Privacy Policy
Effective date: September 30, 2026
This policy explains what data apri. collects, why, who we share it with, and what you can do about it. We've tried to keep it honest and specific: it describes what the service actually does, not vague boilerplate.
apri. is operated by a private individual, the owner of the project. For any question about your data — including as the person responsible for processing it — contact us at support@getapri.app.
What apri. is
apri. turns the links you save into clean cards. We fetch the content behind a link (text, images, video), analyze it with AI, and show you a structured card: the gist, tags, and — for recipes, films, places and the like — their specific fields. The service is available on the web and in the iOS app, and as an extension for Chrome.
1. Data we collect
Your account
- Email address. Needed so you can sign in. Your email is stored by our authentication provider (Supabase). At sign-up we accept only your email, password, and (optionally) a language — we don't ask for or store a name, age, or phone number.
- Password. It is handled and stored by our authentication provider (Supabase) only as a hash. We never see your password in plain text and never store it.
- Sign in with Google (web and app). From the sign-in provider we receive and use only your account identifier and email address. We do not request, read, or store your name or profile picture from Google. What the sign-in provider shares is configured on its side.
Changing the account email isn't currently supported — it is display-only.
What you save, and its content
- The links you save, your tags, your custom card titles, favorites, lists and collections.
- The content we fetch from a link to build a card: the page text, cleaned HTML, caption, author name and publish date (when present on the page). For video and audio — a speech transcript. For images and screenshots — the text recognized in them (OCR).
- Screenshots you upload yourself. These are kept in private storage and served only through temporary signed links. A screenshot may contain personal material (for example, a conversation) — please upload with that in mind.
- AI analysis results: a short summary, tags, the card's structured fields, fact-check notes, recommendations, nutrition estimates for recipes, and a semantic vector (embedding) used for search.
- Extracted items — films, places, recipes and so on, with their fields; for places, geocoded coordinates and address.
The Chrome extension
If you use the apri. extension for Chrome, it sends us only the address (URL) of the page or link you choose to save — when you click the apri. button or the “Save link to Apri” / “Save page to Apri” menu item. The extension does not read page content, does not track your browsing and collects nothing in the background. It works through your existing sign-in on app.getapri.app and never sees your password or sign-in tokens. A link saved from the extension is handled like any other link you save.
Settings and devices
- Settings: interface language, the language used to analyze cards, and your home-screen layout. Your theme (light/dark/system) is stored only in your browser and is not synced across devices.
- Devices for push notifications: a device push token, platform (iOS/Android), and device language — used to send you a "link is ready" notification.
Technical data, analytics and cookies
We do not use third-party analytics, do not track your behavior, and do not log your IP address. There are no analytics tools, tag managers, session recorders, or third-party error-tracking SDKs in the service.
The platforms that run the service (Vercel, Railway) keep their own technical logs at the infrastructure level. Our own application logs are transient (console output); we don't write them to a separate database.
To rate-limit password guessing, we keep records of failed sign-in attempts keyed by the normalized email of the attempt — with no IP address and no account identifier; those records are removed after a successful sign-in.
The cookies we set are functional only:
- session tokens (
apri_access_token,apri_refresh_token) to keep you signed in; - your email for the sidebar label (
apri_user_email); - your interface language (
apri_lang); - your theme (
apri_theme).
We use no advertising or tracking cookies.
- session tokens (
Important: the shared knowledge layer
We store the content of a link and its analysis deduplicated by the link's address: if several people save the same public material, its content and analysis exist as one shared record rather than a copy per person. Your personal layer — which links you saved, your lists, tags and titles — is visible only to you.
2. Why we use data
- To turn a link into a card: to fetch its content and analyze it.
- To let you sign in and use your account.
- To run the service: search across your library, and the "link is ready" notification.
3. Who we share data with (processors)
To run the service we use third-party processors. This list may change — the current one always lives here, and we keep it up to date.
Infrastructure
- Supabase — database, authentication, and file storage.
- Vercel — hosting for the web app and API (region: Frankfurt, EU).
- Railway — the background worker that fetches and analyzes links.
- Inngest — the job queue between the API and the worker.
AI providers used for analysis
These receive the content of the saved material and are the most sensitive recipients:
- OpenAI — text analysis and building search vectors. It receives the post's text, caption, any transcript and recognized text obtained earlier, and — when you search — your query text.
- Google (Gemini) — understanding of video and images/screenshots, including speech transcription and text recognition. It receives the video itself (by link for YouTube, as an uploaded file otherwise) and the image bytes, along with supporting text (title, caption, domain, dates).
Under these providers' API terms, the data sent to them is not used to train their models and is retained only for a limited time (for abuse monitoring).
Fetching pages
- Decodo — a residential proxy used when a platform limits direct access. The address we're fetching passes through it.
- The source platforms themselves (YouTube, Instagram, TikTok, Pinterest, X, Reddit, etc.) — we fetch the public post at the link you saved through their own mechanisms; the saved link is sent to them.
Maps and places
- Google Places — we resolve a place name to coordinates and an address. It receives a string like "place name, city"; your coordinates and personal data are not sent.
- MapTiler — map tiles are loaded directly by your browser (tile coordinates and a public key); no personal data is sent from our side.
Catalogs
These receive only the title/identifier of a work or product — not your personal data:
- poiskkino — films and series (by title or id);
- Wikidata — by title/identifier;
- TVmaze — by IMDb identifier;
- Open Library — by work identifier;
- USDA FoodData Central — by ingredient name (for nutrition estimates).
Notifications
- Apple Push Notification service — receives your device token and a "link is ready" notification; no card content is included.
Where data is stored
The web app and API run in Vercel's Frankfurt (EU) region. The database, authentication and files (Supabase) are stored in the European Union. Other processors store data under their own terms.
4. Retention, export and deletion
- Retention. We keep your data while your account exists. There is currently no scheduled automatic deletion of old cards. (The place-geocoding cache refreshes every 30 days.)
- Export. In your profile you can export your saved list as a CSV file (link, title, category, type, date, status). This export covers the saved list, not the full page content or the full analysis.
- Deletion. You can delete individual saved links, lists, and their items at any time. You can delete your entire account from the profile screen — this removes your personal data: saved links, lists, tags, titles, settings, private screenshots, and device tokens. Not deleted are the shared, deduplicated content and analysis records (tied to a link's address, not to you personally) and the shared cover images — other users who saved the same public material may rely on them.
5. Your rights and how to reach us
You can access your data, export your saved list, and delete your data or account as described above. For any question about your data, write to support@getapri.app.
Under the Republic of Kazakhstan's Law "On Personal Data and its Protection" you have the right, in plain terms, to:
- know what data we hold about you (see this document; you can export your saved list from your profile);
- correct your data (titles, tags and settings in your profile; anything else by writing to us);
- delete your data or your account (from your profile);
- withdraw consent to processing — by deleting your account or by ceasing to use the service.
All of this is available through your profile and by email at support@getapri.app. This does not limit any mandatory rights granted to you by the laws of your country of residence.
6. Children
The service is not intended for anyone under 16. If we learn that an account was created by someone under 16, we will delete their data.
7. Changes to this policy
We may update this policy. The current version is always available in the service; for material changes we'll update the effective date at the top of this document.