FANVELA Privacy Policy

Effective date: 31 July 2026

Document version: 2026-08-17-v15

FANVELA ("FANVELA", "the App") is operated by Zhang Yubo, an independent developer based in Italy ("we", "us", or "Controller"). Privacy requests may be sent to yubo.zhang.bb@gmail.com.

This policy explains how FANVELA processes personal data. It applies to the iOS App, its account and billing service, realtime transcription and translation, optional cloud refinement, optional AI study tools, support, and diagnostics. It does not replace notices that a user must give to people being recorded.

1. Important summary

2. Controller and contact

FANVELA is currently operated by an individual, not a separately incorporated company. The Controller, independent developer, sole operator, and account owner is Zhang Yubo, Italy. Zhang Yubo has final responsibility for product decisions, accounts, supplier contracts, production systems, and personal-data processing.

Organisation and authorised-personnel arrangements:

Authorised staff are bound by confidentiality, purpose limitation, least privilege, and restrictions on unauthorised copying or disclosure. A staff listing does not itself grant access to production administration, provider keys, full payment data, or content stored locally on a user's device. Any actual access must be granted separately by the account owner, use an attributable individual account, and be revoked when no longer required.

Privacy and data-rights contact: yubo.zhang.bb@gmail.com.

When contacting us, describe the request and the Apple sign-in email shown in the App. Do not email recordings, API keys, passwords, identity documents, or unrelated sensitive information unless we ask for a secure method.

3. Data we process

3.1 Device-only data

The App may store typed text, translation history, recordings, transcripts, vocabulary, notes, translation memory, course or usage context, interface preferences, and downloaded system voices in the App's local storage. This data is controlled through the App and iOS. It is not collected by our backend unless the user consents to and uses online text translation, invokes another cloud feature, or submits it in feedback.

3.2 Account and identity data

When the user signs in with Apple, we receive Apple's stable user identifier, the name and email address Apple makes available, and whether the email is a private relay address. We create an internal account identifier, App Account Token, and an authenticated session. Apple may provide name and email only on the first authorization. Our backend exchanges Apple's short-lived authorization code for a refresh token so that it can revoke the App's Sign in with Apple authorization when the user deletes the account. The refresh token is encrypted at rest, is not exposed to the App or support staff, is used only for that revocation and related security operations, and is deleted with the account after revocation.

3.3 Purchases, balances, and service usage

We process App Store product and transaction identifiers, purchase, expiry, revocation and refund status, credited and remaining minutes or characters, session purpose, languages, active duration, job status, token counts, and provider cost records. We do not receive the user's full payment-card details.

3.4 Cloud speech features

For realtime or meeting mode, the device sends microphone audio directly to Soniox using a short-lived credential issued for that session. Soniox may also receive selected source and target languages, terminology, glossary pairs, usage context, and a pseudonymous session reference. Soniox returns transcript and translation tokens and provider usage information.

For cloud recording refinement, the user deliberately uploads an audio file to a temporary Google Cloud Storage object. Soniox receives access to process that recording and returns a transcript, translation, timestamps, language information, and processing metadata.

Soniox states that realtime audio is processed in memory and is not retained after the session, and that it does not train models on customer data. Async transcriptions may remain until deleted. FANVELA requests deletion of async Soniox transcriptions after completion, cancellation, or cleanup. Provider security and retention are also governed by Soniox's documentation and our agreement with Soniox.

3.5 Cloud text-AI features

When the user expressly asks for precise translation, quick study, deep study, or AI vocabulary extraction, selected text or transcript, existing translation, language pair, glossary, translation-memory examples, selected difficulty, course or usage context, and task instructions are sent to OpenAI through the Milan primary backend in supported regions. The Milan backend may retain generated output and token/cost metadata for settlement and the short caching periods described in this policy. Requests from mainland-China and Russian network access are rejected before content is sent or quota is reserved. Raw audio is not sent to text AI.

Since July 20, 2026, FANVELA's AI cloud features (live conversations, meetings, cloud refinement, AI study, precise translation, and photo extraction) are not offered to network environments inside mainland China; those features are unavailable while the user is there, and requests are rejected before content is sent, quota is reserved, or an upload URL is issued. On-device offline translation, recording, and local study tools are unaffected.

Photo extraction: when the user takes a photo or picks an image from the library, the image is sent to OpenAI solely to extract its text. The image is not retained after extraction; the recognized text enters the translation input, and the request is charged from the AI-points balance by extracted characters.

We disable application-level response storage where the service supports that control. OpenAI states that API data is not used to train its models unless the customer opts in. OpenAI may nevertheless retain limited security or abuse-monitoring records unless an approved retention control applies to our account.

