Privacy Policy

Version v1.1 · Effective 2026-09-21

PRIVACY POLICY — SAMEVIA

Effective date: 2026-09-21


§1 INTRODUCTION AND SCOPE

This Privacy Policy explains how Samevia ("we", "us", "our") collects, uses, stores, shares, and protects your personal data when you use the Samevia mobile application and related services (collectively, "Service"). This Policy is designed to comply with the EU General Data Protection Regulation (GDPR), GDPR provisions applicable to minors (GDPR-K), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the United States Children's Online Privacy Protection Act (COPPA), and the EU ePrivacy Directive.


§2 DATA CONTROLLER

The data controller responsible for your personal data is Samevia. For all data protection enquiries, rights requests, or complaints, contact us at support@samevia.com with the subject line "Data Protection Request". We will respond within 30 calendar days.


§3 DATA WE COLLECT

We collect the following categories of personal data:


(a) Account data: email address, display name, and securely hashed password provided at registration.


(b) Profile data: age, country of residence, field of interest, daily learning-time preference, and learning-timeline goal, entered during onboarding to personalise your content experience. These onboarding answers are held in encrypted storage on your own device and are not uploaded to our servers; of them, only your display name is transmitted, to Firebase Authentication.


(c) Usage data: feature interactions, quiz answers, content progress, AI prompt inputs, and session metadata, collected solely to deliver and improve the Service.


(d) Technical data: device type, operating system version, app version, anonymised crash reports, and performance traces, collected via Firebase Crashlytics and Firebase Performance Monitoring.


(e) Payment data: subscription status (active, cancelled, or expired) as notified by Google Play, together with the Google Play purchase token and product identifier that our server uses to verify that a subscription is genuine and belongs to your account. We never receive, store, or process your payment card numbers or banking details.


(f) AI assistant content: the question you send to the in-app AI assistant, together with the text of any file and the image you choose to attach to it. Questions and answers are stored so that a repeated question can be answered from cache. An attached image is relayed to the AI model providers listed in §5 in order to produce the answer and is not stored on our servers.


We do not collect advertising identifiers, precise location data, contacts, browser history, or any third-party cross-site tracking identifiers. We never reach into your photo library or your microphone on our own initiative: an image or file leaves your device only when you attach it to an AI question yourself, and voice input is handled by the Android speech-recognition service built into your device, from which Samevia receives the recognised text only and never an audio recording. Spoken output works the other way and does leave your device: when you ask for a lesson to be read aloud, the text of that lesson is sent to Microsoft Azure Speech, which returns the audio, and that audio is kept in your device cache so the same passage is not fetched twice.


§4 PURPOSES AND LEGAL BASIS FOR PROCESSING

(a) Service delivery: providing your account, personalised learning path, and AI-assisted features. Legal basis: performance of a contract (GDPR Article 6(1)(b)).


(b) Safety and security: detecting fraud, abuse, and technical errors. Legal basis: legitimate interests (GDPR Article 6(1)(f)).


(c) Product improvement: analysing aggregated pseudonymised usage patterns to improve content quality. Legal basis: legitimate interests (GDPR Article 6(1)(f)).


(d) Legal compliance: retaining audit logs as required by applicable law. Legal basis: compliance with a legal obligation (GDPR Article 6(1)(c)).


(e) Communications: sending in-app notifications about material changes to Terms or this Policy. Legal basis: legitimate interests (GDPR Article 6(1)(f)).


We do not use your data for advertising, third-party profiling, or any automated decision-making that produces significant legal effects on you.


§5 SUB-PROCESSORS AND DATA SHARING

We share personal data only with the following categories of processors, each bound by the data processing terms of its service agreement:


(a) Supabase Inc. (USA): database hosting in the EU region (Frankfurt, Germany). Data is encrypted at rest using AES-256.


(b) Google LLC (USA): Firebase Authentication, Firebase Crashlytics, Firebase Performance Monitoring, and Google Play billing. Processing is subject to Standard Contractual Clauses for international transfers.


(c) Cloudflare Inc. (USA): CDN and edge computing infrastructure for the public-facing Privacy Policy web page. No personal data is stored beyond standard server access logs retained for a maximum of 24 hours.


(d) AI model providers — OpenRouter Inc. (USA), Groq Inc. (USA), and Google LLC (Gemini API): the text of your AI question, the content of any file you attached, and any image you attached are transmitted to these providers so that an answer can be generated. Samevia does not attach your account identifier, e-mail address, or name to these requests.


(e) Functional Software, Inc., trading as Sentry (USA): application error and crash telemetry. Sentry receives the device model, operating system version, language, application version, an installation identifier, and the technical detail of any error or crash. This is collected only after you accept this Policy, and it stops when you withdraw that acceptance in Settings.


(f) Microsoft Corporation (USA): Azure Speech, used to read lesson text aloud. The text to be spoken is transmitted to Microsoft, which returns synthesised audio. That audio is then stored in your device cache so the same passage does not have to be fetched again. Your account identifier, e-mail address, and name are not attached to these requests.


(g) Paddle.com Market Ltd (United Kingdom): payment processing for subscriptions purchased through the website. Paddle receives your e-mail address and your account identifier in order to take the payment and to give you a link for managing or cancelling the subscription.


We do not sell, rent, license, or otherwise disclose your personal data to advertisers or data brokers.


