Privacy Policy

Last updated: August 13, 2026

Overview

Qora turns your notes into short lessons with quizzes. This page explains exactly what happens to your content, in plain language. There is no account to create, and we do not sell or share your data with advertisers or data brokers.

What leaves your device, and what does not

Qora is not a fully on-device app. Lesson and quiz generation is done by an AI model running on servers. The table below is the complete picture:

FeatureWhere it runs
Turning a note into a lesson, quiz questions, summaries, and AI chatOn our servers. The text you submit is sent over an encrypted connection to our backend (Convex), which forwards it to a third-party AI provider — Groq, or Replicate when Groq is unavailable — to generate the response.
Reading text from a photo (OCR)On your device. The text is extracted locally — by Apple's Vision framework on iPhone and by Google's ML Kit on Android. The photo itself never leaves your device; only the text you choose to turn into a lesson does.
Voice notes (speech to text)On your device. Transcription uses the on-device speech recognition built into your phone (Apple's on iPhone, Android's on Android). The audio recording never leaves your device.
Your notes, lessons, and progressOn your device. Stored locally in the app. We do not keep a copy on our servers, and there is no cloud sync or backup.

The AI providers

Text you submit for a lesson, quiz, summary, or chat message is processed on our behalf by Groq, using open-weight language models. If Groq is rate-limited or unavailable, the same request is processed instead by Replicate, which runs an equivalent open-weight model. Both act as API providers: per their terms they process the text to return a response and do not use it to train models. We do not send your name, email, or any account identifier with these requests — there is no account, so we have none.

You are asked for your permission before any text is sent, the first time you open the app. You can withdraw that permission at any time in Settings → AI & Data; AI features stop working until you grant it again.

What we log on the server

To keep the service working and diagnose failures, each AI request writes a technical record containing: the type of request (lesson, quiz, summary, chat), the AI model used, whether it succeeded, how long it took, the character count of the input, and an error message if it failed.

The content of your note is not stored in these logs. Only its length is recorded. We do not retain the text of your requests after the response is returned to your device.

Creator codes

Qora sometimes works with creators who introduce the app to their audience. If you enter a creator code in Settings, the app records a randomly generated identifier for your device together with that code, so we can tell the creator how many people they reached and pay them accordingly.

This identifier is created on your device and is not derived from your hardware, your Apple ID, or any advertising identifier. It is not linked to your name, email, or the content of your notes, and it is not shared with advertising networks. Entering a code is entirely optional; if you leave the field empty, only an anonymous record that the app was launched is created.

Measuring our advertising

When we run ads for Qora — on the App Store, Google Play, or a social platform — we need to know which campaigns brought people who actually use the app. For this the app includes AppsFlyer, an attribution service.

What AppsFlyer receives is limited on purpose. It gets the same randomly generated device identifier described above, the fact that the app was installed and opened, and a small number of milestone events: onboarding finished, a lesson was created, a quiz was completed, a subscription was purchased. That is all.

It does not receive the title or content of your notes and lessons, your quiz answers, your name or email, or your location. We deliberately use the build of AppsFlyer that cannot read Apple's advertising identifier (IDFA) at all — which is why Qora never shows you an App Tracking Transparency prompt. Your activity is not combined with data from other companies' apps to build an advertising profile of you.

AppsFlyer's own handling of this data is described in their privacy policy.

Improving the app

To find out where the app is confusing or broken, Qora includes PostHog, a product analytics service. It records which steps of the app you reach — an onboarding step was shown, a lesson was created, a quiz was finished, the subscription screen was opened — together with the same randomly generated device identifier described above. It does not receive your name, email, or location, and no account is created for you.

PostHog also records anonymised session replays: a reconstruction of how the interface responded as you moved through it, used to see where people get stuck. These replays are masked at the source, on your device, before anything is sent: all text you type, all images including photos of your notes, and system layers such as the keyboard are covered and never leave your phone. What remains is the shape and timing of the interface — which button moved, which screen took a long time — not what your notes say.

PostHog's own handling of this data is described in their privacy policy.

This website

The sections above describe the Qora app. This website (qorai.app) is separate: the analytics described below run only when you read these pages, and never inside the app.

If you allow it, this site uses Google Analytics to count which pages are read. You are asked once; if you decline, the analytics script is never loaded and no cookie is set. Your choice is remembered so you are not asked again. Google Signals and ad personalisation are disabled, so this data is not used to build an advertising profile of you.

Reading this site, or declining analytics, has no effect on the app and requires no account.

Data we do not collect

  • No account, name, email address, or phone number
  • No advertising SDKs in the app. The two third-party components are the attribution and product analytics services described above; both receive milestone events, and neither receives the content of your notes, lessons, or quiz answers
  • No advertising identifier — no IDFA and no App Tracking Transparency prompt on iPhone, and no Android advertising ID
  • No location data
  • No contacts, calendar, or health data
  • No copy of your notes on our servers

Subscriptions

Qora Pro subscriptions are processed by the app store you installed Qora from — Apple on iPhone, Google Play on Android — and managed through RevenueCat, which records your subscription status against an anonymous, randomly generated identifier. We never receive your payment details; Apple or Google handles all billing. See our Terms of Use for subscription terms.

Images in lessons

Some lessons show an illustrative image fetched from Wikipedia/Wikimedia Commons. When this happens, your device requests the image directly from Wikimedia; only the standard information in a web request (such as your IP address) is visible to them. Nothing about your note is sent.

Children's privacy

Qora is not directed at children under 13 and we do not knowingly collect personal information from them. Since the app requires no account and collects no personal identifiers, we hold no such information about any user.

Your choices and rights

Your notes live on your device: deleting a note deletes it, and deleting the app removes all of your content permanently. Because we hold no account and no copy of your notes, there is nothing further for us to delete on request. If you want the technical logs associated with your usage reviewed or removed, contact us at the address below.

Data retention

Technical logs described above are retained for up to 30 days and then deleted. Subscription status is retained by your app store (Apple or Google Play) and by RevenueCat for as long as your subscription is active, plus their own retention periods.

Changes to this policy

We may update this Privacy Policy. Any changes will be posted on this page with a new date at the top.

Contact

Questions about this policy: [email protected].