Seshat Privacy Policy

Last updated: 13 August 2026

This policy explains what Seshat collects, where it goes, and how to get rid of it. It is written from the app's actual code, not from a template — every statement below corresponds to something the app really does.


1. Who we are

Seshat is a language-learning app. For the purposes of the GDPR, the developer of Seshat is the data controller. Contact details are in section 11.

2. What we collect

Account information. Your email address and, if you set one, a display name. If you sign in with Google or Apple, we receive your email address and basic profile information from that provider.

Age confirmation. Your date of birth, asked once when your account is created and used only to check that you are old enough to use Seshat (see section 10). We keep only the yes/no result, not the date itself.

Your learning content. The stories you upload or generate, the words you save, your own written meanings, example sentences and notes for those words, any images you attach to a word or story, and your reading and lesson progress.

Problem reports. If you report a problem, we receive the reason you chose, any description you write, your app version and platform, and up to three screenshots if you choose to attach them. Screenshots are stored privately — they are never published, never made available by public link, and are visible only to the Seshat team reviewing your report. They are deleted when your account is deleted.

Usage information. Which languages you study, daily activity totals used for your streak, and technical telemetry about AI requests (see section 4).

Device information. A randomly generated device identifier used to keep your data in sync across your devices, and a push-notification token if you enable notifications.

We do not collect your location, contacts, or advertising identifiers, and we do not track you across other apps or websites.

3. What we do with it

We use the above to provide the app: to store and sync your library across your devices, to show your progress, to generate learning material tailored to your vocabulary, and to enforce daily usage limits fairly.

We do not sell your personal data, and we do not use it for advertising profiling.

4. AI features and Google Gemini

Some features are powered by Google's Gemini AI. These features are off until you explicitly turn them on, and you can turn them off again at any time in Profile → Data & Safety → AI features. While they are off, nothing described in this section is sent anywhere.

When AI features are on, the following is sent to Google:

Feature What is sent
Generating a story The story description you typed, plus a list of words from your word bank with how confident you are in each
"Surprise me" story A list of words from your word bank
Filling in a word The single word you are saving
Foreign-word meanings The foreign word you tapped, taken from the story you are reading
Lesson generation Words from your word bank, your own written meanings for those words, and short sentences (6–140 characters) taken from stories you uploaded
Story processing Foreign-script words found in a story you uploaded, so their meanings can be prepared in advance

Your name, your email address, and your account identifier are never sent to Google. Requests are made under our developer account, not yours.

We use the paid tier of the Gemini API. Under Google's terms for that tier, Google does not use your prompts or the responses to train or improve its models, and retains them only briefly for abuse detection. Google's terms are at https://ai.google.dev/gemini-api/terms.

5. Other services we send data to

Supabase hosts our database, authentication and file storage. All of your account data and learning content is stored there.

A text-analysis service we operate (hosted on Fly.io) receives the full text of stories you upload or generate in order to split them into words and add readings. It analyses the text and returns the result; it does not store your text and does not know who you are.

Both providers are bound to protect your data to the same standard described in this policy.

6. A note on the shared word cache

To avoid paying for the same lookup twice, AI-generated meanings for individual words are cached and shared between users. This cache stores the word you looked up and the AI's answer.

It never stores anything you wrote yourself. Your own meanings, example sentences, notes and images stay in your account and are never placed in the shared cache, so they cannot reach another user.

7. How long we keep it

Your content is kept until you delete it or delete your account.

Cached AI word meanings expire after 180 days.

Technical AI-usage records (how many requests, how many tokens, whether they succeeded — never the content) are retained for cost accounting. When you delete your account these records are anonymised: the link to you is permanently removed, and what remains cannot be traced back to you.

8. Deleting your account

You can delete your account from Profile → Data & Safety → Delete account.

Your account is disabled immediately and you are signed out on every device. After 30 days it is permanently deleted, including your stories, your word bank, your progress and any images you uploaded. During those 30 days you can sign back in and restore everything. After that, it cannot be recovered.

9. Your rights

If you are in the EEA or the UK, you have the right to access, correct, export, delete and restrict processing of your personal data, and to object to it. You can export a complete, machine-readable copy of your data from Profile → Data & Safety → Export my data, and you can delete your account and revoke AI consent directly in the app. For anything else, contact us using section 11 and we will respond within one month.

You also have the right to complain to your local data protection authority.

10. Children

Seshat is for people aged 13 and over. It is a general-audience service and is not directed to children. We do not knowingly collect personal information from anyone under 13.

We ask for your date of birth on a neutral age screen when an account is created. We use that date of birth for one thing only — deciding whether you meet the age requirement — and we do not store it: we keep only the yes/no result of that check. If the answer is no, we do not create an account, and if an account was already created during sign-in (for example through Google or Apple) we delete it along with anything attached to it.

If you believe someone under 13 has given us personal information, contact us using section 11 and we will delete the account and the data.

11. Contact

Questions about this policy, or a request about your data:

ahmedgalal11045@gmail.com

12. Changes

If we change this policy in a way that materially affects how we handle your data, we will tell you in the app before the change takes effect. The date at the top of this page always reflects the current version.