Company

PaperSays Privacy Policy

Last updated: 4 October 2026

PaperSays turns research papers into short audio briefings. You can ask questions about them by text or voice, take notes and check what you learned. This policy explains what we collect, why, who processes it, how long we keep it, and how to delete it.

Who we are: {controller} (“we”). Contact: support@papersays.com.

1. Summary

  • You sign in with Apple or Google. We never see your password.
  • We don’t sell your data and we don’t show ads. We use our own analytics plus Google Firebase (Analytics, Crashlytics, Performance) and PostHog to understand use and fix problems (section 6). Crash and usage data are linked to an internal account ID, never your name or email. We don’t use your advertising ID on iPhone and don’t ask to track you. VERIFY: Android advertising ID decision (section 6)
  • Some features use AI. When you use them, we send only what’s needed to answer: never your name, email address or account details (section 5).
  • Hands-free listens for the wake phrase on your phone, only for the episodes you turn it on for, and only while the episode plays. The sound is processed on the device; nothing is recorded or sent anywhere.
  • If you buy Premium, Apple handles the payment; we never see your card. We get your subscription status from Apple through RevenueCat (section 7). Deleting your account doesn’t cancel a subscription (section 9).
  • You can delete your account in the app (Profile → Delete account). Your personal data is deleted. Anonymous usage totals that can’t be linked back to you are kept (section 8).

2. What we collect and why

DataExamplesWhySource
AccountName, email address, profile picture link, sign-in provider (Apple or Google), an internal user IDCreate and secure your account, show your nameApple / Google when you sign in
PreferencesRole, goals, hubs and topics you follow, episode length, daily reminder time, notification choice, hands-free sensitivity and “keep the mic ready” choice, learning settingsPersonalise your daily briefing and settings across devicesYou (onboarding, Profile)
Listening activitySaved episodes, listening progress and history, queueResume where you stopped, LibraryThe app
Questions and answersQuestions you type or say (as text), the AI’s answers, your ratings of answers (thumbs up / down and reason)Show your conversation history in the Library; improve answer qualityYou
NotesYour notes, the episode moment and quoted transcript line, AI note summariesYour notes, synced across devicesYou
LearningYour quiz answers and review schedule, questions you report as wrong or unclearSpaced review, fixing bad questionsYou
Support messagesTopic, your message, the reply email you enter, plus diagnostics: app version, build, platform, OS version, device model, language setting, the episode and position you were on, data modeAnswer your requestYou (Profile → Help → Contact support)
FeedbackRating 1–5, type (idea / problem / praise), optional comment, app version, platformImprove the appYou (Profile → Help → Leave feedback, or a one-time prompt)
Usage analyticsEvents such as app opened, episode started / completed, question asked (never its text), note created (never its text), settings changed; app version, platform, a random install ID, a session ID, your local dateUnderstand which features and episodes work; fix problemsThe app (first-party, see section 6)
Firebase Analytics dataFirebase app instance ID, automatically collected events (first open, session start, screens viewed, app updates), the in-app events we send (no question, note or message text, no name or email), device model, OS version, language, app version, approximate country / region derived from the IP address, the ad campaign that led to the install; on Android the advertising ID if we keep it (VERIFY / decide)Understand how the app is used; measure which ad campaigns bring installsThe app (Google Firebase, section 6)
Crash reportsStack trace and app state at the crash or error, device model, OS version, orientation, free memory / disk, app version, a Crashlytics installation ID, your internal user ID (a random code, not your name or email), your plan, the hands-free state and audio route (car, Bluetooth, speaker), and the last technical log lines before the crash (no text you typed or said)Find and fix crashesThe app (Google Firebase Crashlytics)
Performance dataApp start time, screen rendering, network request timings (address and duration, no content), timings we measure (for example time to first audio, time to an answer), device model, OS version, app version, approximate countryFind and fix slow or heavy parts of the appThe app (Google Firebase Performance Monitoring)
Product analytics, errors and session replays (PostHog)Your internal user ID and, while signed in, the same in-app events as our own analytics (never question, note or message text, never your name or email), screens viewed, app open / background, errors with their technical details, non-identifying traits (plan, role from onboarding, number of hubs followed, app version, platform, notifications and hands-free on or off, whether the account is a test account), device model, OS version, approximate country derived from the IP address. Session replays of some sessions: a recording of the app’s screens and taps, with every text field masked (questions, notes, email, support form), paused while hands-free is listening. Device logs: after a crash, an error or when you report a problem, the last minutes of the app’s technical log, with any text you typed or said removedSee how people use the app and where they get stuck; find, reproduce and fix errorsThe app (PostHog, section 6)
Purchases and subscriptionPlan (Free or Premium), product (monthly or yearly), store, status (active, cancelled, expired, refunded…), start, renewal and expiry dates, whether it will renew, offer code used, Apple’s transaction IDs, sandbox or real purchase, store country, price and currency of each purchase event. No card or bank details, no billing addressGive you Premium on every device you sign in to, restore purchases, handle refunds and billing problems, accounting and taxApple, through RevenueCat, when you buy, renew, cancel or get a refund
Premium given by usPlan, start and end dates, reason (for example “beta tester”)Give testers or support cases Premium for a limited timeOur team (admin dashboard, audited)
Technical dataIP address and request metadata in our hosting provider’s logsSecurity, abuse prevention, operating the serviceAutomatically, by our hosting provider

