Privacy Policy

Last updated: 12 August 2026

The short version. Retainory has no user accounts, no advertising, and no third-party analytics or advertising SDKs. Your normal study data — including your objectives, saved flashcards, review history, ratings, and scheduling state — stays on your iPhone and is not uploaded to Retainory.

Information leaves your device in limited situations: when an eligible user intentionally submits material for AI flashcard generation; when the app sends limited usage events associated with a random installation identifier; and when technical information is processed to secure the service, prevent abuse, enforce generation limits, and verify genuine copies of the app.

Retainory does not sell your personal information, does not share it for cross-context behavioral advertising, and does not track you across other companies' apps or websites.

1. Who we are

Retainory is a study and spaced-repetition application operated by Mauricio Salinas, an individual, from Chicago, Illinois, United States.

In this Privacy Policy, "Retainory," "we," "us," and "our" refer to Mauricio Salinas in his capacity as the operator of Retainory.

For purposes of privacy laws that use the term "controller," Mauricio Salinas is the controller of personal data processed by Retainory unless applicable law provides otherwise.

You may contact us about privacy at:

2. Scope of this Privacy Policy

This Privacy Policy explains how Retainory handles information when you use the Retainory iOS application and the online services necessary to operate it.

It does not govern Apple's independent processing of information through the App Store, Apple ID, Apple devices, or other Apple services. Apple's handling of that information is governed by Apple's own privacy policies and agreements.

Our Terms of Service separately govern your use of Retainory.

This retainory.com marketing website is served through Cloudflare and uses Cloudflare Web Analytics to measure aggregate traffic, such as page views and referring pages. Cloudflare Web Analytics does not use cookies and does not track visitors across other sites. It is separate from the Retainory app, which sends no analytics events of this kind, and separate from the installation-linked usage events described in Section 10, which apply only inside the app.

3. Retainory has no user accounts

Retainory currently does not require:

We therefore do not maintain a conventional customer account database that identifies individual Retainory users.

4. Study data that stays on your device

Retainory is designed so that your ordinary study library remains local to your iPhone.

The following information is stored locally on your device and is not transmitted to Retainory's servers as part of normal manual study and review functionality:

Retainory does not maintain a server-side copy of that study library.

We cannot ordinarily see, search, retrieve, or restore that locally stored study data.

Retainory currently provides no Retainory-operated cloud synchronization, cloud backup, account recovery, or study-data restoration service.

If you delete Retainory, erase or lose your device, reset your device, or otherwise lose the app's local storage, Retainory cannot restore your study library for you.

Any device-level backup or restoration functionality independently provided by Apple is controlled by Apple and your device settings, not by Retainory.

5. Age eligibility

Retainory uses an age eligibility step before determining which features you may access.

The intended eligibility structure is:

Your age selection is processed locally on your device.

Retainory does not transmit your exact age or date of birth to our backend, include it in telemetry, send it to Google, or include it in an AI prompt.

After the age eligibility process is completed, Retainory needs to retain only the local eligibility state required to determine whether AI features are available. Retainory does not need to retain your exact age or date of birth for this purpose.

The age eligibility process is a self-declared eligibility mechanism unless Retainory expressly states otherwise. We do not represent that a user's identity or age has been independently verified.

6. Material submitted for AI flashcard generation

6.1 When content leaves your device

If you are eligible for AI functionality and intentionally request AI flashcard generation, the material you submit must leave your device so the request can be processed.

This may include:

Retainory currently supports PDF submissions of up to 10 MB.

Nothing is submitted to the AI generation service merely because it exists in your local Retainory study library.

Transmission occurs when you intentionally initiate an AI generation request.

6.2 How generation works

Submitted generation material is transmitted to Retainory's backend.

The backend currently runs on Google Cloud Run in the United States, in the us-central1 region.

Retainory's backend forwards the generation material to Google's Gemini API so that flashcard question-and-answer content and related generation results can be produced.

The resulting flashcards are returned to your device.

6.3 What Retainory keeps

Retainory's application backend is designed to process submitted generation material in memory.

Retainory does not intentionally write the submitted PDF or pasted study material to our application database or persistent application storage.

Once the request has been serviced, Retainory does not maintain a persistent server-side copy of the submitted study material.

Flashcards that you choose to save after generation are stored locally on your device.

7. Google's processing of AI generation content

Retainory currently accesses the Gemini API through a Google Cloud Project associated with an active Cloud Billing account.

