Your data, under your control
Privacy Policy
Effective and last updated: September 8, 2026
1. Scope
This policy explains how Girapphe handles information in the Girapphe website and iOS and Android apps. Girapphe is a private learning and knowledge-review service. We do not automatically harvest historical conversations. Conversation content enters Girapphe only when you deliberately submit selected current-conversation material for review, editing, and approval.
2. Information we process
- Account data, such as your email address, authentication status, and a service-specific user identifier.
- Learning data, including notes, reviewed drafts, saved concepts, ratings, progress, and private graph relationships.
- Technical data needed to operate and secure the service, such as request metadata, locale, guest/session identifiers, rate-limit records, and error logs.
- Subscription and transaction references, entitlement status, plan, store, renewal status, and provider event identifiers. Girapphe does not collect or store raw payment-card details.
- Advertising and consent signals needed to show, measure, limit, or remove sponsored cards. The current mobile implementation requests non-personalized ads only after the applicable consent flow permits an ad request.
3. How we use information
We use information to authenticate you, sync your private learning state, generate and review learning cards, provide search and practice, prevent abuse, maintain subscriptions, honor ad-free access, show consent-gated ads, debug failures, and comply with legal obligations. We do not publish your private notes or use them to mutate the public knowledge graph.
4. Service providers
Girapphe uses vendors that process information for specific operational purposes: Clerk for authentication; Neon/Postgres for application data; Cloudflare for hosting and security; Creem for hosted web checkout, subscription management, and tax/payment processing; Superwall, Apple, and Google for mobile purchase and subscription infrastructure; Google Mobile Ads and its consent tooling for mobile advertising; and Expo/EAS for mobile builds and delivery. Each provider handles information under its own terms and privacy commitments.
5. Retention and deletion
Active account and learning data is kept while you use the service. A note moved to Trash is scheduled for permanent deletion after 14 days unless you restore it. When you delete your account, Girapphe deletes your authentication record, private notes, drafts, tokens, graph data, ratings, and progress. Limited billing, fraud-prevention, security, or tax records may be retained where reasonably necessary or legally required, without keeping your live Girapphe account.
Notes created while signed out are tied to the guest session and are automatically deleted after 90 days. Sign in before relying on longer-lived, account-controlled private knowledge.
Deleting a Girapphe account does not itself cancel an App Store or Google Play subscription. Cancel store renewal before deletion if you do not want billing to continue. Girapphe attempts to cancel supported renewing web billing before completing deletion.
6. Your choices and rights
- Review, edit, restore, or delete private notes from My Notes.
- Change supported ad privacy choices from Account in a configured mobile build.
- Restore purchases or manage a subscription through Creem, the App Store, or Google Play according to where you subscribed.
- Export private knowledge or permanently delete individual import jobs without deleting already approved knowledge.
- Delete your account and associated product data from the web or the in-app Account screen.
- Contact privacy@girapphe.com for access, correction, deletion, or privacy questions.
7. Security and international processing
We use access controls, encrypted transport, owner-scoped data queries, secure mobile token storage, bounded requests, and provider signature checks. No system is perfectly secure. Service providers may process data in countries other than your own, subject to their applicable transfer safeguards.
8. Children
Girapphe is not directed to children who cannot legally consent to an online account in their jurisdiction. A parent or guardian who believes a child provided personal information should contact us so we can review and delete it.
9. Changes and contact
We may update this policy as the product or legal requirements change. We will change the effective date and provide additional notice when appropriate. For help, visit Support or email privacy@girapphe.com.