Prephive

Privacy Policy

Last updated: 25 August 2026 · Effective: 25 August 2026 · applies to Prephive version 1.0 and later.

This policy explains what personal data Prephive collects, why, who processes it for us, where it is stored, how long we keep it, and how you get it out or delete it. It describes how the app actually works, not a generic template.

Prephive is a study aid, not a medical device. It gives no medical advice, diagnosis, or treatment. Please do not upload patient-identifiable information or confidential exam material you are not allowed to share.

On this page: 1. Who is responsible · 2. Short version · 3. What we collect · 4. AI features · 5. Sign-in · 6. No ads, no tracking · 7. Subscriptions · 8. Study Squads · 9. Where data is stored · 10. Retention · 11. Your rights · 12. Saudi PDPL notice · 13. Children · 14. Security · 15. Changes · 16. Contact

1. Who is responsible for your data

The data controller for the personal data described here is:

Prephive (independent developer)
Saudi Arabia
Privacy contact: prephive@quizvaultbox.com

If you have a question about this policy, or want to exercise any of the rights in section 11, write to the privacy contact above.

2. The short version

3. What we collect, and why

The table mirrors the categories declared in our Apple App Privacy label and in the app's iOS privacy manifest. Every category is linked to your account. None of it is used for cross-app or cross-site tracking.

DataExamplesWhyProcessed by
Email addressThe address you sign up with, or the one returned by Google or Apple sign-in (including an Apple private-relay address)Create and secure your account, sign you in, send essential service messagesSupabase
NameDisplay name from your profile or from Google/Apple sign-inPersonalise the app and identify you inside a study squadSupabase
User IDThe account identifier we assign you; the subject identifier from Google or AppleAuthenticate you and key every row of your data to your accountSupabase
Device IDA RevenueCat app-user / device-level identifier used at purchase and restore timeTie a subscription to your account so it survives reinstall and can be restoredRevenueCat
Photos or videosImages, PDFs, and screenshots you choose to import as study material; images you send in a squadExtract or generate questions from your material; share images with your squadSupabase Storage; Google (Gemini) only when you use an AI feature
Audio dataVoice notes you record in study-squad chatDeliver voice messages to your squadSupabase Storage
Other user contentText and notes you paste or upload; the questions, options, and explanations you create or import; squad chat messagesBuild, store, and study your question sets; run squad chatSupabase; Google (Gemini) only for the AI features you trigger
Purchase historySubscription status, receipt validation, entitlement stateUnlock and maintain Premium; restore purchasesRevenueCat, Apple
Product interactionWhich questions you answered, right or wrong, streaks, topic accuracy, feature usageRun your study features (spaced review, stats, study plan, weekly brief) and understand how the app is usedSupabase; aggregated numbers only to Google for the weekly brief

In Apple's terms. Email, name, and user ID are used for App Functionality and Authentication. Photos/videos, other user content, audio, purchase history, and device ID are used for App Functionality. Product interaction is used for App Functionality and Analytics — meaning our own first-party product analytics only (section 6). None of it is used for Tracking.

What we do not collect. No contacts, no location, no HealthKit or health-record data, no browsing history, no financial account or card numbers (Apple handles payment), and no advertising identifier. This build ships no third-party analytics or crash-reporting SDK; if a future version adds crash reporting we will update this policy, the App Privacy label, and the privacy manifest together, before that version ships.

4. AI features and Google Gemini

Several optional features use Google's Gemini API through our own server-side functions. We call Google only when you take an action that needs it. We never stream your data to Google in the background. Here is exactly what is sent:

Google acts as a processor for us: the content is processed to provide the feature you asked for and a result is returned. Text you send to AI features is processed by Google's Gemini API to generate the response; we do not use it to train models of ours. We call the Gemini API through a billed Google Cloud project; under Google's paid-tier API terms, prompts and responses are not used to train Google's models. Google's own handling of data submitted to the Gemini API is governed by Google's terms for that API. Our API keys are held server-side and scrubbed from logs, and we apply per-user daily limits and a monthly budget cap to these features.

Please do not put anything into an upload, note, photo, or voice note that you would not want processed by a third-party AI service — in particular no patient-identifiable information.

5. Accounts and sign-in

You can create an account with email and password, with Sign in with Google, or with Sign in with Apple. Google and Apple return a token plus basic profile fields (email, a name where available, and a stable subject identifier) that we use to create or match your account. If you use Apple's "Hide My Email", we receive only the relay address and never see your real inbox. Authentication is handled by Supabase Auth; we never receive your Google or Apple password.

6. No advertising, no tracking

7. Subscriptions and payments

Prephive Premium is an auto-renewable subscription: US$2.99 per month or US$19.99 per year. Payment is processed by Apple through the App Store — we never see or store your card details. We use RevenueCat as our service provider to validate purchases and manage your entitlement; RevenueCat receives and stores your purchase and transaction history and a RevenueCat app-user / device identifier so your subscription can be matched to your account, survive a reinstall, and be restored. Renewal, cancellation, and refunds are governed by the App Store; you manage or cancel a subscription in your Apple ID settings.

8. Study Squads

If you use Study Squads, the text messages, images, and voice notes you send are shared with the other members of that squad and stored on our backend so the conversation persists. Treat squad content as visible to your squad.

9. Where your data is stored

Google, RevenueCat, and Apple may process data on servers outside your home country, including in the United States. Where a transfer needs a safeguard under applicable law — for example for users in the EU/EEA, the UK, or Switzerland — we rely on the standard contractual clauses and equivalent terms in our agreements with those providers.

10. How long we keep your data

11. Your rights and choices

Depending on where you live you may have rights of access, correction, portability, deletion, restriction, objection, and withdrawal of consent. We honour these for every user, wherever they are, as a baseline.

Delete your account — in the app

  1. Open the Stats tab.
  2. Tap your account row, then Account.
  3. Tap Delete account.
  4. Type DELETE to confirm.

This deletes your profile, your imported and generated questions and sets, your study history, and your squad content from our active systems, subject to the legal-retention exceptions above. If you signed in with Apple, we also ask Apple to revoke the sign-in token for the app. Deletion does not cancel an active App Store subscription — cancel that separately in your Apple ID settings, as described on our support page.

Everything else

We may need to verify your identity before acting on a request, and we answer within the period applicable law requires (generally 30 days under the GDPR). Users in the EU/EEA and the UK may also complain to their local data protection authority. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

12. Notice for users in Saudi Arabia (PDPL)

If you are in the Kingdom of Saudi Arabia, the Personal Data Protection Law (PDPL, Royal Decree M/19 of 1443H, as amended) and its Implementing Regulations apply to our processing of your personal data. This section is the notice the PDPL requires; it adds to, and does not replace, the rest of this policy.

13. Children

Prephive is built for adults and older students preparing for professional examinations. It is not directed at children, and we do not knowingly collect personal data from anyone below the minimum age of digital consent in their country. If you believe a child has given us personal data, write to the privacy contact in section 1 and we will delete it.

14. Security

We protect your data with encryption in transit, authenticated APIs, Postgres row-level security so users reach only their own rows, server-side handling of AI API keys, and scrubbing of secrets from logs. No system is perfectly secure, so we cannot guarantee absolute security, but we work to protect your information and to respond promptly to any incident as the law requires.

15. Changes to this policy

We may update this policy as the app changes or the law changes. When a change is material we update the date at the top and, where appropriate, tell you in the app or by email.

16. Contact

Prephive (independent developer)
Saudi Arabia
Privacy: prephive@quizvaultbox.com
Support: prephive@quizvaultbox.com