Corvica

Privacy Policy

This Privacy Policy explains how Corvica collects, uses, and protects information when you use the Corvica iOS app and related backend services.

Last updated: September 2, 2026

1. Information We Collect

Account information

Email address, display name or nickname, sign-in provider, provider account identifier, and an internal Corvica user ID.

Subscription and purchase information

Subscription tier, subscription status, StoreKit transaction identifiers, original transaction identifiers, renewal and expiration dates, and quota state. Payment card details are processed by Apple and are not collected by Corvica.

App activity and learning data

Playback progress, saved content, folders, marks, notes, summary requests, AI summary quota usage, subscribed channels within Corvica, and notification state.

Age eligibility information

Date of birth may be used to determine access eligibility for age-restricted content and to comply with platform policy.

Device and notification information

Firebase Cloud Messaging registration token and basic app/device information that may be included when a user contacts support.

2. How We Use Information

  • Create and authenticate user accounts.
  • Provide video and podcast playback, bookmarking, note, folder, and learning history features.
  • Process AI summary requests, enforce quota limits, and restore subscription entitlements.
  • Send in-app or push notifications when enabled.
  • Improve reliability, prevent abuse, handle account deletion, and respond to support requests.

3. Third-Party Services

Corvica uses Apple Sign in, Google Sign-In, StoreKit, Firebase Cloud Messaging, YouTube, Apple Podcasts, and backend hosting providers to deliver app features. These third parties may process information according to their own privacy policies. Corvica does not sell personal information and does not use information for cross-app advertising tracking.

4. Data Sharing

We share information only when needed to operate the service, process authentication, deliver notifications, verify subscriptions, provide support, comply with law, or protect users and the service from misuse.

5. Data Security and Protection

We protect all personal and sensitive data with the following mechanisms:

  • Encryption in transit: All communication between the app, our backend, and third-party services is encrypted with TLS (HTTPS). We do not transmit personal data over unencrypted connections.
  • Encryption at rest: Personal data stored in our databases and backups is encrypted at rest by our hosting and database providers.
  • Access control: Production data access is restricted to authenticated service processes and authorized personnel on a least-privilege, need-to-know basis. API requests are authenticated and scoped to the requesting user's own data.
  • Credential handling: Sign-in is delegated to Apple and Google; Corvica never receives or stores user passwords. OAuth tokens are stored securely on the user's device. When a user initiates a YouTube subscription import, the YouTube access token is transmitted over TLS to Corvica's backend, used only to request the subscription list from the YouTube Data API, and is not stored in Corvica's database or intentionally written to application logs.
  • Incident response: If we become aware of a data breach affecting personal data, we will notify affected users and applicable authorities as required by law.

6. Google User Data and YouTube API Services

When you choose to import your YouTube subscriptions, Corvica requests the read-only YouTube scope (youtube.readonly). The app sends the YouTube access token over an encrypted connection to Corvica's backend, which uses it to call the YouTube Data API and retrieve only the list of channels you subscribe to. The access token is processed only for this request and is not stored in Corvica's database. The channel list is returned to the app for your review, and only the channels you explicitly select are saved to your Corvica account so new videos from those channels can be provided to you. We do not access your watch history, comments, likes, or playlists, we never modify anything on your YouTube account, and we do not retain the full subscription list on our servers.

  • Google user data is never sold, never used for advertising, and never shared with third parties.
  • Google user data is not used to develop, improve, or train generalized AI or machine-learning models.
  • You can revoke Corvica's access at any time at myaccount.google.com/permissions, and imported channels can be removed in the app.

Corvica's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Retention and Deletion

We retain account, subscription, usage, and learning data while an account is active or as needed to provide the service. Users may delete their account in the app. When an account is deleted, associated account data is removed or retained only in limited hashed form where necessary to prevent abuse, preserve legal records, or enforce service limits.

8. Children and Age-Restricted Content

Corvica may ask for date of birth to determine whether a user can access age-restricted content. Corvica is not intended to collect personal information from children where parental consent is required by applicable law.

9. Contact

If you have questions about this Privacy Policy or your personal information, contact us at support@corvica.app.

한국어 요약

Corvica는 계정 생성과 로그인, 구독 상태 확인, AI 요약 쿼터 관리, 재생 기록 동기화, 알림 제공, 고객지원 처리를 위해 이메일, 닉네임, 로그인 제공자 정보, 앱 내 사용자 ID, 구독 거래 정보, 재생 진행률, 저장한 콘텐츠, 메모, 마크, 폴더, 구독 채널, 생년월일, FCM 알림 토큰 등을 수집할 수 있습니다. 결제 카드 정보는 Apple이 처리하며 Corvica가 직접 수집하지 않습니다. Corvica는 개인정보를 판매하지 않으며, 타사 앱과 웹사이트를 넘나드는 광고 추적 목적으로 사용하지 않습니다. 모든 데이터는 전송 시 TLS로, 저장 시 암호화로 보호되며 접근은 최소 권한 원칙으로 통제됩니다. 사용자가 YouTube 구독 가져오기를 실행하면 YouTube 액세스 토큰이 암호화된 연결을 통해 Corvica 백엔드로 전송되고, 백엔드는 해당 요청의 구독 채널 목록을 조회하는 용도로만 토큰을 일시적으로 사용합니다. 토큰은 Corvica 데이터베이스에 저장하지 않으며, 전체 구독 목록도 서버에 보관하지 않습니다. 앱에는 구독 채널 목록이 표시되고 사용자가 명시적으로 선택한 채널만 Corvica 계정에 저장됩니다. Google 사용자 데이터는 Google API 서비스 사용자 데이터 정책(제한적 사용 요건 포함)을 준수하여 처리합니다. 문의는 support@corvica.app 으로 보내 주세요.