In short. Capture and Think stay on this device. Cloud AI runs only when you tap Fix text, and then we send that note — not your whole library. Optional My GitHub upload sends Markdown to your repository. This version has no in-app purchases or subscriptions.
1. Who we are
Serendipity (“the app”, “we”). Privacy questions, complaints, and account deletion: contact@shadow-speak.com · https://serendipity-legal.pages.dev/delete.html.
2. Purposes, items, retention
This is what can leave the device in this version.
| Purpose | Items | Kept |
|---|---|---|
| Fix text, only when you run it | The note text you asked to fix | For the request. The proxy does not keep the body |
| Account, free cap, abuse limits | Email, account id, auth token, quota counts, request IP | While the account exists. Deleted within 30 days of a deletion request. IP is a rate-limit key, not a city or country feature |
You can refuse sign-in and Fix text and still type and review notes. Only the capped cloud feature is limited.
3. What stays on the device
- Notes, topics, thoughts, and any link graph
- Photo attachments and dictation text
- Settings, theme, language
- GitHub repo name and write token — not sent to our servers
Capture and Think work without an account. Uninstall or in-app delete removes local notes. We do not hold a copy.
4. Cloud AI — Fix text
- Nothing is sent until you tap Fix text
- We send that note text, not photo binaries or the whole library
-
Path: device → our proxy (Cloudflare Workers) → Google Gemini API
(
generativelanguage.googleapis.com). The model is currently gemini-3.8-flash. We use only the paid API (a Cloud project with billing), not the unpaid quota. We do not turn on Grounding with Google Search. If the provider changes, this policy changes - A free daily cap applies. Google sign-in carries the cap across reinstalls
- We do not train or sell public models on your notes. On the paid API, Google does not use prompts or responses to improve its products. The abuse-monitoring log is described in section 10
5. Jump (off the screens)
Jump remains in the code but is not on the screens of this store build. If a later update turns it on, a run sends only the cited cards, and this policy plus Play Data safety ship the same day.
6. Account
Google sign-in (Supabase Auth) is for the cloud-AI cap. It does not sync your library. App Google sign-in is not Google Drive.
7. My GitHub (optional)
“Upload now” sends Markdown to your GitHub repository. It does not pass through our servers. The token stays on the device. Deleting those files is done on GitHub.
8. Permissions
- Camera — take a photo for a note
- Photos — Android system photo picker, not permanent gallery access
- Microphone and speech recognition — dictation. The OS speech service may process audio. We do not store the audio file
- Notifications — only if you turn them on
9. Processors
- Cloudflare, Inc. — proxy, quota storage, this page
- Supabase — optional account
- Google — optional OAuth
-
Google — Fix text generation (Gemini API,
generativelanguage.googleapis.com, model gemini-3.8-flash) - GitHub — your direct upload, not our processor
They run the product. We do not build advertising profiles from notes.
10. International transfer
Note text for Fix text goes to Google’s Gemini API
(generativelanguage.googleapis.com) over HTTPS at the
moment you run it. Google does not name one country for this API. The
paid-service terms (effective 23 March 2026) say prompts and responses
logged to detect prohibited-use violations may be stored transiently
or cached in any country in which Google or its agents maintain
facilities. Google may keep that log for
55 days.
We do not keep the note body after the reply. Account data (email, id,
token, quota, IP) is processed by Cloudflare, Supabase, and Google,
which may be in the United States or another region they operate, over
HTTPS. Refuse by not signing in and not running Fix text. Capture and
Think still work. Contact is in section 1. If the provider changes, we
bump this version.
11. Deletion
- On-device notes: you delete them or uninstall
- Account and quota: we delete them after a request, within 30 days. We do not merely freeze the account
- Fix-text bodies: not kept by us after the reply. Google’s abuse-monitoring log is described in section 10
Start deletion in Settings (“Request account deletion”) or on the web page. GitHub files and on-device notes are not on our servers, so this request does not erase them.
12. Children
The app is not directed at children. We do not knowingly collect personal information from children. It is not a Families app.
13. Not in this version · if we add paid features later
This version does not collect purchase history, payment card data, advertising ids, note-body analytics, or a full-library backup. There are no in-app purchases.
Optional paid features may be added later. Before that update ships, we will publish a new version of this policy and the Play Data safety form on the same day. The rules we will follow are fixed now:
- Digital goods are billed only through Google Play Billing
- We would receive a product id, purchase token, subscription state, and the existing account id — not your card number
- The processor is Google Play. RevenueCat may confirm the entitlement
- Capture and Think stay usable without payment and without an account. Notes are not sold or used for ads
- The app cannot grant paid status by itself. Only a server-checked entitlement counts
Extra product-improvement collection, if added, stays off until you opt in. Crash reports, if enabled, are a stack and a short message with no note body.
14. Changes
We update the date and version on this page when practices change. Earlier versions: 1.5 (2026-09-24), 1.4 (2026-09-23), 1.3 (2026-09-23), 1.2 (2026-09-01), 1.1 (2026-08-03), 1.0 (2026-08-02).