removed when the attempt finishes; the resulting motion is kept with the match.
You can change an answer from the Match Desk. Choosing “Not my topic” for every issue deletes the stored political profile and returns matching to the neutral fallback.
When both people agree to “Debate something else,” an AI topic host asks a question related to the Match Desk issue areas. It does not reveal either private questionnaire. Each person chooses whether to turn on microphone listening or type. Microphone segments go to our transcription provider; the resulting words and typed contributions go to our AI provider to propose a resolution. This setup text is stored separately from the scored round, is not given to the ballot judge, and is not included in the research corpus. Completed or cancelled discussions clear their setup text. Account deletion also removes any remaining topic discussion involving that account.
The waiting screen may say someone is answering questions or signing in, based on recent interaction with that step. This activity contains no questionnaire answers or public identity and does not reserve a match. A server-derived daily network hash limits duplicate activity; stale activity is excluded after 45 seconds.
When you generate a case, run a rebuttal, request a judge ballot, or hold a typed or voice debate, we store the prompt, the AI's reply, the motion, the format, and the timestamp in our database (Google Firestore). This feeds two product features:
If you want a specific round removed from this loop, email us with the round identifier and we will delete it.
If you are signed in and have generated enough rounds, a nightly automated pass reads your recent rounds and writes a short (~150 word) summary of how you argue: signature moves, strengths, weaknesses, topic affinities. This fingerprint is stored against your account and injected into future AI prompts so the opponent and judge adapt to you. It is visible to you on your profile ("How I think as a debater"), is never shown to other users, and is deleted with your account. The first time one is generated we may send you a one-time email previewing it. If you want the fingerprint deleted or the pass turned off for your account, email us.
If you start a voice round, your microphone audio is captured by your browser and streamed directly to OpenAI's Realtime API over WebRTC using a short-lived ephemeral token that our server mints. Our servers are not in the audio path; we do not record, buffer, or store your raw audio. After the round ends, the text transcript produced by OpenAI's speech-to-text is sent back through our server so the same learning loop described above can apply. OpenAI's handling of audio is governed by OpenAI's privacy policy.
When both people accept screenshot storage in a public recorded round, we also save up to eight pairs of still images: a thumbnail with the public names and topic, and a clean image without those overlays. These show only the published camera or Avatar tiles, never a hidden camera, chat, transcript, or screen share. Thumbnails can represent the replay. The full image library is private to Debatable staff for later design work; front-page publication requires separate permission. Withdrawing recording consent removes these screenshots, and deleting either account removes its saved image sets.
Ordinary live human video rooms do not record by default. A seated participant may request a recording, and every seated participant receives a separate dialog before capture begins. The dialog explains why the replay is being requested, the exact capture scope, who can see it, and that replay or clip links may be shared outside Debatable. Recording starts only if every seat accepts that full scope for the current round. Debatable then stores the video, audio, display names, and motion through Daily.co.
Tournament rooms are the exception. Every tournament round is recorded and stored by Debatable. Registration and check-in require acknowledgement, and the room remains blocked until every assigned person confirms the notice and the recording indicator is live. There is no decline control inside a tournament room. A person who cannot be recorded must leave and withdraw before playing. Preliminary footage is private by default; elimination-round broadcast follows the published event rules. Users under 18 must confirm that a parent or guardian approved the recording.
For an ordinary room, saying no prevents recording from starting. It does not affect the round, and nobody is asked to justify it. An unanswered prompt also means no recording starts. A participant who agreed can withdraw during the round; capture stops and the partial file is marked for deletion at Daily.co rather than published. Each answer is stamped to that round with the policy version and time.
Recorded live rounds are separate from the research corpus. Video and raw audio are never included in corpus exports, used for voiceprints, or used to infer identity or protected traits.
Some surfaces are social, and what you post there is visible to others by design: sparring waitlist posts (your display name plus an optional note, visible to signed-in users), leaderboard entries (display name and record), and the public disclosures board (visible to everyone). Before a disclosure post publishes, its text is run through an automated AI moderation check for harassment, doxxing, and spam; posts that fail are blocked. Direct messages you send to another user to organize a round are stored in our database and visible only to the two participants. All of this is deleted when you delete your account. Don't put anything in a public post you wouldn't want indexed.
If you sign in, we may send a small number of account emails through Resend: a first-round welcome, an occasional activity digest, a win-back note if you've been away, sparring-night and match notifications (someone accepted your invite, a DM arrived, a round you signed up for is starting), and the one-time style-fingerprint email described above. Every email has a one-click unsubscribe link scoped to that stream, and there is a global email opt-out that silences everything. We do not send third-party marketing and we do not share your email address with advertisers.
