Privacy, plainly.

What we collect, why, and how to turn it off. No dark patterns.

Effective 2026-05-14
The short version

If you only read one paragraph

Section 1

Information we collect

Account information

When you sign in with Apple, we receive a sign-in identifier and any name you choose to share. If you select "Hide My Email", we only see the Apple relay address (e.g. xyz@privaterelay.appleid.com). We use this solely to identify your account.

Content you create or generate

This content lives in your iCloud account (encrypted by Apple, not visible to us) when iCloud sync is on, and on your device otherwise.

Device information

Anonymous device metadata: iOS version, device model class, app version, system language. Used for crash diagnostics and analytics. We do not collect IDFA, advertising identifiers, IP-based location, or device fingerprints.

Section 2

How we use your information

Section 3

Third parties

ServicePurposeData sharedRegion
Google Gemini (via our Cloudflare Worker)AI generation and gradingActive request content. Not your email or account ID.Google data centers
Cloudflare WorkersAPI proxySame request payload, passed through. We do not log payloads.Cloudflare edge
AppleSign in with Apple, App Store, iCloudAuth and iCloud as set by AppleApple
TelemetryDeckAnonymous analyticsAnonymized events, no user identifiersEU-hosted

We do not sell your data. We do not use your content to train AI models. We do not show ads.

Section 4

Data retention

Section 5

Children's privacy

PASA is rated 4+ on the App Store and intended for general audiences. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us and we will delete it.

Section 6

Your rights

You can:

To exercise these rights, email kcc.wera.bc@gmail.com. We respond within 30 days.

EU residents have additional rights under GDPR, including the right to lodge a complaint with your local data protection authority.

Section 7

Security

All network traffic uses HTTPS. API keys are stored server-side on Cloudflare Workers, never in the app binary. Your iCloud-synced data is encrypted by Apple. Our Worker validates a shared client token and does not log request bodies.

Section 8

Changes to this policy

When we make material changes, we update the effective date above and notify you via an in-app banner. Continued use of the app after changes constitutes acceptance.

Section 9

Contact

Weerayoot Yotasing
Berlin, Germany
Email: kcc.wera.bc@gmail.com

For privacy requests, please put "Privacy" in the subject line.