Last updated: 4 October 2026
PaperSays turns research papers into short audio briefings. You can ask questions about them by text or voice, take notes and check what you learned. This policy explains what we collect, why, who processes it, how long we keep it, and how to delete it.
Who we are: {controller} (“we”). Contact: support@papersays.com.
1. Summary
- You sign in with Apple or Google. We never see your password.
- We don’t sell your data and we don’t show ads. We use our own analytics plus Google Firebase (Analytics, Crashlytics, Performance) and PostHog to understand use and fix problems (section 6). Crash and usage data are linked to an internal account ID, never your name or email. We don’t use your advertising ID on iPhone and don’t ask to track you. VERIFY: Android advertising ID decision (section 6)
- Some features use AI. When you use them, we send only what’s needed to answer: never your name, email address or account details (section 5).
- Hands-free listens for the wake phrase on your phone, only for the episodes you turn it on for, and only while the episode plays. The sound is processed on the device; nothing is recorded or sent anywhere.
- If you buy Premium, Apple handles the payment; we never see your card. We get your subscription status from Apple through RevenueCat (section 7). Deleting your account doesn’t cancel a subscription (section 9).
- You can delete your account in the app (Profile → Delete account). Your personal data is deleted. Anonymous usage totals that can’t be linked back to you are kept (section 8).
2. What we collect and why
| Data | Examples | Why | Source |
|---|---|---|---|
| Account | Name, email address, profile picture link, sign-in provider (Apple or Google), an internal user ID | Create and secure your account, show your name | Apple / Google when you sign in |
| Preferences | Role, goals, hubs and topics you follow, episode length, daily reminder time, notification choice, hands-free sensitivity and “keep the mic ready” choice, learning settings | Personalise your daily briefing and settings across devices | You (onboarding, Profile) |
| Listening activity | Saved episodes, listening progress and history, queue | Resume where you stopped, Library | The app |
| Questions and answers | Questions you type or say (as text), the AI’s answers, your ratings of answers (thumbs up / down and reason) | Show your conversation history in the Library; improve answer quality | You |
| Notes | Your notes, the episode moment and quoted transcript line, AI note summaries | Your notes, synced across devices | You |
| Learning | Your quiz answers and review schedule, questions you report as wrong or unclear | Spaced review, fixing bad questions | You |
| Support messages | Topic, your message, the reply email you enter, plus diagnostics: app version, build, platform, OS version, device model, language setting, the episode and position you were on, data mode | Answer your request | You (Profile → Help → Contact support) |
| Feedback | Rating 1–5, type (idea / problem / praise), optional comment, app version, platform | Improve the app | You (Profile → Help → Leave feedback, or a one-time prompt) |
| Usage analytics | Events such as app opened, episode started / completed, question asked (never its text), note created (never its text), settings changed; app version, platform, a random install ID, a session ID, your local date | Understand which features and episodes work; fix problems | The app (first-party, see section 6) |
| Firebase Analytics data | Firebase app instance ID, automatically collected events (first open, session start, screens viewed, app updates), the in-app events we send (no question, note or message text, no name or email), device model, OS version, language, app version, approximate country / region derived from the IP address, the ad campaign that led to the install; on Android the advertising ID if we keep it (VERIFY / decide) | Understand how the app is used; measure which ad campaigns bring installs | The app (Google Firebase, section 6) |
| Crash reports | Stack trace and app state at the crash or error, device model, OS version, orientation, free memory / disk, app version, a Crashlytics installation ID, your internal user ID (a random code, not your name or email), your plan, the hands-free state and audio route (car, Bluetooth, speaker), and the last technical log lines before the crash (no text you typed or said) | Find and fix crashes | The app (Google Firebase Crashlytics) |
| Performance data | App start time, screen rendering, network request timings (address and duration, no content), timings we measure (for example time to first audio, time to an answer), device model, OS version, app version, approximate country | Find and fix slow or heavy parts of the app | The app (Google Firebase Performance Monitoring) |
