Short version: PerCuriam reads legal documents aloud on your device. Document content stays on your device except in two clearly disclosed cases: Sync & backup (when you turn it on) and AI Briefs (when you explicitly request one).

What we collect — and what we don't

We collect nothing automatically. PerCuriam has no analytics SDK, no crash reporting service, no advertising network, and no account system. We do not collect identifiers, behavioral data, or usage statistics.

Data stored on your device only

DataWherePurpose
Imported PDFs and web articlesDevice storage, AES-256 encryptedReading
Parsed document textDevice storage, AES-256 encryptedReading
Playback position and speedDevice storage, unencryptedResume where you left off
User pronunciation editsDevice storage, unencryptedCustomized speech
App settings (theme, voice, profile)Device storage, unencryptedPreferences

All encrypted data uses a hardware-backed key in the Android Keystore that never leaves the secure element.

Network use

PerCuriam uses the internet only in three explicitly user-initiated cases:

  1. Web article import — when you share or paste a URL, the app fetches the article text from that URL.
  2. Sync & backup — when you have turned on Sync (off by default), your encrypted library syncs to your account.
  3. AI Briefs — when you tap "Create brief — sends this document" (Professional subscribers only), the document text is sent to our server to generate a brief.

The app does not phone home, check for updates, or contact any server outside these three cases.

Sync & backup (optional — off by default)

PerCuriam optionally syncs your library across devices. Sync is off by default; you must explicitly enable it.

End-to-end encryption

Everything you sync is encrypted on your device before it leaves. The encryption key is derived from a 12-word recovery phrase that only you hold. We never see this phrase, and we cannot reset it or recover your data if you lose it.

The server stores only ciphertext — encrypted bytes that are meaningless without your recovery phrase. Your document content, matter names, reading positions, and pronunciation settings are never stored in plaintext on any server.

What the server stores when sync is on

DataForm on serverPurpose
Your email addressPlaintextAccount authentication (sign-in)
Encrypted document blobsCiphertext onlyCross-device sync
Encrypted metadata (matter names, positions, pronunciations)Ciphertext onlyCross-device sync
Sync timestamps, object IDs, device IDsPlaintextSync mechanics

Server-visible plaintext is limited to sync mechanics (opaque IDs, timestamps, sizes). No user-meaningful content is ever stored unencrypted.

Infrastructure processor

Cloud sync uses Supabase, Inc. (supabase.com) as our infrastructure provider. Supabase processes data in accordance with their Data Processing Agreement. Supabase cannot read your document content or metadata because it is encrypted with a key we do not hold.

Deleting your data

You can delete your account at any time: Settings → Sync & backup → Delete account & synced data. This immediately erases all your synced data from our servers. Your local library on this device is not affected.

A web-based deletion page is available at percuriam.app/delete-account. For an email-based deletion request, contact privacy@percuriam.app.

AI Briefs (Professional — explicit per-generation consent)

Professional subscribers can generate AI-written summaries, issues analyses, and timelines from any document in their library. This is the only PerCuriam feature that sends document text off-device.

What is sent

When you tap "Create brief — sends this document," the app sends to our server:

Nothing else is sent: not your email, not your matter names, not your reading position, not any other document.

How it is processed

The document text is forwarded to Anthropic, PBC (the AI provider). Anthropic processes the request to generate the brief and returns the result. The text is not stored by us or Anthropic — the request is ephemeral, processed in real time only.

Your consent

Every brief generation requires an explicit tap of the "Create brief — sends this document" button. There is no opt-in-once or remembered consent: each tap is one consent for one send.

AI content note: The brief is generated by an AI language model. It may contain errors, omissions, or hallucinations. Do not rely on a brief as a substitute for reading the opinion. The brief is a listening aid, not legal advice.

Infrastructure processors

The report funnel

If you use Report this document (the flag icon on a failed import), the app packages the problem PDF and a diagnostic log into a zip file in your own cache folder. The app then opens your email app pre-addressed to us — you choose whether to send it, which email account to use, and what additional notes to include. We never see this report unless you send it yourself.

Third-party services

PerCuriam does not use any third-party analytics, advertising, or tracking service.

The app uses these open-source components that run entirely on your device:

None of these components send data to external servers.

Children

PerCuriam is not directed at children under 13 and does not knowingly collect information from children.

Changes

If we make material changes to this policy, we will update the effective date above. Since we collect no personal data, changes are expected to be minor and infrequent.

Contact

Questions: amalacornel@gmail.com