Some pages offer browser push notifications (for example, to tell you a sparring match was found while the tab is in the background). These only work if you explicitly grant the browser permission prompt. If you do, we store the push subscription token your browser issues; it is deleted when you delete your account, and you can revoke the permission at any time in your browser settings.
Paid subscriptions purchased through the Debatable web service are processed by Stripe, and by Razorpay for supported Indian-rupee payments. The iOS app contains no checkout or external purchase link. We never see your full card number, CVC, UPI credentials, or bank details. The processor returns to us a customer ID, the last four digits of your card, your billing country, and the subscription status. Their handling is governed by Stripe's privacy policy and Razorpay's privacy policy.
Every request to the site logs the standard web-server fields: IP address, user agent, the URL requested, the referrer, and a timestamp. We use these to rate-limit abuse, debug failures, and produce aggregate usage statistics. For anonymous rate limiting, your IP address is used as a short-lived counter key in Upstash Redis; those counters expire automatically within 24 hours and are never joined to your account or your rounds. Anonymous session IDs are hashed before rounds are stored under them. Raw access logs are retained for up to 30 days by our hosting provider (Netlify).
The app uses your browser's localStorage and sessionStorage to remember your preferences (theme, last-used format, draft text, anonymous-session quota counter) and uses cookies set by Firebase Authentication to keep you signed in. We do not set advertising cookies. We do not use Facebook Pixel or other third-party cross-site tracking pixels on the app. For first-party product analytics (which screens are visited, which features are used, where users get stuck) we use Firebase Analytics, Google Analytics 4, and GoatCounter (a privacy-focused, cookie-free pageview counter). We also use PostHog for product analytics and session replay: a recording of how the page moved (clicks, scrolls, navigation) that we watch to find where people get stuck. Replay starts only after you interact with the page, and it is designed to leave your content out: every text field is masked before it is sent, so nothing you type is recorded; direct messages, chat, and the inbox pages are excluded; and camera video, screen shares, and avatar masks are blocked from the recording and show as empty boxes. If you are signed in, the replay is linked to your account id, never to your name or email. You can turn replay off in your browser by opening any page with ?replay=off in the address. You can clear all of this at any time by clearing site data for itsdebatable.com in your browser, and you can opt out of GA on the broader web via Google's opt-out add-on.
We use the following sub-processors to deliver the service. Each is bound by its own privacy and security commitments at the links below. We do not authorize any of them to use your private content to train their public foundation models. Provider-side enterprise / API agreements (which we operate under) generally exclude API-submitted data from training; you should review each provider's policy for the current details.
| Provider | Purpose | Policy |
|---|---|---|
| Google Firebase | Authentication, Firestore database, hosting of your saved rounds and profile, Firebase Analytics for first-party product analytics. | Firebase privacy |
| PostHog | Product analytics and session replay (page movement with all inputs masked, DMs and video excluded). US-hosted. | PostHog privacy |
| Google Analytics 4 | First-party product analytics (pageviews, feature events). Property ID is account-scoped to Debatable; data is not shared for advertising. | Google privacy |
| Netlify | Static site hosting, edge functions, request logs, and uploaded profile picture storage. | Netlify privacy |
| Anthropic | Claude AI brain (case generation, rebuttals, judging). | Anthropic privacy |
| OpenAI | GPT AI brain; Realtime voice; text-to-speech fallback. | OpenAI privacy |
| Google AI | Gemini AI brain. | Gemini terms |
| xAI | Grok AI brain. | xAI privacy |
| DeepSeek | DeepSeek AI brain. | DeepSeek privacy |
| OpenRouter | Open Lab brain pool (Hermes, Mistral, Qwen, Llama). | OpenRouter privacy |
| ElevenLabs | Premium text-to-speech (Pro tier). | ElevenLabs privacy |
| Inworld | Optional premium text-to-speech (Pro tier). | Inworld privacy |
| Cartesia | Optional premium text-to-speech (Pro tier A/B). | Cartesia privacy |
| Resend | Sending account and notification emails. | Resend privacy |
| Upstash | Short-lived rate-limit counters (expire within 24 hours). | Upstash privacy |
| GoatCounter | Privacy-focused, cookie-free pageview analytics. | GoatCounter privacy |
| Stripe | Payment processing (when billing is active). | Stripe privacy |
| Razorpay | Payment processing for INR payments (when billing is active). | Razorpay privacy |
| Daily.co | Video rooms for live human-vs-human debates and cloud storage for opt-in ordinary-room recordings and required tournament recordings. An ordinary recording withdrawn during the round is deleted from Daily.co. | Daily privacy |
When you start a typed round, only the brain you select is called. When you start a voice round, your audio goes only to OpenAI Realtime; at higher difficulty settings, the motion (not your audio or identity) may also be sent to several other brains in parallel to prepare research notes before the round starts. When you run an AI-judged ballot, the panel may call several brains in parallel as documented on the round page.
