Privacy Policy
This page says what VIA asks you for, what it keeps, who else sees it, and how to get rid of it. It is written to be read by the person using the app. Where something has a legal name, we use the name and then say what it means in the same sentence.
Recording a lesson works, playing one back works, and having one written out works. Deleting a single recording does not. This is a narrow mark, and the narrowness is now narrower still: recording, listening again, and turning a lesson into text you can study from are all switched on. What is still not built is the last one — there is no way to delete a single recording, and the only removal there is remains deleting your whole account. Parts of this page describe deleting one as though it existed, because we would rather tell you the shape of the thing before it arrives than after; every one of those passages is marked and links back here. The marks come off one at a time, as each part is built — playing a recording back was the first to go, and having one written out is the second.
The short version
- We ask for three things when you sign up: an email address, a password, and your date of birth.
- Your date of birth is not kept. It is read once to check your age and then thrown away.
- We do not store your password. It passes through on its way to the company that runs sign-in for us, and we never write it down.
- We keep the study material you put in, your chats, your focus-timer history, and a record of how much AI processing your account has used.
- Your questions and your study material are sent to Google to be answered by an AI model. That request goes to Google's EU multi-region, and we still treat it as data that may leave the EU — see “The AI part, and where it happens”.
- VIA uses your phone's microphone only while you are recording a lesson, and the audio goes to your own private storage. Recording alone does not send anything to Google. If you ask for a recording to be written out, that audio is sent to Google to be turned into text, and it goes outside the EU to do it — see “Recording a lesson”.
- There are no cookies and no analytics anywhere — not in the app, not on this page.
What we ask for when you sign up
Three fields, and nothing else:
- Email address. Kept. It identifies your account.
- Password. Not kept by us — see “What happens to your password”.
- Date of birth. Not kept by us — see “What happens to your date of birth”.
We do not ask for your name, your school, your phone number, or a payment card. There is nowhere in VIA to enter any of those.
What happens to your date of birth
You enter it, the app works out your age from it, and if you are 14 or older the account is created. Then the date is gone. To be precise about all three parts of that:
- It is not saved. There is no field for a date of birth anywhere in our database. Not an empty one — none at all.
- It is not passed on. When we create your account with the company that runs sign-in for us, the message we send them carries your email address and your password and nothing else. We send that company a second message straight afterwards, asking it to email you a link confirming your address; that one carries your email address and the word “signup”. Neither message carries the date.
- It is not written to a log. If your date of birth is rejected — because it is missing, unreadable, or in the future — the message you get back names the problem and does not repeat the date.
Because nothing is kept, there is no retention period for it and no deletion to schedule. It simply does not exist after the moment your age is checked.
What happens to your password
Your password reaches our server once, when you sign up, and is immediately passed on to the company that runs sign-in for us. We do not store it. We do not scramble it and store the result. We do not log it. There is no password field in our database.
That company stores a scrambled version — a hash — so that it can check your password without holding the password itself. That is their system, not ours, and we cannot read what they hold.
One consequence worth knowing: because we never see your stored password, we cannot reset it for you, and nobody who breaks into our database finds a password there.
What we store while you use VIA
Everything in this table is tied to your account and is removed when your account is removed. Two rows are different in a way worth flagging before you read them: a document you upload and a lesson you record are both FILES, and neither lives in the database with everything else here. What that costs is set out under “Deleting your account and your material”.
