Hearworthy app
App Privacy
- Effective
- Last reviewed
Who is responsible
Gianfranco Gasbarri, acting personally in Portugal, is responsible for Hearworthy's handling of personal data. Email privacy questions or requests to privacy@hearworthy.com.
This policy covers the Hearworthy iPhone app, app account, episode-generation service, subscription records, and support. The separate Website Privacy page covers the public marketing website.
Data Hearworthy handles
Hearworthy handles these data when you use the app:
- Account data. Sign in with Apple and Clerk provide an account identifier, session data, and an email address or Apple private relay address. Hearworthy's service maps the identity-provider subject to an internal user ID. It does not store your Apple password.
- Questions and episode data. Hearworthy processes your question and the source records, script, narration segments, audio-delivery records, and generation state needed to make and deliver your Simple episode.
- Learning history. When you create an episode, Hearworthy keeps your question, any focus you chose, the date, and, once it is ready, the episode's title, chapter outline, and suggested follow-up questions with your account. This learning history remains after episode content is purged and after you delete an episode, so Hearworthy can develop explanations that build on subjects you have explored. It is not used for analytics, advertising, or quality evaluation, and is not sent to analytics or billing providers. Hearworthy keeps it until you delete your account. To object to this use or erase your history without deleting your account, email the privacy address above. Legal basis: legitimate interests in providing a more useful service.
- Subscription data. Apple and RevenueCat provide purchase, product, trial, service-period, renewal, refund, and subscription-state data. RevenueCat receives the internal account UUID, purchase records, and app, device, network, and SDK metadata needed for billing. Hearworthy stores records needed to verify entitlement and maintain the credit ledger. For billing, Hearworthy does not send email, episode content, listening events, advertising identifiers, or app-set subscriber attributes to RevenueCat. Hearworthy does not receive your full payment-card details.
- Private library data. After you choose where to save episodes, the app automatically stores finished audio and playback state on this device. If you choose Save to iCloud, it also stores audio, library metadata, and listening position in your private iCloud database. This uses your iCloud storage. Hearworthy cannot browse your private CloudKit database.
- Optional episode notifications. If you enable episode updates, Hearworthy stores an app installation identifier, an Apple push token, your notification preference, and delivery records. The app can acknowledge an episode status you have viewed to suppress a redundant alert. Notifications contain fixed text and routing identifiers, not your question or episode content. These acknowledgments are not used as listening analytics.
- Service and security data. Hosting and identity providers process network details such as IP address, request time, device or app details, authentication tokens, and security signals when needed to deliver and protect the service. Hearworthy does not use this data to track you across other companies' apps or websites.
- Support data. If you email Hearworthy, the controller and email providers receive your email address, message, attachments, and normal routing data. If you choose in-app Contact support, RevenueCat receives the email address and message you enter and forwards them to Hearworthy with a link to your RevenueCat customer profile. Both fields are required. Hearworthy leaves optional embedded customer details off and does not automatically attach your episode content or feedback. You choose what context to include. Support is separate from episode feedback and does not enable app usage analytics.
- Basic business report data. After Hearworthy gives you the current notice, it can use account, episode-state, credit-kind, and verified purchase dates already held for the service to calculate restricted aggregate reports. These reports measure creation, repeat creation, first paid purchase, renewals, refunds, and credit use. They do not include your question or episode content. You can turn off this use in Privacy and analytics.
- Optional app usage data. If you choose Share app usage, Hearworthy collects app session, creation-form, paywall, purchase-attempt, playback, listening-time, feature-use, queue-loss, and player-performance events. Episode events include the stored generation version and selected voice; app events include release and build versions. It uses a random analytics identity and opaque episode references. It does not send your account ID, question, title, script, sources, audio, advertising ID, or precise location to the analytics provider.
You can send a voluntary usefulness rating and an optional fixed reason from episode detail. Hearworthy uses your choices and the episode reference to improve quality under your consent to that submission. Feedback does not enable app usage sharing and is not sent to PostHog. You can update or remove it in episode detail. Feedback expires after 365 days and is removed with your account. Questions and episode content are excluded.
Do not include secrets, confidential records, or personal data that is not needed for your question.
Why Hearworthy uses the data
Hearworthy uses account, question, episode, and subscription data to provide the service you request, verify purchases, grant credits, sync your library, prevent abuse, secure accounts, diagnose failures, and answer support requests. Depending on the purpose, the legal basis is performance of the contract, steps you request before a contract, a legal obligation, or legitimate interests in service security and reliability.
Hearworthy uses a narrow set of existing service records for basic business reports based on its legitimate interest in understanding whether the service creates and keeps customer value. It excludes your account from later report computations if you turn off Basic business reports. It collects optional app usage data only after you choose Share app usage. You can withdraw that consent at any time.
Hearworthy does not sell personal data. It does not use personal data for targeted advertising and does not track you across other companies' apps or websites.
Providers
Hearworthy uses these providers only for the stated service roles:
- Apple: Sign in with Apple, StoreKit subscription billing, App Store services, the user's private CloudKit database, and Apple Push Notification service for optional episode updates.
