Privacy Policy
This policy explains what personal data Prephive collects, why, who processes it for us, where it is stored, how long we keep it, and how you get it out or delete it. It describes how the app actually works, not a generic template.
On this page: 1. Who is responsible · 2. Short version · 3. What we collect · 4. AI features · 5. Sign-in · 6. No ads, no tracking · 7. Subscriptions · 8. Study Squads · 9. Where data is stored · 10. Retention · 11. Your rights · 12. Saudi PDPL notice · 13. Children · 14. Security · 15. Changes · 16. Contact
1. Who is responsible for your data
The data controller for the personal data described here is:
Prephive (independent developer)
Saudi Arabia
Privacy contact: prephive@quizvaultbox.com
If you have a question about this policy, or want to exercise any of the rights in section 11, write to the privacy contact above.
2. The short version
- We collect the account details you give us (email, name) and the study content you create or upload (notes, questions, photos, voice notes) plus your study activity (what you answered and how you did).
- Optional AI features send the content you choose to Google (Gemini API), which processes it to produce your result and return it to us.
- We use Supabase to store your account and content, and RevenueCat with Apple to run subscriptions.
- We run no advertising, use no advertising identifier (IDFA), and do not track you across other companies' apps or websites.
- You can delete your account and its data from inside the app, and you can ask us for an export.
3. What we collect, and why
The table mirrors the categories declared in our Apple App Privacy label and in the app's iOS privacy manifest. Every category is linked to your account. None of it is used for cross-app or cross-site tracking.
| Data | Examples | Why | Processed by |
|---|---|---|---|
| Email address | The address you sign up with, or the one returned by Google or Apple sign-in (including an Apple private-relay address) | Create and secure your account, sign you in, send essential service messages | Supabase |
| Name | Display name from your profile or from Google/Apple sign-in | Personalise the app and identify you inside a study squad | Supabase |
| User ID | The account identifier we assign you; the subject identifier from Google or Apple | Authenticate you and key every row of your data to your account | Supabase |
| Device ID | A RevenueCat app-user / device-level identifier used at purchase and restore time | Tie a subscription to your account so it survives reinstall and can be restored | RevenueCat |
| Photos or videos | Images, PDFs, and screenshots you choose to import as study material; images you send in a squad | Extract or generate questions from your material; share images with your squad | Supabase Storage; Google (Gemini) only when you use an AI feature |
| Audio data | Voice notes you record in study-squad chat | Deliver voice messages to your squad | Supabase Storage |
| Other user content | Text and notes you paste or upload; the questions, options, and explanations you create or import; squad chat messages | Build, store, and study your question sets; run squad chat | Supabase; Google (Gemini) only for the AI features you trigger |
| Purchase history | Subscription status, receipt validation, entitlement state | Unlock and maintain Premium; restore purchases | RevenueCat, Apple |
| Product interaction | Which questions you answered, right or wrong, streaks, topic accuracy, feature usage | Run your study features (spaced review, stats, study plan, weekly brief) and understand how the app is used | Supabase; aggregated numbers only to Google for the weekly brief |
In Apple's terms. Email, name, and user ID are used for App Functionality and Authentication. Photos/videos, other user content, audio, purchase history, and device ID are used for App Functionality. Product interaction is used for App Functionality and Analytics — meaning our own first-party product analytics only (section 6). None of it is used for Tracking.
What we do not collect. No contacts, no location, no HealthKit or health-record data, no browsing history, no financial account or card numbers (Apple handles payment), and no advertising identifier. This build ships no third-party analytics or crash-reporting SDK; if a future version adds crash reporting we will update this policy, the App Privacy label, and the privacy manifest together, before that version ships.
4. AI features and Google Gemini
Several optional features use Google's Gemini API through our own server-side functions. We call Google only when you take an action that needs it. We never stream your data to Google in the background. Here is exactly what is sent:
- Import questions from a document. Text extracted from your file — and, if the file cannot be parsed cleanly on your device and you opt into AI re-extraction, the original PDF or image itself — is sent so the questions your source already contains can be structured into the app.
