Skip to content
WorkRythm: AI Study Cards
Home Terms Contact Account Deletion

Privacy

WorkRythm: AI Study Cards Privacy Policy

Effective date: September 5, 2026

This policy explains what information WorkRythm processes, why it is needed, where it is stored, which providers receive it, and how you can request access or deletion.

Who We Are and Scope

WorkRythm: AI Study Cards is developed by DuVarian Games & Software. This policy covers the WorkRythm mobile app and its public support pages. For privacy questions or requests, contact duvariangames@gmail.com.

Sign-In and Account Information

WorkRythm supports Google Sign-In, Sign in with Apple on supported Apple devices, email and password accounts, and anonymous guest access. Depending on the method you choose, Firebase Authentication provides an account identifier, authentication provider, email address, and display name. We store the fields needed to identify and operate your WorkRythm account. When an Apple-authenticated user deletes an account, the app requests fresh Apple authorization and revokes the associated Apple token before the WorkRythm account is removed.

Google Sign-In

If you select Google Sign-In, WorkRythm receives your Google account identifier, email address, display name, and sign-in provider through Google Sign-In and Firebase Authentication. We use this information only to authenticate you, identify and display your WorkRythm profile, and associate your account settings, reminder preferences, AI token balance, unlocked items, and purchase entitlements with that account.

WorkRythm does not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other sensitive or restricted Google user data. We do not sell Google Sign-In data, use it for advertising, or share it except with the service providers needed to authenticate and operate the account as described below.

Information Stored in Firebase

  • Account identifier, email address, display name, authentication provider, and account timestamps.
  • Interface language, time zone, notification preferences, reminder times, and a Firebase Cloud Messaging token after notification permission is granted.
  • AI token balance and token transaction records, reward limits, rate-limit records, ad-removal or focus-pass state, unlocked avatar items, and related entitlement state.
  • WorkRythm copies of purchase and entitlement events received from RevenueCat so purchases can be applied safely and only once.
  • Temporary photos you deliberately submit to an AI+ photo feature.

Study Data Stored on Your Device

Your flashcard decks, quizzes, tasks and task stages, AI+ result history, study preferences, Pomodoro history, statistics, and spaced-repetition records are stored in WorkRythm's local app storage on your device. WorkRythm does not sync this study library to Firestore as cloud study content.

Files that you export or share outside WorkRythm are copies under your control and are no longer managed by the app's local storage.

AI+ Inputs, Documents, Photos, and Outputs

AI+ can create flashcards, quizzes, topic summaries, photo explanations, and learning paths. When you request one of these features, WorkRythm sends the prompt or messages needed for that request through Firebase Cloud Functions to OpenAI.

For supported TXT, Markdown, CSV, PDF, and DOCX files, WorkRythm extracts text on your device and sends the relevant extracted text with your request; the original document file is not uploaded as a document. For photo-based requests, the selected image may be uploaded temporarily to Firebase Storage so OpenAI can process it. AI image uploads become eligible for deletion after 24 hours and are checked by an automatic cleanup that runs daily, so deletion normally occurs during the next cleanup cycle.

The generated result is returned to the app. AI+ history, including the inputs and outputs shown in that history, is stored locally on your device with a limit of 50 entries per AI+ feature. Do not submit personal, confidential, medical, legal, financial, or third-party material unless you have the right to use it and accept that it will be processed for your request.

Analytics, Diagnostics, Notifications, and App Protection

  • Firebase Analytics processes app-open, sign-in, creation, quiz, flashcard, and Pomodoro usage events. While you are signed in, analytics may be associated with your WorkRythm user identifier.
  • Firebase Crashlytics processes crash reports and technical diagnostics such as device, operating system, and app-version information needed to identify reliability problems.
  • Firebase Cloud Messaging processes the notification token and reminder settings needed to deliver study reminders you enable.
  • Firebase App Check processes app and device attestation signals to help reject automated abuse and unauthorized requests. These signals are not study content.

