← TC Fusion

Papote Privacy Policy

Effective date: August 27, 2026 · Last updated: August 29, 2026

This Privacy Policy explains how TC Fusion LLC ("TC Fusion," "we," "us," or "our") handles personal data when you use the Papote mobile application and related services (together, the "Service"). It also describes your rights under the EU and UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA/CPRA"), and other applicable laws.

The short version

Contents
  1. Who we are
  2. What we collect
  3. What stays on your device
  4. Optional iCloud backup
  5. YouTube and embedded video
  6. Subscriptions and payments
  7. Analytics, crash reports, the off switch, and ad measurement
  8. Legal bases (GDPR)
  9. Sub-processors
  10. Retention
  11. Your rights
  12. Children
  13. International transfers
  14. Security
  15. Changes
  16. Contact

1. Who we are

Papote is published by TC Fusion LLC, a limited liability company registered in the United States. For privacy questions, contact privacy@tcfusion.dev. TC Fusion is the data controller for the processing described here.

2. What we collect

Papote is designed to need as little about you as possible. We do not ask for a name, email address, phone number, or social login, and there is no account to create.

CategoryExamplesWhere it goes
Learning data Saved words, review schedule and results, streaks, daily goal, watch history, level estimate Your device only. Stored in an on-device database. Not transmitted to us.
Catalog requests Requests for French clips and transcripts at your level and chosen topics Our content servers. These requests are not tied to an account; server logs may briefly contain your IP address for security and abuse prevention.
Product analytics Pseudonymous events such as "app opened," "video watched," "word saved," "paywall viewed," plus device model, OS version, app version, coarse country PostHog (European Union). Keyed to a random device-generated identifier, not to your identity. Off entirely if you switch analytics off in Settings.
Crash diagnostics Stack traces, device model, OS version, app version, breadcrumb of screens visited Sentry (United States). The same Settings switch turns these off too.
Subscription status Whether a trial or subscription is active, product purchased, purchase and expiry dates, a store-issued transaction identifier RevenueCat (United States) and the app store you purchased from. Keyed to an anonymous identifier, not to your name.
Ad measurement App installs and app opens from Meta's SDK; trial starts and subscription starts and renewals sent by RevenueCat, with the amount and currency; device and app details; an anonymous identifier created on your device; your advertising identifier only if you allow tracking Meta Platforms (United States and European Union), from Meta's SDK on your device and from RevenueCat's servers through Meta's Conversions API. The Settings switch turns the on-device part off. We never send your saved words, watch history, name, or email.
Optional iCloud backup A copy of your learning data, written as one file, only if you turn the backup on Your own iCloud account, inside the app's iCloud container. We never receive it and cannot read it. See Section 4.
Support correspondence Whatever you choose to write to us, and the email address you write from Our email provider, kept only as long as needed to resolve the issue.

We do not collect your contacts, photos, precise location, microphone or camera input, or health data. We collect your device advertising identifier only if you allow tracking when we ask, and you can change that answer later. Meta's SDK, which measures our ads, is the one advertising-related SDK in Papote, and we never show ads inside the app.

3. What stays on your device

Everything that makes Papote yours, meaning the words you saved, when they're next due, how many clips you've watched, your streak, lives in a local database on your phone. We designed it this way deliberately: there is no profile of your learning on our servers to leak, subpoena, or sell.

The trade-off is that we hold no copy to give back to you. If you delete the app, reset it, or switch phones without a backup, your saved words and progress are gone. Section 4 covers the two ways to keep a copy. Your subscription itself is not affected, as Section 6 explains.

4. Optional iCloud backup

Papote can keep a backup of your learning data, and it is off until you switch it on in Settings. When it is on, the app writes a single file into its own iCloud container on your Apple ID. That container is yours: the file appears in the Files app under the Papote folder, and you can copy, move, or delete it. We never receive the file, we hold no key to it, and we cannot read it or delete it for you. Apple's handling of iCloud is governed by Apple's Privacy Policy.

The same data is also available on demand as a manual export you can save or send wherever you like. It is the same file format as the iCloud backup, so a file pulled out of iCloud Drive can be pasted back into the app by hand, and an export made by hand can be restored the same way.

