PRIVACY POLICY
Your lectures are yours.
Overview
AstraLect turns recordings and imported media into timestamped transcripts and study notes. This policy explains what the iOS app and its cloud service process, why they process it, and the choices available to you.
Data stored on your device
Recording sessions, local drafts, downloaded audio, cached lectures, playback state, and app preferences can be stored on your device. A guest can keep an unsubmitted draft locally without creating an account. Removing the app normally removes local data, subject to the behavior of your device backups.
Account and lecture data
When you sign in with Apple or Google, we receive the account identifiers and profile details that the provider makes available, such as an email address or display name. Our service uses a Supabase account identifier to keep your account, library, Credits balance, and subscription state separate from other users.
If you ask AstraLect to process a lecture in the cloud, we process the title and metadata you provide, the audio or video audio track, its duration, the transcript, timestamps, generated study notes, source mappings, and processing status. These materials are used to provide your library, transcription, note generation, playback, export, and account synchronization.
Cloud processing providers
Cloud processing is initiated by your action and requires a signed-in account. Uploaded media is stored in protected cloud object storage while it is needed to run the job and provide your library. Audio is sent to AssemblyAI for speech transcription. The resulting transcript text is sent to our hosted notes-generation provider, currently KIE using a GPT-5.6 Luna model. The notes provider does not receive the original audio as part of note generation.
Supabase provides authentication and account data services. Cloudflare provides parts of the worker, queue, and object-storage infrastructure. These providers process data only to support the service, security, reliability, or legal obligations applicable to them. AstraLect does not sell lecture content or use it for advertising.
Purchases and Credits
Apple processes App Store purchases and payment details. RevenueCat receives the App Store subscription status, product and entitlement information, restore and purchase events, and the Supabase account identifier used as the RevenueCat app user ID. We do not receive or store your full payment-card number. Our service maintains the Credits ledger needed to apply plan limits, renewals, usage, and refunds.
Anonymous product analytics
AstraLect uses TelemetryDeck for limited product analytics. It may receive events such as opening a screen, starting or finishing a workflow, viewing a paywall, opening a legal link, or encountering a categorized error, together with a pseudonymous installation or device identifier and general technical context such as app version, operating-system version, device model, language, region, time zone, and display characteristics.
TelemetryDeck does not receive lecture titles, audio, transcript text, notes, source URLs, email addresses, Supabase tokens, user UUIDs, purchase receipts, transaction identifiers, prices, or payment information from AstraLect. The analytics are not used to track you across other apps or websites.
Microphone, Photos, and Files
AstraLect requests microphone access only when you choose to record. It requests Photos or Files access only when you choose an import or export action. Do not record a class, meeting, or person unless you have the consent and legal permission required where you are.
Retention and deletion
Active cloud audio, transcripts, notes, and related metadata are retained only as needed to provide your library, playback, synchronization, Credits accounting, security, and support. You can delete an individual lecture or all lectures from the app. You can also delete your account; account deletion removes active cloud content and local app data, while a minimal record may remain when needed for fraud prevention, billing reconciliation, dispute handling, or legal obligations. Backups and provider systems may take time to complete deletion.
Security and sharing
We use encrypted connections, signed upload and download access, authentication, and access controls appropriate for the service. No internet service can guarantee absolute security. We may disclose information when required by law, to protect users and the service, or as part of a business transfer. We do not share lecture content for targeted advertising.
Your choices
You can use local recording and playback without uploading a draft, choose whether to sign in, delete lectures, delete your account, and contact us about a privacy request. Depending on where you live, you may have additional rights to access, correct, restrict, or delete personal information. We may need to verify your request before acting on it.
Children
AstraLect is not directed to children under 13, or the minimum age required by local law. We do not knowingly collect personal information from children below that age.
Changes
We may update this policy when AstraLect or its data practices change. The effective date above identifies the current version. Continued use after an update means the updated policy applies to future use, to the extent permitted by law.
Contact
Privacy questions and requests: support@astrailab.com