If you use the BYOK tier, you provide your own Anthropic API key. We store the key encrypted at rest, scoped to your account, and use it only to call the Anthropic API on your behalf for rounds you initiate. We do not use BYOK keys for other users. You can rotate or delete the key at any time from your account settings. BYOK is Anthropic-only; we will refuse cross-provider keys with a labeled error.
Our Firebase project is hosted on Google Cloud's multi-region US infrastructure. Netlify serves traffic from edge locations worldwide but persistent storage is in the United States. By using the service from outside the United States, you consent to the transfer of your data to the United States for processing. We rely on the standard contractual mechanisms each sub-processor publishes for international transfers.
Before your first spoken round, Debatable asks whether it can store what you say. Nothing is stored until you answer, and closing or dismissing the prompt counts as a no. You can change the answer any time under "Store my round transcripts" in your profile settings.
Say yes and we store: the text transcript of the round, turn by turn, with who spoke, how far into the round each turn happened, which speech it fell in, and whether a turn was interrupted. Alongside it we keep the motion, the format, the side you took, and the ballot. Transcripts are written while the round is running, not only at the end, so a closed tab or a dropped connection does not cost you the round.
Who can read it. A stored transcript is private to your account. It is not on the leaderboard, not on your public profile, and not readable by your opponent or by spectators. Nothing from it is published unless you publish that round yourself.
Anonymous when it improves the AI. Rounds do feed the internal learning loop, and that path carries the text only. Your name, your email and your account id do not travel with it into any model prompt. That is a different and much narrower thing than the licensed research corpus in §7, which ships data outside Debatable and is a separate opt-in you have to grant on its own.
Say no and: the round still runs and the AI judge still writes your ballot from what is in the browser at the time. Nothing is written to our servers, including the training-signal record we would otherwise keep, so the ballot cannot be reopened later from a link and the round does not count toward your progress or your leaderboard entry.
Rounds against another person. The same prompt covers live rounds debated against another human. What gets stored under your account is your own speeches plus the judge's ballot. Your opponent's speeches are stored under their account only if they said yes themselves, and neither of you can read the other's stored copy. Partnered and four-team rounds are not stored at all, because one person's yes cannot cover a teammate's words.
Audio from AI Voice Rounds is not stored on either answer. The separate all-party recording choice for live human video rounds is described under Live human round recordings.
Debatable holds an internal corpus of completed rounds (motion, side, format, the prompt that produced the AI's reply, the reply itself, your turns, voice transcripts, ratings, and judge ballots). This corpus is what the nightly learning loop reads from when it distills per-format patterns back into the AI's system prompt; that part is internal and runs on every account.
Separately, we may license an anonymized subset of the corpus to AI research organizations studying argumentative dialogue, debate pedagogy, or voice-mode language models. Anonymized in this context means stripped of your name, email, account id, IP address, and any device fingerprints; what remains is the speech itself plus structural metadata (format, side, motion, rating).
Research sharing is on by default in the settings and research prompt, but no rounds are included until you confirm that you are 18 or older and save with sharing on. We ask after repeat visits or completed rounds, explaining how real arguments help researchers study opposing views and test the consistency of AI judgments. You can turn sharing off in that prompt or in "Research & training corpus" in your profile settings. Existing opt-outs stay off. Choosing "Not now" leaves your current choice unchanged and pauses the question for 14 days. We still require a saved 18-or-older confirmation; rounds from users who have not made that confirmation are never licensed, and the server re-checks the confirmation before marking any round as contributable. The opt-in applies to future rounds only; rounds you finished before confirming your age and saving with sharing on are never retroactively included. You can turn the opt-in off at any time in profile settings, after which no further rounds will be included; rounds that were already in the corpus under your prior consent stay subject to that consent. If you want your rounds withdrawn from the corpus, "Withdraw my rounds from research" in your profile settings removes them from every future shipment immediately, including rounds that landed under a prior consent. For a single round rather than all of them, or to start a best-effort recall of copies already shipped to a recipient, email hello@itsdebatable.com with the round date and motion. Anonymous (signed-out) traffic is never included in the licensed corpus. Each time you grant or withdraw either consent (the round-storage choice in §6 or this corpus opt-in) we record the date, the screen you used, and the version of this policy you saw; that log exists so we can prove every round in the corpus was consented, and it is never shared beyond that purpose. A nightly automated check re-verifies every corpus row against these rules and removes any row that no longer meets them.