Each time the user expressly starts a cloud feature, the App makes a minimal HTTPS request to a network-region provider and derives a two-letter country/region code from the current public egress IP. The code is used only to enforce the mainland-China cloud restriction, prefer the EU speech region for European networks, and choose between the United States and Japan speech regions elsewhere. It does not change languages, quota, or price. The App does not request GPS, read the Apple ID or App Store country, or retain the IP address in the diagnostic response. A VPN, proxy, or carrier gateway may cause the code to describe the egress point rather than physical location; the device time zone is used only if the network check fails. European speech capacity is isolated from United States and Japan capacity, so non-European requests do not fall back to the European speech pool.

3.6 Google Cloud online text translation

After the user expressly consents to Google Cloud processing, normal text translation sends the current typed text, source language, target language, and only the user-glossary entries matched for that request to Cloud Translation. Apple sign-in is not required. Our backend does not retain the request text or translation; it stores only an irreversible hash of a random installation identifier, request counts, and character usage for rate limiting, cost protection, and abuse prevention. This online translation service may process content outside the user's country.

This feature is not offered to network environments inside mainland China; requests are rejected before text is sent and the App automatically uses on-device translation. The user may also withdraw Google Cloud consent. After withdrawal, while offline, during a service failure, or after a protection limit is reached, the App automatically uses on-device translation. Device-only input is not sent to a translation server, but the device model may be less accurate than the full cloud model.

3.7 Diagnostics and feedback

Automatic diagnostics are optional, off by default, and enabled only after the user expressly allows them in a separate prompt after sign-in or in Settings; they can be turned off at any time. If enabled, the App may send crash, hang, performance, device model, iOS version, App version, locale, feature name, error code, sanitized error message, and limited technical metadata such as connection type, expensive-network status, and Low Power Mode. Reports are linked to the signed-in account so the account owner can identify an affected user in the restricted operations console; lists use an anonymous reference by default and reveal the account email only when a specific report is opened. Diagnostics are designed not to include audio, source text, translations, vocabulary content, Wi-Fi names, carrier name, full IP address, precise location, advertising identifiers, or unique device identifiers; common secrets, emails, and sensitive paths are redacted. Manual feedback contains the text the user chooses to submit.

3.8 Technical and security data

Our servers process request time, app version and build, session token, the country/region code and signal source used for cloud availability and speech-region selection, network and service errors, rate-limit counters, fraud and cost-anomaly signals, and security logs needed to operate and protect the service. Production logs are configured to redact authorization headers and purchase payloads.

3.9 Optional YouTube video study (supplement dated 2026-09-09)

Update dated 2026-09-16: after reading the link-import notice and selecting Add, the App directly connects to Google/YouTube to load the official embedded player and attempt to retrieve available public captions. Pasting or typing alone sends no request. Existing study entries reconnect when the user selects Load or Retrieve captions. Google/YouTube receives the IP address, device/browser information, video identifier and playback interactions, may show advertising inside its player, and does not guarantee EU-only processing. This service is subject to the [YouTube Terms of Service](https://www.youtube.com/t/terms) and [Google Privacy Policy](https://policies.google.com/privacy). This is not our Google Cloud hosting service, and our Cloud CDPA does not replace the terms applicable to YouTube.

The player uses a nonpersistent WebView data store. Caption requests use a separate cookie store for YouTube access consent, without reading browser or YouTube account credentials. The App does not request advertising identifiers, download or extract YouTube audio/video, or bypass payment, age, region, verification or embedding restrictions. Leaving video study stops the player and cancels unfinished caption tasks. Accessible captions, translations, video identifier, title and learning position are saved locally. Initial translation may download on-device language packs and does not invoke paid cloud transcription. Public caption retrieval depends on the platform's current data format and is not guaranteed for every video or indefinitely. Authorized SRT / VTT import remains available. Manual AI study retains existing provider consent, regional restrictions and billing rules. Links, caption retrieval and playback traffic are not proxied through Haofanyi's backend. Deleting a study entry removes its in-app content, not the YouTube video or original Photos media.

4. Purposes and legal bases

Where the GDPR applies, we rely on:

Consent may be withdrawn in the App. Withdrawal does not affect processing already lawfully completed, but the relevant cloud feature cannot operate without the data it needs.

5. Recipients and processors

We disclose data only as needed to:

Current provider details, roles, data categories, regions, transfer safeguards, retention links, and subprocessor resources are listed in the App under Privacy and Data, and at the Processor and International Transfer Notice linked from this policy.

6. International transfers and regions

Our application backend and temporary recording storage are primarily configured in Google Cloud's Milan region. Online text translation is not represented as processing typed text only in Milan or the EU. Google and its approved subprocessors may process translation content or service metadata, or provide support from other locations under the applicable Google Cloud Data Processing Addendum and transfer safeguards.

