Effective date: August 27, 2026 · Last updated: August 29, 2026
This Privacy Policy explains how TC Fusion LLC ("TC Fusion," "we," "us," or "our") handles personal data when you use the Papote mobile application and related services (together, the "Service"). It also describes your rights under the EU and UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA/CPRA"), and other applicable laws.
Papote is published by TC Fusion LLC, a limited liability company registered in the United States. For privacy questions, contact privacy@tcfusion.dev. TC Fusion is the data controller for the processing described here.
Papote is designed to need as little about you as possible. We do not ask for a name, email address, phone number, or social login, and there is no account to create.
| Category | Examples | Where it goes |
|---|---|---|
| Learning data | Saved words, review schedule and results, streaks, daily goal, watch history, level estimate | Your device only. Stored in an on-device database. Not transmitted to us. |
| Catalog requests | Requests for French clips and transcripts at your level and chosen topics | Our content servers. These requests are not tied to an account; server logs may briefly contain your IP address for security and abuse prevention. |
| Product analytics | Pseudonymous events such as "app opened," "video watched," "word saved," "paywall viewed," plus device model, OS version, app version, coarse country | PostHog (European Union). Keyed to a random device-generated identifier, not to your identity. Off entirely if you switch analytics off in Settings. |
| Crash diagnostics | Stack traces, device model, OS version, app version, breadcrumb of screens visited | Sentry (United States). The same Settings switch turns these off too. |
| Subscription status | Whether a trial or subscription is active, product purchased, purchase and expiry dates, a store-issued transaction identifier | RevenueCat (United States) and the app store you purchased from. Keyed to an anonymous identifier, not to your name. |
| Ad measurement | App installs and app opens from Meta's SDK; trial starts and subscription starts and renewals sent by RevenueCat, with the amount and currency; device and app details; an anonymous identifier created on your device; your advertising identifier only if you allow tracking | Meta Platforms (United States and European Union), from Meta's SDK on your device and from RevenueCat's servers through Meta's Conversions API. The Settings switch turns the on-device part off. We never send your saved words, watch history, name, or email. |
| Optional iCloud backup | A copy of your learning data, written as one file, only if you turn the backup on | Your own iCloud account, inside the app's iCloud container. We never receive it and cannot read it. See Section 4. |
| Support correspondence | Whatever you choose to write to us, and the email address you write from | Our email provider, kept only as long as needed to resolve the issue. |
We do not collect your contacts, photos, precise location, microphone or camera input, or health data. We collect your device advertising identifier only if you allow tracking when we ask, and you can change that answer later. Meta's SDK, which measures our ads, is the one advertising-related SDK in Papote, and we never show ads inside the app.
Everything that makes Papote yours, meaning the words you saved, when they're next due, how many clips you've watched, your streak, lives in a local database on your phone. We designed it this way deliberately: there is no profile of your learning on our servers to leak, subpoena, or sell.
The trade-off is that we hold no copy to give back to you. If you delete the app, reset it, or switch phones without a backup, your saved words and progress are gone. Section 4 covers the two ways to keep a copy. Your subscription itself is not affected, as Section 6 explains.
Papote can keep a backup of your learning data, and it is off until you switch it on in Settings. When it is on, the app writes a single file into its own iCloud container on your Apple ID. That container is yours: the file appears in the Files app under the Papote folder, and you can copy, move, or delete it. We never receive the file, we hold no key to it, and we cannot read it or delete it for you. Apple's handling of iCloud is governed by Apple's Privacy Policy.
The same data is also available on demand as a manual export you can save or send wherever you like. It is the same file format as the iCloud backup, so a file pulled out of iCloud Drive can be pasted back into the app by hand, and an export made by hand can be restored the same way.
Automatic backup is available on iOS only. On Android there is no automatic cloud backup, and the manual export is how you move your data to a new phone. Turning the backup off stops future backups; it does not delete the file already in your iCloud container, because that file is yours and only you can reach it.
Papote does not host, download, or re-upload video. Every clip plays inside the official YouTube player, embedded in the app, and each clip credits and links back to the channel that made it.
Transcripts, translations, and word glosses shown alongside a clip are produced by us in advance, stored in our catalog, and served identically to everyone at that level. They are not generated from anything about you.
Papote is a paid app: after the introduction, access requires a subscription. Purchases are handled entirely by Apple or Google. We never see or receive your card number, billing address, or app-store account credentials.
We use RevenueCat to check whether a purchase is valid and still active. RevenueCat identifies your purchase with a random, app-generated identifier, not your name or email. This is what lets "Restore purchases" work if you reinstall the app or get a new phone, even though Papote has no accounts.
We use PostHog (hosted in the European Union) to understand how the app is used in aggregate: which screens people reach, where onboarding loses people, whether a feature is working. Events are keyed to a random identifier generated on your device. We do not combine this with any identity, and we do not use it for advertising or cross-app tracking.
PostHog can also reconstruct a session as a redacted screen recording, so we can see where the app confuses people: which screens were visited and where taps landed. Redaction happens on your device before anything is sent. Every piece of text, every image and every video is replaced with a blank rectangle, so a replay never contains a caption, a video frame, a word you saved, or anything you typed. Replays are keyed to the same random identifier, kept for 30 days, and the analytics switch in Settings turns them off along with everything else in this section.
We use Sentry to receive crash and error reports so we can fix bugs. Reports contain technical diagnostics, not your saved words or learning history.
Settings has one switch that covers both. Turn analytics off and the app stops sending PostHog events and Sentry reports on your device, for as long as it stays off. Nothing about the app is withheld or degraded if you do.