| Product analytics, errors and session replays (PostHog) | Your internal user ID and, while signed in, the same in-app events as our own analytics (never question, note or message text, never your name or email), screens viewed, app open / background, errors with their technical details, non-identifying traits (plan, role from onboarding, number of hubs followed, app version, platform, notifications and hands-free on or off, whether the account is a test account), device model, OS version, approximate country derived from the IP address. Session replays of some sessions: a recording of the app’s screens and taps, with every text field masked (questions, notes, email, support form), paused while hands-free is listening. Device logs: after a crash, an error or when you report a problem, the last minutes of the app’s technical log, with any text you typed or said removed | See how people use the app and where they get stuck; find, reproduce and fix errors | The app (PostHog, section 6) |
| Purchases and subscription | Plan (Free or Premium), product (monthly or yearly), store, status (active, cancelled, expired, refunded…), start, renewal and expiry dates, whether it will renew, offer code used, Apple’s transaction IDs, sandbox or real purchase, store country, price and currency of each purchase event. No card or bank details, no billing address | Give you Premium on every device you sign in to, restore purchases, handle refunds and billing problems, accounting and tax | Apple, through RevenueCat, when you buy, renew, cancel or get a refund |
| Premium given by us | Plan, start and end dates, reason (for example “beta tester”) | Give testers or support cases Premium for a limited time | Our team (admin dashboard, audited) |
| Technical data | IP address and request metadata in our hosting provider’s logs | Security, abuse prevention, operating the service | Automatically, by our hosting provider |
VERIFY (OBS-003 / OBS-004 build): the app links Crashlytics and PostHog with the internal user ID only, masks every text input in replays, pauses replay during hands-free and scrubs device logs before upload.
We do not collect: precise location, contacts, photos, the iPhone advertising identifier (IDFA), card or other payment details (Apple processes payments), health data, or voice recordings.
3. Microphone and hands-free
The app uses the microphone only for features you start:
| Feature | When the mic is on | What happens to the sound |
|---|---|---|
| Voice question (mic button in Ask) | While you hold the conversation open | Turned into text by your phone’s speech recognition (section 4); the text is sent as your question |
| Note dictation | While you dictate | Turned into text; only the text is saved |
| Hands-free (“Hey Aiden”, iPhone only) | Only for an episode you turned it on for, only while that episode is playing, also with the screen locked | The phone listens for the wake phrase on the device. Nothing is recorded or stored. Only after you say the wake phrase and ask a question or dictate a note is the text of that question or note used, as above |
Hands-free details:
- Off for every episode until you turn it on with the mic button at the top of the player. A consent screen explains what happens each time you turn it on.
- Mic off when paused, by default. If you choose “Keep the mic ready while paused” (Profile → Hands-free), the mic stays open but does not recognise anything for the time you pick (1, 5, 15 or 30 minutes), so pressing play from the lock screen can resume listening. When that time runs out the mic turns off.
- Processed on the device. Hands-free uses Apple’s on-device speech recognition only. The microphone sound never leaves your phone: it isn’t sent to us, to Apple’s servers or to any AI provider, and it isn’t stored. Only the text of a question or note you say after the wake phrase is used (sent as a question, or saved as a note).
- Hands-free is a Premium feature (the Free plan may include a small allowance). Paying for Premium pays for the AI answers and the spoken voice, not for microphone access.
- Your phone’s microphone indicator (the orange dot on iPhone) shows whenever the mic is open.
- Turn it off for any episode with the same button, or deny the microphone in your phone’s Settings.
4. Speech recognition
- Hands-free (wake phrase, commands, questions, notes): Apple’s on-device speech recognition. Audio does not leave the phone.
- Voice questions and note dictation from the screen: your phone’s built-in speech recognition (Apple on iPhone, Google on Android). Notes ask for on-device recognition first. When on-device recognition isn’t available, and for on-screen voice questions, the phone’s recognizer may send audio to Apple or Google to transcribe it, under their privacy terms. VERIFY: the on-screen voice Q&A mic does not request on-device recognition (
speech_to_text_input_service.dart:onDeviceis set only for note dictation, with a retry on the server recognizer). Product decision needed: require on-device for Q&A too, or keep this sentence. - Optional cloud transcription (currently off): we may turn on more accurate cloud transcription for spoken questions and notes only (never the wake phrase or commands). The audio clip of that question or note (up to 60 seconds) is sent to our server and then to a third-party speech-to-text provider to be transcribed. We don’t store the audio. Our logs keep only counts and duration, never the audio or text. Status 2026-10-04:
stt_mode=device, so this is not used. VERIFY before turning it on: (a) the speech-to-text provider’s retention / no-training terms for audio (provider: internal appendix), (b) the hands-free consent copy (“Nothing is recorded or kept. Only a question you ask is sent.”) and the on-screen privacy text must then say the audio of the question is sent for transcription.
