Study Scripts — Privacy Policy

Effective date: 1 January 2026

This Privacy Policy describes how Study Scripts (“Study Scripts”, “we”, “us”, or “our”) handles information when you use the Study Scripts mobile application (the “App”). We are committed to protecting your privacy and being transparent about our practices.

By using the App, you agree to this Privacy Policy.

1. Summary

• We do not sell your personal data.

• Notes, bookmarks, and app data are stored on your device. If you enable iCloud Sync, your bookmarks (and related metadata) are stored in your private iCloud account via Apple’s CloudKit to sync across your devices.

• Purchases and subscriptions are processed by Apple via StoreKit; we do not receive your payment card details.

• We use Firebase Analytics to understand aggregate app usage and improve the App. See “Third‑Party Services” and “Information We Collect” for details.

• We may process your Apple Push Notification service (APNs) device token to send you push notifications you opt into; we do not use the token for tracking across apps.

• We may generate and store a pseudonymous install ID on our Cloudflare backend to support push delivery, rate limiting, abuse prevention, or feature configuration; the install ID is not used for advertising or cross‑app tracking.

• You can contact us at contact@studyscripts.com.

2. Information We Collect

• Personal Information

We do not directly collect personal information (e.g., name, email, address) within the App.

• Notes, Bookmarks, and In‑App Content

By default, notes, bookmarks, and related content you view or store in the App remain on your device. If you enable iCloud Sync, your bookmarks (and related metadata such as title, URL, folder, tags, and timestamps) are stored in your private iCloud account using Apple’s CloudKit to sync across your devices. We do not receive or store your bookmarks or their contents on our servers, and we do not have access to your iCloud account. Apple provides and operates iCloud and CloudKit under its own terms and privacy policies.

• Purchase and Subscription Information

Purchases and subscriptions are handled by Apple’s App Store using StoreKit. We do not receive your full payment details. We may receive limited, non‑identifying transaction information from Apple (e.g., product identifiers, purchase status) to validate subscriptions and unlock content.

• Diagnostic and Analytics Information

We use Firebase Analytics (a service provided by Google) to collect non‑identifying, aggregated usage information to help us understand how the App is used and improve reliability and user experience. Examples include screens viewed, feature interactions, approximate location (country/region), device and OS versions, and app version. Firebase Analytics is configured for anonymous, first‑party analytics only. We do not access or use advertising identifiers (such as IDFA), and we do not track users across apps or websites owned by other companies. We do not use Firebase Analytics to collect your notes, bookmarks, or other in‑app content.

If enabled in our configuration, Firebase may also collect crash/diagnostic signals or performance metrics necessary to maintain service quality. We do not combine Firebase Analytics data with information that directly identifies you.

• Device and Usage Information (Minimal)

The App may perform minimal on‑device checks (e.g., app version, OS version) to ensure compatibility and functionality.

• Push Notifications and APNs Device Token

If you opt in to receive push notifications, Apple may provide us (via the App) with a device token issued by the Apple Push Notification service (APNs). The device token is a pseudonymous identifier used solely to deliver push notifications to your device. We do not use the device token to track you across apps, and we do not combine it with information that directly identifies you.

• Install ID (Cloudflare)

We may generate and store a pseudonymous install identifier (“install ID”) associated with your app installation to support service functionality such as push delivery routing, rate limiting, abuse prevention, and feature configuration. The install ID does not contain your name, email, or payment information and is not used for targeted advertising or cross‑app tracking.

3. How We Use Information

• To provide core App functionality, including browsing content and bookmarking.

• To provide optional iCloud Sync for bookmarks across your devices when you enable this feature.

• To process and validate purchases and subscriptions through Apple’s StoreKit to determine feature access.

• To understand aggregate usage and improve reliability and user experience through Firebase Analytics and on‑device diagnostics.

• To maintain the security and stability of the App.

• To deliver push notifications you opt into by using your APNs device token.

• To support service operations (e.g., push routing, rate limiting, abuse prevention, and feature configuration) using a pseudonymous install ID on Cloudflare.

4. Data Storage and Retention

• Local Storage

Notes, bookmarks, settings, and app data are stored on your device. This data remains until you remove it or uninstall the App.

• iCloud Storage (If Enabled)

If you enable iCloud Sync, your bookmarks and related metadata are stored in your private iCloud account via Apple’s CloudKit. This data persists in iCloud until you remove it (e.g., by deleting bookmarks in the App) or disable iCloud Sync. We do not control Apple’s iCloud retention policies. You can manage iCloud storage in your device settings.

• Purchases and Receipts

Apple maintains your purchase history and receipts. We do not control Apple’s retention policies. You can manage your subscriptions in your Apple ID settings.

• Analytics Data

Firebase Analytics retains event data according to Google’s/Firebase’s standard retention periods, which may vary by region and product configuration. We use default or reduced retention where appropriate for our use case. For details, see Google’s Privacy Policy and Firebase Data Processing and Retention documentation.

• Push Tokens and Install IDs

We collect APNs device tokens to deliver push notifications to your device. Apple refreshes or invalidates these tokens as devices change or when you disable notifications. We use these tokens solely for notification delivery and related operational purposes (e.g., delivery reliability and troubleshooting), and we do not use them to track you across apps or websites.

We also generate an app-specific install identifier (“install ID”) that helps with operational needs such as push routing, rate limiting, abuse prevention, and feature configuration. The install ID is not linked to your identity and is used only for app functionality and operations. It is retained only as long as necessary for these purposes and is deleted or rotated when no longer required or upon reasonable request where technically feasible.

