PRIVACY

Privacy Policy

Effective date: July 26, 2026

PopEar is an iOS app that helps you practice English listening using curated YouTube clips and a spaced-repetition review system. This policy explains what we collect, how we use it, and your rights over it.

We keep this simple because the app is simple: no ads, no advertising trackers, no selling data, no marketing profiling. Beyond your learning activity, the only data we collect is first-party usage analytics and crash reports, used solely to fix bugs and improve the app — both described below.

What we collect

Anonymous account identifier

  • When you first open the app, Supabase generates an anonymous user ID for you. This ID is not tied to your name, email, phone, or any real-world identity. You can use PopEar fully without providing any personal information.
  • If you later choose to upgrade to a permanent account (for example by linking an email), we will collect only the email address you provide at that point.

Learning activity

  • Which clips you watch and when (watch history).
  • Your progress within a clip (step completion, playback position, phase within Step 2).
  • Your ratings of clip difficulty.
  • Sentences you save and the flashcards they become.
  • Spaced-repetition review outcomes (cards reviewed, your ratings, timestamps).
  • Derived scores (vocabulary score, listening score, daily streak).

App preferences

Settings you configure inside the app, including your native language, learning goal, and skill level. These are stored both on your device and on our servers so they persist across reinstalls and across devices.

Device information

Technical information the app needs to run (iOS version, device model). We do not build a device fingerprint and we do not use this for advertising.

Usage analytics

To understand which features actually help people learn — and where they get stuck — we record a small set of in-app events. These are derived signals, not the content of what you do:

  • When you open the app.
  • Which learning steps you reach in a clip, and when you move between them.
  • Whether a fill-in-the-blank answer was correct, revealed, or wrong — the result only, never the text you type.
  • When you replay a sentence, and at what playback speed.
  • When you tap a highlighted vocabulary word (the curated word itself, not anything you enter).
  • When you switch between typing and tap mode, and when you open review.

These events are stored on our own Supabase backend — there is no third-party analytics company involved. Each event carries your anonymous account ID, a random per-install ID, and a per-session ID so we can follow a single session, but nothing that identifies you as a real person.

Crash and error reports

When the app hits a crash or an unexpected error, it sends a diagnostic report to Sentry, our error-monitoring provider. A report includes what went wrong (an error message and stack trace), your device model and iOS version, your IP address, and a short trail of the in-app actions leading up to it, associated with your anonymous account ID so we can tell whether a bug hit one person or many. Sentry derives an approximate location (roughly city level) from that IP address, which helps us see whether a problem is specific to one country or network; we do not use it for anything else, and we never collect GPS or precise location. We deliberately do not capture screenshots, screen recordings, or the text you type.

What we do not collect

  • No name, phone number, GPS or precise location, contacts, photos, health data, or any identifier we don't need.
  • No advertising SDKs, ad networks, or cross-app tracking.
  • No selling, renting, or sharing your data with advertisers or data brokers.
  • No screen recordings, screenshots, or capture of the text you type. The usage analytics and crash reports described above are first-party and diagnostic — never used for advertising or resale.

How we use your data

We use the data above solely to:

  • Deliver the learning experience (play clips, track progress, run spaced repetition).
  • Personalize which clips are recommended to you based on your in-app activity and skill level.
  • Diagnose bugs, monitor crashes, and understand which features help learners so we can improve the app.

We do not use your data for advertising, profiling outside the app, or any purpose not listed here.

Where your data is stored

  • On your device: progress and flashcard data is stored locally on your iPhone using SQLite and AsyncStorage. Your Supabase session token is stored in the iOS Keychain.
  • On our servers: the same data is synced to a Supabase Postgres database so you don't lose progress if you reinstall or switch devices. Supabase, Inc. is our backend provider; their privacy policy is at supabase.com/privacy.
  • With Sentry: crash and error reports are sent to Sentry's infrastructure in the European Union for diagnosis.