Under Google's terms applicable to that configuration as of the date of this Privacy Policy, Retainory's Gemini API access is treated as a paid service for Google's data-use provisions.

Under those current paid-service terms, Google states that prompts and responses submitted through the paid Gemini API are not used to improve Google's products.

Google nevertheless states that, for paid services, it may log prompts and responses for a limited period for purposes including detecting and preventing prohibited use, maintaining service safety and security, and complying with required legal or regulatory disclosures.

Google may also process technical and operational information associated with providing the Gemini API, such as authentication details, service usage information, operational status, safety-filter events, errors, performance metrics, device or token identifiers where applicable, and IP addresses under Google's applicable terms.

Provider terms and practices can change.

If a change to our AI provider or its data-handling terms materially changes how information submitted through Retainory is processed, we will update this Privacy Policy as appropriate.

8. Sensitive or confidential content

Retainory is designed for ordinary study material.

You should not submit information that is unnecessary for your study request or information you are not authorized to disclose.

In particular, avoid submitting highly sensitive or confidential information such as:

Retainory does not require this type of information to generate ordinary study flashcards.

Because users may submit free-form text or documents, Retainory cannot prevent a user from placing sensitive information inside a generation request.

If you voluntarily include such information, it will be processed as part of the generation request in the same manner as the rest of the submitted material.

Retainory does not use submitted study material to train a Retainory-owned generative AI model.

9. Installation identifier

When Retainory is installed, the app generates a random installation identifier.

This installation identifier is created by Retainory. It is not:

We use the installation identifier to associate limited technical events with the same Retainory installation without requiring an account or knowing the user's real-world identity.

Reinstalling Retainory generates a new installation identifier.

Retainory does not maintain a mechanism designed to link the newly generated installation identifier with the installation identifier from the prior installation.

Although we do not intentionally link this identifier to your name or other direct identity information, privacy laws may classify persistent or pseudonymous identifiers as personal information or personal data. We therefore describe and protect this identifier accordingly.

10. Usage events

Retainory sends limited usage events to help us understand whether important application flows work and how product features are being used.

Examples may include:

Usage events may be associated with the random installation identifier described above.

Usage telemetry does not include:

We use these events for purposes such as:

Retainory does not use a third-party advertising, attribution, or analytics SDK for this telemetry.

11. Apple App Attest and device integrity

Retainory uses Apple's App Attest technology, which is part of Apple's DeviceCheck framework.

App Attest helps us determine whether requests to our backend originate from a genuine instance of Retainory running in an expected Apple environment.

App Attest creates cryptographic information, including a public key identifier associated with an application attestation key.

Retainory uses the App Attest key identifier for two principal purposes:

  1. verifying the authenticity and integrity of requests sent to Retainory's backend; and
  2. enforcing per-device generation limits so one application installation cannot unfairly consume generation capacity.

Retainory may retain the relevant App Attest key identifier and associated per-device generation counters while the associated app installation remains installed and in active use.

We do not intentionally associate the App Attest identifier with a name, email address, Apple ID, or Retainory account.

Because it can distinguish an attestation key or installation for security purposes, we treat it as pseudonymous technical information rather than claiming that it can never constitute personal information under applicable privacy law.

12. IP addresses and rate limiting

Like other internet services, Retainory's backend receives network connection information when your device makes an online request.

Retainory uses the client IP address transiently for purposes such as:

Where Retainory persists an IP-derived value as a rate-limit counter key, the backend stores a one-way SHA-256-derived value rather than storing the plaintext IP address as that counter key.

IP-derived rate-limit information is retained only for as long as reasonably necessary to operate and enforce Retainory's rate-limiting and abuse-prevention controls.

Retainory does not use IP addresses or IP-derived identifiers for advertising, cross-app tracking, or behavioral advertising profiles.

13. Application logs

Retainory generates limited operational logs to help operate, secure, and diagnose the backend.

Retainory's own application-level logs are designed not to contain raw IP addresses or raw App Attest key identifiers.

Before certain technical identifiers are written to Retainory's application logs, Retainory converts them into truncated HMAC-SHA256 tags using a server-side secret.

This is intended to reduce exposure of raw technical identifiers while preserving limited operational ability to recognize repeated technical activity where necessary.

HMAC-tagged values are not used for advertising or to identify users by name.

