Privacy Policy
Draft. This document has not been reviewed by a lawyer. It is published so that what the app does is stated plainly, and it must be reviewed before any store submission.
What this build actually is. Your study material and progress live entirely on your own device. There is no account, no sign-in, no cloud sync and no server holding your study material. The app sends anonymous usage statistics (section 5), which you can turn off, and on iPhone and iPad it connects to RevenueCat, the service that will handle in-app purchases (section 6). Nothing described below assumes a feature that is not in the app you are using.
1. The short version
Zynlo is built to work without knowing anything about you. In this build, your study material and progress stay on your device. There is no account to create, none of your material is uploaded, and we do not hold a copy of your study material or your review history. The app sends anonymous usage statistics, which are not linked to you or your cards, and you can turn them off (section 5). On iPhone and iPad it also connects to RevenueCat, which will handle in-app purchases (section 6).
2. What is stored, and where
All of the following is kept in your browser or app storage, on your device only:
- The subjects and cards you import or create
- Your review history, due dates and scheduling state
- Your attempt history, including answers you type while studying
- Your settings, saved views, and anything you have archived or moved to Trash
None of it is transmitted to us.
3. Answers you type
When you type an answer, Zynlo keeps it so it can show you what you keep getting wrong. You can delete every typed answer at any time from You → Privacy → Forget my typed answers. Doing that does not affect your schedule or your review history, because they are kept separately.
4. What we never send anywhere
Zynlo does not send your study material to any AI service. If you choose to generate material using ChatGPT, Claude, Gemini or another assistant, that happens in that assistant’s own app, under its own privacy policy, entirely outside Zynlo. Zynlo only ever sees the file you bring back and import yourself.
5. Anonymous usage statistics
To understand how Zynlo is used, the app sends a small record, called an event, when certain things happen. This is on unless you turn it off, and you can turn it off at any time in You → Privacy → Share anonymous usage stats. Turning it off stops events at once: anything not yet sent is discarded, and the random install ID described below is deleted from your device.
Each event contains only:
- the event’s name (listed below) and the time it happened
- a random install ID, made up on your device the first time an event is recorded. It is not derived from your device, your name or any account, and it is not linked to your subjects, your cards or your answers
- the platform (iOS, Android or web) and the Zynlo version number
- a few details belonging to that event: which tab was opened and for how many seconds, how long the app was open, the hour of the day it was opened, the kind of notification tapped (for example a study reminder), and which of Zynlo’s own announcements was shown, closed or tapped
- on the web only, with the first event: the campaign tags in the link that brought you to Zynlo (utm_source, utm_medium, utm_campaign, utm_content, utm_term) or, if there are none, the domain of the website that linked to it (the domain only, never the page)
The events this build sends are app_open, session_end,
screen_time and tab_view (opening the app, how long it stays open, which tab
you are on), onboarding_complete (finishing the first-run setup), notif_open
(opening Zynlo from one of its notifications), and broadcast_shown,
broadcast_dismiss and broadcast_cta (Zynlo’s own in-app
announcements). The app’s code also contains events for features this build does not have, such
as sign-in, purchases and sharing. They cannot fire here, and if any of those features is switched on
they will be listed on this page first.
No event ever contains your subjects, cards, answers, name, email address, contacts or location, and no advertising identifier is read.
Where it goes. Events are stored in Zynlo’s own database, hosted by Supabase in the European Union (Ireland). No third-party analytics service receives them, they are not used for advertising, and they are never sold or shared. As with any connection, the server sees your IP address when an event arrives; it is not saved in the event. The app also asks the same server whether Zynlo has an announcement to show, such as a new version being available; that request sends nothing about you.
How long it is kept. Events are kept for 13 months and then deleted automatically.
6. In-app purchases on iPhone and iPad (RevenueCat)
Zynlo uses RevenueCat, a service run by RevenueCat, Inc., to handle in-app purchases in the iPhone and iPad app. No purchases are offered yet. The iOS app already connects to RevenueCat each time it starts, so that once purchases exist it can tell which ones this installation owns. The web app and the Android app do not contact RevenueCat.
When the iOS app connects, RevenueCat receives:
- an anonymous ID that RevenueCat creates for this installation. It is not your name, email address or Apple ID, and it is not the install ID used for usage statistics in section 5
- information about the app and the device that RevenueCat’s software needs to work and, as with any connection, your IP address
- an attribution token from Apple, which lets RevenueCat tell whether the app was installed from an Apple Search Ads advertisement. Apple provides this token without the App Tracking Transparency prompt
- once purchases exist, the purchases you make in Zynlo, so it can confirm what you own and restore it on a new device
Your subjects, cards and answers are never sent to RevenueCat. When purchases are offered, Apple takes the payment and RevenueCat records what you are entitled to; neither Zynlo nor RevenueCat sees your card details. RevenueCat processes this information under its own privacy policy.
7. What this build does not do
Stated explicitly, because a privacy policy that lists capabilities the app does not have is worse than useless. This build has:
- No accounts or sign-in, and so no email address on file
- No cloud sync or server-side backup
- No third-party analytics, and no tracking across other apps or websites (the anonymous usage statistics in section 5 go only to Zynlo’s own database)
- No crash or error reporting sent off the device
- No advertising, and no advertising SDK
- No push notifications, and so no device token
- No purchases offered yet. When they are, Apple takes the payment and RevenueCat records what you are entitled to (section 6), so Zynlo never holds payment details
If any of these is added, this policy will be updated before it is switched on.
8. Cookies
Zynlo sets no tracking cookies. It uses your browser’s local storage to hold the data described in section 2, which never leaves your device, and the random install ID and web campaign tags described in section 5, which leave it only inside usage events and are deleted when you turn usage statistics off.
9. Children
Zynlo is not directed at children under 13, and asks no one for their name, email address or any other contact details.
10. Your rights
Rights such as access, correction, export and erasure normally apply to data a company holds about you. We hold none of your study material. In practice this means you already have complete control: your material is on your device, the App can export all of it to a file you keep, and you can erase it yourself at any time. See Deleting your data. The usage events in section 5 carry only a random install ID, so we cannot find them from your name or email; turning usage statistics off deletes that ID from your device, and every event is deleted after 13 months.
11. Changes to this policy
If what the App does changes, this policy will be updated to match before the change ships.
12. Contact
Questions about privacy: [email protected]