Privacy
Privacy Policy
Vesprit is operated by an individual developer. This policy explains exactly what data Vesprit handles, who else touches it, and what you can do about it. It is written to be read, not to be survived.
Two things are worth saying up front, because they are the two facts most likely to matter to you.
Your study material is stored on our servers. Everything you paste into Vesprit lives in our database, in the United States, for as long as your account exists. Vesprit is not a local-only app and does not claim to be.
We collect product analytics in the app. They are pseudonymous, not anonymous, and they never contain any of your study content. Section 7 says precisely what is in them. This website collects nothing at all.
If anything here is unclear, email support@vesprit.app and ask.
1. The short version
| What | Where it goes |
|---|---|
| The text you paste, and the concepts extracted from it | Our database (Google Firestore, US) |
| Every recall attempt, including the answer you typed | Our database (Google Firestore, US) |
| Your email address and password | Clerk, our sign-in provider (US) |
| The text you paste, for concept extraction only | Anthropic (US), with no identifier attached |
| Product analytics from the app: counts, screens, outcomes | PostHog (US) |
| Crash reports: error traces, no content, no IP address | Sentry (US) |
| Subscription status | RevenueCat (US), and Google Play or the App Store |
We do not sell your data. We do not share it for advertising. Nobody buys access to it. The list above is the whole list.
2. Two parts: the website and the app
This policy covers two separate things, and they collect different data.
- The website, vesprit.app. A marketing site that collects nothing unless you type your email into it. Section 3 covers it.
- The Vesprit app. Requires an account, and is where all study data lives. Sections 4 onward cover it.
Using the website does not create an account and does not connect you to any app data.
3. The website (vesprit.app)
3.1 We do not track you on this website
There are no analytics on vesprit.app. No visitor counting, no page-view tracking, no advertising trackers, no marketing pixels, no session recording, no behavioural profiling, no fingerprinting.
We genuinely do not know that you were here.
3.2 The waitlist form
The only data this website collects is what you type into the waitlist form.
If you enter your email address, we store it so we can tell you when Vesprit is available. If you fill in the optional "what are you preparing for?" field, we store that too. It tells us which exams and certifications the people interested in Vesprit are actually studying for.
That is the entire form. There is no hidden field, no tracking pixel attached to it, and no data broker on the other end.
Your email is held by Kit (formerly ConvertKit), the service that receives the form. You can ask us to remove it at any time by emailing support@vesprit.app, and we will delete it. Joining the waitlist does not create a Vesprit account.
3.3 Fonts
This website loads its typefaces from Google Fonts. That means Google's servers receive your IP address and browser information when the page loads. We do not control that and receive nothing from it. Apart from that font request, and sending the waitlist form if you submit it, the page makes no external requests at all.
3.4 Cookies
Neither the website nor the app sets any cookies.
The website has no analytics to set them for. The app is a native Android app with no browser in it, so cookies are not a thing that can happen there. We checked rather than assumed.
This is why you will not see a cookie banner on vesprit.app. Its absence is the correct outcome, not an oversight.
4. The app: what we store, and why
Everything below is stored in Google Firestore, our database, hosted in the United States. It is keyed to your account. There are exactly three collections, and this is all of them.
4.1 Sources
The full text of everything you paste in, up to 500,000 characters, plus a title, yours or taken from the first line if you did not give one.
We keep the full text for two reasons: so you can go back and read the source, and so extraction can be retried if it fails or improves.
4.2 Concepts
The question-and-answer pairs the AI pulled out of each source. These are what your recall sessions quiz you on.
4.3 Attempts
Every recall attempt you make, including the answer you typed, up to 2,000 characters, and the result: hit, partial, or miss.
This is the record the whole product is built on. The fade score, the at-risk ranking, the timeline and the activity grid are all computed from it. Your typed answer is kept so that AI-assisted grading remains possible later.
Please read section 10 before you rely on being able to remove an individual attempt. You cannot, and the reason is honest but it is a real limitation.
4.4 What we do not store
We want to be specific, because a lot of apps in this category do collect these and we do not.
- No files or uploads. There is no file upload feature in Vesprit today, and nothing is ever written to file storage.