| What it is called here | What it actually is |
|---|---|
| Your account | Your email address, the date we first saw you sign in, and which sign-in method created the account. |
| Chats | Every message you send VIA and every answer it gives back, in full. |
| Study topics | The topics in your library — their titles, the subject you filed them under, and whether you pinned them. |
| Study material | The text you pasted, the text pulled out of a link or a video's captions, or the text read out of a PDF you uploaded, stored word for word. If you added a link, the link itself is stored too. |
| Uploaded documents | The PDF file itself, kept exactly as you sent it, in private storage that is not part of the database. We also keep a note of where it is, how big it is, how many pages we read, and whether reading it worked. Your name is nowhere in the file's address: it is a scrambled code, and a list of the stored files on its own says nothing about who any of them belongs to. |
| Recordings | The audio file itself, exactly as your phone recorded it, in the same private storage and with the same kind of scrambled address as an uploaded document. Beside it we keep the recording's number, its title, whether the upload finished, how big the file is, and how long your phone said you recorded for — that last one is your phone's own count, not a length we read out of the audio, because nothing on our side ever opens it. |
| Search index | Your study material chopped into pieces, each with a numeric fingerprint, so VIA can find the relevant part when you ask a question. The pieces contain the same words your material does. |
| Recently Deleted | Topics you deleted but have not yet cleared out, and the date you deleted each one. |
| Focus sessions | Each timer session: how long, which mode, whether you finished it. |
| Jump-to points | When VIA points you at a moment inside a video, it records the quote and the second it starts at, so the link keeps working. |
| Usage record | One line per AI request: the date, which feature, which model, how many tokens, and what that request cost us to run. It does not contain your question or the answer. |
There is one more table in our database, and it is worth naming so that it is not mistaken for something it is not. Caption timing holds, for a YouTube video, the list of times at which each caption line starts. It is a cache of public information about the video — identical for everyone who ever adds it, and it holds no text from the video, no account, and no link back to any person. Deleting your account does not touch it, because it was never yours.
One more thing is held, and it is not in the database either — the uploaded file and the recording above are the others. To make VIA harder to use as a way of firing confirmation emails at somebody else's inbox, our server counts how many have been asked for, against two things: the email address they were asked for and the internet address the request came from. That count sits in the server's memory for an hour and is then dropped — deleted outright, whether or not anybody ever asks about that address again. It is never written to disk, and restarting the server forgets it.
What is kept only on your phone
Some things never reach our servers at all. They sit in your phone's own storage and they are not backed up by us:
- Your sign-in tokens, in the phone's secure storage: the short-lived one the app sends us with every request, and a longer-lived one it uses to get a fresh short-lived one without asking you to type your password again. Kept beside them is a note of whether you signed out, so that a phone you left is not treated as a phone that never signed in.
- Your flashcards.
- Your weekly timetable.
- Your subject list.
- Light or dark mode, how your library is sorted, the order you dragged your subjects into, and whether you collapsed the quick-notes panel.
Two things follow from that, and you should know both. If you delete the app or switch phones, these are gone and we cannot get them back — they were never on our side. And everything in that list except the sign-in tokens is filed under the account that wrote it, so somebody else signing in on the same phone starts empty rather than in your library.
One thing is on your phone as well as with us, rather than only there, and this section would be misleading without it. When you record a lesson, your phone writes the audio to VIA's own storage on the phone and then uploads that file — and nothing in VIA deletes the local copy afterwards. So a recording exists in two places: in your private storage with us, and in the app's storage on the phone that made it. The phone's copy is inside VIA and no other app can read it, it goes when you delete the app, and your phone may clear it on its own when it needs the space. It is not removed by deleting your account — see “Deleting your account and your material”.
That copy is not only sitting there: it is what plays when you tap a recording, as long as it is still on the phone, so listening back usually needs no network and moves no data. If your phone has cleared it, VIA falls back to the copy in your storage with us — see “Recording a lesson”. Deleting your account removes the note of which file belongs to which recording, along with everything else kept only on this phone; it does not remove the audio file itself, which is the sentence above and is not softened by this one.
What happens when you add a link or a video
When you paste a web link into a topic, our server visits that page and pulls the readable text out of it. When you paste a YouTube link, our server asks YouTube for that video's existing captions. The request comes from our server, not from your phone, so the site you linked to sees us rather than you — but it does mean the link you chose has left your device.
We do not download videos and we do not visit anything you have not asked us to.
Recording a lesson
VIA uses your phone's microphone only while you are recording, and only after you tap the record button. Nothing listens in the background, there is no wake word, and the app does not open the microphone to do anything else. Your phone asks for microphone permission the first time, in its own words rather than ours, and you can take that permission back in your phone's settings at any time — VIA cannot record without it.