Automatic backup is available on iOS only. On Android there is no automatic cloud backup, and the manual export is how you move your data to a new phone. Turning the backup off stops future backups; it does not delete the file already in your iCloud container, because that file is yours and only you can reach it.

5. YouTube and embedded video

Papote does not host, download, or re-upload video. Every clip plays inside the official YouTube player, embedded in the app, and each clip credits and links back to the channel that made it.

Because the video is played by YouTube's own player, Google receives information directly from that player, including your IP address, device information, and which video was played, and may set cookies or similar identifiers on your device. That processing is governed by Google's Privacy Policy, not by this one. We do not receive your YouTube account information, and Papote never asks you to sign in to Google.

Transcripts, translations, and word glosses shown alongside a clip are produced by us in advance, stored in our catalog, and served identically to everyone at that level. They are not generated from anything about you.

6. Subscriptions and payments

Papote is a paid app: after the introduction, access requires a subscription. Purchases are handled entirely by Apple or Google. We never see or receive your card number, billing address, or app-store account credentials.

We use RevenueCat to check whether a purchase is valid and still active. RevenueCat identifies your purchase with a random, app-generated identifier, not your name or email. This is what lets "Restore purchases" work if you reinstall the app or get a new phone, even though Papote has no accounts.

7. Analytics, crash reports, the off switch, and ad measurement

We use PostHog (hosted in the European Union) to understand how the app is used in aggregate: which screens people reach, where onboarding loses people, whether a feature is working. Events are keyed to a random identifier generated on your device. We do not combine this with any identity, and we do not use it for advertising or cross-app tracking.

PostHog can also reconstruct a session as a redacted screen recording, so we can see where the app confuses people: which screens were visited and where taps landed. Redaction happens on your device before anything is sent. Every piece of text, every image and every video is replaced with a blank rectangle, so a replay never contains a caption, a video frame, a word you saved, or anything you typed. Replays are keyed to the same random identifier, kept for 30 days, and the analytics switch in Settings turns them off along with everything else in this section.

We use Sentry to receive crash and error reports so we can fix bugs. Reports contain technical diagnostics, not your saved words or learning history.

Settings has one switch that covers both. Turn analytics off and the app stops sending PostHog events and Sentry reports on your device, for as long as it stays off. Nothing about the app is withheld or degraded if you do.

How we measure our ads

We run ads for Papote on Facebook and Instagram. To see which of those ads bring people who go on to try the app or subscribe, we send Meta a short list of events. Meta's SDK inside the app reports installs and app opens. RevenueCat sends trial starts, subscription starts, and renewals from its own servers through Meta's Conversions API, with the amount and currency of the purchase.

Those events carry an anonymous identifier that Meta's SDK creates on your device, your device and app details (model, OS version, app version, language, IP address), and your advertising identifier if you allowed tracking. Your name, email, phone number, saved words, watch history and learning progress are never part of it. We do this so we spend less on ads that don't work. Meta may also use these events for its own purposes under the Meta Privacy Policy, and you can review or disconnect what apps send it under Activity off Meta technologies.

On iOS we explain what we are asking for in our own words, and then Apple's App Tracking Transparency prompt appears. Say no and we do not share your advertising identifier, and Meta is told that tracking is not permitted, which limits what Meta may do with the events. You can change your answer any time in Settings > Privacy & Security > Tracking. On Android, Settings > Google > Ads lets you reset or delete your advertising ID.

The same analytics switch in Settings turns off Meta's event logging and advertising identifier collection on your device. Meta's SDK still starts with the app, so a launch may register once as an anonymous app open. The subscription events RevenueCat sends from its own servers carry on while you have a subscription, without your advertising identifier.