5. AI features
Some features use AI: answers to your questions, spoken answers, AI note summaries and, in some modes, speech-to-text. When you use them, we send only what’s needed to answer: your question, the paper’s text and, for follow-ups, the recent questions in that conversation. We never send your name, email address or account details to the AI services.
AI is part of how these features work, so there is no separate AI switch. If you don’t want your questions processed by AI services, don’t use Ask, spoken answers or AI note summaries; listening to episodes doesn’t send anything to them.
The details:
| What | Sent to | What is sent |
|---|---|---|
| Answering your question | Third-party AI service providers, through our server | Your question text, up to the last 6 turns of that conversation, the paper and episode text. Not your name, email or user ID. VERIFY the request carries no user identifier (the provider adapter sends model, messages, limits only; see the internal appendix) |
| Spoken answers | A third-party voice provider (text-to-speech), through our server | The answer text only (not your question). Generated audio may be cached on our storage by answer text so identical answers aren’t regenerated. VERIFY the cache key has no user ID |
| AI note summaries | Third-party AI service providers, through our server | The answer or transcript passage being saved (≤ 1,500 characters) |
| Optional cloud transcription (off) | A third-party speech-to-text provider | See section 4 |
- These providers may process your data outside your country. VERIFY + legal advice for EU / UK / other users (international transfer basis, DPA availability; provider locations in the internal appendix) — flagged in
docs/00-strategy/release-plan.md§3 (“Legal before launch”). - We do not use your questions, notes or answers to train AI models. VERIFY whether our AI and voice providers’ API terms (internal appendix) let them use API inputs for training or keep them, and for how long; state their terms here, don’t promise more than they allow.
- We can change the AI provider and model without an app update. If we change the provider we’ll update this policy first. VERIFY whether an alternative provider is planned at launch.
- AI answers can be wrong. Each answer shows whether it comes from the paper or from general knowledge. Nothing in the app is medical advice.
6. Analytics and crash reports
Our own analytics (source of truth for product metrics):
- Events go to our own database.
- Events contain IDs, categories and numbers only, never the text of your questions, notes or messages, and never your name or email. We don’t store IP addresses with events.
- Before you sign in, events use a random install ID (reset when you reinstall). After you sign in, they’re linked to your account.
- Opt out: Profile → Privacy → “Share anonymous usage data”. The app then stops sending events and our server discards any it receives. VERIFY wording: events are linked to the account while signed in, so “anonymous” in the switch label may need to become “usage data” (product + legal call).
- Raw events are kept 13 months, then deleted. Daily totals computed from them (for example, how many people finished an episode that day) are kept longer.
Google Analytics for Firebase (OBS-002):
- Measures how the app is used (screens, sessions, a short list of key in-app events) and which ad campaigns (Google Ads; Meta later) lead to installs and first use.
- Uses a Firebase app instance ID. We don’t send your name, email, or the text of anything you write or say. VERIFY OBS-002 sends no Supabase user ID (
setUserIdnot called) and only allow-listed events with ids / enums. - Google may process this data in the US and elsewhere, under Google’s Firebase terms; Google acts as our processor for Analytics, except where we link it to Google Ads (then Google’s own terms also apply). VERIFY with legal; set the Firebase “data sharing” settings deliberately.
- Retention: we set Google Analytics data retention to 2 months (the shortest option) for event-level data VERIFY / decide (options 2 or 14 months); reports with totals are kept by Google.
- iPhone: no advertising identifier (IDFA), no tracking prompt. Campaign results come from Apple’s SKAdNetwork (aggregated, no user ID). Decision open: if we later add ad-network attribution that uses the IDFA (Meta, Google), the app will ask permission first (App Tracking Transparency) and this policy will change before that.
