PRIVACY POLICY — SAMEVIAN
Effective date: 2026-05-17
§1 INTRODUCTION AND SCOPE
This Privacy Policy explains how Samevian ("we", "us", "our") collects, uses, stores, shares, and protects your personal data when you use the Samevian mobile application and related services (collectively, "Service"). This Policy is designed to comply with the EU General Data Protection Regulation (GDPR), GDPR provisions applicable to minors (GDPR-K), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the United States Children's Online Privacy Protection Act (COPPA), and the EU ePrivacy Directive.
§2 DATA CONTROLLER
The data controller responsible for your personal data is Samevian. For all data protection enquiries, rights requests, or complaints, contact us at support@samevia.com with the subject line "Data Protection Request". We will respond within 30 calendar days.
§3 DATA WE COLLECT
We collect the following categories of personal data:
(a) Account data: email address, display name, and securely hashed password provided at registration.
(b) Profile data: age, country of residence, field of interest, daily learning-time preference, and learning-timeline goal, entered during onboarding to personalise your content experience. These onboarding answers are held in encrypted storage on your own device and are not uploaded to our servers; of them, only your display name is transmitted, to Firebase Authentication.
(c) Usage data: feature interactions, quiz answers, content progress, AI prompt inputs, and session metadata, collected solely to deliver and improve the Service.
(d) Technical data: device type, operating system version, app version, anonymised crash reports, and performance traces, collected via Firebase Crashlytics and Firebase Performance Monitoring.
(e) Payment data: subscription status (active, cancelled, or expired) as notified by Google Play, together with the Google Play purchase token and product identifier that our server uses to verify that a subscription is genuine and belongs to your account. We never receive, store, or process your payment card numbers or banking details.
(f) AI assistant content: the question you send to the in-app AI assistant, together with the text of any file and the image you choose to attach to it. Questions and answers are stored so that a repeated question can be answered from cache. An attached image is relayed to the AI model providers listed in §5 in order to produce the answer and is not stored on our servers.
We do not collect advertising identifiers, precise location data, contacts, browser history, or any third-party cross-site tracking identifiers. We never reach into your photo library or your microphone on our own initiative: an image or file leaves your device only when you attach it to an AI question yourself, and voice input is handled by the Android speech-recognition service built into your device, from which Samevian receives the recognised text only and never an audio recording.
§4 PURPOSES AND LEGAL BASIS FOR PROCESSING
(a) Service delivery: providing your account, personalised learning path, and AI-assisted features. Legal basis: performance of a contract (GDPR Article 6(1)(b)).
(b) Safety and security: detecting fraud, abuse, and technical errors. Legal basis: legitimate interests (GDPR Article 6(1)(f)).
(c) Product improvement: analysing aggregated pseudonymised usage patterns to improve content quality. Legal basis: legitimate interests (GDPR Article 6(1)(f)).
(d) Legal compliance: retaining audit logs as required by applicable law. Legal basis: compliance with a legal obligation (GDPR Article 6(1)(c)).
(e) Communications: sending in-app notifications about material changes to Terms or this Policy. Legal basis: legitimate interests (GDPR Article 6(1)(f)).
We do not use your data for advertising, third-party profiling, or any automated decision-making that produces significant legal effects on you.
§5 SUB-PROCESSORS AND DATA SHARING
We share personal data only with the following categories of processors, each bound by the data processing terms of its service agreement:
(a) Supabase Inc. (USA): database hosting in the EU region (Frankfurt, Germany). Data is encrypted at rest using AES-256.
(b) Google LLC (USA): Firebase Authentication, Firebase Crashlytics, Firebase Performance Monitoring, and Google Play billing. Processing is subject to Standard Contractual Clauses for international transfers.
(c) Cloudflare Inc. (USA): CDN and edge computing infrastructure for the public-facing Privacy Policy web page. No personal data is stored beyond standard server access logs retained for a maximum of 24 hours.
(d) AI model providers — OpenRouter Inc. (USA), Groq Inc. (USA), and Google LLC (Gemini API): the text of your AI question, the content of any file you attached, and any image you attached are transmitted to these providers so that an answer can be generated. Samevian does not attach your account identifier, e-mail address, or name to these requests.
We do not sell, rent, license, or otherwise disclose your personal data to advertisers or data brokers.
§6 DATA RETENTION
(a) Account and profile data: retained for the duration of your account and permanently deleted within 30 days of account deletion, in accordance with GDPR Article 17 (right to erasure).
(b) Pseudonymised analytics: retained for a maximum of 24 months from the date of collection.
(c) Audit and compliance logs: retained for 7 years as required by applicable legal obligations.
(d) Crash reports: retained for 90 days on Firebase, after which they are automatically purged.