- No photos, camera access, microphone, or contacts.
- No location data of any kind.
- No advertising identifiers.
- No address book, calendar, or device file access.
5. Signing in (Clerk)
Sign-in is email and password, handled by Clerk. Clerk holds:
- Your email address.
- Your password. Clerk holds it, we never see it, and we cannot read it.
- Session records and ordinary authentication metadata, including IP address, device information, and sign-in timestamps. This is how any authentication provider detects suspicious sign-ins.
There is no Google, Apple, or other social sign-in. We do not receive a social profile, because there isn't one.
Your Clerk user ID is the identifier that ties everything together. It is your database key, your analytics identifier, your crash-report identifier, and your subscription identifier. This matters in section 11, where deletion is described.
Clerk processes this data in the United States.
6. The AI extraction (Anthropic)
When you save a source, the text you pasted is sent to Anthropic so that a Claude model can pull testable concepts out of it. This is the only place your study text leaves our own systems, and it is worth being exact about it.
What is sent: the raw text of your source, and a fixed instruction telling the model to extract concepts. That is all.
What is not sent: no user ID, no email address, no document ID, no title, no device information, nothing that identifies you. We check that you are signed in before making the request, but the identity is used only to decide whether the request is allowed. It is not forwarded.
The practical consequence is stronger than the usual promise. Anthropic receives study text that it has no means of connecting to a person, because we never give it anything to connect it to.
How Anthropic handles it: under Anthropic's commercial API terms, inputs and outputs are not used to train Anthropic's models, and are retained only for a limited operational period, with longer retention for content flagged under their trust and safety processes. We are describing someone else's policy here, so read it yourself rather than taking our word: privacy.claude.com.
What is not AI-processed: everything else. The fade score, the at-risk ranking, the timeline and the activity grid are ordinary arithmetic over your own data. No model is involved in them. Your recall answers are never sent to Anthropic or to any AI service.
7. Product analytics in the app (PostHog)
We collect product analytics in the Vesprit app. This section describes what is actually happening, in the present tense, because it is.
PostHog is a processor for the app only. It runs nowhere on vesprit.app, and the two are not connected in any direction. See section 3.1.
7.1 It is pseudonymous, not anonymous
We will not call this anonymous, because it isn't. When you sign in, analytics events are attached to your account ID, and we can connect that ID back to your account. Before you sign in, events carry a random identifier generated on your device. Signing out detaches the identity.
7.2 What we collect
Behavioural events only. Counts, outcomes, and screen names. The complete list:
- A source was added, and how many characters it contained. The length, not the text.
- Extraction succeeded, how many concepts came out, and whether the source was truncated.
- Extraction failed, and whether the model was actually reached.
- The free source limit was reached.
- The paywall was shown, and why.
- Purchase events: started, completed, cancelled, failed, pending, restored.
- A recall session finished, with four tallies: answered, hit, partial, miss.
- Screen views, as a path such as /recall or /timeline.
- App opened, backgrounded, installed, updated.
- Standard device, operating system, and app version properties collected by the analytics SDK.
Notice what these have in common. They are counts, grades, short outcome labels, and product identifiers. No text you wrote appears in any of them.
7.3 What we deliberately do not collect
- No study content of any kind. No source text, no titles, no concept prompts, no recall answers, no email addresses.
- No touch autocapture. It is switched off deliberately, because the labels on our buttons are your concept prompts. Autocapture would leak your study material as a side effect of you tapping around the app.
- No session replay. The module is not installed, and the setting is explicitly off as well.
- No screenshots and no view hierarchy capture.
7.4 Why we can say that with confidence
Two reasons, and the second is the one that matters.
First, it is structural rather than a promise about our intentions. Every analytics event is declared in a single closed list in our code. Sending a property that is not on that list is a compile error, so study content cannot reach analytics by accident. It would take someone deliberately editing one reviewable file.
Second, we checked. We ran the app on a real device and read the resulting event stream in PostHog directly. Every claim above about what is collected was observed happening, and every claim about what is absent was confirmed absent in the actual events, not merely read off a configuration file.