14. Google Cloud infrastructure logs

Retainory's application-level logging is separate from the infrastructure-level logging performed by Google Cloud.

Google Cloud Run and related Google Cloud infrastructure may independently process or record ordinary connection and operational metadata associated with requests to the hosted service.

Depending on Google's infrastructure and configuration, this may include information such as:

The 30-day Retainory application-log retention period described below should not be read as a promise that every Google-controlled infrastructure log is deleted within 30 days.

Infrastructure-level records maintained independently by Google are subject to the applicable Google Cloud configuration, contractual terms, technical requirements, and legal obligations.

15. Information you send us directly

If you contact Retainory by email or otherwise communicate with us directly, we receive the information you choose to provide.

This may include:

We use direct communications to:

Do not send sensitive study material through a support email unless it is necessary to resolve your issue.

We retain direct communications for as long as reasonably necessary for the purpose of the communication, dispute resolution, security, recordkeeping, or applicable legal obligations.

16. What Retainory does not do

Under Retainory's current architecture:

If these practices materially change, this Privacy Policy and applicable App Store disclosures will be updated.

17. How we use information

We use the limited information described in this Privacy Policy for the following purposes.

Providing requested AI functionality

We process material that an eligible user explicitly submits so that Retainory can generate the flashcards the user requested.

Operating Retainory

We process technical information necessary to send and receive network requests and operate online features.

Reliability and debugging

We process limited usage and operational information to identify failures, broken flows, errors, and performance problems.

Product improvement

We use limited usage events to understand how Retainory features are used and whether they work as expected. We do not include study content in this telemetry.

Security and abuse prevention

We process App Attest information, IP-related information, request information, generation counters, and operational logs to:

Legal obligations

We may process or preserve information where reasonably necessary to comply with applicable law, valid legal process, enforceable governmental requests, or to establish, exercise, or defend legal claims.

18. Service providers

Retainory intentionally uses a limited number of outside providers to operate the Service.

Google Cloud

Retainory uses Google Cloud, including Google Cloud Run, to host its backend.

Google Cloud processes technical, connection, operational, and customer data as necessary to provide the hosted infrastructure.

Retainory's current backend is hosted in the United States in the us-central1 region.

Google Gemini API

Google's Gemini API receives study material only when an AI-eligible user intentionally initiates an AI flashcard-generation request.

Under Retainory's current paid-service configuration, Google's current terms state that prompts and responses are processed under Google's applicable data-processing terms and are not used to improve Google's products.

Google may nevertheless perform limited logging and other processing described in Section 7.

Apple

Apple distributes Retainory through the App Store and provides technologies used by Retainory, including App Attest and DeviceCheck.

Apple may independently process information associated with the App Store, Apple accounts, Apple devices, App Attest, DeviceCheck, or other Apple services.

Apple's independent processing is governed by Apple's own privacy policies and agreements.

19. Retention

Retainory follows different retention rules depending on the information involved.

Local study data

Your normal Retainory study library remains on your device. Retainory does not maintain a server-side copy.

AI generation material

Retainory's application backend processes submitted generation material in memory and does not intentionally persist a server-side copy after servicing the request.

Google may retain or log prompts and responses for a limited period under the terms applicable to the paid Gemini API, including for security, prohibited-use detection, and required legal or regulatory disclosures.

Usage events

Retainory usage events are retained for up to 30 days and then deleted.

Retainory application-level operational logs

Retainory application-level operational logs are retained for up to 30 days and then deleted.

App Attest identifiers and per-device generation counters

These may be retained while the associated Retainory installation remains installed and in active use, as necessary to authenticate requests and enforce generation limits.

IP-derived rate-limit keys

These are retained according to the period reasonably necessary to operate the relevant rate-limit or abuse-prevention control. The retained rate-limit key is derived from the IP address rather than stored as the plaintext IP address.

Google infrastructure logs

Google-controlled platform or infrastructure logs may follow Google Cloud's applicable technical configuration, contractual retention rules, security requirements, and legal obligations. Retainory does not represent that every Google-controlled platform log follows Retainory's 30-day application-log retention period.

Legal preservation

Information may be retained longer where reasonably necessary to comply with applicable law, valid legal process, security obligations, or to establish, exercise, or defend legal claims.

20. Security

We use technical and organizational measures intended to reduce the risk of unauthorized access, misuse, interception, or disclosure.

Current measures include:

No method of electronic storage, transmission, authentication, or security is completely secure.

