Micabo · iPhone and site
Privacy policy
Last updated: 2 September 2026.
This policy describes the data Micabo processes when you use the site micabo.app or the iPhone app (identifier com.micabo.ios). Both clients share the same account and the same database. It also applies if you do not yet have an account and are only browsing the site.
The controller is Micabo. For any question, correction or deletion: team@micabo.app.
What Micabo is
Micabo turns a course (PDF, photo, document, video) into a sheet and flashcards, then brings them back before you forget them. An exam mode tightens revision as a date approaches. You can share a course with friends, or keep it to yourself.
What data we process
The account. Email address, identifiers provided by Apple or Google if you choose those sign-in methods, and a username. We do not store your password: email sign-in uses a link, not a secret we would keep.
The academic path. Country of study, level, subjects, and school if you give it. This is used to write the sheet in the right language and the right system, and to show you classmates from the same school if a course is shared.
Your courses. The files or links you upload, the text extracted from them, the generated sheets and cards, diagram images, exams (name, date, target grade) and the revision history (when a card comes back, how you rated it).
Friends. Friend requests, your friends list, and the visibility you set on each course at import: you only, your friends, or classmates at your school. There is no public catalogue where a stranger would stumble on your sheets.
The subscription. The status of your Pro access (active, trial, cancelled), not your card number. Payment is collected by Apple on iPhone, by Stripe on the site. RevenueCat holds the right, so that the iPhone and the browser agree.
The waitlist. If you leave your address before you have an account, we keep it to notify you of the opening, together with the page you came from. It is not linked to an account and is not visible through the app.
Feedback. If you send a bug or an idea from the app, we keep the message, the type (bug or idea), and the link to your account, so we can reply. They are kept for 24 months, then deleted. They are not used to profile you.
Generation usage. A counter per day and per function (sheet, cards, explanation), without the course content. It is used to limit abuse, not to profile you.
The directory. Your username and, if you have given it, your school. That is what a friend or classmate sees, not your email or your preferences.
What stays on the device. On iPhone, some pieces (occlusion images, audio for a card) may never leave the phone. Answers from the onboarding path stay on the device first, then are written to the database once the account is opened.
We do not sell your data. We do not show advertising. We do not train a language model on your courses, unless an explicit setting offers that one day — and that setting does not exist today.
Why we process them
The legal bases, within the meaning of the GDPR:
- Performance of the contract — creating the account, importing a course, writing the sheet and the cards, reviewing them, syncing iPhone and site, managing the subscription.
- Legitimate interest — securing the service, preventing abuse, diagnosing a fault, measuring the site's audience in aggregated form, and reading the feedback you send us. This interest does not come before yours: the isolation is in the database, not only in the application.
- Legal obligation — retaining what billing or accounting require, for the prescribed time.
- Consent — when you choose to share a course, open the camera, or sign in with Apple or Google.
Who has access
Your courses are readable only by you, unless you have shared them. Every request to the database is evaluated with your identity: there is no query that can ask for someone else's courses. Feedback you send is read by the team, at team@micabo.app. Nobody else has access to it from the application.
Service providers see some of the data, solely to provide the service:
- Supabase (European Union, Stockholm region) — account, database, files.
- Vercel — hosting of the site, technical logs (IP address, URL) and audience measurement: the number of page views, the page you came from, the country and the device type, without a cookie and without an identifier that follows you. Processing may take place outside the European Union, under the provider's standard contractual clauses.
- Apple and Google — if you sign in with them, or if you pay on the App Store.
- Stripe — payment on the site.
- RevenueCat — subscription status, shared between iPhone and site.
- fal.ai and the models it calls (today, language models, notably from Google) — the text or image of your course, for the time it takes to write the sheet or the cards. They are not allowed to use it for anything other than that generation.
- YouTube / Google — if you import a video, we read its metadata and subtitles.
Some of these providers are established outside the European Union. The transfer then takes place only to provide the service, and relies on the safeguards provided by the GDPR (adequacy decision or the provider's standard contractual clauses).
Cookies and trackers
The site sets the cookies needed for the session (to recognise you from one page to the next once you are signed in) and an interface-language preference cookie (micabo.ui_locale), kept for one year, which remembers English, French, German, Spanish or Turkish. We do not set an audience-measurement cookie, nor an advertising cookie, nor cross-site tracking. The site does count its visits, but without writing anything on your device: the measurement keeps a page view, its origin, a country, a device type, and nothing that would let us recognise you from one visit to the next or on another site. That is why there is no consent banner: there is nothing to refuse on that side.
The iPhone does not use cookies. It keeps a session token in the device's Keychain.
How long we keep them
For as long as the account exists. Feedback is deleted after 24 months at the latest. If you delete it, from Settings on the site or in the iPhone app, or by writing to us, we erase the profile, the courses (including the extracted text), the sheets, the cards, the history, the exams, the friendships, the usage counters, the feedback and any address left on the waitlist.
A course you have shared disappears for your friends when you delete it. A friend who has already reviewed your cards keeps their own history, not your document.
After deletion, providers retain what the law or their contract requires: Stripe or Apple invoices, a RevenueCat subscription identifier, technical logs (Vercel, Supabase) for a few weeks. fal.ai receives the text for the time it takes to write the sheet; we do not ask it to keep it.
Your rights
You can access your data, correct it, export it, object to processing, or request erasure. To download a copy: Settings → “Download my data”. To delete the account: Settings → “Delete account”, on the site or in the iPhone app. You can also write to team@micabo.app. We reply within a month.
You can also lodge a complaint with the CNIL (cnil.fr).
Minors
Micabo is aimed at students, including those in secondary school. We do not ask for a date of birth. If you are under fifteen, use of the service must be with the agreement of a person with parental authority. We do not use a minor's data for advertising, nor for commercial profiling.
The iPhone, in addition to the site
The app may ask for access to your photos or camera to import a course. This is not required: the site accepts an uploaded file. Notifications, if you allow them, are only used to remind you of a review. The same account opens the app and the site.
Changes
If this policy changes in a material way, we update the date at the top of the page. Continued use after that date applies to the new version, unless the law requires a separate agreement.
The terms of use complement this text.