7.5 Where analytics goes
PostHog US Cloud, in the United States. PostHog receives your device's IP address at the network layer and derives coarse location from it, as is standard. We have not enabled IP anonymisation, so we will not claim it. See section 9.
8. Crash reporting (Sentry)
When the app crashes or hits an error, a report goes to Sentry so we can fix it. It contains the error and stack trace, app and device context, and your account ID.
Sentry is configured not to receive personal information: IP address collection and request headers are explicitly disabled, screenshots and view hierarchy capture are off, session replay is not installed, and interface interaction breadcrumbs are dropped before sending, again because our on-screen labels are your concept prompts.
Sentry holds your account ID, the error, and device context. Nothing you wrote. Sentry processes this in the United States.
9. IP addresses
A blanket "we do not collect IP addresses" would be false, so here is the accurate version.
We do not collect or store IP addresses ourselves. We have no server that logs them and no database field that holds one. But your device connects to several services directly, and each of them sees your IP address as an unavoidable part of how the internet works:
- Cloudflare, which hosts our backend and sees every API request.
- Clerk, at sign-in, sign-up, and session refresh, and it retains IP as part of normal authentication security.
- Google / Firebase, because your device reads and writes the database directly.
- PostHog, because analytics events are sent from your device.
- Google Play or the App Store, for purchases.
Anthropic does not see your IP address. Your device never talks to Anthropic. The request comes from our backend, so Anthropic sees our server's address.
Sentry is deliberately configured not to receive it at all.
10. Records you cannot edit or delete individually
This is a genuine limitation and we would rather state it than bury it.
Recall attempts are permanent once written. You cannot edit an attempt, you cannot delete an individual attempt, and neither can we through the normal app. The database rules forbid it, and they forbid it for you and for us equally. The app deliberately shows no edit or delete control on an attempt, because pressing one could only produce an error.
The reason is that the forgetting model is only meaningful over a complete and unedited record. A fade score computed from a history you could prune would be a score you could talk yourself into, which defeats the point of the product.
Individual sources and concepts also have no delete control in the app today.
So the honest statement of what you can remove is: your remedy is deletion at the account level, which removes everything, permanently. Section 11 covers it. If you are exercising a right of erasure under data protection law, full account deletion is how we satisfy it.
11. Deleting your account
There is a fuller walkthrough at vesprit.app/delete-account. The essentials:
11.1 How to request it
Email support@vesprit.app from the address on your account and ask us to delete it. We will confirm and carry it out within 7 days.
Self-service deletion inside the app is being built and is not yet available. When it ships we will update this policy and the deletion page. Until then, the email route above is the way it works, and it is the only way it works.
11.2 What deletion removes
- Everything you have added, including the full text of anything you pasted.
- Every concept extracted from it.
- Your whole recall history, every answer and every result.
- Your account itself: your email address and sign-in details.
11.3 It is permanent, and there are no backups
Our database is on a plan with no backup facility. No scheduled backups are configured and none are possible. Once deletion completes, the data is gone and cannot be recovered, by you or by us. There is no grace period and no restoration path. Most apps cannot say this. We can, and we would rather you knew it before you ask than after.
11.4 What deletion does not do
Deleting your account does not cancel your subscription
Google Play or Apple hold your subscription, and only they can cancel it. If you delete your account without cancelling, you will keep being charged for an app you can no longer open. Cancel in the store first, then ask us to delete.
Step-by-step instructions are on the deletion page.
Deletion does not reach records held by our analytics, crash reporting and subscription providers automatically. Those records are keyed to your account ID, and deleting your account destroys that ID and the email needed to look it up. So there is an order to this:
If you want your analytics, crash-report and subscription records removed too, ask us before your account is deleted. We remove them by hand and confirm when it is done. Once the account is gone we can no longer find those records. At that point they are an identifier with nothing behind it, and they expire on our providers' normal retention schedules.
We will not describe this as automatic, because it isn't. It is a person doing it, in response to your email.
It does not purge our providers' operational logs. Hosting and authentication providers keep ordinary request logs, including IP addresses, which rotate on their own schedules. We cannot delete these per user and will not claim otherwise.
We never held your payment details, so there is nothing there to delete.
