1. Who We Are
Memory Weaver is an independent iOS application. Questions about this policy can be directed to support@memory-weaver.app. References to “we,” “us,” or “our” in this policy refer to the developer of Memory Weaver.
2. What Data We Collect
Data stored only on your device (never sent to us):
- Your flashcard decks, cards, and review history
- PDF files and book content you import into the app
- Spaced repetition scheduling data (SM-2 intervals, ease factors, due dates)
- Streak counts and weekly challenge progress
- App settings and theme preferences
This data lives in a local database on your iPhone or iPad. We have no access to it.
Data processed by our servers when you use the AI feature:
- Your uploaded file: When you submit a PDF or other document, the file is temporarily uploaded to our backend server. Our server extracts text from the page range you select, then discards the uploaded file. The extracted text is then sent to OpenAI to generate flashcard content.
- An anonymous device token: The app generates a random identifier the first time you use the AI feature. This token is stored only on your device and is sent to our server with each AI request solely to track your monthly usage quota. It is not associated with an account, name, email, or Apple ID.
- Subscription status: If you purchase or restore Memory Weaver Plus, RevenueCat receives the anonymous device token as the App User ID and processes product identifiers, purchase status, renewal status, and expiration dates supplied by Apple. We do not receive your payment-card information.
- Request metadata: Our backend server and hosting provider (Render) may log standard request metadata, including timestamps, request size, and response codes, and may transiently capture your IP address. These logs are used for service operation and security monitoring. They are not intentionally linked to your device token or flashcard content.
We do not ask for your name, email address, Apple ID, account credentials, precise location, or payment-card information.
3. How We Use Your Data
AI flashcard generation: When you use the AI feature, the following happens in sequence:
- Your document is uploaded to our backend server over an encrypted HTTPS connection.
- Our server extracts the text from the page range you selected. The uploaded file is then discarded from our server.
- The extracted text is sent to the OpenAI API to generate flashcard content.
- The generated flashcards are returned to your device. OpenAI’s handling of this text is governed by their API data usage policy (see Section 4).
Quota tracking: Your anonymous device token is used solely to count how many AI sessions you have used. During the one-time 30-day free trial, this counter tracks your total trial usage; for Plus subscribers, it resets monthly. It is not associated with your identity.
Subscription verification: Our backend checks RevenueCat for an active Plus entitlement associated with the anonymous device token before applying the Plus monthly AI allowance.
4. Data Sharing and Third Parties
We do not sell, rent, or trade any user data.
OpenAI: Text extracted from your documents is sent to the OpenAI API for flashcard generation. OpenAI processes this data under their API data usage policies. As of the date of this policy, OpenAI does not use API-submitted data to train their models by default. You can review OpenAI’s API data privacy practices at openai.com/enterprise-privacy. We encourage you to review these policies before submitting sensitive material through the AI feature.
Render (backend hosting): Our backend server is hosted on Render. Render may process request metadata including IP addresses as part of standard hosting operations. For details, see render.com/privacy.
Apple: Memory Weaver is distributed through the Apple App Store. Apple may collect analytics and crash data under their own privacy policy, which you can review at apple.com/legal/privacy.
RevenueCat: RevenueCat manages subscription entitlement verification and receives the anonymous App User ID and purchase metadata described above. RevenueCat processes this data under its privacy policy at revenuecat.com/privacy.
5. Data Retention and Deletion
All flashcard data is stored on your device and is deleted when you uninstall the app.
Uploaded documents are discarded from our backend server immediately after text extraction. They are not stored.
Your anonymous device token and quota counter are stored on our backend server. RevenueCat retains subscription records as needed to provide and verify purchases. You may contact us at support@memory-weaver.app to request deletion of records we control; Apple and RevenueCat may retain transaction records where required for billing, fraud prevention, tax, or legal compliance.
Server request logs retained by Render are subject to Render’s own data retention policies.
6. Children’s Privacy
Memory Weaver is a learning and study tool that may be used in educational contexts, including by teenagers. However, the app is not directed at children under 13 and we do not knowingly collect any information from children under 13.
Please do not submit student records, children’s personal information, confidential school records, or other sensitive personal material through the AI feature.
If you are a parent or guardian and believe that a child under 13 has submitted documents through the AI feature, please contact us at support@memory-weaver.app. We will promptly delete the associated quota record and any server records we can reasonably locate.
7. Security
All communication between the app and our backend uses HTTPS (TLS 1.2 or higher). Your local flashcard data is protected by your device’s built-in encryption (enabled when you use a passcode or Face ID/Touch ID).
In the event of a security incident that may affect your data, we will notify affected users as required by applicable law.
8. Your Rights
Because we do not ask for or collect account-level identifying information, there is no personal profile to access, correct, or export on our side. To request deletion of your quota record and any server records we can reasonably locate, contact us at support@memory-weaver.app and we will respond within 30 days of receiving your request.
If you are located in the European Economic Area, United Kingdom, or California, you may have additional rights under applicable privacy laws (GDPR, UK GDPR, CCPA). We believe we process minimal personal data as defined by those laws — primarily transient request metadata on our hosting provider’s infrastructure. We instruct our hosting provider to minimize log retention. EU and California residents are welcome to contact us with any privacy requests.
9. Changes to This Policy
We may update this privacy policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Continued use of Memory Weaver after a change constitutes your acceptance of the revised policy. For material changes — such as the introduction of new data collection, in-app purchases, or new third-party integrations — we will provide advance notice via the App Store update description or within the app before the change takes effect.
10. Contact
If you have questions or concerns about this privacy policy, please contact us:
- Email: support@memory-weaver.app
- Website: memory-weaver.app