(e) On-device data: encrypted using SQLCipher AES-256 and deleted immediately upon account deletion or app uninstallation.
§7 YOUR RIGHTS
Depending on your jurisdiction, you have the following rights with respect to your personal data:
(a) Right of access (GDPR Article 15; CCPA/CPRA): obtain a copy of all personal data we hold about you.
(b) Right to rectification (GDPR Article 16): correct inaccurate or incomplete personal data.
(c) Right to erasure (GDPR Article 17; CCPA/CPRA): request deletion of your data. Account deletion is available in Settings, then Account, then Delete Account.
(d) Right to restriction (GDPR Article 18): request that we limit processing of your data in certain circumstances.
(e) Right to data portability (GDPR Article 20): receive your data in a structured, machine-readable format.
(f) Right to object (GDPR Article 21): object to processing based on our legitimate interests.
(g) Right to opt out of sale or sharing (CCPA/CPRA Section 1798.120): California residents may opt out of any sale or sharing of personal data. We do not sell or share personal data for cross-context behavioural advertising.
(h) Right to non-discrimination (CCPA/CPRA Section 1798.125): exercising your privacy rights will not result in denial of service or any other retaliatory treatment.
To exercise any of these rights, use the Privacy controls in Settings or send a written request to support@samevia.com. We will respond within 30 days (GDPR) or 45 days (CCPA/CPRA), with a possible 90-day extension where permitted.
§8 CHILDREN'S PRIVACY
The Service is not directed to children under 13 years of age. We do not knowingly collect personal data from children under 13 without verifiable parental consent, in compliance with COPPA and GDPR-K.
Users between the ages of 13 and 17 must obtain verifiable parental or legal guardian consent before using any career-track, financial-literacy, or market-analysis module restricted to users aged 18 and older under ILO Convention 138.
If we become aware that we have collected personal data from a child under 13 without the required parental consent, we will delete that data without undue delay. Parents or guardians who believe their child has provided personal data without consent should contact us immediately at support@samevia.com.
§9 SECURITY MEASURES
We implement industry-standard technical and organisational measures to protect your personal data:
(a) Data in transit: protected by TLS 1.3 on all API and database connections.
(b) Data at rest on servers: encrypted using AES-256 on Supabase EU-region servers.
(c) Data at rest on device: encrypted using SQLCipher AES-256 in the on-device Room database.
(d) Access controls: role-based access with Row-Level Security enforced at the database layer.
(e) Security monitoring: crash and anomaly reports reviewed within 48 hours; critical security issues acknowledged within 48 hours of disclosure to support@samevia.com.
No system is perfectly secure. In the event of a data breach likely to result in high risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
§10 INTERNATIONAL DATA TRANSFERS
Your personal data may be transferred to and processed in countries outside your country of residence, including the United States, where data protection laws may differ from those in your home jurisdiction.
For transfers from the European Economic Area to third countries, we rely on Standard Contractual Clauses adopted by the European Commission as the legal transfer mechanism under GDPR Article 46(2)(c). Supabase stores your data on EU-region servers in Frankfurt, Germany, to minimise cross-border transfers wherever possible.
§11 COOKIES AND ANALYTICS
The Samevian mobile application does not use browser cookies. Firebase Analytics and Firebase Performance collect pseudonymised device identifiers and usage telemetry solely to improve application quality, in accordance with the EU ePrivacy Directive. You may opt out of all analytics collection at any time in Settings, then Privacy and Data, then Analytics. Opting out will not affect your access to any Service feature.
The public-facing Privacy Policy web page served via Cloudflare Workers uses no tracking cookies and no advertising scripts. Server access logs are retained for a maximum of 24 hours.
§12 BREACH NOTIFICATION
In the event of a personal data breach, we will: (a) notify the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR Article 33, unless the breach is unlikely to result in risk to the rights and freedoms of individuals; and (b) notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34, including the nature of the breach, the data categories affected, the likely consequences, and the measures taken to address it.
§13 CHANGES TO THIS PRIVACY POLICY
We reserve the right to update this Privacy Policy at any time to reflect changes in our data practices or applicable law. We will notify you of material changes via an in-app notification at least 30 days before the revised Policy takes effect. Your continued use of the Service after the effective date of any revision constitutes your acceptance of the updated Privacy Policy. If you do not agree, you may delete your account before the effective date.
§14 CONTACT AND DATA PROTECTION
Data Controller: Samevian
Data Protection Contact: support@samevia.com (subject: "Data Protection Request")
Security disclosures: support@samevia.com (48-hour acknowledgement SLA)
General enquiries: 5 business days response target
Supervisory authority complaints: You have the right to lodge a complaint with the data protection supervisory authority in your country of residence at any time.