- Android: Firebase can read the Android advertising ID for campaign attribution. Decision open (VERIFY): keep it (declare in Play, explain here, users can reset / delete it in Android Settings → Privacy → Ads) or disable collection (
google_analytics_adid_collection_enabled = false). - EEA / UK users: Google Consent Mode v2 consent signals are required for ad measurement there. VERIFY / decide a consent prompt or default “denied” for ad storage / ad user data in those regions (OBS-002).
Website analytics (papersays.com, WEB-011, WEB-012):
- The website measures which pages are read, whether the 60-second preview is played, and whether the App Store button is tapped. It uses Google Analytics 4 (the same Google property as the app) and our own counts. We switch off Google signals and ad features, send no user ID, name, email or text you type, and no event holds personal data.
- In the EU, UK and Switzerland, Google Analytics stays off for storage until you press “Accept” on the notice at the bottom of the page; “Decline” keeps it off. Without consent Google may still receive cookieless pings used for modelled totals. Your choice is kept in your browser (local storage) and you can clear it any time.
- Everywhere else the analytics cookie is on by default and no advertising cookies are set at all.
- Google Analytics keeps event-level data for 14 months. Our own website counts are anonymous totals (no cookie, no IP address kept with them). Cloudflare Web Analytics measures page speed without cookies. VERIFY with legal: wording per region, Google as processor, the data retention in section 6 and the Android email list in section 2.
- PostHog (our processor, the same project as the app) also receives the website’s page views and the same events (pages read, preview played, store button tapped). It never records the screen (no session replay), never captures what you type, and honours your browser’s “Do Not Track” setting. In the EU, UK and Switzerland it does not load at all until you press “Accept”; “Decline” keeps it off. Everywhere else it runs without cookies or browser storage (each page view gets a fresh random ID that is forgotten when you leave), unless you pressed “Accept”, which lets it keep a random ID in your browser so visits can be counted as one visitor.
- When you tap “Get the app” or “Open in app”, that random website ID is added to the link. If you then open the app from that link (or install it from Google Play through it), the app links the website visits to your app account’s internal ID, so we can see which pages lead to installs. Installs through the App Store can’t be linked. Data is stored in PostHog’s US region (
us.i.posthog.com, the same project as the app; section 6) under PostHog’s DPA.
Firebase Crashlytics (OBS-001, OBS-003):
- When the app crashes or hits a serious error, a report goes to Google Firebase Crashlytics so we can fix it. It contains technical data (section 2) and your internal user ID, so we can see which problems one person hit and help them. Kept 90 days by Google VERIFY current Crashlytics retention.
Firebase Performance Monitoring (OBS-003):
- Measures how fast the app starts, how smoothly screens draw, how long network requests take, and a few timings we add (for example time to first audio). Technical data only (section 2); no content of requests. VERIFY Google’s Performance Monitoring retention (about 90 days in the console).
PostHog (OBS-004, our processor):
- Shows us how the app is used, one person at a time (a timeline of in-app events and screens), plus errors, session replays and device logs (section 2). Linked to your internal user ID after you sign in; before that, to a random ID. Never your name or email, never the text of your questions, notes, messages or speech.
- Session replay: a recording of the screens of some sessions (the share is set by us). Every text input is masked, so what you type is never recorded. Replay pauses while hands-free is listening and while the app is in the background.
- Device logs: after a crash, an error, or when you report a problem, the last minutes of the app’s technical log go to PostHog, with text you typed or said removed.
- Data is stored in PostHog’s US region (
us.i.posthog.com, the founder’s project) under PostHog’s DPA VERIFY (sign / accept the DPA; for EU / UK users this is an international transfer, section 6). Retention: see section 8. - Test and staff accounts are marked as internal so they’re left out of our reports.
Opting out: turning off “Share anonymous usage data” in Profile → Privacy turns off all of it on that phone: our own analytics, Firebase Analytics, Crashlytics, Performance Monitoring and PostHog (events, errors, replays and logs). VERIFY (OBS-003 / OBS-004 build) that the one switch covers every tool, and the switch wording (data is linked to the account, so “anonymous” should become “usage data”). Android users can also reset or delete the advertising ID in Android settings.
7. Who processes your data
We use these service providers. They process data for us under their terms. We don’t sell your data. The only data that reaches an advertising company is install-campaign measurement from Firebase to Google Ads (section 6).