VERIFY (OBS-003 / OBS-004 build): the app links Crashlytics and PostHog with the internal user ID only, masks every text input in replays, pauses replay during hands-free and scrubs device logs before upload.

We do not collect: precise location, contacts, photos, the iPhone advertising identifier (IDFA), card or other payment details (Apple processes payments), health data, or voice recordings.

3. Microphone and hands-free

The app uses the microphone only for features you start:

FeatureWhen the mic is onWhat happens to the sound
Voice question (mic button in Ask)While you hold the conversation openTurned into text by your phone’s speech recognition (section 4); the text is sent as your question
Note dictationWhile you dictateTurned into text; only the text is saved
Hands-free (“Hey Aiden”, iPhone only)Only for an episode you turned it on for, only while that episode is playing, also with the screen lockedThe phone listens for the wake phrase on the device. Nothing is recorded or stored. Only after you say the wake phrase and ask a question or dictate a note is the text of that question or note used, as above

Hands-free details:

  • Off for every episode until you turn it on with the mic button at the top of the player. A consent screen explains what happens each time you turn it on.
  • Mic off when paused, by default. If you choose “Keep the mic ready while paused” (Profile → Hands-free), the mic stays open but does not recognise anything for the time you pick (1, 5, 15 or 30 minutes), so pressing play from the lock screen can resume listening. When that time runs out the mic turns off.
  • Processed on the device. Hands-free uses Apple’s on-device speech recognition only. The microphone sound never leaves your phone: it isn’t sent to us, to Apple’s servers or to any AI provider, and it isn’t stored. Only the text of a question or note you say after the wake phrase is used (sent as a question, or saved as a note).
  • Hands-free is a Premium feature (the Free plan may include a small allowance). Paying for Premium pays for the AI answers and the spoken voice, not for microphone access.
  • Your phone’s microphone indicator (the orange dot on iPhone) shows whenever the mic is open.
  • Turn it off for any episode with the same button, or deny the microphone in your phone’s Settings.

4. Speech recognition

  • Hands-free (wake phrase, commands, questions, notes): Apple’s on-device speech recognition. Audio does not leave the phone.
  • Voice questions and note dictation from the screen: your phone’s built-in speech recognition (Apple on iPhone, Google on Android). Notes ask for on-device recognition first. When on-device recognition isn’t available, and for on-screen voice questions, the phone’s recognizer may send audio to Apple or Google to transcribe it, under their privacy terms. VERIFY: the on-screen voice Q&A mic does not request on-device recognition (speech_to_text_input_service.dart: onDevice is set only for note dictation, with a retry on the server recognizer). Product decision needed: require on-device for Q&A too, or keep this sentence.
  • Optional cloud transcription (currently off): we may turn on more accurate cloud transcription for spoken questions and notes only (never the wake phrase or commands). The audio clip of that question or note (up to 60 seconds) is sent to our server and then to a third-party speech-to-text provider to be transcribed. We don’t store the audio. Our logs keep only counts and duration, never the audio or text. Status 2026-10-04: stt_mode = device, so this is not used. VERIFY before turning it on: (a) the speech-to-text provider’s retention / no-training terms for audio (provider: internal appendix), (b) the hands-free consent copy (“Nothing is recorded or kept. Only a question you ask is sent.”) and the on-screen privacy text must then say the audio of the question is sent for transcription.