The recorder tells you something every time you look at it, and we are repeating it here because it is the part that involves somebody other than you: “Make sure your teacher and anyone nearby know you're recording.” That line is under the record button permanently rather than in a box you dismiss once, because the day it matters is a day you are in a room with someone who has not agreed to be recorded. A microphone picks up whoever is talking, not only the person who meant to be recorded.
Recording stops if you leave the app. If you switch to another app or lock your phone, the recording ends there. Everything up to that moment is kept. We say it here because it changes what is in the file: a recording can be shorter than the lesson was, and it is not a fault in the file if it is.
Where the audio goes. The file goes from your phone straight into the same private storage an uploaded document would use — it does not pass through our server on the way, and we keep no second copy of it. The phone keeps one, though: see “What is kept only on your phone”, which says what that costs. Its address in our storage is built the same way as a document's: a scrambled code standing in for your account, then the word “recordings”, then a random file name. Your name is nowhere in it, and a list of the stored files on its own says nothing about who any of them belongs to. In the database we keep the row described under “What we store while you use VIA” and nothing more.
A recording is not sent to Google unless you ask for it to be written out. This is the part worth being exact about, because it is the one place on this page where your own voice, and other people's, can leave your storage. Recording alone does nothing but store the file: it is not transcribed, it is not turned into study material, it is not put in the search index, and no AI model is given it. Until you ask, our own server does not open it either — it knows how big the file is and what type it says it is, and that is the whole of what it knows about the contents.
Having a recording written out, and where that audio goes. Transcription is optional, and nothing happens to a recording until you choose it. When you choose it, VIA sends that audio to Google so that Google can return a text transcript; the text is stored as study material in the topic you picked, is put in that topic's search index, and can be asked questions about. The audio may include the lecturer's voice and anyone else who spoke, not only yours. Everything this page says elsewhere about a model getting things wrong without saying so applies at least as strongly to speech as to a scanned page.
VIA uses Google's paid Cloud service, and the model it uses for this is the one Google identifies as Gemini 3.5 Transcribe, currently a Preview — that is, pre-general-availability — model. Google's current Cloud terms state that Google will not use customer data to train or fine-tune AI/ML models without prior permission or instruction. VIA does not give that permission.
That is not a promise that Google keeps no copy. Google may log requests for a limited time to detect abuse and keep the service secure. Those are two different things and we keep them in two different sentences on purpose: the first is about training, the second is about logging, and only the first is the one we can point at a term for.
This request does not go to Google's EU multi-region, and that is a real difference from the rest of this page. The Preview model runs on Google's global infrastructure rather than an EU-only endpoint. The audio is therefore transferred outside the EEA, including to the United States and other countries where Google or its sub-processors operate. Because the model is Preview, Google's standard data-location commitments for generally available Cloud services do not apply to this processing in the same way. What that leaves settled and unsettled is set out under “Where your data is stored”.
Choosing is the whole of it. There is no setting that sends recordings automatically, no schedule and no background job that reaches a recording, and a recording you never choose is a file that never leaves your storage. A lesson longer than about 36 minutes is refused rather than cut into pieces, because a transcript with a silent gap in it reads exactly like a complete one.
The original recording stays where it is. Having a recording written out does not consume it, replace it or move it — it remains in your Recordings list, and the text is a second thing rather than a thing that took its place. Nothing is written on the recording to say you did it, so asking twice files two copies of the text, and neither one knows which recording it came from.
You can play a recording back, and how that works is worth one paragraph. Tap a recording in the list and the card at the top of the screen becomes a player with a position, a length, and a bar you can drag. If the file your phone made is still on the phone, that is what plays — nothing is downloaded and nothing leaves your storage. If it is not there any more, VIA fetches your copy from your private storage instead, and to do that our server hands your app a temporary link to that one file. The link works for an hour and then stops working. The hour is a limit on the link, not on the recording, which stays exactly as it was; the next time you tap play, your app asks for a new link. Anyone holding one of those links while it lasts could play that one recording, which is why the app keeps it to itself and never shows it to you.