8. Legal bases (GDPR)

PurposeLegal basis
Delivering the video catalog and learning content you requestPerformance of a contract (Art. 6(1)(b))
Validating and restoring subscriptionsPerformance of a contract (Art. 6(1)(b))
Product analytics to improve the appLegitimate interests (Art. 6(1)(f)): improving a service you chose to use, using pseudonymous data, with an off switch in Settings. Where local law requires consent for analytics, we ask for it.
Crash diagnostics and security or abuse preventionLegitimate interests (Art. 6(1)(f))
Measuring which of our ads lead to trials and subscriptionsLegitimate interests (Art. 6(1)(f)): pseudonymous events about our own ads, with the opt-outs in Section 7
Sharing your advertising identifier for that measurementConsent (Art. 6(1)(a)), given through Apple's tracking prompt or your Android ad settings, and withdrawable in the same place
Writing your backup to your own iCloud containerConsent (Art. 6(1)(a)), given by turning the backup on, and withdrawable by turning it off
Responding to support requestsLegitimate interests (Art. 6(1)(f)), or performance of a contract

9. Sub-processors

These providers process limited data on our behalf:

ProviderPurposeRegion
SupabaseVideo catalog, transcripts, content pipelineUnited States
PostHogProduct analyticsEuropean Union
SentryCrash and error diagnosticsUnited States
RevenueCatSubscription validation and restoreUnited States
Meta Platforms, Inc. / Meta Platforms Ireland Ltd.Advertising measurement (Meta SDK, Conversions API)United States and European Union
Google (YouTube)Video playback in the embedded playerGlobal
Apple / Google PlayApp distribution and payment processingGlobal
Cloudflare, Google FirebaseDomain, DNS, and this websiteGlobal

Apple iCloud is not on this list on purpose. When you turn the optional backup on, the file goes into your own iCloud account under your agreement with Apple, and we are not a party to it.

10. Retention

11. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. California residents have rights to know, delete, correct, and to opt out of "sale" or "sharing." We do not sell personal information. Sending Meta the pseudonymous ad measurement events described in Section 7 may count as "sharing" for cross-context behavioral advertising under the CCPA and CPRA, so you can opt out: decline tracking on iOS, turn the analytics switch off in Settings, or write to privacy@tcfusion.dev.

Because Papote has no accounts, most of your data isn't identifiable to you by us. The fastest way to exercise deletion of your learning data is to delete the app, and to delete the backup file in the Files app if you turned iCloud backup on. For analytics, crash, or subscription records, write to privacy@tcfusion.dev. To locate the right records we may need the anonymous identifier shown in the app under Settings, or your app-store receipt, or both. We respond within 30 days.

If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.

Deleting your data

Your learning data lives on your phone, so deleting the app deletes it. If you turned iCloud backup on, delete the backup file in the Files app too, under the Papote folder. Only you can reach it.

For analytics, crash, subscription and ad measurement records, write to privacy@tcfusion.dev. Include the anonymous identifier shown in the app under Settings, your app-store receipt, or both, so we can find the right records. We delete or anonymise them within 30 days, and we ask RevenueCat and Meta to do the same with the identifiers we hold. Whatever Meta has collected on its own side, you can manage under Activity off Meta technologies.

12. Children

Papote is not directed to children under 13 (or under 16 where local law sets that age), and we do not knowingly collect personal data from them. The app displays third-party video from public YouTube channels. We curate the catalog for language learning, and we still recommend parental judgement for younger teenagers. If you believe a child has provided us personal data, contact us and we will delete it.

13. International transfers

We are based in the United States and some of our providers are too. Where personal data is transferred out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) or another approved transfer mechanism.

14. Security

Data in transit is encrypted with TLS. Access to our systems is limited to people who need it and protected by multi-factor authentication. Keeping your learning data on your device instead of on our servers is itself a deliberate security measure. No system is perfectly secure, and we cannot guarantee absolute security.

15. Changes

If we change this policy materially, we will update the date at the top and, where the change is significant, notify you in the app. Continuing to use the Service after a change means you accept the updated policy.

16. Contact

TC Fusion LLC, privacy@tcfusion.dev
Support: support@tcfusion.dev or trent@tcfusion.dev

Papote is not affiliated with, endorsed by, or sponsored by YouTube or Google. Video content belongs to the creators who made it and is played through YouTube's official embedded player.

French dictionary data: WikDict by Karl Bartel. Data from Wiktionary via DBnary, licensed CC BY-SA 4.0. www.wikdict.com