Purchases, Subscriptions, and Entitlements

Apple App Store or Google Play processes the payment transaction. RevenueCat processes a WorkRythm account identifier, product and entitlement information, transaction status, and related purchase events so the app can restore purchases and maintain subscriptions, AI token purchases, avatar unlocks, focus-pass access, and ad-removal state. WorkRythm does not receive or store your full payment-card number.

Advertising

Google AdMob provides interstitial and rewarded advertisements. On iOS and iPadOS, WorkRythm requests non-personalized ads and disables the Google Mobile Ads same-app identifier; it does not request App Tracking Transparency permission. On Android, AdMob may use the Android advertising identifier and may provide personalized advertising or measurement depending on your Google settings, consent status, region, and applicable platform requirements. Google Sign-In data is not used by WorkRythm to personalize ads.

How We Use Information

  • Authenticate users and maintain account, profile, settings, reminder, token, and entitlement state.
  • Process the AI+ request you initiate and return the generated study material.
  • Deliver notifications and study reminders you enable.
  • Restore purchases, grant purchased or earned items, and prevent duplicate transactions or abuse.
  • Measure product operation, diagnose crashes, improve reliability, and protect the service.
  • Respond to support, privacy, and account-deletion requests and meet legal, security, accounting, and platform obligations.

Service Providers and Sharing

We share only the information needed for the functions described in this policy with:

  • Google Firebase and Google Cloud for authentication, Firestore, Storage, Cloud Functions, Analytics, Crashlytics, Cloud Messaging, and App Check.
  • OpenAI for AI+ requests and generated responses.
  • RevenueCat, Apple App Store, and Google Play for purchases, subscriptions, restoration, and entitlement processing.
  • Google AdMob for advertising and related consent or measurement signals.
  • Email and support providers when you contact us.

These providers process information under their own terms and privacy obligations. We may also disclose information when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.

Retention and Account Deletion

Account profile and service-state records are retained while your account is active. AI image uploads follow the cleanup cycle described above. Rate-limit, transaction, purchase-event, security, and diagnostic records are retained only for the period needed to operate the feature, prevent abuse, resolve disputes, satisfy platform or accounting requirements, or meet a legal obligation.

After a completed WorkRythm account deletion, the app removes the active WorkRythm account, eligible user-linked cloud records and AI uploads, and local app data on that device. A one-way pseudonymous deletion marker is kept for 30 days to prevent delayed purchase webhooks from recreating deleted account data. Provider-controlled store or RevenueCat purchase records, aggregated analytics, crash reports, bounded security logs, backups awaiting rotation, or records required by law may remain for their applicable retention periods and are not used to restore the deleted profile.

See Account Deletion for the exact in-app steps, email alternative, deleted-data scope, and device limitations.

Security

We use authenticated requests, Firebase Security Rules, App Check, server-side authorization, scoped storage paths, rate limits, and access controls intended to protect WorkRythm data. No storage or transmission system is completely secure, so we cannot guarantee absolute security.

Your Choices and Rights

You can choose a sign-in method, decline optional notification access, change reminder settings, remove locally stored study items, and delete your account from Settings. Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal data, and to withdraw consent where processing relies on consent.

To make a privacy request, email duvariangames@gmail.com. We may request reasonable verification before acting on an account-specific request. You may also contact the relevant privacy authority where local law provides that right.

Children

WorkRythm is not directed to children below the age at which they may independently consent to an online service under applicable local law. If you believe a child supplied personal information without required authorization, contact us so we can investigate and delete it where appropriate.

International Processing

Our service providers may process information in countries other than your own. Where required, processing relies on provider safeguards, contractual protections, and applicable transfer mechanisms.

Changes to This Policy

We may update this policy when WorkRythm's features, service providers, data practices, or legal and platform requirements change. We will update the effective date and provide any additional notice required by law.

WorkRythm: AI Study Cards is developed by DuVarian Games & Software.
HomeTermsContactAccount Deletion