Privacy Policy
Effective 16 September 2026
What the apps I publish collect, why they collect it, who else handles it, and how to get all of it deleted.
01Who this policy covers
I am Reuben Chagas Fernandes, an independent software developer based in Goa, India. I build and publish the mobile and web applications this policy refers to as the Apps. For the purposes of data protection law, I am the data controller for the personal data described here.
This policy applies to every App published under my developer accounts on the Apple App Store and Google Play, and to this website at reuben-fernandes.xyz. Where an individual App publishes its own privacy policy, that policy applies to that App instead of this one.
You can reach me about anything in this document at 18reuchagasfernandes@gmail.com.
02What I collect
I collect only what an App needs in order to work. Depending on which App you use, and which features you use inside it, that can include:
- Account information — your email address, display name and an authentication identifier, collected when you create an account. This is what lets you sign in and reach your data from more than one device.
- Conversation content — the prompts, messages, translations and model responses produced while you use an App. These are stored so your history is still there when you come back to it.
- Images you provide — photos you select from your library or capture with the camera so that an App can describe, translate or transform them.
- Subscription status — whether you hold an active subscription or purchase, as reported to the App by Apple or Google. I never receive or store your card number, billing address or any other payment details.
- Technical and diagnostic data — App version, operating system version, device model, language and region settings, and crash and error reports used to diagnose faults.
What I do not collect
I do not collect precise location, contacts, calendar entries, health or fitness data, biometric identifiers, or advertising identifiers. The Apps carry no advertising SDKs and no third-party analytics or tracking SDKs. I do not sell or rent personal data, I do not share it with data brokers, and I do not use your content to build advertising profiles.
03Why I use it, and on what basis
- To provide the App you asked for — creating and securing your account, sending your prompts to a model and returning the answer, saving your history, and unlocking paid features. Legal basis: performance of a contract with you.
- To keep the service working and safe — fixing crashes, investigating faults, preventing abuse, fraud and automated misuse, and enforcing the Terms of Service. Legal basis: my legitimate interest in a secure and functioning service.
- Optional device permissions — camera and photo library access are requested only at the moment a feature needs them. Legal basis: your consent, which you can withdraw at any time in your device settings.
- To meet legal obligations — keeping records of purchases for tax and accounting purposes, and responding to lawful requests. Legal basis: compliance with a legal obligation.
I do not use your conversations or your images to train my own models, and I do not use them for marketing.
04AI processing and the companies involved
The Apps do not run large language models on my own hardware. When you send a prompt, a message or an image, it is transmitted over an encrypted connection to a third-party AI provider, which generates the response and returns it to the App. That transmission is how the Apps work, and it cannot be switched off while still using the AI features.
The providers and service companies that may process your data on my behalf are:
- Cohere Inc. (Canada) — text, translation and vision inference. See the Cohere privacy policy.
- Google LLC / Google Ireland Limited (Gemini API) — text and vision inference. See the Google privacy policy.
- MongoDB, Inc. (MongoDB Atlas) — the managed database where account records and conversation history are stored. See the MongoDB privacy policy.
- Apple Inc. and Google LLC — app distribution, in-app purchases and subscription management on their respective stores.
These companies act as processors or sub-processors under their own terms and security commitments. They are permitted to handle your data in order to deliver the service to you, not for their own unrelated purposes.
Please do not put sensitive information into a prompt. Avoid submitting government identifiers, financial account details, health records, passwords, or other people's personal data. Anything you type or upload leaves your device and is processed by the providers listed above.
05Where data is stored, and for how long
Account records and conversation history are stored in MongoDB Atlas. The AI providers process your prompts and images on their own infrastructure. This means your data may be processed in, or transferred to, countries other than the one you live in — including India, the European Union and the United States. Where data leaves the European Economic Area or the United Kingdom, the transfer relies on the safeguards those providers maintain, such as Standard Contractual Clauses.
I keep data only as long as it is useful to you or required of me:
- Conversations and saved images — kept until you delete them individually, or until you delete your account.
- Account records — kept for the life of your account, then erased within 30 days of a deletion request.
- Crash and diagnostic logs — kept for up to 90 days, then deleted or reduced to anonymous aggregates.
- Purchase and tax records — kept for as long as tax and accounting law requires, which in India can be up to eight years. These records show that a transaction happened; they do not contain your conversations.
06Deleting your data and your account
You can delete individual conversations at any time from inside the App. You can also delete your entire account from within the App, without emailing me first and without any waiting period: open Settings, choose Account, then Delete Account, and confirm.
Deleting your account permanently removes your account record, your email address, your stored conversations and any images attached to them. Deletion is completed within 30 days, and copies held in encrypted backups are overwritten within 90 days. If you would rather I did it for you, email 18reuchagasfernandes@gmail.com from the address on the account.
Two things worth knowing. Removing the App from your device does not delete your account or the data held for it — use Delete Account first. And deleting your account does not cancel a paid subscription: subscriptions are billed by the app store, so cancel separately in your Apple ID subscription settings or in Google Play.
07Your rights over your data
Wherever you live, you can ask me for a copy of the data I hold about you, correct it if it is wrong, delete it, restrict or object to how it is used, or have it sent to you in a portable format. You can also withdraw a consent you previously gave, without that affecting anything done beforehand.
- If you are in the EEA, the UK or Switzerland — these are your rights under the GDPR and equivalent UK law. You also have the right to lodge a complaint with your national data protection authority.
- If you are in India — under the Digital Personal Data Protection Act, 2023 you have the right to access, correct, complete, update and erase your data, the right to grievance redressal, and the right to nominate someone to exercise your rights on your behalf if you die or become incapacitated. I act as the grievance officer for the Apps and can be reached at the email address below.
- If you are in California — I do not sell or share personal information as those terms are defined by the CCPA, and you will never be treated differently for exercising a privacy right.
To exercise any of these, email me from the address on your account so that I can confirm it is really you. I answer within 30 days, and sooner where the law requires it.
08Children
The Apps are not directed at children and I do not knowingly collect personal data from a child. Under India's Digital Personal Data Protection Act, 2023, processing the data of anyone under 18 requires verifiable parental consent, and the Apps are not intended for use by under-18s without it. In the EEA and the United Kingdom the equivalent threshold is between 13 and 16, depending on the country.
If you believe a child has provided me with personal data, email me and I will delete the account and its contents promptly.
09How the data is protected
- All traffic between the Apps, my backend and the AI providers runs over TLS.
- The database is access-controlled and reachable only by the App's backend, using credentials held in secret storage and never shipped inside the App.
- Passwords, where an App uses them, are stored only as salted hashes. I never see your password in readable form.
- Access to production data is limited to me, and only when it is needed to investigate a fault or a request from you.
No system is perfectly secure and I cannot promise absolute security. If a breach affects your personal data, I will notify you and the relevant regulator without undue delay, as applicable law requires.
10Changes to this policy
If this policy changes, the revised version is published on this page with a new effective date. When a change materially affects how your data is handled, I will tell you inside the App or by email before it takes effect. Continuing to use an App after a change takes effect means you accept the updated policy.
11Contact
Reuben Chagas Fernandes — independent developer, Goa, India.
Email, including for data protection requests and grievances: 18reuchagasfernandes@gmail.com
See also the Terms of Service, which govern your use of the Apps.