Privacy Policy
Effective date: August 15, 2026
This Privacy Policy explains how same3le handles information when you use the website, Progressive Web App, local import tools, voice-study features, and future account or subscription services.
1. Current prototype versus production accounts
You can study without creating an account. Paste, local Excel, Anki, CSV, TSV, TXT, demo, and ordinary studying remain available while signed out.
If you sign in, Supabase stores authentication information (such as your user id and email) and any Google Sheet identifiers you choose to save. Local imported deck contents remain in this browser in Account Sync v1 and are not uploaded to a same3le application database. same3le does not intentionally store spoken answers, audio, or transcripts.
Paid subscriptions are not active. Legal operator identity, monitored privacy contacts, custom SMTP, and related launch items still need to be completed before public account signup is treated as production-ready.
2. Information handled today
| Information | How it is used | Where it is handled |
|---|---|---|
| Authentication email and session | Optional sign-in so a saved Google Sheet can reopen on another device. | Supabase Auth, if you sign in. |
| Saved Google Sheet identifiers | Remembers a display name, spreadsheet id, sheet tab id, last-opened time, and last source row. | Supabase Postgres with Row Level Security. Raw Sheet URLs and question text are not stored. |
| Required legal acceptance and optional marketing preference | Records that you accepted the Terms, Privacy Policy, and Acceptable Use Policy. Marketing consent is separate and optional. | Supabase, if you create an account. |
| Settings and local progress | Remembers mode, speed, timing, voice, matching preference, and current position on this device. | Browser local storage. |
| Pasted question-and-answer text | Parses structured Q&A into a spoken study session. | Processed locally in browser memory; not uploaded to a same3le account database in v1. |
| Local Excel, Anki, CSV, TSV, and TXT files | Extracts structured questions and answers for the study session. | Read and parsed in the browser. File contents are not uploaded to a same3le application server in v1. |
| Google Sheet data | Creates the study session. | Requested directly from Google by the browser. If you save the sheet, only identifiers needed to request it again are stored by Supabase. |
| Spoken answers | Converts speech to text for answer matching. | May be processed by the browser, operating system, or speech-service provider. same3le does not intentionally store audio or transcripts. |
| Technical request information | Delivers and protects the website and third-party code dependencies. | The hosting provider, Supabase, and when required for modern Anki decompression the decoder CDN, may receive ordinary request information such as IP address, user agent, timestamps, and requested asset. |
3. Local Anki processing
When an Anki .apkg file contains a legacy SQLite collection, same3le reads that collection locally. Some modern Anki packages contain a zstd-compressed collection. The importer first attempts to use a browser-native decompressor. If that is unavailable, the browser may download a pinned open-source zstd decoder module from a third-party CDN. The deck file itself is not intentionally sent to that decoder CDN; the downloaded code runs against the deck in the browser. If the decoder cannot be loaded, the user is instructed to export an older-compatible Anki package instead.
The current Anki importer does not intentionally persist Anki scheduling data, review history, images, audio, or card-template state in a same3le database. It extracts text needed to create oral-study questions.
4. Planned production-account information
Once additional account features are activated, same3le expects to collect or generate:
- Account identifier and email address
- Account creation and last-sign-in timestamps
- Terms and Privacy Policy versions accepted
- Optional marketing consent and preference changes
- Saved Google Sheet identifiers and lightweight last-opened progress
- Plan name, subscription status, renewal period, and payment-provider customer reference when payments launch
- Limited events such as demo completion, successful question-list load, session completion, ten-question milestone, seven-day return, and Pro-interest response
- Account-deletion or privacy-request records
The planned backend is not intended to receive raw payment-card numbers. A payment processor should handle card entry. Question text, answer text, local file contents, audio, transcripts, raw Google Sheet URLs, precise location, advertising identifiers, and cross-site browsing data should not be collected by default.
5. Purposes
Information may be used to provide and secure accounts, authenticate users, remember preferences, administer Free and Pro access, process and document subscriptions, measure whether core workflows function, answer support or privacy requests, prevent abuse, comply with law, and communicate transactional service information. Promotional email requires separate optional consent where required.
6. Vendors
The Service currently or potentially uses:
- Hosting provider: to deliver static application files and process ordinary server logs.
- Google: when you provide a link-accessible Google Sheet.
- Browser or operating-system speech services: for speech synthesis and recognition.
- Decoder CDN: only when a modern Anki package requires the optional pinned browser zstd decoder fallback.
- Supabase: authentication, Postgres records for saved Google Sheet identifiers and consent, Row Level Security, and the JavaScript client loaded from a third-party CDN.
- Email provider: for one-time codes, magic links, security messages, service notices, and separately consented marketing.
- Payment processor: planned for subscription checkout, billing, tax-related transaction records, and billing-portal access. Payments are not active in this version.
The final vendor names, processing purposes, and links to their policies will be confirmed before production collection begins.
7. Sale, sharing, and advertising
same3le does not intend to sell personal information or share it for cross-context behavioral advertising. The prototype does not use advertising pixels. If this practice changes, this policy and any legally required opt-out controls will be updated before the change.
8. Retention
Browser settings and prototype access data remain until you remove local access, clear site data, or the browser deletes them. Pasted Q&A and local-file contents are not intentionally persisted by the current import feature after the page or in-memory session is discarded. Planned production retention targets are: account and consent records while the account is active plus a limited legal period; subscription and transaction records as required for accounting, disputes, and law; security logs approximately 30–90 days unless an incident requires longer retention; and product-usage events approximately 12 months. Final periods will be confirmed before production launch.
9. Your choices and rights
Depending on where you live and which laws apply, you may have rights to access, correct, delete, or obtain a copy of personal information; withdraw marketing consent; appeal a denied request; and opt out of certain sale, sharing, targeted advertising, or profiling. same3le intends to honor Global Privacy Control signals if a legally relevant sale or sharing practice is ever introduced, but no such practice is planned.
The production account should provide self-service account deletion, marketing preference controls, and a documented privacy-request process. Identity verification may be required before fulfilling a request.
10. Children
The Service is not directed to children under 13 and the planned account service is restricted to users age 18 or older. We do not knowingly collect personal information from children through production accounts. If a child’s information is discovered, contact information will be provided for deletion requests before accounts launch.
11. Security
Planned safeguards include HTTPS, Supabase authentication, Row Level Security, least-privilege access, separate public and server secrets, rate limiting, secure authentication redirects, dependency and secret scanning, limited data collection, and an incident-response process. Local processing reduces application-server collection but does not eliminate browser, device, extension, hosting, speech-provider, or network risks. No security measure can guarantee absolute protection.
12. International and regional use
The prototype is intended for access from the United States. Internet routing and vendors may process request information in other locations. A regional gate is not proof of citizenship or residence. International expansion would require an updated legal and privacy review.
13. Changes
This policy may be updated when Supabase accounts, email, subscriptions, analytics, or new features launch. Material changes will receive a new effective date and, when appropriate, account holders will be notified or asked to acknowledge the revised version.
14. Contact
Before production account collection begins, this section will identify the legal operator, mailing address, privacy email, support email, and methods for submitting and appealing privacy requests. Until those details are live, the current browser-first prototype should not be treated as a production subscriber database.