At a glance
Collected
- Email and user ID from Sign in with Apple
- Questions transcribed from your photos, and your practice history, synced via Supabase (Seoul)
- Cropped figures — illustrations and diagrams that cannot be rendered as text
- Page photos you send to create questions (sent to Google Gemini)
- Question content, notes, queries, and figure crops you send for explanations (sent to OpenAI)
- Anonymous usage analytics
Never collected
- The original page photos are never stored on our servers
- No location, contacts or browsing history
- No ads and no advertising identifiers
- No third-party analytics SDKs
- No sharing or publishing to other users
The full policy below is the authoritative version.
Privacy Policy
Effective: 2026-08-23 · Last updated: 2026-08-30
1. Overview
This Privacy Policy explains how Qpeat (“the App”) collects, uses, and protects your personal information.
2. Information we collect
- Email address — Provided by Apple during Sign in with Apple, including private relay emails. Used for authentication and account identification.
- User ID — A unique identifier provided by Apple. Used for syncing and account management.
- User content — The passages, questions, choices, and answers transcribed from your photos, the notes you write, your folders and tags, and your practice history. Used for syncing across devices.
- Figure crops — Illustrations, photos, and diagrams that cannot be rendered as text are stored as cropped images so the question still works as printed. They are kept in a private bucket only you can read.
- AI processing data — The page photo you submit when creating questions is sent to the Google Gemini API. When you ask for an explanation or a suggested answer, that question's stem, choices, and passage, the notes you wrote on it, the query you typed, and any figure crops attached to it are sent to the OpenAI API. Neither request carries your email address, account identifier, or purchase information, and the page photo is never sent to OpenAI (see section 3).
- Purchase history — The fact that a subscription was purchased, renewed, or cancelled, and when it expires. Payment itself is handled by Apple; we never receive payment details such as card numbers. Used only to determine whether your subscription is active and to lift your usage limits accordingly.
- Usage analytics — Anonymous usage events (for example, which features you use and how often) along with app and OS version, used only to analyze and improve the App. Tied to a randomly generated install identifier, and to your account identifier when you are signed in. Never used for advertising or tracking.
3. Information we do not collect
- The original page photos — They are never stored on our servers. A photo is used only while your request to create questions is being processed, and is discarded once the response is returned. The only images retained are the figure crops described in section 2.
- Location data
- Contacts
- Search or browsing history
- Health or fitness data
- Advertising identifiers (the App shows no ads)
4. Third-party services
- Apple — Sign in with Apple: Handles user authentication. Apple's privacy policy applies.
- Supabase — Authentication, sync, and figure storage: Data is stored on Supabase cloud servers in the Seoul region, South Korea.
- RevenueCat — Subscription state: Handles subscription purchases, renewals, and cancellations on our behalf. Your account identifier and the purchase information issued by Apple are passed to RevenueCat. RevenueCat's privacy policy applies.
- Google Gemini — Turning photos into questions: The page photos described in section 2 are sent to the Google Gemini API. Google's data handling policy applies.
- OpenAI — Suggested answers and AI explanations: The question content, notes, query, and figure crops described in section 2 are sent to the OpenAI API. OpenAI's data handling policy applies.
The App shows no ads and uses no third-party analytics SDKs (such as Firebase); usage analytics is processed only on servers we operate, and we do not sell or share your data for marketing purposes.
5. AI subprocessors and international transfers
Reading questions out of a photo, and generating explanations and suggested answers, are entrusted to the two providers below. The requests are made by our server, not by the app; the API keys live only on the server.
- Google LLC — Converting the questions in a photo into text
- OpenAI, L.L.C. — Generating suggested answers and explanations
Both involve a transfer of data outside South Korea, on the following terms.
- Destination country — United States
- When and how — At the moment you request question creation (Google) or an explanation or suggested answer (OpenAI), over an encrypted connection (HTTPS).
- What is transferred — Google: the page photo you took. OpenAI: the question's stem, choices, and passage text, the notes and query you entered, and the figure crops attached to the question (up to 3 per question, up to 8 for a batched request).
- Purpose — Carrying out the entrusted work described above
- Retention — Discarded once the request has been processed. Each provider may retain it for a limited period for abuse monitoring; for OpenAI that period is up to 30 days.
- If you would rather not — Simply do not use question creation from photos, or AI explanations and suggested answers. Both run only when you explicitly request them, and declining leaves every other feature available.
Both providers state that content sent through their APIs is not used to train their AI models.
6. Nothing is shared with other users
The App has no feature for sharing or publishing your questions to anyone else. Stored questions and figures are readable only from your own account, enforced by row-level security.
7. Data retention
Your data is retained until you delete your account. Upon account deletion, your questions, practice history, folders, tags, figure images, and authentication information are permanently removed. Usage analytics is kept only in aggregate, with the identifier pointing to you stripped out.
One thing does remain: an anti-abuse hash. The free credits granted at sign-up are limited to one per person, and that limit would mean nothing if deleting and re-creating an account issued them again. So we keep the bare fact that credits were granted, as an irreversible hash and a timestamp. When you delete your account, the part of that record pointing to your account is cleared; the remaining hash cannot identify you or be linked back to any other data.
8. Your rights
- Access — View all your questions and practice history within the app.
- Export — Export any set of questions as a printable PDF worksheet.
- Deletion — Delete individual questions and practice records at any time, or your whole account via Me → Delete Account, which takes effect immediately.
9. Security
All communication is encrypted via HTTPS. Requests to create questions or fetch explanations are verified using user authentication tokens. The App does not store passwords, as it only supports Sign in with Apple.
10. Children's privacy
The App is not directed at children under the age of 13, and we do not knowingly collect personal information from children.
11. Changes to this policy
This policy may be updated from time to time. Changes will be reflected by updating the “Last updated” date above.
- 2026-08-30 — Added OpenAI as the provider handling explanations and suggested answers, and set out the AI subprocessors and international transfers in section 5.
- 2026-08-23 — Initial version.