5. AI features

Some features use AI: answers to your questions, spoken answers, AI note summaries and, in some modes, speech-to-text. When you use them, we send only what’s needed to answer: your question, the paper’s text and, for follow-ups, the recent questions in that conversation. We never send your name, email address or account details to the AI services.

AI is part of how these features work, so there is no separate AI switch. If you don’t want your questions processed by AI services, don’t use Ask, spoken answers or AI note summaries; listening to episodes doesn’t send anything to them.

The details:

WhatSent toWhat is sent
Answering your questionThird-party AI service providers, through our serverYour question text, up to the last 6 turns of that conversation, the paper and episode text. Not your name, email or user ID. VERIFY the request carries no user identifier (the provider adapter sends model, messages, limits only; see the internal appendix)
Spoken answersA third-party voice provider (text-to-speech), through our serverThe answer text only (not your question). Generated audio may be cached on our storage by answer text so identical answers aren’t regenerated. VERIFY the cache key has no user ID
AI note summariesThird-party AI service providers, through our serverThe answer or transcript passage being saved (≤ 1,500 characters)
Optional cloud transcription (off)A third-party speech-to-text providerSee section 4
  • These providers may process your data outside your country. VERIFY + legal advice for EU / UK / other users (international transfer basis, DPA availability; provider locations in the internal appendix) — flagged in docs/00-strategy/release-plan.md §3 (“Legal before launch”).
  • We do not use your questions, notes or answers to train AI models. VERIFY whether our AI and voice providers’ API terms (internal appendix) let them use API inputs for training or keep them, and for how long; state their terms here, don’t promise more than they allow.
  • We can change the AI provider and model without an app update. If we change the provider we’ll update this policy first. VERIFY whether an alternative provider is planned at launch.
  • AI answers can be wrong. Each answer shows whether it comes from the paper or from general knowledge. Nothing in the app is medical advice.

6. Analytics and crash reports

Our own analytics (source of truth for product metrics):

  • Events go to our own database.
  • Events contain IDs, categories and numbers only, never the text of your questions, notes or messages, and never your name or email. We don’t store IP addresses with events.
  • Before you sign in, events use a random install ID (reset when you reinstall). After you sign in, they’re linked to your account.
  • Opt out: Profile → Privacy → “Share anonymous usage data”. The app then stops sending events and our server discards any it receives. VERIFY wording: events are linked to the account while signed in, so “anonymous” in the switch label may need to become “usage data” (product + legal call).
  • Raw events are kept 13 months, then deleted. Daily totals computed from them (for example, how many people finished an episode that day) are kept longer.

Google Analytics for Firebase (OBS-002):

  • Measures how the app is used (screens, sessions, a short list of key in-app events) and which ad campaigns (Google Ads; Meta later) lead to installs and first use.
  • Uses a Firebase app instance ID. We don’t send your name, email, or the text of anything you write or say. VERIFY OBS-002 sends no Supabase user ID (setUserId not called) and only allow-listed events with ids / enums.
  • Google may process this data in the US and elsewhere, under Google’s Firebase terms; Google acts as our processor for Analytics, except where we link it to Google Ads (then Google’s own terms also apply). VERIFY with legal; set the Firebase “data sharing” settings deliberately.
  • Retention: we set Google Analytics data retention to 2 months (the shortest option) for event-level data VERIFY / decide (options 2 or 14 months); reports with totals are kept by Google.
  • iPhone: no advertising identifier (IDFA), no tracking prompt. Campaign results come from Apple’s SKAdNetwork (aggregated, no user ID). Decision open: if we later add ad-network attribution that uses the IDFA (Meta, Google), the app will ask permission first (App Tracking Transparency) and this policy will change before that.
  • Android: Firebase can read the Android advertising ID for campaign attribution. Decision open (VERIFY): keep it (declare in Play, explain here, users can reset / delete it in Android Settings → Privacy → Ads) or disable collection (google_analytics_adid_collection_enabled = false).
  • EEA / UK users: Google Consent Mode v2 consent signals are required for ad measurement there. VERIFY / decide a consent prompt or default “denied” for ad storage / ad user data in those regions (OBS-002).