AI Voice Round audio is not stored. Only the text transcript is eligible. Video and audio from consented live human recordings are excluded from the licensed corpus. If you use the BYOK tier, BYOK-routed rounds are excluded from corpus licensing regardless of the toggle, since the upstream provider's API agreement governs that data path.
Some pages show a one-question card asking how much you agree with a stated proposition, how confident you are, and optionally why. We call this the opinion panel. Answering is always voluntary, you can skip any question, and dismissing the card stops it appearing for thirty days.
Your answers are stored against a pseudonymous panelist id, not your account id. For signed-in accounts that id is a salted one-way hash of your account id; if you are signed out it is a salted hash of a random identifier your browser generates. We keep the link between your account and your panelist id in one place so we can find and delete your answers if you ask, and that link is never included in anything we share.
We ask the same propositions again after about ten weeks. The point is to measure whether people's views move, so a second answer is more useful to us than a first one. We deliberately do not show you your previous answer when we re-ask, because seeing it would change what you say. If a question follows a round, we also record which round it followed and, if you write one, your own description of what changed your mind.
Licensing panel answers is covered by the same opt-in as the round corpus in §7, with the same required 18-or-older confirmation, the same default-on preference that preserves existing opt-outs, and the same future-rounds-only rule. If you have not turned that on, your answers are used only to show you and other visitors the aggregate split, and are never included in anything licensed to an outside party. Answers from signed-out visitors are never licensed, matching §7. Anything you type in a "why" box is run through the same identifier-stripping pass as the rest of the corpus before export.
The panel may also ask a few optional questions about you: how long you have debated, whether you compete at school or university level, your world region, and your age band. Every one of these is skippable, none is required to answer propositions, and all of them are coarse bands rather than precise details. If you tell us you are under 18, your panel answers are excluded from licensing even if the corpus toggle is on.
Regardless of where you live, you can:
Users in the European Economic Area, the United Kingdom, Switzerland, and California have additional statutory rights under the GDPR, UK GDPR, and CCPA/CPRA. The rights above already cover the substantive list; for formal regulator-facing requests, email hello@itsdebatable.com with the words "data subject request" in the subject and we will respond within the statutory window. We do not sell or share personal information for cross-context behavioral advertising under the CCPA/CPRA definitions.
The service is not directed at children under 13. Do not create an account or use the voice round if you are under 13. Users between 13 and 18 should use the service with the supervision and consent of a parent or guardian; school-team accounts are intended to be administered by an adult coach. If we learn that we hold data for a user under 13, we will delete it promptly. Reports of suspected underage use go to hello@itsdebatable.com.
We use HTTPS everywhere, Firebase App Check on the AI brain endpoints, server-side per-IP rate limits on anonymous traffic, encrypted-at-rest storage in Firestore, and short-lived ephemeral tokens for the WebRTC voice path so the OpenAI API key is never sent to your browser. No internet service can promise perfect security; if you believe an account has been compromised, email us immediately at hello@itsdebatable.com.
The AI's case generation, rebuttals, judging ballots, scores, and feedback are produced by large language models. They are designed for debate practice and are not human judgments. The style fingerprint described in §2 is also automated: it summarizes your past rounds to personalize future ones, nothing more. Public disclosure posts pass through an automated moderation check before publishing; if your post is blocked and you believe the call was wrong, email us and a human will review it. Scores, rankings, fingerprints, and moderation outcomes are not used to make decisions with legal or similarly significant effects on you. You should treat AI output as practice feedback, not as professional coaching, legal, academic, or admissions advice. See the Terms of Service for the full disclaimer.
If we make material changes, we will update the "Last updated" date at the top of this page with a summary of what changed, and for changes that expand what we collect or share, notify signed-in users by email before the change takes effect. The current version is always available at itsdebatable.com/privacy.
Questions, deletion or export requests, security reports, or regulator-facing inquiries: hello@itsdebatable.com. We aim to respond within 7 days for general questions and within the statutory windows (typically 30 days) for formal data-subject requests.