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Database, sign-in, file storage, server functions | All account and app data in section 2, technical logs | VERIFY region of the production project (BE-025; not yet created) |
| Apple (App Store, Sign in with Apple, speech recognition, notifications) | Payments for Premium (Apple is the seller of record); sign-in; transcription when on-device isn’t available | Purchase and billing details (held by Apple under its own privacy policy; we never receive card details); sign-in identity; audio of on-screen voice input (section 4) | Apple |
| RevenueCat | Checks purchases with Apple and tells our server your subscription status (our processor) | Our internal account ID (used as RevenueCat’s customer ID; not your name or email), your device’s purchase receipts, subscription status and purchase history (section 2, Purchases) | US VERIFY RevenueCat DPA, sub-processors and retention |
| Google (Google Sign-In, Android speech recognition) | Sign-in; transcription on Android | Sign-in identity; audio of on-screen voice input | |
| Third-party AI service providers | AI answers, note summaries | Section 5 | May be outside your country |
| A third-party voice provider | Spoken answers; optional cloud transcription (off) | Section 5 | May be outside your country |
| Google Firebase (Analytics, Crashlytics, Performance Monitoring) | Usage analytics, install-campaign attribution, crash reports and performance timings (crash reports linked to your internal user ID) | Section 6 | US and other Google locations |
| PostHog | Product analytics per person, error tracking, session replay (text inputs masked), device logs (our processor) | Your internal user ID, in-app events, screens, errors, replays and logs (section 2; never your name, email or the text you type or say) | US (us.i.posthog.com); PostHog DPA VERIFY and sub-processors |
| Google Ads (Meta later) | Measuring which ads led to installs | Campaign conversions from Firebase (no name, email or content); on Android the advertising ID if kept | |
| Vercel | Hosts our private admin dashboard (staff only) | Staff sessions; dashboard pages read the database | VERIFY hosting choice (BE-029) |
Not used today, will be added here before they are: Firebase Cloud Messaging (push notifications, BE-021..023; same Firebase project), Meta ad attribution, a web-search API for answers (QA-LIVE-022), Google Play billing (Android).
Our staff can see account, support and feedback data in the admin dashboard to run the service and answer requests. They cannot read your notes (there is no admin access to note text; counts only). Authorised staff can read questions and answers, for example to investigate a reported wrong answer. VERIFY / decide: RLS today gives admins “read all” on qa_threads / qa_messages (data-model.md RLS table); either keep this sentence or remove admin read like notes (notes-spec D11).
We may disclose data if the law requires it.
8. How long we keep data
| Data | Kept |
|---|---|
| Account, preferences, follows, saves, listening progress, Q&A history, learning progress | Until you delete them or your account |
| Notes | Until you delete them; a deleted note’s text is removed at once, its empty record after 30 days |
| Support messages and feedback | Until your account is deleted (deleted with it). VERIFY / decide a fixed period (for example 24 months) for active accounts |
| Raw analytics events | 13 months |
| Usage totals (aggregates) | Kept. After account deletion they stay under a new random key that can’t be linked to you (see below) |
| AI usage records (cost, tokens, timings; no text) | Kept for cost control; the link to you is removed when you delete your account |
| Subscription records (product, store, status, dates, Apple transaction IDs) | Kept for {N} years for accounting, tax, refunds and fraud checks (VERIFY {N} with the accountant; likely 6–10 years depending on the controller’s country). After you delete your account they’re kept without your account ID |
| Purchase events received from RevenueCat (event type, product, price, currency, store, dates, transaction IDs) | Same as subscription records. When you delete your account, your account ID and the personal fields in them (customer IDs, aliases, transfer IDs, attributes, email if any) are removed |
| RevenueCat’s own copy | While you have an account. When you delete your account, we ask RevenueCat to delete its customer record for you (your internal account ID, purchase receipts and purchase history at RevenueCat) right after our own deletion (PAY-011). Apple keeps its own purchase records under Apple’s privacy policy. VERIFY RevenueCat’s DPA retention wording |
| Firebase Analytics (Google) | Event-level data per our retention setting (2 or 14 months, VERIFY / decide); aggregated reports longer |
| Crash reports (Crashlytics) | About 90 days (VERIFY). Linked to your internal user ID; after you delete your account they’re not deleted one by one but expire on this schedule |
| Performance data (Firebase Performance Monitoring) | About 90 days (VERIFY) |
| PostHog events and person record | Per PostHog’s retention for our plan (VERIFY: free plan, events about 1 year), and deleted when you delete your account (section 9) |
| PostHog session replays | About 30 days (VERIFY PostHog free plan replay retention) |
| PostHog device logs and errors | Per PostHog’s retention for our plan (VERIFY) |
| Hosting logs and backups | Per our hosting provider’s plan. VERIFY Supabase log retention and backup retention for the chosen plan (Pro: daily backups) |
| On your phone | Cached content, settings and an analytics queue until you sign out, delete your account or uninstall. Per-episode hands-free choices (last 50 episodes) stay on the device |
9. Deleting your account and your rights
- In the app: Profile → Delete account. This deletes your account, profile, preferences, follows, saves, listening progress, Q&A history, notes, learning progress, support messages and feedback, and clears the app’s data for you on that phone.