All data in transit is encrypted with HTTPS/TLS. Server-side access is restricted by Row Level Security so each user can only read and write their own rows.

International data transfers

Our backend runs on Supabase's infrastructure in Singapore, and crash reports are processed by Sentry in the European Union. Depending on your location, your data may be processed in or transferred to these or other countries as part of normal cloud service operations. Where required by law (such as for users in the European Union or United Kingdom), we rely on standard contractual clauses or equivalent legal mechanisms to safeguard your data during transfer.

Third parties

PopEar uses a small, deliberate set of third-party services:

  • Supabase: backend database, authentication, and file storage. The data described above is stored on Supabase infrastructure.
  • Sentry (Functional Software, Inc.): crash and error monitoring. When the app hits a crash or error, a diagnostic report is sent to Sentry so we can find and fix it; these reports are processed on Sentry's infrastructure in the European Union. Their privacy policy is at sentry.io/privacy.
  • YouTube: video clips play through YouTube's official iframe player. When you watch a clip, your device communicates with YouTube directly to stream the video, and YouTube's privacy policy applies to that interaction (policies.google.com/privacy). We do not control what YouTube collects during playback, and PopEar does not tell YouTube who you are. By using PopEar, you are also bound by the YouTube Terms of Service, which you can find at youtube.com/t/terms.
  • Apple: distributes the app via the App Store under Apple's own privacy practices.

We do not use any third-party SDK for advertising, ad targeting, cross-app tracking, or selling your data. Our usage analytics run on our own Supabase backend, not a third-party analytics service.

Data retention

  • Learning activity (watch history, flashcards, reviews) is kept as long as your account exists, because it's what makes the app useful.
  • If you delete your account using the in-app button, your server-side data — including the usage-analytics events tied to it — is removed immediately. If you request deletion by email, we remove your server-side data within 30 days.
  • Diagnostic crash reports sent to Sentry age out automatically under Sentry's retention schedule; they are not erased by the in-app delete, but they hold only the technical diagnostic data described above, tied to an anonymous ID with no real-world identity.
  • Local data on your device is removed when you delete the app. However, your account credentials are stored in the iOS Keychain, which persists across app uninstalls. This means reinstalling PopEar on the same device will restore your existing anonymous account along with all server-side data. To fully delete your account and all associated data, use the in-app delete option or request it by email (see Your Rights below).

Your rights

At any time you can:

  • Access your data: email us and we will provide a machine-readable export.
  • Delete your data: the fastest way is in the app: open Settings, tap Delete my data, and confirm. This immediately removes your account and all associated data from our servers, wipes local data on your device, and signs you out. If you can't access the app, email us with the subject line "Delete my account" along with the anonymous user ID; we will delete your server-side data within 30 days and confirm by reply.
  • Ask questions: email us about anything in this policy.

If you are in the European Union, United Kingdom, or California, you have additional rights under GDPR, UK GDPR, or CCPA, including access, correction, deletion, portability, and objection. Exercise them by contacting us at the email above.

Children

PopEar is not directed at children under 16, and we do not knowingly collect data from children under 16. We do not actively verify age beyond the App Store's age rating system and the parental controls available on iOS. If you believe a child has used the app, contact us and we will delete their data.

Security

  • Data in transit is encrypted with TLS.
  • Session tokens on iOS are stored in the Keychain, which is hardware-backed.
  • Server data is protected by Supabase's security controls and per-user Row Level Security policies.

No system is perfectly secure, but we follow industry-standard practices and only collect what the product actually needs.

Changes to this policy

We may update this policy as the app evolves. The July 26, 2026 update added the Usage analytics and Crash and error reports sections to describe first-party diagnostic data the app now collects; it did not add advertising, tracking, or any sale of your data. When we make material changes we update the effective date at the top of this page, and where a change would meaningfully expand what we collect, we will surface a notice in the app.

Contact

Email: [email protected]