Privacy Policy

Effective date: July 8, 2026 · Last updated: July 8, 2026 · v2.0

This Privacy Policy explains what information Adsorp AI collects when you use our apps and website, why we collect it, who we share it with, and the choices you have. We've tried to write it in plain language while still being precise about legal terms where it matters. Where a clause reflects a provisional or unresolved legal question rather than settled practice, we've marked it with a ⚠ warning rather than asserting certainty we don't have.

1. Definitions

“Personal Data” means any information relating to an identified or identifiable natural person. “Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion. “Controller” means the entity that determines the purposes and means of processing — for the data described in this policy, that is Adsorp. “Processor” or “Sub-processor” means a third party that processes Personal Data on our behalf, under our instructions (see Section 7).

2. Who we are

Adsorp AI (“Adsorp”, “we”, “us”) is currently operated by an individual founder, Alok Choudhary, based in Bokaro, Jharkhand, India, as a sole proprietorship pending future incorporation. Once incorporated, this policy will be updated to reflect the registered entity. For the purposes of this policy, Adsorp acts as the data controller for the personal data described below. For any privacy question or request, contact legal@adsorp.ai.

3. What information we collect

Account information: when you sign in (via Google or email through Firebase Authentication), we receive your email address, display name, profile photo URL, a unique user ID, and sign-in provider. We also record your IP address on first login, which we use to look up your country (for regional pricing/commission purposes) via a third-party geolocation lookup.

Content you create: chat messages you send to the AI tutor, the topics and context you provide for AI-generated books, the resulting book content, translations, and audio captions. If you type personal information into a chat or book prompt, that text is stored as part of your content.

Usage and billing data: which AI/TTS models and features you use, how much of each book or PDF you've read and for how long, your credit balance, and your transaction/payment history.

Waitlist signups: if you join our waitlist before creating an account, we store your email address, IP address, and browser user-agent string.

Device permissions: on mobile and desktop, the app requests microphone access only when you use voice input (for example, voice search or voice chat) and storage/file access only when you import or export a PDF, AI book file, or music folder. We do not request camera, contacts, or location permissions on your device — country is inferred server-side from IP address, not from device location services. iOS additionally declares an optional Face ID capability for an app-lock feature.

4. Legal basis for processing

Where applicable data protection law (such as the GDPR) requires a legal basis for processing, we rely on:

• Performance of a contract — creating and operating your account, and delivering the AI tutoring, translation, and text-to-speech features you request, is necessary to provide the service you signed up for. • Legitimate interests — we process IP address and basic usage data for fraud prevention, service security, and to keep regional pricing/commission calculations accurate, balanced against your rights and interests. • Consent — joining the waitlist, and any future marketing communications, is based on your consent, which you may withdraw at any time by contacting legal@adsorp.ai. • Legal obligation — where we retain records, such as transaction records, to comply with tax or accounting law.

5. Sensitive device permissions

On mobile and desktop, the app requests microphone access only when you use voice input (for example, voice search or voice chat) and storage/file access only when you import or export a PDF, AI book file, or music folder. We do not request camera, contacts, or location permissions on your device. iOS additionally declares an optional Face ID capability for an app-lock feature.

6. How we use your information

We use this information to operate your account, process the AI explanations/translations/audio you request, calculate and deduct credits for what you use, process payments, personalize suggested content, and improve the product. We do not run any advertising or analytics-tracking SDK in the app today (no Firebase Analytics, Crashlytics, or similar) — the app only talks to the sub-processors listed in Section 7.

7. Sub-processors

We share data with a small number of named sub-processors, each engaged only for the specific purpose below. None of these sub-processors are permitted to use your data for their own purposes.

• Firebase Authentication (Google LLC) — purpose: identity verification and sign-in — data: email, display name, user ID — location: Google's global infrastructure — transfer basis: Google has historically participated in the EU-US Data Privacy Framework (⚠ verify current certification status at dataprivacyframework.gov before relying on this). • OpenRouter, Inc. — purpose: routes your chat messages to the underlying AI model to generate a response — data: message text and conversation history — location: United States — transfer basis: contractual data-processing terms with OpenRouter (⚠ verify their current safeguard mechanism directly with them). • Google Cloud Text-to-Speech and the Gemini API (Google LLC) — purpose: convert text you select into speech — data: the text you ask to have read aloud — location: Google's global infrastructure — transfer basis: Data Privacy Framework (⚠ verify current status). • PayPal, Inc. — purpose: process subscription payments — data: user ID, selected plan, and payment amount (not your email or full name) — location: United States — transfer basis: PayPal has historically participated in the Data Privacy Framework (⚠ verify current status). • A third-party IP-geolocation lookup service — purpose: determine your country from your IP address, to apply correct regional pricing — data: IP address only. • Google Cloud Run, region asia-south1 (Mumbai, India) — purpose: hosts our backend application servers — data: all data described in this policy, while in transit or being processed. • Oracle Cloud Infrastructure, region ap-hyderabad-1 (Hyderabad, India) — purpose: hosts our PostgreSQL database — data: all data described in this policy, at rest.