- Generate questions from your notes. The notes you upload are sent, and the model composes practice questions using only the vocabulary and facts in your source. A validator on our server rejects any generated question that introduces terms absent from your source.
- Explanation tutor. The question, its topic, the correct answer, and the existing explanation are sent to produce a simpler explanation, a hint, or a memory aid.
- Weekly brief. Only aggregated numbers from your last seven days (questions attempted, number correct, accuracy, and the name of your weakest topic) are sent. The text of your questions is not sent for this feature.
- Categorisation and translation. Question text you import may be sent to suggest a category, or to translate it when you ask.
Google acts as a processor for us: the content is processed to provide the feature you asked for and a result is returned. Text you send to AI features is processed by Google's Gemini API to generate the response; we do not use it to train models of ours. We call the Gemini API through a billed Google Cloud project; under Google's paid-tier API terms, prompts and responses are not used to train Google's models. Google's own handling of data submitted to the Gemini API is governed by Google's terms for that API. Our API keys are held server-side and scrubbed from logs, and we apply per-user daily limits and a monthly budget cap to these features.
5. Accounts and sign-in
You can create an account with email and password, with Sign in with Google, or with Sign in with Apple. Google and Apple return a token plus basic profile fields (email, a name where available, and a stable subject identifier) that we use to create or match your account. If you use Apple's "Hide My Email", we receive only the relay address and never see your real inbox. Authentication is handled by Supabase Auth; we never receive your Google or Apple password.
6. No advertising, no tracking
- No advertising. Prephive shows no ads and belongs to no ad network.
- No IDFA, no tracking prompt. We do not access Apple's Advertising Identifier and we do not combine your data with data from other companies. The iOS privacy manifest declares
NSPrivacyTracking = falsewith no tracking domains. - No third-party tracking SDKs.
- First-party analytics only. The "Analytics" purpose on product interaction means we look at usage inside Prephive to operate and improve it. That stays on our own backend, linked to your account, and is never sold or shared for advertising.
7. Subscriptions and payments
Prephive Premium is an auto-renewable subscription: US$2.99 per month or US$19.99 per year. Payment is processed by Apple through the App Store — we never see or store your card details. We use RevenueCat as our service provider to validate purchases and manage your entitlement; RevenueCat receives and stores your purchase and transaction history and a RevenueCat app-user / device identifier so your subscription can be matched to your account, survive a reinstall, and be restored. Renewal, cancellation, and refunds are governed by the App Store; you manage or cancel a subscription in your Apple ID settings.
8. Study Squads
If you use Study Squads, the text messages, images, and voice notes you send are shared with the other members of that squad and stored on our backend so the conversation persists. Treat squad content as visible to your squad.
9. Where your data is stored
- Account and content: our Supabase project, hosted in the European Union — Central EU (Frankfurt),
eu-central-1(confirmed 25 August 2026), protected by Postgres row-level security so you can reach only your own rows (squad content is shared with squad members by design). - AI processing: Google, via the Gemini API.
- Subscriptions: RevenueCat and Apple.
Google, RevenueCat, and Apple may process data on servers outside your home country, including in the United States. Where a transfer needs a safeguard under applicable law — for example for users in the EU/EEA, the UK, or Switzerland — we rely on the standard contractual clauses and equivalent terms in our agreements with those providers.
10. How long we keep your data
- Account and content (profile, question sets, imported and generated questions, study history, squad messages): kept while your account exists, because the app needs them to work.
- AI processing: the content you submit is processed to return your result, and the structured result is saved to your account. We keep no separate long-term archive of raw prompts beyond what is needed to run and debug the feature. Google's retention of API submissions is governed by Google's terms.
- Subscription records: retained by RevenueCat and Apple for the life of the subscription and as long as tax, accounting, and dispute rules require.
- After deletion: when you delete your account we remove your personal data from our active systems, except limited records we must keep for legal, tax, security, or fraud-prevention reasons. Backups age out on our normal rotation.
