Your data, under your control

Privacy Policy

Effective and last updated: September 8, 2026

1. Scope

This policy explains how Girapphe handles information in the Girapphe website and iOS and Android apps. Girapphe is a private learning and knowledge-review service. We do not automatically harvest historical conversations. Conversation content enters Girapphe only when you deliberately submit selected current-conversation material for review, editing, and approval.

2. Information we process

  • Account data, such as your email address, authentication status, and a service-specific user identifier.
  • Learning data, including notes, reviewed drafts, saved concepts, ratings, progress, and private graph relationships.
  • Technical data needed to operate and secure the service, such as request metadata, locale, guest/session identifiers, rate-limit records, and error logs.
  • Subscription and transaction references, entitlement status, plan, store, renewal status, and provider event identifiers. Girapphe does not collect or store raw payment-card details.
  • Advertising and consent signals needed to show, measure, limit, or remove sponsored cards. The current mobile implementation requests non-personalized ads only after the applicable consent flow permits an ad request.

3. How we use information

We use information to authenticate you, sync your private learning state, generate and review learning cards, provide search and practice, prevent abuse, maintain subscriptions, honor ad-free access, show consent-gated ads, debug failures, and comply with legal obligations. We do not publish your private notes or use them to mutate the public knowledge graph.

4. Service providers

Girapphe uses vendors that process information for specific operational purposes: Clerk for authentication; Neon/Postgres for application data; Cloudflare for hosting and security; Creem for hosted web checkout, subscription management, and tax/payment processing; Superwall, Apple, and Google for mobile purchase and subscription infrastructure; Google Mobile Ads and its consent tooling for mobile advertising; and Expo/EAS for mobile builds and delivery. Each provider handles information under its own terms and privacy commitments.

5. Retention and deletion

Active account and learning data is kept while you use the service. A note moved to Trash is scheduled for permanent deletion after 14 days unless you restore it. When you delete your account, Girapphe deletes your authentication record, private notes, drafts, tokens, graph data, ratings, and progress. Limited billing, fraud-prevention, security, or tax records may be retained where reasonably necessary or legally required, without keeping your live Girapphe account.

Notes created while signed out are tied to the guest session and are automatically deleted after 90 days. Sign in before relying on longer-lived, account-controlled private knowledge.

Deleting a Girapphe account does not itself cancel an App Store or Google Play subscription. Cancel store renewal before deletion if you do not want billing to continue. Girapphe attempts to cancel supported renewing web billing before completing deletion.

6. Your choices and rights

7. Security and international processing

We use access controls, encrypted transport, owner-scoped data queries, secure mobile token storage, bounded requests, and provider signature checks. No system is perfectly secure. Service providers may process data in countries other than your own, subject to their applicable transfer safeguards.

8. Children

Girapphe is not directed to children who cannot legally consent to an online account in their jurisdiction. A parent or guardian who believes a child provided personal information should contact us so we can review and delete it.

9. Changes and contact

We may update this policy as the product or legal requirements change. We will change the effective date and provide additional notice when appropriate. For help, visit Support or email privacy@girapphe.com.