Privacy policy

PageBite · Last updated: 18 September 2026

The short version

The German version of this policy is the legally binding one. This English version is provided for your convenience.

1. Controller

Henri Irmscher — Appentwicklung
Seckbacher Landstr. 66
60389 Frankfurt am Main
Germany

Email: henri.irmscher@gmail.com

This policy covers the PageBite app and this website.

2. An anonymous account instead of registration

When you scan your free page in onboarding, or at the latest right before you see the subscription options, the app creates an anonymous account with our service provider Supabase. It consists of a random identifier. We don't need your name or email address for it. We use the same identifier at RevenueCat to link your subscription to your account.

We automatically delete anonymous accounts without a subscription after 30 days. The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR).

3. What data we process

Data Where Purpose Legal basis How long
Photos of your book pages Only on your phone (temporary folder) Text recognition on the device Art. 6(1)(b) GDPR Deleted right after text recognition
Recognized page text On your phone; sent briefly to Google Gemini Create cards, show the original text Art. 6(1)(b) GDPR On the phone until you delete the page, your account or the app. At Google see section 5
AI output (key ideas, quizzes, flashcards) Phone and Supabase (Frankfurt am Main) Learning, backup, sync Art. 6(1)(b) GDPR Until you delete it or your account
Books (title, author) and page labels Phone and Supabase Organizing cards Art. 6(1)(b) GDPR Until you delete them or your account
Review history (ratings, next review) Phone and Supabase Scheduling reviews Art. 6(1)(b) GDPR Until you delete the card or your account
Account (anonymous identifier; optionally your email address) Supabase Sign-in, sync Art. 6(1)(b) GDPR Until you delete your account. Anonymous accounts without a subscription: 30 days
Subscription status Apple or Google, RevenueCat, Supabase Access to the features Art. 6(1)(b) GDPR Until you delete your account. Apple and Google keep their own records
Consent records (statistics, AI processing) with time Phone and Supabase Proof of your choice Art. 6(1)(c) GDPR with Art. 7(1) GDPR Until you delete your account
Onboarding answers (reading goal, obstacle, reading volume) Phone; at PostHog only with consent Default settings, for example new cards per day; statistics Art. 6(1)(b) GDPR; PostHog: Art. 6(1)(a) GDPR Until you delete the app. PostHog see section 6
Usage statistics PostHog (EU) Improving the app Art. 6(1)(a) GDPR with § 25(1) TDDDG Until you delete your account or ask us to delete them
Counter of scans per day Supabase Protection against abuse and costs (weekly limit) Art. 6(1)(f) GDPR 30 days
Cost log of AI requests (account identifier, model, number of tokens, cost; no text) Supabase Monitoring and limiting costs Art. 6(1)(f) GDPR 400 days. If you delete your account, we remove the account identifier right away
Record of the free page (account identifier, time) Supabase One free page per account, protection against abuse Art. 6(1)(f) GDPR Until you delete your account. Anonymous accounts without a subscription: 30 days
Technical logs (IP address, time, request data) Supabase, Google Cloud, PostHog, RevenueCat Security and operations Art. 6(1)(f) GDPR According to the providers' retention periods

Our legitimate interest (Art. 6(1)(f) GDPR) is running the app securely and protecting it against abuse.

What your reading list can reveal

The books you read can reveal something about your health, your beliefs or your political views. That is why we protect this data especially well: it never goes into usage statistics, the original text stays on your phone, the servers are in the EU, access is strictly limited to your account, and you can delete everything at any time.

Daily reminder

If you turn on the daily reminder, the app plans the notifications on your phone only, using the notification feature of iOS or Android. They only say how many cards are due, never what is on your cards or in your books. We do not use push notifications, and none of this is sent to us or anyone else. You can turn the reminder off in Settings at any time.

4. Scanning: photos stay on your phone

5. AI processing with Google Gemini

Before your first scan, the app asks for your permission. Only then is the recognized text of a page sent to our server and from there to Google Gemini. Google Gemini creates the key idea, quiz and flashcards from it. Our server does not store the page text and does not write it into any logs.

In onboarding you can scan one page for free before you subscribe. Until you buy, the result stays on your phone only. So that each account gets only one free page, our server stores your account identifier and the time. We delete this record with your account. The legal basis is our legitimate interest in limiting abuse and costs (Art. 6(1)(f) GDPR).

6. Usage statistics (only with consent)

On first launch, we ask whether we may collect usage statistics. Both answers are equally easy to choose. If you say no, the app does not even start the statistics service.

7. Subscription and purchases

You buy the subscription through Apple's App Store or Google Play. Apple and Google process your payment data under their own responsibility. We never see payment data. RevenueCat manages for us whether your subscription is active and reports this to our server. For this, RevenueCat receives your anonymous account identifier and the purchase data from the store (product, period, status).

8. Backup, sync and sign-in with an email code

9. Recipients and processors

These service providers process data on our behalf. We have data processing agreements with all of them.

Service Task Data location Basis for transfers
Supabase Inc. Database, accounts, server functions, sending sign-in codes EU (Frankfurt am Main) Data processing agreement; US company: EU Standard Contractual Clauses and EU-US Data Privacy Framework
Google Cloud (Google Cloud EMEA Ltd. / Google LLC) AI processing with Gemini EU (location eu) Cloud Data Processing Addendum; EU Standard Contractual Clauses and EU-US Data Privacy Framework
PostHog Inc. Usage statistics, only with consent EU cloud Data processing agreement; EU Standard Contractual Clauses and EU-US Data Privacy Framework
RevenueCat Inc. Managing subscription status USA Data processing agreement; EU Standard Contractual Clauses and EU-US Data Privacy Framework

Apple (App Store) and Google (Google Play, and Google ML Kit on Android) act under their own responsibility. Their own privacy policies apply.

Transfers to the USA

RevenueCat processes data in the USA. Supabase, Google and PostHog are US companies, even though your data is stored in the EU. For the USA, the European Commission's adequacy decision for the EU-US Data Privacy Framework applies (Art. 45 GDPR). In addition, the agreements include EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). Your content such as cards and page texts stays in the EU.

10. Retention and deletion

11. Security

12. Your rights

Under the GDPR you have these rights:

To use them, write to henri.irmscher@gmail.com. This also covers data held by our service providers, for example at PostHog.

You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (datenschutz.hessen.de).

13. Minimum age

PageBite is intended for people aged 16 and over. We do not knowingly collect data from younger children.

14. Changes

If the app or the law changes, we update this policy. The date at the top shows the current version. If anything about the AI processing changes, the app asks for your permission again before your next scan.