Privacy policy
Effective date: 2026-08-10
Scope
This privacy policy applies to mobile applications and related services published by Pierre-Dominic Simard.
Contact
Questions: pierdo.dev@gmail.com
Local storage
If an app stores preferences (e.g. settings), those data remain on your device.
Device features
Some apps may use device features (for example: Text-to-Speech) to provide functionality. These features run on your device. We do not receive the content processed by those features.
Data export
Some apps let you export data (e.g. CSV files). Exported files are written to a temporary cache on your device and shared via the system share sheet. No data is uploaded to our servers during export.
Digit Span Trainer
Local-only data. Training rounds, preferences, skin unlocks, tutorial progress, saved Digit Span Lab programs, local goals, active Lab drill progress, and the last generated Lab report snapshot are stored on your device with IndexedDB. They do not leave the device on their own.
Sign-in is optional for local features. Google sign-in is not required for Free Core training, Stats, themes, CSV, or Digit Span Lab purchase and restore controls. Google Play still requires a Google Play account to buy or restore Lab. Coach Google sign-in is required only for AI Coach, so lifetime samples and purchased Coach insights stay with the correct Coach account. Google may provide a stable account identifier, email address, and display name. The profile fields are shown locally; they are not sent to the Coach backend or included in Coach Pack measurement. A short-lived identity token is sent to the Coach backend for verification when you sign in.
AI Coach. When you tap an AI Coach button, a digest of recent training statistics—best span, recent accuracy per mode, weekly round counts, and Journey progress—is sent over HTTPS to our backend to generate a personalized response. Signed-in accounts receive 10 lifetime sample insights, with at most one successful sample per UTC day. A one-time Coach Pack adds 365 non-expiring purchased insights. Existing subscribers retain the Coach service they already purchased. Failed, unavailable, not-ready, cached, and deterministic-fallback requests do not use a sample or purchased insight. We do not sell this data or share it with advertisers.
Digit Span Lab. Lab is a separate permanent local-feature unlock. It adds saved custom programs, advanced local drills, serial-position and response-time analysis, deeper comparisons, local goals, and a shareable local report. Lab includes no AI Coach samples or purchased Coach insights, and Lab analytics and reports are not sent to the AI Coach backend.
A verified Lab grant remains on the device when you sign out of Coach, delete Coach cloud memory, or change the optional Coach account. If current RevenueCat information is unavailable or belongs to a different purchase owner, the app preserves an already verified grant. Authoritative inactive information for the same original purchase owner, such as a refund or revocation, relocks Lab creation, editing, and drills. It does not delete saved programs or the last saved report: those remain locally readable and the report remains shareable. Free Core remains usable, and premium analytics are not recomputed while Lab is relocked.
Purchase-safety records. The app keeps two separate local duplicate-charge safeguards. A Coach Pack record contains the signed-in Coach account identifier, product identifier, known pre-purchase Coach balance, verification status, and timestamps. The Lab control record contains the exact Lab product, verification timestamps, generation/revision fences, and a purchase-owner binding made with a Lab-specific SHA-256 namespace over RevenueCat's original app-user ID. The Lab record does not store the raw RevenueCat or Google identifier. Neither record contains payment-card or Google Play transaction data.
Digit Span billing and safeguards
Digit Span Lab and Coach Pack purchases are processed by Google Play and
managed through RevenueCat. Lab uses the fresh non-consumable product
digit_span_lab_lifetime and entitlement
digit_span_lab; it is not inferred from an older lifetime or
subscription product. Its localized price is supplied at runtime by
Google Play through RevenueCat. Coach Pack is the separate, repeatable
365-insight product, and purchased insights do not expire. An existing
legacy Coach subscription remains managed on the terms already purchased.
Before a Coach Pack purchase, the app records the current authoritative Coach balance. It reports a pack as added only after RevenueCat returns a higher balance. An uncertain purchase result or balance refresh blocks another purchase until the same signed-in account checks again and the increase is confirmed. If the Google or RevenueCat account changes, the stale result is ignored and the original account's lock is retained.
Before opening Google Play for Lab, the app durably saves an exact-product, hashed-owner pending record. It reports Lab as owned only after RevenueCat returns the exact active entitlement and the owner-bound grant is saved and read back. Explicit cancellation clears the guard. Network errors, timeouts, account changes, or uncertain results retain it and block another Lab purchase until an authoritative same-owner check or Restore Lab purchase resolves it. Lab purchase and restore do not require Coach Google sign-in.