Website analytics (papersays.com, WEB-011, WEB-012):

  • The website measures which pages are read, whether the 60-second preview is played, and whether the App Store button is tapped. It uses Google Analytics 4 (the same Google property as the app) and our own counts. We switch off Google signals and ad features, send no user ID, name, email or text you type, and no event holds personal data.
  • In the EU, UK and Switzerland, Google Analytics stays off for storage until you press “Accept” on the notice at the bottom of the page; “Decline” keeps it off. Without consent Google may still receive cookieless pings used for modelled totals. Your choice is kept in your browser (local storage) and you can clear it any time.
  • Everywhere else the analytics cookie is on by default and no advertising cookies are set at all.
  • Google Analytics keeps event-level data for 14 months. Our own website counts are anonymous totals (no cookie, no IP address kept with them). Cloudflare Web Analytics measures page speed without cookies. VERIFY with legal: wording per region, Google as processor, the data retention in section 6 and the Android email list in section 2.
  • PostHog (our processor, the same project as the app) also receives the website’s page views and the same events (pages read, preview played, store button tapped). It never records the screen (no session replay), never captures what you type, and honours your browser’s “Do Not Track” setting. In the EU, UK and Switzerland it does not load at all until you press “Accept”; “Decline” keeps it off. Everywhere else it runs without cookies or browser storage (each page view gets a fresh random ID that is forgotten when you leave), unless you pressed “Accept”, which lets it keep a random ID in your browser so visits can be counted as one visitor.
  • When you tap “Get the app” or “Open in app”, that random website ID is added to the link. If you then open the app from that link (or install it from Google Play through it), the app links the website visits to your app account’s internal ID, so we can see which pages lead to installs. Installs through the App Store can’t be linked. Data is stored in PostHog’s US region (us.i.posthog.com, the same project as the app; section 6) under PostHog’s DPA.

Firebase Crashlytics (OBS-001, OBS-003):

  • When the app crashes or hits a serious error, a report goes to Google Firebase Crashlytics so we can fix it. It contains technical data (section 2) and your internal user ID, so we can see which problems one person hit and help them. Kept 90 days by Google VERIFY current Crashlytics retention.

Firebase Performance Monitoring (OBS-003):

  • Measures how fast the app starts, how smoothly screens draw, how long network requests take, and a few timings we add (for example time to first audio). Technical data only (section 2); no content of requests. VERIFY Google’s Performance Monitoring retention (about 90 days in the console).

PostHog (OBS-004, our processor):

  • Shows us how the app is used, one person at a time (a timeline of in-app events and screens), plus errors, session replays and device logs (section 2). Linked to your internal user ID after you sign in; before that, to a random ID. Never your name or email, never the text of your questions, notes, messages or speech.
  • Session replay: a recording of the screens of some sessions (the share is set by us). Every text input is masked, so what you type is never recorded. Replay pauses while hands-free is listening and while the app is in the background.
  • Device logs: after a crash, an error, or when you report a problem, the last minutes of the app’s technical log go to PostHog, with text you typed or said removed.
  • Data is stored in PostHog’s US region (us.i.posthog.com, the founder’s project) under PostHog’s DPA VERIFY (sign / accept the DPA; for EU / UK users this is an international transfer, section 6). Retention: see section 8.
  • Test and staff accounts are marked as internal so they’re left out of our reports.

Opting out: turning off “Share anonymous usage data” in Profile → Privacy turns off all of it on that phone: our own analytics, Firebase Analytics, Crashlytics, Performance Monitoring and PostHog (events, errors, replays and logs). VERIFY (OBS-003 / OBS-004 build) that the one switch covers every tool, and the switch wording (data is linked to the account, so “anonymous” should become “usage data”). Android users can also reset or delete the advertising ID in Android settings.

7. Who processes your data

We use these service providers. They process data for us under their terms. We don’t sell your data. The only data that reaches an advertising company is install-campaign measurement from Firebase to Google Ads (section 6).

