Privacy Policy
Effective 19 September 2026. Last revised 19 September 2026.
Reteva turns pages of a PDF you choose into study questions. Doing that means sending those pages off your phone. This page says exactly what leaves, who receives it, how long anyone keeps it, and what stays on your device.
The short version. The pages you select are sent to Reteva’s server and on to Google Gemini to be read. The questions come back and are stored on your phone. Reteva has no accounts, asks for no name or email, and keeps no copy of your document once the questions are made.
What we do not do
- There are no accounts. Reteva never asks for your name, email address or phone number.
- There is no advertising, no ad network and no advertising identifier.
- There is no third-party analytics SDK in the app.
- We do not sell personal information, and we do not share it for cross-context advertising.
- These web pages set no cookies and load nothing from anybody else.
Your documents
What is sent
You pick a PDF and choose a page range. When you tap Continue on the disclosure the app shows you before its first upload, two things happen:
- The whole PDF is sent to Reteva’s server once so the number of pages can be counted. The app has no PDF parser of its own.
- Only the pages you selected are then extracted and sent to Google Gemini to be read. Pages outside your range are not sent to Google.
Reteva’s server is a Cloudflare Worker. Cloudflare processes the request as our infrastructure provider.
Who processes it
Google Gemini, through the Google Generative Language API, generates the questions. Your pages are sent to Google under Google’s terms for paid API use. See Google’s Gemini API terms and Google’s privacy policy.
How long it is kept
The uploaded page range is stored temporarily in Google’s Files API while the questions are generated, and Reteva asks Google to delete it as soon as generation finishes.
We will not claim deletion is instant or guaranteed. The delete request can fail — a network problem, or Google returning an error. When it does, Reteva records the failure and the file is left to expire under Google’s own retention for the Files API rather than being removed by us at that moment. Reteva never re-uploads the document to retry, and keeps no copy of it either way.
Reteva’s own server does not store your document at all. It holds the extracted pages only in memory for the length of the request, and the job record — which contains the generated questions, not the document — is deleted one hour after the job finishes.
What comes back, and where it lives
The questions, answer options, explanations, topics and the short source excerpt quoted under each correction are stored on your device, in the app’s local database. So are your answers, your streak and everything else about your studying. None of it is sent to a Reteva server.
Shared quizzes
If you share a quiz, its questions and the title you gave it are uploaded to Reteva’s server and given a short share code. Anyone with that code can import the quiz for as long as it lives.
- What a share contains: the questions, their answers, explanations, source excerpts, and the quiz title.
- What it does not contain: the original PDF, its filename, your device identifier, or anything identifying you. Someone importing your quiz receives the questions, the title and the date, and nothing else.
- Retention: a share expires 14 days after it is last opened. Each time somebody opens it, the 14 days start again.
- Revoking: the device that created a share holds a delete token and can revoke it. That token is never given to anybody who reads the share.
A quiz you share is content you are publishing. Do not share anything containing personal, confidential or copyrighted material — see the Terms of Use.
Reports about shared content
If you report a shared quiz, Reteva records that a report was made against that share code, the category you chose, and the time. Reports are used to disable shares and to stop abuse.
Reports are not public and do not name you. The person who created the quiz is not told who reported it. To stop one device flooding the system with reports, the report is recorded against the same pseudonymous installation identity described below.
Feedback you send us
If you use the feedback form, the message you write, the category you choose, your device identifier, and — only if you type one — your email address are delivered to a private Discord channel the Reteva team reads. Nothing else about your studying is attached. Up to five submissions per device per day are accepted.
Device and installation identifiers
Device identifier
On first launch the app generates a random identifier and keeps it locally. It is sent with requests so the server can apply limits per installation. It is tied to no account, no email and nothing else about you, and deleting the app’s data resets it. It is not an advertising identifier and is not used for tracking.
Network address
Reteva’s server sees the IP address of every request, as any server does. It is used to apply rate limits and is never written to our logs. Where a log needs to say “these requests came from one place”, it records a salted one-way hash instead, which cannot be turned back into an address.
App Attest
Reteva includes support for Apple’s App Attest, which lets a server confirm a request came from a genuine, unmodified copy of the app rather than from a script. It produces a cryptographic key held in your device’s Secure Enclave and an identifier derived from its public key. It reveals nothing about you or your device beyond that this is a real installation of Reteva.
App Attest is currently switched off in Reteva’s deployed server. When it is enabled, the installation identifier derived from that key is also what daily processing limits are counted against.
Notifications
If you allow notifications, Reteva schedules reminders with iOS. Your notification preferences and the record of which reminders have been sent are stored on your device only. No notification content, schedule or history is sent to a Reteva server, and there is no push server — every reminder is scheduled locally by the app.
Purchases
Reteva is a paid subscription. Purchases are handled entirely by Apple. Reteva never sees your payment details. Your subscription status is read from Apple and stored on your device so the app knows whether it is unlocked.
If Reteva later uses RevenueCat to manage subscriptions, RevenueCat will receive a purchase identifier and receipt information from Apple on our behalf, and this page will be updated to say so before that happens.
What our server logs
Reteva’s server writes diagnostic logs. They contain:
- Outcomes, counts, durations, page counts, byte sizes and status codes
- Job identifiers and device identifiers
- Salted one-way hashes standing in for network addresses and installation identities
They deliberately never contain:
- Your document, or any part of it
- Filenames or document titles
- Question text, answer options, explanations or source excerpts
- Course names
- API keys or raw network addresses
How long things are kept
| What | Where | How long |
|---|---|---|
| Your PDF | Reteva server | Not stored. In memory for the request only. |
| Selected pages | Google Gemini Files API | Deletion requested as soon as generation ends. If that request fails, until Google’s own expiry. |
| Generation job and its questions | Reteva server | 1 hour after the job finishes. |
| Questions, answers, progress | Your device | Until you delete them or the app. |
| Shared quiz | Reteva server | 14 days from when it was last opened. |
| Per-installation request counters | Reteva server | Up to 2 days. |
| Monthly processing totals (counts and amounts, no content) | Reteva server | Up to 45 days. |
| Attestation challenges | Reteva server | 2 minutes. |
| Feedback messages | Private Discord channel | Until the team deletes them. |
Children
Reteva is not directed at children under 13 and we do not knowingly collect personal information from them.
Your choices, and how to ask about data
- Everything about your studying is on your device. Deleting the app removes the questions, your answers, your progress and your device identifier. We cannot delete that for you, because we never had it.
- To revoke a shared quiz, open it in the app on the device that created it and revoke the share. It stops being importable immediately.
- To ask about, or ask us to delete, anything held on Reteva’s server — a shared quiz, a report, or a feedback message — contact us using the address on the Support page and include the share code where there is one. Because there are no accounts, a share code or the content of the message you sent is what lets us find the right record.
- Depending on where you live you may have rights to access, correct, delete or object to processing of personal information. Use the same contact route.
Changes
If what Reteva does with your documents materially changes, the in-app disclosure version is increased and the app asks you again before the next upload. The revision date at the top of this page changes whenever anything here does.
Contact
See the Support page for how to reach us.