While the Lab record is unresolved or unreadable, the app temporarily prevents RevenueCat owner changes, including Coach purchase linking, Coach restore, and Coach sign-out. The user is directed to Check or Restore Lab first. A record from a different owner remains blocked with support guidance rather than being cleared by the current owner.
Coach Pack measurement. We measure only four milestones: a sample insight succeeded, the Coach Pack screen was viewed, a purchase was started, and a purchase was completed. Reports contain event counts grouped by UTC ISO week and a small allowlist of entry sources. They do not contain Coach prompts or responses, training statistics, product prices, transaction identifiers, Google profile data, or advertising data. Random event markers expire after 32 days, hashed purchase-source attribution after 14 days, and identifier-free weekly aggregate counts after 400 days.
Device, permissions, export, and backup. Digit Span uses the device text-to-speech engine and does not request microphone access or record voice input. It uses Internet access for AI Coach and billing and does not request location, contacts, camera, or microphone permissions. CSV imports and exports training rounds only; it never imports or exports the Lab grant, purchase guard, programs, goals, sessions, or report snapshot. CSV and Lab report sharing use the system share sheet and do not upload those files or report text to our servers. Android cloud backup and device-to-device transfer are disabled so a local Lab grant/control record cannot unlock another device by being copied. On a new or cleared device, use Restore Lab purchase for a fresh Google Play and RevenueCat check.
Digit Span Trainer is intended for general audiences, including students. We do not knowingly collect personal data from children. We never collect or transmit contacts, photos, location, microphone or camera content, browsing activity, or the contents of other apps.
Digit Span account, retention, and deletion
Reset All Progress deletes on-device rounds, preferences, saved Lab programs, goals, active sessions, and report snapshots. It preserves the verified Lab grant and any unresolved Lab or Coach Pack duplicate-charge guard. A Lab guard from before Reset is fenced from its old callback and must be checked through the current-owner Restore Lab flow. Uninstalling the app or clearing its system storage removes local data, grants, and safety records; purchases can then be restored from Google Play.
AI Coach operational records keep the lifetime sample balance with the app account; daily allowance, replay-protection, short-lived completed response, and spend records expire or are pruned automatically. Limited rolling Coach-memory and entitlement records may be retained longer for continuity and purchased access. RevenueCat retains the billing identifier, Lab entitlement, purchased insight balance, and any existing subscription as needed for restoration and under its retention policy. A Google Sign-In identifier is retained while you remain signed in; if Coach Pack verification is unresolved, that account identifier remains in the local safety record until authoritative recovery or system-level app-data removal.
To request deletion of off-device data tied to your Digit Span Trainer account, email pierdo.dev@gmail.com with the subject "Digit Span data deletion". We will delete or disassociate the Google Sign-In identifier and related AI Coach records under our control. Identifier-free weekly measurement counts cannot be linked back to an account and expire after 400 days.
Deleting Coach cloud data or signing out of Coach does not delete the independent Google Play/RevenueCat Lab purchase or its local verified grant. Google Play or RevenueCat purchase deletion and refund requests follow those providers' processes. Some billing, fraud-prevention, tax, and legally required payment records may remain with those providers.
Dial-In
Local foundation. Shot logs, beans, equipment settings, preferences, and the deterministic Coach stay on your device. Core logging and deterministic next-shot guidance work offline without an account. CSV export writes a temporary file and opens the system share sheet; Dial-In does not upload that file.
Optional Internal Remote Coach. A separately configured pilot is available only to invited Internal Testing users. When a tester explicitly requests a remote plan, Dial-In sends its service a bounded envelope containing numeric dose and yield, closed observed-fact IDs, bounded equipment-safety context, and four app-approved options. It does not send notes, bean or roaster names, CSV files, full shot history, contacts, location, advertising identifiers, or arbitrary chat text. The model selects only an opaque option ID; the app validates that ID and computes all displayed instructions and numeric targets locally. Invalid or unavailable results fall back to the free deterministic Coach.
Anonymous access. The app generates a random install proof in private app storage. The Dial-In service pseudonymizes it with a keyed hash to enforce the one-loop Internal allowance; it is not a hardware identifier and the raw proof is not stored by the service.