If you run Adsorp fully offline using a local AI engine (such as Ollama or a local TTS server) on your own device, that content is processed entirely on your device and is not sent to any sub-processor. We do not sell your personal information.

8. International data transfers

Adsorp's infrastructure is based in India (see Section 7). If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, using Adsorp means your personal data is transferred outside those regions — first to our India-based infrastructure, and in some cases onward to sub-processors located in the United States.

India does not currently have a European Commission adequacy decision, meaning such transfers are not automatically presumed to provide an adequate level of protection under the GDPR. Where required, we currently rely on your explicit, informed consent to this transfer (given by using the service after being presented with this policy) as the legal basis, under GDPR Article 49(1)(a). We are evaluating Standard Contractual Clauses as a more durable long-term mechanism as we scale.

⚠ This section reflects a provisional, good-faith approach for an early-stage company and has not been reviewed by a qualified data protection lawyer. If you are an enterprise customer, or a regulator, with questions about this mechanism, contact legal@adsorp.ai.

9. Data retention and deletion

We keep your account and content data for as long as your account is active. If you want your account and associated data deleted, email legal@adsorp.ai — we currently process deletion requests manually (this is a genuine limitation we're working to automate), and will complete GDPR-qualifying deletion requests within 30 days as required by law.

10. Data breach notification

If we become aware of a security incident affecting your personal data, we will notify affected users without undue delay, and where legally required, notify the relevant supervisory authority. ⚠ We are a small, early-stage team and do not yet have formal incident-detection or monitoring tooling in place. We are not in a position to commit to a fixed notification timeframe (such as the GDPR's 72-hour guideline) today, and will act as quickly as our current operational capacity allows while we build out this capability.

11. Children's privacy

Adsorp is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact legal@adsorp.ai and we will remove it.

12. Your rights under GDPR

If data protection law applies to you (including the GDPR), you have the right to:

• Access the personal data we hold about you. • Rectify inaccurate personal data. • Erase your personal data (the “right to be forgotten”), subject to legal retention requirements. • Restrict or object to certain processing. • Data portability — receive your data in a structured, commonly-used format. • Withdraw consent at any time, where processing is based on consent. • Lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, email legal@adsorp.ai. Because we currently process these requests manually rather than through an automated self-service system, we will acknowledge your request within 7 business days and complete GDPR-qualifying requests within 30 days as required by law.

13. California residents

Adsorp does not currently meet the revenue or data-volume thresholds that trigger full obligations under the California Consumer Privacy Act (CCPA/CPRA). We do not sell or share your personal information for cross-context behavioral advertising. If you are a California resident with questions about your data, you can still contact us at legal@adsorp.ai and we will respond on a best-effort basis. We intend to build a formal CCPA compliance program, including a verifiable consumer request process, if and when our user base or revenue approaches the applicable thresholds.

14. Security

We apply reasonable technical and organizational safeguards to protect your information. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

15. Changes to this policy

We may update this policy as the product evolves. If we make material changes, we'll update the “last updated” date above and, where appropriate, notify you in the app. See the revision history below for a summary of past changes.

16. Contact us

Questions about this policy or your data can be sent to legal@adsorp.ai.

Revision history

v2.0July 8, 2026Restructured into numbered sections; added Definitions, Legal Basis for Processing, an expanded Sub-processors list, International Data Transfers, Data Breach Notification, enumerated GDPR rights, and a California Residents section. Corrected hosting infrastructure from Hetzner to Google Cloud Run (asia-south1) and Oracle Cloud Infrastructure (ap-hyderabad-1).
v1.0July 1, 2026Initial plain-language Privacy Policy published.
Adsorp — AI-Powered Education Platform