Soniox has enabled EU, United States, and Japan regions for our organization. Realtime speech requests from European networks use only the EU region. Other regions choose and fail over only between the United States and Japan regions and cannot consume European speech capacity. No cloud-speech credential is issued inside mainland China. Async recording refinement remains processed in the disclosed Soniox region used for that job.

OpenAI processing may occur in the EEA, United States, and other locations described in OpenAI's DPA and subprocessor list. Eligible data-residency or stricter retention controls apply only if enabled for our project.

European Soniox realtime speech requests use only the EU region; other regions choose and fail over only between the United States and Japan regions and cannot consume European speech capacity. No AI cloud feature is offered to network environments inside mainland China, and text-AI features are currently unavailable from Russian network access. These requests are rejected before content is sent or quota is reserved.

The minimal network-diagnostic request used for routing is processed through Cloudflare's global network and may be handled at edge locations or by approved subprocessors outside the user's country. The App extracts only the two-letter country/region code and sends that code and its signal source with the current feature request; it does not retain the public IP contained in the diagnostic response.

For EEA transfers, we use the processors' DPAs, adequacy decisions where available, and Standard Contractual Clauses or other lawful safeguards as applicable. We will maintain transfer and processor records and assess supplementary safeguards.

For users physically inside mainland China, FANVELA offers no AI cloud feature (live conversations, meetings, cloud refinement, AI study, precise translation, or photo extraction): such requests are rejected before processing, with no transfer of audio, text, images, or task metadata; on-device offline translation, recording, and local study data stays on the device. Users located abroad — including customers using a China-region App Store account — are unaffected and are routed by their actual access region.

For Russian network access, text-AI features including precise translation, AI study, AI vocabulary extraction, and photo extraction are currently unavailable. Requests are rejected before content is sent or quota is reserved. Realtime speech and on-device features continue under their respective rules.

7. Retention

We may retain a minimal suppression or security record where necessary to honour deletion, prevent fraud, or defend legal claims. We will not use such a record to recreate the deleted account.

8. User rights and choices

Depending on applicable law, users may request access, a portable copy, correction, restriction, objection, withdrawal of consent, and deletion. EU users may complain to the Garante per la protezione dei dati personali or their local supervisory authority. Users in China may exercise the rights granted by the Personal Information Protection Law, including requesting an explanation of processing rules and withdrawing consent.

The App provides:

Requests may also be sent to yubo.zhang.bb@gmail.com. We may ask for proportionate verification and will respond within the period required by applicable law. We will not request an Apple password.

Deleting the cloud account does not cancel an Apple subscription. Subscription management and refund requests remain available through Apple. Conversely, cancelling a subscription does not automatically delete account data.

9. Recording and third-party rights

The person starting a recording is responsible for deciding whether recording, transcription, translation, storage, export, and sharing are lawful in the relevant country and setting. Laws vary for classrooms, workplaces, medical settings, private conversations, public spaces, and cross-border use.

The initial consolidated notice explains the user's recording responsibility. Before every recording starts, the App again requires the user to actively confirm that participants were informed and every permission required by law was obtained. Recording does not begin without that confirmation; system recording indicators remain unaffected.

FANVELA does not determine whether a participant notice or consent is legally sufficient. A user must not secretly record, monitor, publish, or distribute another person's voice or words where prohibited, and must respect confidentiality, intellectual-property, employment, education, health, and professional-secrecy rules.

10. Children and students

Cloud accounts are intended for users aged 16 or older, or users acting with a parent or guardian where local law permits. The App is not directed to children and must not be used to make educational admission, grading, discipline, medical, employment, or other high-impact decisions about a child. A teacher, institution, or parent using the App is responsible for its own legal basis, notices, permissions, and safeguarding obligations.

11. Security

Measures include TLS in transit, provider keys kept on the server rather than in the production App, short-lived Soniox credentials, authenticated account sessions, attributable administrator accounts, role-based least-privilege access, access revocation, regional cloud configuration, log redaction, rate limits, cost and abuse controls, and deletion jobs. Staff must not share the owner's account or provider keys; any necessary access should remain attributable. No service is completely secure. Users should protect their device and Apple account and promptly report suspected unauthorized access.

12. Automated output and decisions

Transcription, translation, language detection, summaries, and terminology suggestions are generated automatically and may be incomplete, delayed, biased, or incorrect. FANVELA does not use these outputs to make legal or similarly significant decisions about users. Users must verify important content against the original audio and qualified sources.

13. Changes

We may update this policy when features, providers, regions, law, or retention practices change. Material changes will be presented in the App and may require renewed acceptance or consent. The effective date above identifies the current version.

14. Contact

Privacy, access, export, correction, deletion, objection, or consent request: yubo.zhang.bb@gmail.com.