ProviderPurposeDataLocation
SupabaseDatabase, sign-in, file storage, server functionsAll account and app data in section 2, technical logsVERIFY region of the production project (BE-025; not yet created)
Apple (App Store, Sign in with Apple, speech recognition, notifications)Payments for Premium (Apple is the seller of record); sign-in; transcription when on-device isn’t availablePurchase and billing details (held by Apple under its own privacy policy; we never receive card details); sign-in identity; audio of on-screen voice input (section 4)Apple
RevenueCatChecks purchases with Apple and tells our server your subscription status (our processor)Our internal account ID (used as RevenueCat’s customer ID; not your name or email), your device’s purchase receipts, subscription status and purchase history (section 2, Purchases)US VERIFY RevenueCat DPA, sub-processors and retention
Google (Google Sign-In, Android speech recognition)Sign-in; transcription on AndroidSign-in identity; audio of on-screen voice inputGoogle
Third-party AI service providersAI answers, note summariesSection 5May be outside your country
A third-party voice providerSpoken answers; optional cloud transcription (off)Section 5May be outside your country
Google Firebase (Analytics, Crashlytics, Performance Monitoring)Usage analytics, install-campaign attribution, crash reports and performance timings (crash reports linked to your internal user ID)Section 6US and other Google locations
PostHogProduct analytics per person, error tracking, session replay (text inputs masked), device logs (our processor)Your internal user ID, in-app events, screens, errors, replays and logs (section 2; never your name, email or the text you type or say)US (us.i.posthog.com); PostHog DPA VERIFY and sub-processors
Google Ads (Meta later)Measuring which ads led to installsCampaign conversions from Firebase (no name, email or content); on Android the advertising ID if keptGoogle
VercelHosts our private admin dashboard (staff only)Staff sessions; dashboard pages read the databaseVERIFY hosting choice (BE-029)

Not used today, will be added here before they are: Firebase Cloud Messaging (push notifications, BE-021..023; same Firebase project), Meta ad attribution, a web-search API for answers (QA-LIVE-022), Google Play billing (Android).

Our staff can see account, support and feedback data in the admin dashboard to run the service and answer requests. They cannot read your notes (there is no admin access to note text; counts only). Authorised staff can read questions and answers, for example to investigate a reported wrong answer. VERIFY / decide: RLS today gives admins “read all” on qa_threads / qa_messages (data-model.md RLS table); either keep this sentence or remove admin read like notes (notes-spec D11).

We may disclose data if the law requires it.

8. How long we keep data

DataKept
Account, preferences, follows, saves, listening progress, Q&A history, learning progressUntil you delete them or your account
NotesUntil you delete them; a deleted note’s text is removed at once, its empty record after 30 days
Support messages and feedbackUntil your account is deleted (deleted with it). VERIFY / decide a fixed period (for example 24 months) for active accounts
Raw analytics events13 months
Usage totals (aggregates)Kept. After account deletion they stay under a new random key that can’t be linked to you (see below)
AI usage records (cost, tokens, timings; no text)Kept for cost control; the link to you is removed when you delete your account
Subscription records (product, store, status, dates, Apple transaction IDs)Kept for {N} years for accounting, tax, refunds and fraud checks (VERIFY {N} with the accountant; likely 6–10 years depending on the controller’s country). After you delete your account they’re kept without your account ID
Purchase events received from RevenueCat (event type, product, price, currency, store, dates, transaction IDs)Same as subscription records. When you delete your account, your account ID and the personal fields in them (customer IDs, aliases, transfer IDs, attributes, email if any) are removed
RevenueCat’s own copyWhile you have an account. When you delete your account, we ask RevenueCat to delete its customer record for you (your internal account ID, purchase receipts and purchase history at RevenueCat) right after our own deletion (PAY-011). Apple keeps its own purchase records under Apple’s privacy policy. VERIFY RevenueCat’s DPA retention wording
Firebase Analytics (Google)Event-level data per our retention setting (2 or 14 months, VERIFY / decide); aggregated reports longer
Crash reports (Crashlytics)About 90 days (VERIFY). Linked to your internal user ID; after you delete your account they’re not deleted one by one but expire on this schedule
Performance data (Firebase Performance Monitoring)About 90 days (VERIFY)
PostHog events and person recordPer PostHog’s retention for our plan (VERIFY: free plan, events about 1 year), and deleted when you delete your account (section 9)
PostHog session replaysAbout 30 days (VERIFY PostHog free plan replay retention)
PostHog device logs and errorsPer PostHog’s retention for our plan (VERIFY)
Hosting logs and backupsPer our hosting provider’s plan. VERIFY Supabase log retention and backup retention for the chosen plan (Pro: daily backups)
On your phoneCached content, settings and an analytics queue until you sign out, delete your account or uninstall. Per-episode hands-free choices (last 50 episodes) stay on the device