You cannot delete a single recording today, and we are not going to phrase that gently. (See the note at the top — this paragraph describes what exists, and the one after it describes what does not.) There is no delete button on a recording, no route behind one, and nothing that removes one on its own. Deleting a topic does not reach a recording, because a recording is not filed under a topic. The only way to remove a recording from our storage today is to delete your whole account, which removes all of them along with everything else — see “Deleting your account and your material”. If that is not what you want, the thing to do is not record until it is built.
When deleting one is built, a deleted recording is meant to go to Recently Deleted and be kept for 30 days before it is cleared out, the way a deleted topic is. (Not built yet — see the note at the top. Nothing described in this paragraph exists: there is no 30-day window on a recording today, because there is nothing that can put one into it.) The honest reading of that sentence is that it is a plan, not a safety net you have. Read it beside “Recently Deleted”, which says how the 30 days actually behave for the one thing that has them.
The AI part, and where it happens
When you ask VIA a question inside a topic, we send Google your question, the recent messages in that chat, and the relevant parts of your own study material, so that the model can answer from your material rather than making something up. Google's model writes the answer and sends it back. Something smaller happens when material is first added, to build the search index listed under “What we store while you use VIA”.
Uploading a PDF sends the whole document to Google, once. This is a bigger thing than building the search index and we are not going to bury it in there. VIA cannot read a PDF by itself. When you upload one, our server sends every page of it to Google's model in a single request and asks it to type out the text; what comes back is what gets stored as your study material, and it is what VIA reads from then on. That includes anything on those pages you were not thinking about when you uploaded them — a name in a header, a handwritten note in a margin, whatever is in a photograph on the page.
The model can get it wrong without saying so, and you should know that before you study from it. Where it can see that something is unreadable it marks the spot, and where a picture stood it says so. But we tested it on deliberately poor scans and found the opposite failure too: it sometimes produces clean, confident text for something it could not actually read, with no mark of any kind. There is nothing in VIA that detects that, and we are not going to pretend there is. The original file is kept exactly as you sent it, so the page itself is always the thing to check against.
A recording is not sent by this route, and everything in this section is about text. If you ask for a recording to be written out, that audio goes to a different Google model, at a different endpoint, on different terms — it is not the route described here and it does not go where this section says these requests go. It has a section of its own: “Recording a lesson”. Recording alone sends nothing anywhere.
Two limits on that, both of which are true today:
- VIA gives the model no tools. It cannot search the web, look anything up on a map, or fetch a page while it answers. It sees only what we send it.
- We do not send your email address or any account identifier along with the question.
These requests go to Google's EU multi-region. VIA reaches Google through Vertex AI — Google Cloud's version of the service — with a service account rather than an ordinary API key, and it names the location in every request it sends. The models VIA uses for the requests described in this section are on Google's published list of models it will keep data at rest in the EU multi-region for. “EU multi-region” is a group of locations in Europe rather than one country, which is why no city is named here: we would be naming one we cannot point at.
One thing VIA sends Google is an exception to that sentence, and it is the audio. The model that writes out a recording is not on that list and is not reached at that location: it is a Preview model, it answers only at Google's global endpoint, and it refuses every EU address we can give it. So the sentence above is true of text and is not true of audio. We would rather split the two than write one sentence that covers half of what we send — “Recording a lesson” is where the audio one is written out in full.
What we are not telling you, because we have not been told it either: where Google actually runs the model. Keeping data in a region and doing the computing in it are two different promises, and only the first is one we can point at. So we go on counting this as an international transfer — data that may leave the EU — covered by the safeguards set out under “Where your data is stored” rather than by EU storage. We would rather say this plainly than imply a guarantee that is not there.
Where your data is stored
The way we put it, and the commitment we are making: student data is stored in the EU, with GDPR safeguards for any international transfers.
The specific region is Frankfurt, Germany. We name the region rather than saying "Europe", because "Europe" would include places that are not in the EU and would make the commitment in bold mean less than it says.