- Your subscription is not cancelled. Deleting your account (or the app) doesn’t cancel Premium: Apple keeps billing you until you cancel. Cancel first in Settings → your name → Subscriptions; the app reminds you and offers “Manage subscription” before deleting.
- RevenueCat: right after your account is deleted, we also ask RevenueCat (our purchase processor) to delete its customer record for you. This doesn’t change anything at Apple: your subscription and Apple’s purchase records stay with Apple.
- What stays, unlinked from you: reports you made about a quiz question (the reason you picked) stay so we can fix the question, without your account. AI usage records (cost and timing, no text) stay without your account. Subscription records and purchase events stay for accounting and tax (section 8) without your account ID; the personal fields in the purchase events are removed.
- What stays, anonymised: usage totals. Your past analytics events are re-labelled with a random key generated once at deletion and never stored next to your old ID, your device IDs on those events are removed, and the link from your devices to you is deleted. Nothing left identifies you; the totals (for example daily listeners) don’t change.
- PostHog: right after your account is deleted, our server asks PostHog to delete your person record and its events (if PostHog can’t be reached, the result is logged and we follow up). The app also clears its PostHog ID on that phone. VERIFY PostHog’s deletion timing (events are removed in a background job) and that session replays of the person are removed with it.
- Firebase data: Firebase Analytics data isn’t linked to your account. Crash reports are linked to your internal user ID, but Google offers no per-user deletion for them, so they expire under the retention above (about 90 days); without your account the ID no longer points to anyone. On account deletion the app calls Firebase
resetAnalyticsData()and deletes unsent crash reports. Deleting the app resets the Firebase IDs on that phone. VERIFY / decide: also send the app instance ID to the GA4 User Deletion API (OBS-002). - Apple sign-in: we also revoke the app’s access to your Apple ID when you delete your account. VERIFY: not built yet (BE-008,
delete-accountfunction); must ship before iOS launch. - Without the app: email support@papersays.com from the address on your account, or use the web form at https://papersays.com/delete-account. VERIFY: Google Play requires a web link for account deletion requests (LAUNCH-002).
- Depending on where you live (for example the EU, UK or California) you may have the right to access, correct, export, restrict or object to processing of your data, and to complain to your data protection authority. Contact support@papersays.com; we answer within 30 days. VERIFY legal bases per purpose (contract: account and features; legitimate interest: analytics, security, with opt-out; consent: microphone) and whether a data export feature is needed (notes can already be exported as Markdown).
10. Children
PaperSays is not meant for children. You must be at least 16 to use it (or the minimum age in your country, if higher). We don’t knowingly collect data from children; if you think a child has given us data, contact us and we’ll delete it. VERIFY minimum age (13 vs 16) with legal; the app has no age check today.
11. Security
Data is encrypted in transit (HTTPS). Access to the database is restricted per user by row-level security; staff access requires an admin account. API keys for AI providers are kept on our servers only, never in the app. VERIFY encryption at rest for the chosen Supabase plan before stating it.
12. Notifications
If you allow notifications, the daily briefing reminder and the “Hands-free is off” notice are scheduled on your phone; no device token is sent to us today. When we add push notifications we’ll store a device token and update this policy.
13. Changes
We’ll post changes here and update the date. If a change is significant (for example a new AI provider or new data use), we’ll tell you in the app before it applies.
14. Contact
{controller} · support@papersays.com