Semper — Privacy Policy

Last updated: 2026-08-05 Product: Semper DIC Android app and optional cloud sync backend Contact: support mailbox configured as SUPPORT_EMAIL for the deployment

This policy describes personal data processed by Semper when you use the app and, if enabled, the Semper cloud backend. Analysis itself runs on-device; the cloud path is optional and only active when the app is built with an API base URL.

1. Controllers and processors

RoleWho
App operator / controllerThe organization that distributes your build and operates the GCP/Firebase project
Subprocessors (typical)Google (Firebase Auth, Firestore, Google Drive, Firebase Crashlytics, Cloud Logging / Cloud Run), Resend (transactional email for access-request notifications)

No large-language-model or generative-AI provider is integrated.

2. Data we process

2.1 Account and authentication (Firebase Authentication)

2.2 Access control and devices (Firestore)

2.3 Analysis metadata and files (Firestore + Google Drive)

2.4 Diagnostics (Firebase Crashlytics and Analytics) — opt-in

2.5 Operational logs (Cloud Logging / Error Reporting)

2.6 Notifications (Resend)

2.7 Audit trail

3. Purposes and legal bases (summary)

PurposeExamplesBasis (typical)
Provide the productSign-in, sync, restore, quotasContract / legitimate interest
Access controlPending approval, admin approve/revokeLegitimate interest / compliance
SecurityDevice attestation, rate limits, auditLegitimate interest
Reliability (server)Cloud Logging, readiness probesLegitimate interest
Reliability (app diagnostics)Crashlytics / Analytics crash reportsConsent — opt-in, withdrawable in Settings
Support onboardingResend access-request mailLegitimate interest

Exact legal bases depend on your jurisdiction and the deploying organization’s policies; replace this section with counsel-approved language before public launch if required.

4. Retention

DataRetention
Firebase Auth accountUntil you delete the account or an admin removes it
Firestore profile, devices, sessions, file docsUntil account/session erasure via the app/API
Drive artifactsDeleted with session or account erasure (Shared Drive trash may retain per Workspace policy)
CrashlyticsPer Firebase project retention settings (UNKNOWN until verified in console)
Cloud LoggingPer GCP log retention (UNKNOWN until verified; default often 30 days)
Resend message contentPer Resend retention (UNKNOWN until verified)
Audit logsRetained after erasure for security/compliance; not included in user export of analysis content

Scheduled Firestore exports / PITR, where enabled, follow FIRESTORE_DATA_PROTECTION.md.

5. Your rights — export and deletion

6. Sharing

Data is shared with subprocessors above to operate the service. It is not sold. Admin operators of your deployment can approve users and view operational logs according to project IAM.

7. Security (summary)

TLS in transit (Cloud Run / Gateway), deny-all client Firestore rules (server SDK only), device attestation for high-consequence mutations, rate limits, security headers, and opaque client error bodies on Cloud Run. See CLOUD_ARCHITECTURE_GCP.md.

8. Children

Semper is intended for professional / research use, not for children under 16 (or the applicable age of digital consent).

9. Changes

Material changes will update the “Last updated” date. Significant changes to cloud processing should be reflected in-app or in release notes.

10. Contact

Use the in-app support / help action or the configured support email for privacy requests (export, deletion, access questions).