We therefore cannot guarantee absolute security.

Retainory does not claim that Retainory itself has obtained SOC 2, ISO 27001, or another independent security certification unless we expressly state that such a certification has actually been obtained.

21. No sale, advertising sharing, or cross-app tracking

Retainory does not sell personal information.

Retainory does not share personal information for cross-context behavioral advertising.

Retainory does not use personal information to track you across other companies' apps or websites for targeted advertising or advertising measurement.

Retainory does not provide data to data brokers.

Because Retainory does not currently sell or engage in qualifying sharing of personal information for cross-context behavioral advertising, there is currently no sale or qualifying sharing from which a user needs to opt out through a "Do Not Sell or Share My Personal Information" mechanism.

If this practice changes, we will update this Privacy Policy and implement legally required privacy controls before engaging in the changed practice.

22. Your privacy choices

Local study information

Because your study library is stored locally, you can control that information through Retainory and your device.

Deleting the relevant study data from the app removes the local data according to the application's functionality.

Deleting Retainory removes the app's locally stored Retainory data from the device, subject to any independent device-level backup system controlled by Apple.

AI generation

You are not required to use AI generation merely to use eligible manual study features.

If you do not want study material transmitted to Retainory's backend and Gemini, do not initiate an AI generation request.

Communications

You can choose what information to provide when contacting Retainory.

23. Privacy rights and requests

Depending on where you live, you may have rights concerning personal information that Retainory processes.

These rights may include rights to:

Retainory does not maintain user accounts or a real-world identity database.

As a result, we may be unable to determine that a particular pseudonymous installation identifier, log entry, rate-limit value, or technical event belongs to you.

We will not collect substantially more identity information merely to identify a technical record unless applicable law requires us to do so.

If we can reasonably verify and locate personal information associated with you, we will respond to applicable privacy requests as required by law.

To submit a privacy request, email support@retainory.com.

Please use the subject line: Privacy Request

We may ask for information reasonably necessary to understand, verify, and fulfill the request.

24. California privacy information

This section applies to California residents to the extent California privacy law applies to Retainory.

Some obligations under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), apply only to entities that meet statutory applicability thresholds.

Whether or not every CCPA obligation presently applies to Retainory, the factual descriptions of our practices in this Privacy Policy are intended to remain accurate.

Categories of personal information

Depending on how you use Retainory, we may process categories that can include:

Identifiers and technical identifiers. Examples include:

Internet or electronic network activity. Examples include:

User-provided content. This includes material intentionally submitted for AI flashcard generation.

Communications. If you contact Retainory, we may process your email address and information you include in your message.

Potential sensitive personal information contained in submitted material. Retainory does not request sensitive information as a condition of ordinary AI generation. However, free-form text or PDFs could contain sensitive information if a user voluntarily submits it.

Sources

We obtain this information:

Business purposes

We use this information for the purposes described in this Privacy Policy, including:

Sale and sharing

Retainory does not sell personal information.

Retainory does not share personal information for cross-context behavioral advertising.

California rights

Where the CCPA applies, California residents may have rights including:

Because Retainory does not sell or share personal information as those terms are used for cross-context behavioral advertising, there is currently no such sale or sharing to opt out of.

Requests may be submitted to support@retainory.com.

25. European Economic Area and EU GDPR

This section applies where the European Union General Data Protection Regulation ("EU GDPR") applies.

Controller

The controller is:

Mauricio Salinas
Individual operator of Retainory
Chicago, Illinois, United States
Email: support@retainory.com

Legal bases

Where EU GDPR requires a legal basis, Retainory relies on the following bases.

AI generation content. Processing material you intentionally submit for generation is necessary to provide the AI generation service that you specifically requested and to perform our agreement with you.

Usage events. We rely on our legitimate interests in understanding whether Retainory is functioning correctly, diagnosing problems, maintaining the product, and improving functionality while limiting telemetry and excluding study content.

App Attest, IP processing, request integrity, rate limits, security logs, and generation limits. We rely on legitimate interests in:

Direct communications. We process communications as necessary to respond to your request, perform our agreement with you, comply with legal obligations, or pursue legitimate interests in support and dispute resolution, depending on the circumstances.

Legal compliance. Where required, we process information to comply with a legal obligation.

We do not rely on legitimate interests where those interests are overridden by applicable rights and freedoms.

We apply particular care where processing relates to younger users.