11. Your rights and choices
Depending on where you live you may have rights of access, correction, portability, deletion, restriction, objection, and withdrawal of consent. We honour these for every user, wherever they are, as a baseline.
Delete your account — in the app
- Open the Stats tab.
- Tap your account row, then Account.
- Tap Delete account.
- Type
DELETEto confirm.
This deletes your profile, your imported and generated questions and sets, your study history, and your squad content from our active systems, subject to the legal-retention exceptions above. If you signed in with Apple, we also ask Apple to revoke the sign-in token for the app. Deletion does not cancel an active App Store subscription — cancel that separately in your Apple ID settings, as described on our support page.
Everything else
- Export your data: email prephive@quizvaultbox.com from the address on your account and we will send your account and study data in a portable format.
- Correct your data: edit your profile in the app, or write to us.
- Stop AI processing: simply do not use the optional AI features. The rest of the app keeps working.
- Manage your subscription: in your Apple ID / App Store settings.
We may need to verify your identity before acting on a request, and we answer within the period applicable law requires (generally 30 days under the GDPR). Users in the EU/EEA and the UK may also complain to their local data protection authority. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
12. Notice for users in Saudi Arabia (PDPL)
If you are in the Kingdom of Saudi Arabia, the Personal Data Protection Law (PDPL, Royal Decree M/19 of 1443H, as amended) and its Implementing Regulations apply to our processing of your personal data. This section is the notice the PDPL requires; it adds to, and does not replace, the rest of this policy.
- Who is processing, and why. The controller is named in section 1. We collect the data listed in section 3 for the purposes stated beside each item — running your account, storing and studying your content, running the optional AI features you trigger, and managing your subscription. We do not collect personal data we do not need for those purposes.
- Legal basis. We process your personal data because it is necessary to provide the service you asked for under our Terms of Use, and, where you choose to use an optional AI feature, on the basis of your consent to that specific processing. You may withdraw that consent at any time simply by not using those features.
- Whether providing data is required. An email address and a password (or a Google/Apple sign-in) are required to have an account; without them we cannot create one. Everything else — your notes, photos, voice notes, and imported questions — is entirely optional and is collected only when you choose to add it.
- No sale, no advertising, no automated decisions. We do not sell personal data, we run no advertising, and we do not use your personal data for any automated decision-making that produces legal or similarly significant effects for you.
- Transfer outside the Kingdom. Your account and content are stored on our Supabase project in the European Union (Frankfurt), and our processors — Google, RevenueCat, and Apple — may process data in other countries including the United States. This transfer is necessary to perform the service you asked for and to operate the app you have chosen to use. We rely on contractual safeguards with each processor, limit the transfer to what the feature needs, and do not transfer your data to any party for its own purposes.
- Your PDPL rights. You have the right to be informed, to access your personal data, to obtain a copy of it in a readable format, to request correction of anything inaccurate or incomplete, and to request destruction of your personal data when it is no longer needed. Section 11 explains how to exercise each of these — deletion is available in the app, and access, copies, and corrections by email to the privacy contact in section 1.
- Complaints. If you believe we have handled your personal data improperly, contact us first at the privacy address in section 1. You may also complain to the Saudi Data & Artificial Intelligence Authority (SDAIA), the competent supervisory authority under the PDPL.
13. Children
Prephive is built for adults and older students preparing for professional examinations. It is not directed at children, and we do not knowingly collect personal data from anyone below the minimum age of digital consent in their country. If you believe a child has given us personal data, write to the privacy contact in section 1 and we will delete it.
14. Security
We protect your data with encryption in transit, authenticated APIs, Postgres row-level security so users reach only their own rows, server-side handling of AI API keys, and scrubbing of secrets from logs. No system is perfectly secure, so we cannot guarantee absolute security, but we work to protect your information and to respond promptly to any incident as the law requires.
15. Changes to this policy
We may update this policy as the app changes or the law changes. When a change is material we update the date at the top and, where appropriate, tell you in the app or by email.
16. Contact
Prephive (independent developer)
Saudi Arabia
Privacy: prephive@quizvaultbox.com
Support: prephive@quizvaultbox.com