Everything that leaves the EU, or that we cannot show stays in it, is named on this page: AI processing of your text by Google, under “The AI part, and where it happens”; audio you ask to have written out, under “Recording a lesson”; and email delivery, under “Who else touches your data”. Each is an international transfer under GDPR.
The audio is the one the commitment in bold covers least well, and we would rather say so than round it off. It does not go to an EU endpoint at all: the transcription model answers only at Google's global endpoint, so the request leaves the EEA by design rather than by an unanswered question about where a model is run. And because that model is a Preview one, Google's data-location commitments for its generally available Cloud services do not apply to it in the same way. We are not telling you that our standard transfer paperwork with Google is a settled wrapper around this one: Google's own terms treat pre-general-availability services differently, and we have not been able to establish that this model is covered in the way a generally available one would be. What we can tell you is what the transfer is, that it is optional, that nothing is sent unless you ask, and that the no-training term set out under “Recording a lesson” is the one commitment here we can point at in writing.
Who else touches your data
These are our sub-processors — other companies that handle some of your data so that VIA can work. This list is complete as at the date at the top of this page. It will change as VIA changes, and when it does, this page and that date change with it. Where we know a change is coming, that company's Status says so.
| Who | What they do | Where | Status |
|---|---|---|---|
| Supabase | Runs sign-in, stores your account and everything listed under “What we store while you use VIA”, and holds your files in private storage — the lessons you record, and the PDFs you upload. | Frankfurt, Germany (EU) | In use today, and it holds both kinds of file today — your recordings and your uploaded documents alike. |
| Google Cloud (Vertex AI) | Runs the AI model that writes answers and builds the search index, and — only when you ask for a recording to be written out — the separate Preview model that turns that audio into text. | For text, Google's EU multi-region for data at rest; where the model is actually run we cannot tell you, so it stays an international transfer — see “The AI part, and where it happens”. For audio, Google's global endpoint, outside the EEA — see “Recording a lesson”. | In use today, for both. Text goes on every question you ask. Audio goes only on the one you choose, and never otherwise. |
| Render | Hosts the server the app talks to. | Set per deployment. | In use today. We plan to move this elsewhere. |
| Cloudflare | Hosts the page you are reading. It never sees your account or your study material — this page is not part of the app. | Served from a global network. | In use today, for these pages only. |
| Resend | Delivers the mail VIA asks for — today that is the message confirming your address. | United States — so an international transfer, not EU storage. | In use today. Two separate claims, and we keep them apart because only the first is settled by the app's own code. VIA asks Supabase to send you a message confirming your address: that is what the app does, and you can hold us to it. Our Supabase project is then configured to hand that message to Resend to deliver: that is a setting we made on the project rather than anything the app decides, and it is the same kind of claim as the region named under “Where your data is stored”. |
Deleting your account and your material
You can delete your account from inside the app, under Settings. VIA asks you twice before it does anything — the first time listing everything that goes, the second asking only whether to go ahead — and nothing is deleted until you answer the second. There is no waiting period and no way to take it back.
When your account row is removed, the database removes everything hanging off it in the same operation: your chats and every message in them, your topics, your study material, the search index built from it, your Recently Deleted list, your focus sessions, your jump-to points, your usage record, and your recordings. That is not a cleanup job that runs afterwards and might be missed — the database enforces it as part of the same delete. The app's own warning screen lists the same things in the same order; it does not yet name the recordings, which is a wording we owe it rather than a difference in what is removed.
Your files are the exception, and this is the honest version of it. There are two kinds of them now — the lessons you record, and the documents you upload — and neither is in the database, so the delete above cannot reach either. What happens instead is that we read down where each of your files is before the delete — that record goes with everything else — and then ask the storage system to remove them afterwards. Almost always that works and the files are gone. If that last step fails, or if our server is restarted at the wrong moment, a file can be left behind: your account, your material and every trace of who it belonged to are already gone, and what remains is a file at an address nothing points at any more. Our server writes a line recording that when it can. There is no second job that goes looking for such files, and building one is work we owe.