9. Deleting your account and your rights

  • In the app: Profile → Delete account. This deletes your account, profile, preferences, follows, saves, listening progress, Q&A history, notes, learning progress, support messages and feedback, and clears the app’s data for you on that phone.
  • Your subscription is not cancelled. Deleting your account (or the app) doesn’t cancel Premium: Apple keeps billing you until you cancel. Cancel first in Settings → your name → Subscriptions; the app reminds you and offers “Manage subscription” before deleting.
  • RevenueCat: right after your account is deleted, we also ask RevenueCat (our purchase processor) to delete its customer record for you. This doesn’t change anything at Apple: your subscription and Apple’s purchase records stay with Apple.
  • What stays, unlinked from you: reports you made about a quiz question (the reason you picked) stay so we can fix the question, without your account. AI usage records (cost and timing, no text) stay without your account. Subscription records and purchase events stay for accounting and tax (section 8) without your account ID; the personal fields in the purchase events are removed.
  • What stays, anonymised: usage totals. Your past analytics events are re-labelled with a random key generated once at deletion and never stored next to your old ID, your device IDs on those events are removed, and the link from your devices to you is deleted. Nothing left identifies you; the totals (for example daily listeners) don’t change.
  • PostHog: right after your account is deleted, our server asks PostHog to delete your person record and its events (if PostHog can’t be reached, the result is logged and we follow up). The app also clears its PostHog ID on that phone. VERIFY PostHog’s deletion timing (events are removed in a background job) and that session replays of the person are removed with it.
  • Firebase data: Firebase Analytics data isn’t linked to your account. Crash reports are linked to your internal user ID, but Google offers no per-user deletion for them, so they expire under the retention above (about 90 days); without your account the ID no longer points to anyone. On account deletion the app calls Firebase resetAnalyticsData() and deletes unsent crash reports. Deleting the app resets the Firebase IDs on that phone. VERIFY / decide: also send the app instance ID to the GA4 User Deletion API (OBS-002).
  • Apple sign-in: we also revoke the app’s access to your Apple ID when you delete your account. VERIFY: not built yet (BE-008, delete-account function); must ship before iOS launch.
  • Without the app: email support@papersays.com from the address on your account, or use the web form at https://papersays.com/delete-account. VERIFY: Google Play requires a web link for account deletion requests (LAUNCH-002).
  • Depending on where you live (for example the EU, UK or California) you may have the right to access, correct, export, restrict or object to processing of your data, and to complain to your data protection authority. Contact support@papersays.com; we answer within 30 days. VERIFY legal bases per purpose (contract: account and features; legitimate interest: analytics, security, with opt-out; consent: microphone) and whether a data export feature is needed (notes can already be exported as Markdown).

10. Children

PaperSays is not meant for children. You must be at least 16 to use it (or the minimum age in your country, if higher). We don’t knowingly collect data from children; if you think a child has given us data, contact us and we’ll delete it. VERIFY minimum age (13 vs 16) with legal; the app has no age check today.

11. Security

Data is encrypted in transit (HTTPS). Access to the database is restricted per user by row-level security; staff access requires an admin account. API keys for AI providers are kept on our servers only, never in the app. VERIFY encryption at rest for the chosen Supabase plan before stating it.

12. Notifications

If you allow notifications, the daily briefing reminder and the “Hands-free is off” notice are scheduled on your phone; no device token is sent to us today. When we add push notifications we’ll store a device token and update this policy.

13. Changes

We’ll post changes here and update the date. If a change is significant (for example a new AI provider or new data use), we’ll tell you in the app before it applies.

14. Contact

{controller} · support@papersays.com