Sign-in and sandbox purchases. Google Sign-In starts only after an explicit Internal Buy or Restore action. The service verifies the Google ID token, uses only its stable account subject, and then discards the token. It derives a separate opaque RevenueCat user ID; neither the raw Google subject nor email address is used as the RevenueCat owner. Google Play and RevenueCat process the finite sandbox Coach Pack purchase and restoration state. No subscription, unlimited access, or public purchase availability is offered by this pilot.
Service retention. Pending plans expire after 10 minutes; terminal replay/tombstone records after 24 hours; opaque sessions after 15 minutes; privacy-minimal audit entries after 7 days; commerce reconciliation entries after 90 days; and bounded monthly spend controls within 62 days. The anonymous consumed marker remains until remote access is deleted. The service does not retain shot history, notes, bean names, provider prompts/responses, Google tokens, or raw purchase identifiers as Coach memory or audit data.
Dial-In data deletion
Dial-In's Delete All Data action deletes local shots, beans, equipment, and Coach data even when the device is offline. Uninstalling the app or clearing its storage also removes local data.
If Remote Coach access exists, Delete All Data also asks the Dial-In service to delete its pseudonymous access, pending-plan, session, and local reconciliation state. If that request cannot be confirmed, the app retains only the opaque original-principal credential and a pending deletion marker needed to retry; it does not claim that remote deletion succeeded. A different Google account cannot complete deletion for the original owner.
You may also email pierdo.dev@gmail.com with the subject "Dial-In data deletion" for help with off-device data under our control. Some purchase and payment records remain with Google Play and RevenueCat as required for billing, fraud prevention, tax, or law. Deleting data does not refund a purchase.
Sub-processors
The following third-party services receive limited data when you use Digit Span Trainer's AI Coach or Coach Pack measurement, use Dial-In's invited Internal Remote Coach, sign in to a supported app, or make or restore purchases.
- Fireworks AI (United States) — runs the AI model that generates Digit Span Trainer Coach responses. Receives the training statistics digest at the time of each Coach tap. It does not receive the separate Coach Pack measurement payload and does not persist the generation input on its side.
- OpenRouter and Anthropic (Dial-In Internal candidate) — route and run the closed option-selection request only if the invited pilot is enabled. They receive observed fact IDs and four option definitions, but no app user/install identifier, request ID, numeric recipe or equipment values, shot history, notes, or purchase state. The request asks for one option ID, denies provider data collection, and requires a Zero Data Retention endpoint. This does not make a blanket retention or no-training claim for OpenRouter account metadata, Cloudflare delivery logs, processor backups, or any other unverified live surface.
- Cloudflare Workers, Durable Objects, and KV — routes and rate-limits Coach requests. Digit Span stores app-scoped lifetime sample allowance, short-lived request-completion and replay-protection records, spend protection, entitlement state, and limited rolling Coach memory; it does not store raw round history. Dial-In's invited Internal pilot uses separate Durable Objects for pseudonymous allowance, short-lived session, pending-plan, reconciliation, spend-protection, and minimal audit state under the Dial-In retention periods above; it does not store server-side Coach memory. Cloudflare processes request network metadata, including IP addresses, for delivery, security, and rate limiting.
- Google Sign-In — verifies identity only when you explicitly sign in to Digit Span Trainer's AI Coach or choose Dial-In's Internal Buy or Restore action. For Digit Span, Google may provide an account identifier, email address, and display name; profile fields are shown locally and are not sent to the Coach backend or Coach Pack measurement. Dial-In's service verifies the ID token, uses its stable subject to derive opaque service identifiers, and discards the token; it does not retain Google profile fields for Remote Coach.
- RevenueCat — manages subscription and in-app purchase state and sends authenticated purchase events. For Digit Span, it manages the permanent Lab entitlement, purchased Coach insight balance, and existing legacy subscription state. Google Play purchase and restore events are associated with a RevenueCat app-user identifier; the app's local Lab control record stores only a product-specific hash of RevenueCat's original app-user ID, not that raw ID. Dial-In uses a separate service-derived opaque user ID for finite Internal Coach Pack balance, debit, restoration, refund, and revocation reconciliation; it does not give RevenueCat the raw Google subject as that owner.