Aiotto Privacy Policy — build 33 release text

This repository copy is the build-33 source of truth. The public page and App Store privacy answers must contain materially identical facts before build 33 is submitted. Publication and legal approval are external release gates; this engineering record does not claim either has occurred.

Information Aiotto processes

Aiotto is local-first. Recordings, imported media, transcripts, translations, notes, tags, summaries, playback progress, downloaded podcasts and local statistics are stored in the App's private container. Imported and recorded media are excluded from device backup. The remaining private index may be included in an operating-system backup according to the user's Apple backup settings. Aiotto does not use an advertising or analytics SDK and does not sell personal information or use it for cross-app tracking.

When the user chooses account or cloud functions, Aiotto may process:

The client stores only the opaque session credential in an API-origin-scoped Keychain item. It never contains provider API keys, signing secrets or internal server paths. Network requests use encrypted transport to the public Aiotto API boundary. A failed task does not create a result, and the client does not automatically replay a non-idempotent upload after an ambiguous response.

Explicit network actions

Local recordings are never uploaded automatically. Audio is sent only after the user confirms cloud transcription. Transcript text is sent only after the user explicitly requests summary, translation, explanation, definition or mind map generation. Exact-selection tools send the selected passage and its containing segment so the requested result can preserve context. These requests go only to the authenticated Aiotto API; any private AI processor, model choice, prompt and credential remain server-side and are not selectable by the App. Account deletion immediately revokes the local session and asks the service to delete account-scoped data that is no longer required for security, fraud prevention, transaction records or law. Operational cloud records and temporary processing files are retained only for the period needed to complete the requested function, protect the service, resolve errors and satisfy applicable obligations.

Podcast charts and searches send the selected storefront or search text to Apple's public podcast directory. Opening a public feed or downloading an episode connects directly to the publisher or media host. Those providers may receive ordinary network metadata and apply their own policies.

For a recognized public YouTube link, Aiotto shows a local placeholder first. Only after the user taps the video card does an ephemeral WebKit view connect to YouTube's privacy-enhanced embed service. The embedded player receives no Aiotto transcript, translation, note or attached audio. It reports only bounded playback time and state so Aiotto can show locally stored, timestamp-aligned subtitles and translations.

When the user taps Import for a public URL or YouTube link, Aiotto sends that link through its authenticated API so the service can return article text or native timed captions. A YouTube caption result does not imply that original audio is available. Original audio is requested only after the user separately taps Attach original audio; the service keeps the account-scoped processing copy temporarily and the App downloads the completed media through the same authenticated API boundary.

When the user explicitly requests EPUB parsing, Aiotto uploads only the selected book through the authenticated API. The upload is limited to 20 MiB and retained for at most 24 hours. The account-scoped parse job is retained for at most 7 days, and the parsed document metadata and chapters for at most 1 year unless the user deletes the cloud account sooner. The App requests one chapter at a time and does not automatically upload local PDF files. A failed parse does not produce a document and does not consume the completed-work allowance.

When the user selects Otto and confirms the live-audio notice, Aiotto streams microphone audio through the authenticated Aiotto API for simultaneous source transcription and translation while keeping the device recording as the local safety copy. The App stores only final validated bilingual pairs; a disconnect clears provisional text, and it does not silently substitute local text or synthetic speech for a missing server result.

Disabled network functions in build 33

Build 33 does not enable the cloud podcast-directory proxy, Sign in with Apple, App Store server verification, exact-selection AI translation, AI explanation, AI definition or mind-map generation. Compiled fail-closed boundaries for those functions do not collect data while their release flags are disabled. Any later enablement requires a new privacy, provider, retention and App Store review.

User choices and deletion

Users can delete individual local items in Aiotto. Uninstalling the App removes its private local container subject to the operating system's behavior. Users can sign out or request cloud-account deletion in Settings; local study data is not silently deleted with the cloud account. Requests for access, correction or deletion can be sent to .

Aiotto is not directed to children under 13. If the operator learns that personal information from a child was processed without the required consent, reasonable steps will be taken to delete it. Reasonable access controls, encrypted transport and audit measures are used, but no Internet service can guarantee absolute security.

The policy may be updated when product behavior, providers or law changes. The public page will identify the effective date of the applicable version.