We run ads for Papote on Facebook and Instagram. To see which of those ads bring people who go on to try the app or subscribe, we send Meta a short list of events. Meta's SDK inside the app reports installs and app opens. RevenueCat sends trial starts, subscription starts, and renewals from its own servers through Meta's Conversions API, with the amount and currency of the purchase.
Those events carry an anonymous identifier that Meta's SDK creates on your device, your device and app details (model, OS version, app version, language, IP address), and your advertising identifier if you allowed tracking. Your name, email, phone number, saved words, watch history and learning progress are never part of it. We do this so we spend less on ads that don't work. Meta may also use these events for its own purposes under the Meta Privacy Policy, and you can review or disconnect what apps send it under Activity off Meta technologies.
On iOS we explain what we are asking for in our own words, and then Apple's App Tracking Transparency prompt appears. Say no and we do not share your advertising identifier, and Meta is told that tracking is not permitted, which limits what Meta may do with the events. You can change your answer any time in Settings > Privacy & Security > Tracking. On Android, Settings > Google > Ads lets you reset or delete your advertising ID.
The same analytics switch in Settings turns off Meta's event logging and advertising identifier collection on your device. Meta's SDK still starts with the app, so a launch may register once as an anonymous app open. The subscription events RevenueCat sends from its own servers carry on while you have a subscription, without your advertising identifier.
| Purpose | Legal basis |
|---|---|
| Delivering the video catalog and learning content you request | Performance of a contract (Art. 6(1)(b)) |
| Validating and restoring subscriptions | Performance of a contract (Art. 6(1)(b)) |
| Product analytics to improve the app | Legitimate interests (Art. 6(1)(f)): improving a service you chose to use, using pseudonymous data, with an off switch in Settings. Where local law requires consent for analytics, we ask for it. |
| Crash diagnostics and security or abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Measuring which of our ads lead to trials and subscriptions | Legitimate interests (Art. 6(1)(f)): pseudonymous events about our own ads, with the opt-outs in Section 7 |
| Sharing your advertising identifier for that measurement | Consent (Art. 6(1)(a)), given through Apple's tracking prompt or your Android ad settings, and withdrawable in the same place |
| Writing your backup to your own iCloud container | Consent (Art. 6(1)(a)), given by turning the backup on, and withdrawable by turning it off |
| Responding to support requests | Legitimate interests (Art. 6(1)(f)), or performance of a contract |
These providers process limited data on our behalf:
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Video catalog, transcripts, content pipeline | United States |
| PostHog | Product analytics | European Union |
| Sentry | Crash and error diagnostics | United States |
| RevenueCat | Subscription validation and restore | United States |
| Meta Platforms, Inc. / Meta Platforms Ireland Ltd. | Advertising measurement (Meta SDK, Conversions API) | United States and European Union |
| Google (YouTube) | Video playback in the embedded player | Global |
| Apple / Google Play | App distribution and payment processing | Global |
| Cloudflare, Google Firebase | Domain, DNS, and this website | Global |
Apple iCloud is not on this list on purpose. When you turn the optional backup on, the file goes into your own iCloud account under your agreement with Apple, and we are not a party to it.
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. California residents have rights to know, delete, correct, and to opt out of "sale" or "sharing." We do not sell personal information. Sending Meta the pseudonymous ad measurement events described in Section 7 may count as "sharing" for cross-context behavioral advertising under the CCPA and CPRA, so you can opt out: decline tracking on iOS, turn the analytics switch off in Settings, or write to privacy@tcfusion.dev.
Because Papote has no accounts, most of your data isn't identifiable to you by us. The fastest way to exercise deletion of your learning data is to delete the app, and to delete the backup file in the Files app if you turned iCloud backup on. For analytics, crash, or subscription records, write to privacy@tcfusion.dev. To locate the right records we may need the anonymous identifier shown in the app under Settings, or your app-store receipt, or both. We respond within 30 days.
If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
Your learning data lives on your phone, so deleting the app deletes it. If you turned iCloud backup on, delete the backup file in the Files app too, under the Papote folder. Only you can reach it.
For analytics, crash, subscription and ad measurement records, write to privacy@tcfusion.dev. Include the anonymous identifier shown in the app under Settings, your app-store receipt, or both, so we can find the right records. We delete or anonymise them within 30 days, and we ask RevenueCat and Meta to do the same with the identifiers we hold. Whatever Meta has collected on its own side, you can manage under Activity off Meta technologies.
Papote is not directed to children under 13 (or under 16 where local law sets that age), and we do not knowingly collect personal data from them. The app displays third-party video from public YouTube channels. We curate the catalog for language learning, and we still recommend parental judgement for younger teenagers. If you believe a child has provided us personal data, contact us and we will delete it.
We are based in the United States and some of our providers are too. Where personal data is transferred out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) or another approved transfer mechanism.
Data in transit is encrypted with TLS. Access to our systems is limited to people who need it and protected by multi-factor authentication. Keeping your learning data on your device instead of on our servers is itself a deliberate security measure. No system is perfectly secure, and we cannot guarantee absolute security.
If we change this policy materially, we will update the date at the top and, where the change is significant, notify you in the app. Continuing to use the Service after a change means you accept the updated policy.
TC Fusion LLC, privacy@tcfusion.dev
Support: support@tcfusion.dev or
trent@tcfusion.dev
Papote is not affiliated with, endorsed by, or sponsored by YouTube or Google. Video content belongs to the creators who made it and is played through YouTube's official embedded player.
French dictionary data: WikDict by Karl Bartel. Data from Wiktionary via DBnary, licensed CC BY-SA 4.0. www.wikdict.com