- RevenueCat: subscription purchases, restores, entitlement checks, refund-request handling, and forwarding in-app support requests as a processor. With the consent given when starting a trial or subscribing, RevenueCat tells Apple whether a transaction was delivered, whether sample content is provided, and Hearworthy's refund preference. Apple decides the outcome. RevenueCat does not receive episode content or listening events for this purpose. Contact privacy@hearworthy.com to withdraw refund-request data sharing.
- Clerk: account identity, sessions, and account deletion.
- Cloudflare: API delivery, security, and temporary episode-audio storage.
- Neon: application database hosting.
- Trigger.dev: episode-generation job orchestration.
- OpenAI: question and script moderation, research and writing, and narration when the released provider route uses OpenAI.
- ElevenLabs: narration scripts and audio generation for the current app voices.
- Inworld: narration scripts and audio generation when you choose a voice served by Inworld.
- Cartesia: narration scripts and audio generation when you choose a voice served by Cartesia.
- PostHog Cloud EU: optional app usage analytics only after you choose Share app usage.
- Email providers: route and store support and privacy messages.
These providers can process data in countries outside Portugal or the European Economic Area. Where law requires it, Hearworthy and its providers must use a valid transfer safeguard, such as an adequacy decision or Standard Contractual Clauses.
Retention and deletion
Hearworthy removes notification delivery records about 30 days after their final status and removes app registrations after 90 days without an authenticated refresh. Turning off episode updates stops new eligible alerts and invalidates pending deliveries after the server confirms the change. Already submitted alerts cannot be recalled. Account deletion removes associated notification data.
Hearworthy keeps hosted episode content and temporary audio only while needed for delivery. The normal server purge runs about 30 days after completion, and object storage has a 35-day lifecycle backstop. Deleting an episode everywhere requests earlier removal from the service, private iCloud library, and current device.
Learning history remains after episode content is purged or you delete an episode. Hearworthy keeps it until you delete your account or ask to erase your history.
Trial credits expire at the trial end. Paid credit grants expire 90 days after each monthly grant starts. Hearworthy keeps transaction, entitlement, ledger, audit, security, and deletion records only for as long as needed for billing, fraud prevention, dispute handling, accounting, security, and legal duties. Provider backups and security records can remain for a limited period under each provider's retention rules.
Account deletion queues deletion of the RevenueCat customer and retries until the request succeeds. RevenueCat may retain limited backup, security, or legally required records under its processor agreement. Its DPA includes Standard Contractual Clauses for transfers that require them. RevenueCat Charts are used for billing operations; product conversion and retention reports use Hearworthy's own objection-aware, suppressed aggregates.
Hearworthy keeps support and privacy messages in its mailbox only while needed to answer or handle the request, then deletes them unless a legal duty requires retention. Mailbox backups and security logs follow the email provider's schedule. RevenueCat processes in-app support data under its processor agreement; it does not publish a separate ticket-retention period. Account deletion does not automatically delete delivered email. Contact privacy@hearworthy.com to request access to or deletion of support messages.
Your private CloudKit library remains in your Apple account until the app deletes it or Apple removes it under your iCloud settings. Local downloads remain until you delete them, delete the account through the app, or remove the app and its data.
Open Account and select Delete account to delete the Clerk identity and start removal of associated Hearworthy app data. Hearworthy can retain a one-way account tombstone and the minimum transaction, audit, security, or legal records needed to prevent replay, prove deletion, handle disputes, or meet legal duties. Deleting a Hearworthy account does not cancel an Apple subscription. Use Manage subscription in the app or Apple's subscription settings if you want billing to stop.
Hearworthy keeps optional app usage data in PostHog for no more than one year. When you turn off Share app usage, Hearworthy stops collection, clears pending app events, and requests deletion of the analytics linked to that consent period. Deletion can take time to finish in the provider. Hearworthy tracks and retries the request until it is confirmed. Turning sharing on again creates a new random analytics identity.
Your choices and rights
You can enable or disable Episode updates in Account → Notifications on each iPhone. Apple notification settings provide separate system controls. Enabling episode updates does not enable marketing or app usage analytics.
You can delete individual episodes, delete your account in the app, manage the Apple subscription, and choose whether to place app data in iCloud through Apple's settings. Privacy and analytics lets you turn off Basic business reports and choose whether to Share app usage. Service-operation records that Hearworthy still needs for billing, security, deletion, or a legal duty remain under their separate retention rules.
Depending on the law and the data involved, you can ask for access, correction, deletion, restriction, or portability, and you can object to processing based on legitimate interests. Email privacy@hearworthy.com. Hearworthy may ask for enough information to confirm your identity.
You can complain to Portugal's Comissão Nacional de Proteção de Dados or another competent data-protection authority.
Children and changes
Hearworthy does not knowingly collect personal data from children who cannot consent to the service under applicable law. A parent or guardian who believes a child supplied personal data can contact privacy@hearworthy.com.
Hearworthy will post material policy changes at this URL and update the effective or review date. If law requires another form of notice or consent, Hearworthy will provide it before the change applies.