§6 DATA RETENTION

(a) Account and profile data: retained for the duration of your account and permanently deleted within 30 days of account deletion, in accordance with GDPR Article 17 (right to erasure).


(b) Pseudonymised analytics: retained for a maximum of 24 months from the date of collection.


(c) Audit and compliance logs: retained for 7 years as required by applicable legal obligations.


(d) Crash reports: retained for 90 days on Firebase, after which they are automatically purged.


(e) On-device data: encrypted using SQLCipher AES-256 and deleted immediately upon account deletion or app uninstallation.


§7 YOUR RIGHTS

Depending on your jurisdiction, you have the following rights with respect to your personal data:


(a) Right of access (GDPR Article 15; CCPA/CPRA): obtain a copy of all personal data we hold about you.


(b) Right to rectification (GDPR Article 16): correct inaccurate or incomplete personal data.


(c) Right to erasure (GDPR Article 17; CCPA/CPRA): request deletion of your data. Account deletion is available in Settings, then Account, then Delete Account.


(d) Right to restriction (GDPR Article 18): request that we limit processing of your data in certain circumstances.


(e) Right to data portability (GDPR Article 20): receive your data in a structured, machine-readable format.


(f) Right to object (GDPR Article 21): object to processing based on our legitimate interests.


(g) Right to opt out of sale or sharing (CCPA/CPRA Section 1798.120): California residents may opt out of any sale or sharing of personal data. We do not sell or share personal data for cross-context behavioural advertising.


(h) Right to non-discrimination (CCPA/CPRA Section 1798.125): exercising your privacy rights will not result in denial of service or any other retaliatory treatment.


To exercise any of these rights, use the Privacy controls in Settings or send a written request to support@samevia.com. We will respond within 30 days (GDPR) or 45 days (CCPA/CPRA), with a possible 90-day extension where permitted.


§8 AGE REQUIREMENTS AND CHILDREN'S PRIVACY

The Service is offered to users aged 18 and over. The account holder must be 18 or older, and it is the account holder who accepts this Policy.


A person under 18 may use the Service only through an account created and supervised by a parent or legal guardian. The parent or guardian remains the account holder, accepts this Policy on the minor's behalf, and may exercise every right in §7 on their behalf.


We do not knowingly collect personal data from children under 13 under any circumstances, in compliance with COPPA and GDPR-K. If we become aware that we have collected personal data from a child under 13, we will delete it without undue delay.


Career-track, financial-literacy and market-analysis modules are available only to the adult account holder.


Parents or guardians who believe a minor has provided personal data to us without their consent should contact support@samevia.com. We will delete that data within 30 calendar days.


§9 SECURITY MEASURES

We implement industry-standard technical and organisational measures to protect your personal data:


(a) Data in transit: protected by TLS 1.3 on all API and database connections.


(b) Data at rest on servers: encrypted using AES-256 on Supabase EU-region servers.


(c) Data at rest on device: encrypted using SQLCipher AES-256 in the on-device Room database.


(d) Access controls: role-based access with Row-Level Security enforced at the database layer.


(e) Security monitoring: crash and anomaly reports reviewed within 48 hours; critical security issues acknowledged within 48 hours of disclosure to support@samevia.com.


No system is perfectly secure. In the event of a data breach likely to result in high risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.


§10 INTERNATIONAL DATA TRANSFERS

Your personal data may be transferred to and processed in countries outside your country of residence, including the United States, where data protection laws may differ from those in your home jurisdiction.


For transfers from the European Economic Area to third countries, we rely on Standard Contractual Clauses adopted by the European Commission as the legal transfer mechanism under GDPR Article 46(2)(c). Supabase stores your data on EU-region servers in Frankfurt, Germany, to minimise cross-border transfers wherever possible.


§11 COOKIES AND ANALYTICS

The Samevia mobile application does not use browser cookies. Firebase Analytics and Firebase Performance collect pseudonymised device identifiers and usage telemetry solely to improve application quality, in accordance with the EU ePrivacy Directive. You may opt out of all analytics collection at any time in Settings, then Privacy and Data, then Analytics. Opting out will not affect your access to any Service feature.


The public-facing Privacy Policy web page served via Cloudflare Workers uses no tracking cookies and no advertising scripts. Server access logs are retained for a maximum of 24 hours.


§12 BREACH NOTIFICATION

In the event of a personal data breach, we will: (a) notify the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR Article 33, unless the breach is unlikely to result in risk to the rights and freedoms of individuals; and (b) notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34, including the nature of the breach, the data categories affected, the likely consequences, and the measures taken to address it.


§13 CHANGES TO THIS PRIVACY POLICY

We reserve the right to update this Privacy Policy at any time to reflect changes in our data practices or applicable law. We will notify you of material changes via an in-app notification at least 30 days before the revised Policy takes effect. Your continued use of the Service after the effective date of any revision constitutes your acceptance of the updated Privacy Policy. If you do not agree, you may delete your account before the effective date.


§14 CONTACT AND DATA PROTECTION

Data Controller: Samevia

Data Protection Contact: support@samevia.com (subject: "Data Protection Request")

Security disclosures: support@samevia.com (48-hour acknowledgement SLA)

General enquiries: 5 business days response target

Supervisory authority complaints: You have the right to lodge a complaint with the data protection supervisory authority in your country of residence at any time.