12. How long we keep things
We have no automated retention or expiry. Your data lives until your account is deleted. That is the whole retention policy, and we would rather say that than invent a schedule we do not operate.
Waitlist emails on this website are kept until launch, or until you ask us to remove them.
Our processors apply their own retention to logs and telemetry, on their schedules, not ours.
13. Where your data is processed
Everything is processed in the United States. There is no European option anywhere in the stack.
| Service | What it holds | Region |
|---|---|---|
| Google Firestore | Sources, concepts, attempts | US multi-region (nam5) |
| Clerk | Email, password, sessions | US |
| Cloudflare | Backend requests, stores nothing | Global edge, in transit only |
| Anthropic | Study text, with no identifier | US |
| PostHog | Product analytics, from the app only | US |
| Sentry | Crash reports | US |
| RevenueCat | Subscription status | US |
| Google Play / Apple | Payments and subscriptions | Their own infrastructure |
| Kit | Waitlist email and goal, from the website only | US |
Cloudflare runs our backend at the network edge nearest you. It stores nothing, so there is no location where data sits at rest, only handling in transit.
13.1 If you are in the UK or the EU
Using Vesprit means your personal data is transferred to and processed in the United States. The safeguard we rely on for that transfer is the Standard Contractual Clauses, and for UK users the UK International Data Transfer Addendum. Those clauses reach every provider we send your data to except one, by one of two routes. We would rather tell you which is which than write one sentence that covers the gap.
- Agreement executed by us. Kit and Sentry. Kit's data processing agreement binds on account creation rather than by signature; Sentry's was signed on 14 August 2026.
- Incorporated by reference into terms we accepted. Google (Firebase), Cloudflare, Anthropic, Clerk and RevenueCat each carry their data processing terms inside the service agreement itself, so those terms took effect when we accepted it, with no separate signing step in existence to perform. Anthropic's also carries the UK Addendum and the Swiss addendum; RevenueCat's carries the UK Addendum.
- Not yet in place: PostHog. PostHog's agreement needs a separate signing step that we have not completed, so the safeguard above does not currently extend to the product analytics PostHog holds. PostHog holds no data from anyone outside our own testing, and the agreement will be executed before it does.
Some of these providers, Clerk among them, are also certified under the EU-US and UK-US Data Privacy Framework.
We are not going to pretend there is an EU-hosted alternative in place. There isn't. If US processing is not acceptable to you, the honest answer is that Vesprit is not currently a good fit.
14. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to complain to a data protection authority.
Exercise any of them by emailing support@vesprit.app. We will respond within 30 days, and we will not charge you or make you jump through hoops.
Two honest notes on how these work here.
- Erasure is satisfied by full account deletion, described in section 11.
- Correction does not extend to individual recall attempts, for the reason in section 10. If the record matters to you and you want it gone, account deletion removes all of it.
Our legal bases for processing, for UK and EU users: performing our contract with you, for storing and processing your study material and running your account; our legitimate interests in a working, secure, improving product, for crash reporting, security, and in-app product analytics; and consent where the law requires it, which you can withdraw at any time.
We do not ask for cookie consent because we set no cookies and store nothing on your device for tracking purposes. See section 3.4.
15. Children
Vesprit is not for anyone under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has an account, email support@vesprit.app and we will delete it.
Where local law sets a higher minimum age for consenting to online services without a parent, that higher age applies to you.
16. Security
Your data is protected by database rules that allow each account to read and write only its own records, verified on every request. Passwords are held by Clerk and never reach us. Our backend verifies your session before doing anything, and it stores nothing itself.
We are an individual developer, not a company with a security team, and we will not claim more than that. If you find a security problem, email support@vesprit.app and we will treat it seriously.
17. Changes to this policy
If we change what we collect or who processes it, we will update this page and change the date at the top. For anything material, we will tell you in the app before it takes effect.
Two specific commitments.
- If we ever turn analytics off, or turn on something this page says is off, this page changes at the same time.
- If we ever add analytics to this website, this page will say so before it goes live, not after.
18. Contact
Privacy questions, data requests, deletion requests, and complaints all go to the same address, and a person reads it.