The advice that used to follow this — delete the things you care about from inside the app first, then delete your account — only ever worked for material you can delete one at a time. You cannot do that with a recording, so for recordings there is no first step to take: deleting your account is the only removal there is, and it carries the risk above. (See the note at the top.) For a document, the advice stands.
Your sign-in record goes with it, in the system that holds your email address and your password hash. Those are two different systems and the app asks them in that order, so if the second one cannot be reached your material is gone either way and the app tells you plainly that the sign-in record may still be standing, and asks you to email us so we can remove it by hand.
The material kept only on this phone is erased too — your flashcards, your timetable, your subject list and your app settings, the things listed under “What is kept only on your phone”. We have no copy of any of it, so this is the one part of deleting your account that destroys something outright rather than asking our server to. The app says so before you confirm.
The phone's own copy of a recording is not erased by that, and it is the larger of the two things left behind here. Deleting your account clears the flashcards, timetable, subject list and settings named above; it does not go looking for the audio files the recorder wrote, so those stay on the phone until you delete the app or the phone reclaims the space. Nothing can reach them but VIA. If you want them gone at once, delete the app.
With something left out of that, on a phone that has had VIA installed since before the app began keeping each account's material separately: a copy of your flashcards, timetable and subject list from before that change can still be sitting in the phone's own storage. Nothing in VIA reads it — not the app, and not anybody who signs in on that phone afterwards — and it goes when the app does.
In our database, the one thing that survives is the caption timing named at the end of “What we store while you use VIA”, because it is public information about a video and holds nothing of yours.
You can also email us at support@viastudy.app and ask us to do it for you. That route still works, and it is the one to use if the app cannot reach us or if the sign-in record was the half that was left behind.
You can also delete things one at a time inside the app, without deleting your account: deleting a topic removes its material, its search index and its chats along with it, and deleting a single piece of study material removes that one. Both ask the storage system to remove any uploaded file too, with the same caveat as above — the record goes for certain, the file goes in all but the unlucky cases.
Recently Deleted
When you delete a topic it goes to Recently Deleted rather than disappearing. It is meant to be cleared out after 30 days. Topics are the only thing in it. A recording cannot go there, because there is no way to delete one — see “Recording a lesson”. When deleting a recording is built, a deleted one is meant to be kept here for the same 30 days (not built yet — see the note at the top).
Being exact about how that works, because it is not a scheduled job: the clear-out happens the next time you open Recently Deleted. If you never open it, a topic can sit there past 30 days. It is still yours, still private, and still deleted along with everything else if you ask us to delete your account — but we are not going to tell you it vanishes on day 30 when what actually triggers it is you opening that screen. You can always delete a topic permanently yourself from that screen, which takes effect at once.
If recordings ever join this list, assume the same caveat until this page says otherwise: a 30-day window that is cleared out by you opening a screen is not a timer running in the background, and we would rather you knew which of the two you had. (See the note at the top.)
Cookies
These pages set no cookies. They load no font, no image, no script and nothing from any other site — only their own text and one stylesheet. There is nothing here to track you with.
The app sets no cookies either, and contains no analytics, no advertising and no crash-reporting service. What it saves on your phone is the material under “What is kept only on your phone”, plus the bookkeeping that keeps that material apart: which account is signed in, and whether the one-off move to per-account storage has already run. All of it is there to make the app work rather than to watch you.
Your rights
Under the GDPR — the EU's data protection law — you can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, and object to how we use it. You can also complain to your country's data protection authority.
Deleting is the one you can do yourself, from Settings in the app — see “Deleting your account and your material”. The others go to support@viastudy.app and we handle them by hand, because VIA has nothing built into it that exports your data for you. If you ask for a copy, that is what you will get — the material listed under “What we store while you use VIA”.
Changes to this page
When what VIA does changes, this page changes and the date at the top changes with it. The sub-processor table is the part most likely to move, and the changes we already know are coming are the ones marked in its Status column.