5. Third‑Party Services

• Apple App Store and StoreKit

Used for purchases, subscriptions, and receipt validation. Your payment processing and account management are handled by Apple under Apple’s terms and privacy policies.

• Apple iCloud and CloudKit (Optional Sync)

If you enable iCloud Sync, Apple’s iCloud and CloudKit services store your bookmarks and related metadata to synchronize across your devices. This storage is associated with your Apple ID and is governed by Apple’s terms and privacy policies. We do not receive or store your bookmarks on our servers.

• Apple Push Notification service (APNs)

If you opt in to push notifications, APNs delivers notifications to your device using a device token. The token is a pseudonymous routing identifier used solely for delivering notifications. Apple processes push delivery under its terms and privacy policies.

• Cloudflare (Backend and Storage)

We may use Cloudflare (e.g., Workers, KV/R2, queues, or similar services) to operate secure, performant backend functionality and to store a pseudonymous install ID and/or push routing data. Cloudflare processes this data under its own terms and privacy policies and implements security controls to protect data in transit and at rest. We do not use Cloudflare to serve targeted advertising or to profile users across unrelated services.

• Firebase Analytics (Google)

We use Firebase Analytics to collect aggregated usage information to help us understand how the App is used and to improve features and reliability. Firebase may receive device identifiers, app instance identifiers, and usage events (e.g., screens viewed, feature interactions). We do not use Firebase for targeted advertising, and we do not sell your personal data.

You can learn more about Firebase’s data practices here: https://firebase.google.com/support/privacy

Google’s Privacy Policy: https://policies.google.com/privacy

• Content Delivery (Static Assets)

The App may load remote images or other content assets via signed URLs from a storage provider or CDN over HTTPS. This is standard web content delivery and does not involve your personal data being uploaded to us.

All third‑party services operate under their own terms and privacy policies.

6. Security

We implement reasonable technical and organizational measures to protect information handled by the App. Because the App stores your notes and bookmarks on your device, you can further protect your data using your device’s built‑in security features (e.g., passcode, Face ID/Touch ID). If you enable iCloud Sync, bookmarks stored in iCloud are protected by Apple’s iCloud security and your Apple ID settings. APNs device tokens and install IDs processed via our Cloudflare backend are protected using industry‑standard security measures (e.g., TLS in transit, restricted access, and least‑privilege controls). No system is completely secure; you use the App at your own risk.

7. Children’s Privacy

The App is not directed to children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us at contact@studyscripts.com and we will take appropriate action.

8. Your Choices and Controls

• Notifications: You can enable or disable push notifications at any time in your device settings. Disabling notifications will prevent further use of your device token for push delivery.

• Analytics controls: You can limit analytics collection by adjusting your device settings (e.g., “Allow Apps to Request to Track” on iOS; reset or limit advertising identifiers). Where supported, the App may also provide an in‑app control to reduce analytics collection.

• Enable or disable iCloud Sync for bookmarks in the App’s settings.

• Stop syncing by turning off iCloud for the App in your device settings. Turning off sync may keep existing bookmarks on your device and in iCloud until you delete them.

• Delete local data by uninstalling the App from your device.

• Manage or cancel subscriptions in Settings → Apple ID → Subscriptions.

• Restore previously purchased items using the “Restore Purchases” option in the App.

9. International Users

We do not operate servers to store your notes or bookmarks. Static content assets may be delivered over global content delivery networks (CDNs) via HTTPS. If you access our website or hosted content, your requests may be routed through servers outside your country. If you enable iCloud Sync, iCloud storage and processing are provided by Apple and may involve data centers outside your country, as governed by Apple’s policies. Firebase Analytics is provided by Google and may process data on servers located outside your country. Cloudflare may process the pseudonymous install ID and push routing data on servers in regions it operates. See the respective providers’ privacy policies for details.

10. Legal Bases (EEA/UK Users)

Where applicable under the GDPR/UK GDPR:

• Performance of a Contract: To provide the App’s core functionality; to deliver push notifications you opt into; and to provide optional bookmark synchronization via iCloud/CloudKit when you enable this feature.

• Legitimate Interests: To understand aggregate app usage and improve reliability and security using Firebase Analytics and diagnostics; to operate backend services (e.g., Cloudflare) for security, rate limiting, abuse prevention, and feature configuration using a pseudonymous install ID, in a manner that respects user privacy.

• Compliance with Legal Obligations: To comply with applicable laws, regulations, and valid legal requests.

11. Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, or restrict certain processing of your information. Because the App does not collect personal data on our servers, most data is stored on your device and under your control. If you contact us regarding rights requests, we will explain what we can reasonably do given our data‑minimization approach, and we will provide information we hold (e.g., configuration details, pseudonymous install ID where applicable) where possible.

• EEA/UK: You may have rights under GDPR/UK GDPR (access, rectification, erasure, restriction, portability, objection).

• California (CCPA/CPRA): We do not sell or share personal information as defined by the CCPA/CPRA. You may have rights to know, delete, correct, and limit use of sensitive information (not collected by us). You can exercise rights by contacting us at contact@studyscripts.com.

12. Links to Other Sites

The App and our website may contain links to external sites (e.g., Terms of Use, Privacy Policy pages, support pages). We are not responsible for the content or privacy practices of those sites. Please review their privacy policies.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Effective date” above and posting the updated policy on our website and/or within the App. Your continued use of the App after changes become effective constitutes acceptance of the updated policy.

14. Contact Us

If you have questions or requests regarding this Privacy Policy, please contact:

Email: contact@studyscripts.com