EU GDPR rights

Subject to applicable conditions and exceptions, you may have rights to:

Retainory does not use server-side automated decision-making or profiling intended to produce legal or similarly significant effects concerning users.

The on-device age eligibility rule determines feature availability based on the age category the user selects.

The FSRS study scheduler determines suggested review timing for study purposes and does not make legal or similarly significant decisions about you.

Representative

Retainory is operated from the United States and does not currently have an establishment in the European Economic Area.

Where applicable law requires Retainory to designate a representative in the European Union, Retainory will maintain that designation and make the representative's contact information available in this Privacy Policy or an accompanying privacy notice.

You may always contact the controller directly at support@retainory.com.

26. United Kingdom privacy information

Where the UK GDPR applies, Mauricio Salinas is the controller for Retainory.

Contact:

Mauricio Salinas
Chicago, Illinois, United States
Email: support@retainory.com

The purposes and legal bases described in Section 25 apply under the UK GDPR to the extent corresponding UK law recognizes those bases.

Subject to applicable law, UK users may have rights to:

Retainory is operated from the United States and does not currently have a UK establishment.

Where UK law requires Retainory to designate a UK representative, Retainory will maintain that designation and make the representative's contact information available in this Privacy Policy or an accompanying privacy notice.

You may always contact Retainory directly at support@retainory.com.

27. International processing and transfers

Retainory is operated from the United States.

Retainory's backend currently runs in the United States.

If you use Retainory from another country, the limited information described in this Privacy Policy may be transmitted to or processed in the United States.

Google may also process information in other countries where Google or its service providers maintain facilities, subject to its applicable contractual terms and legal obligations.

Where applicable privacy law requires safeguards for international transfers, Retainory uses or relies on legally recognized transfer mechanisms available under the applicable service-provider agreements.

For Google Cloud and applicable paid Gemini processing, Google's current data-processing terms provide mechanisms for restricted transfers that may include approved Standard Contractual Clauses or another legally recognized transfer solution, depending on the circumstances.

No international-transfer mechanism removes your rights under applicable privacy law.

28. Children and teenagers

Retainory is not directed to children under 13.

Children under 13 may not use Retainory.

The age eligibility process occurs locally.

Retainory does not send the user's exact age or date of birth to the backend, telemetry systems, Google Cloud, or Gemini for the purpose of determining age eligibility.

A user who indicates that they are under 13 is not eligible to continue using Retainory.

Users who indicate that they are between ages 13 and 17 may use eligible manual study features but are not eligible for Retainory's AI generation functionality.

If we obtain actual knowledge that we have collected personal information online from a child under 13 in circumstances subject to the Children's Online Privacy Protection Act ("COPPA") without the authorization required by law, we will take appropriate steps required by applicable law, which may include deleting information reasonably identifiable as relating to that child.

If you believe a child under 13 has provided information to Retainory, contact support@retainory.com.

Retainory should not be used to submit another child's personal, medical, educational, or confidential information for AI processing.

29. Users in other jurisdictions

Privacy and data-protection laws vary by jurisdiction.

If the law where you live provides privacy rights beyond those specifically described in this Privacy Policy, Retainory will honor applicable non-waivable rights to the extent required by law.

You may contact support@retainory.com to submit a request or ask whether a particular local right applies to Retainory's processing.

30. Automated processing

Retainory uses software algorithms as part of ordinary application functionality. For example:

These systems are used to operate the app, secure the Service, and provide study functionality.

Retainory does not use this automated processing to make decisions concerning matters such as employment, credit, housing, insurance, legal status, or other decisions intended to produce legal or similarly significant effects.

31. Changes to this Privacy Policy

We may update this Privacy Policy when:

When the policy changes, we will update the "Last updated" date.

If a change materially affects how Retainory collects, uses, retains, or discloses personal information, we will provide reasonable notice through Retainory, retainory.com, or another appropriate method before the change takes effect where required by law.

If applicable law requires consent for a changed processing activity, we will obtain the required consent before relying on that processing.

32. Contact us

For privacy questions, complaints, or privacy-rights requests, contact:

Mauricio Salinas
Individual operator of Retainory
Chicago, Illinois, United States
Email: support@retainory.com
Website: retainory.com

For privacy requests, using the subject line "Privacy Request" will help us identify and respond to your message.

This Privacy Policy should be read together with the Retainory Terms of Service.