Alca Labs
Privacy Policy
Last updated September 6, 2026
Reps is built local-first, runs no analytics, and sells nothing about you. This page describes exactly what we store, where it goes, and how to get rid of it.
The short version
- We do not run analytics, trackers, advertising pixels, or third-party session recording. There are none in the product.
- We never sell or rent your personal information, and we never will.
- You can browse and study any shared deck without an account at all.
- Your study data lives in your own browser first. It only reaches our server if you sign in.
What we collect
Guest use: loading pages makes ordinary web requests. Your progress in a guest study session is held in memory and is gone when you close the tab. If you submit feedback or sign up for mobile updates, we receive the information you choose to submit.
If you create an account, the account itself is an Alca Labs account, shared across our apps. We store your email address and, if you sign in with Google, the name and profile image Google returns. Passwords are hashed by our authentication provider and are never visible to us.
Your study data is stored so it can sync between your devices: your decks, cards, folders, tags, study progress and scheduling data, streaks, daily rep counts, and any cards you flag. If you opt in to leaderboards, we additionally store a public handle you choose, your school, your weekly rep count, and your current streak. If you publish a deck, the text of that deck becomes publicly readable by anyone with the link, bylined with your handle.
What we do not collect: we do not ask for your real name, date of birth, phone number, or address. We do not collect your location. We do not build advertising profiles.
Card details never reach us. If you subscribe, you enter your card on Stripe’s own checkout page. We receive only what Stripe tells us: that a subscription is active, which plan, and when it renews. We never see or store your card number.
The iOS app
Reps for iOS stores your study library in a local database on your device and your login session in the iOS Keychain. When signed in, it automatically syncs your study data with Reps so you can use it across devices. Signing out keeps that account’s local study data for your next sign-in; it does not transfer it to another account.
AI grading is off by default in the iOS app. If you enable it in Status, your written answer and the card’s question, reference answer, explanation, and keywords can be sent through Reps to the configured AI provider (Google, OpenAI, or Anthropic). You can turn it off at any time. With AI grading off, answers are graded on your device; ordinary study-data sync still operates while signed in.
The native app bundles its fonts and does not fetch them from Google or Adobe. Signing in opens the shared Alca authentication website in a system browser, where the authentication providers described below apply. The native app does not include advertising or tracking SDKs.
Status contains links to this policy and the terms, plus Delete Reps data. After confirmation, deletion removes your Reps study data and membership, cancels Reps billing, and clears that account’s local study data and login session on this device. Your shared Alca identity and other Alca products remain. If cleanup fails, the app pauses study and sync and offers a retry.
Mobile updates
If you opt in to mobile updates, we store your email address, signup date, and consent record in Neon. No Alca account is created. We use this list only for news about Reps for mobile, including early access and launch updates.
We keep your signup until you ask us to remove it or we no longer need it for mobile launch updates. To withdraw consent or request deletion, email erikyaspelin@gmail.com.
Where your data goes
We use a small number of processors, and only these:
- Supabase — authentication (your email and login session).
- Neon — the Postgres database holding your synced study data.
- Vercel — hosting and standard server request logs.
- Google (Gemini API), OpenAI, or Anthropic — AI card generation and answer grading, depending on the configured provider.
- Resend — sending account emails such as your sign-up code and renewal notices.
- Stripe — payments, if you subscribe. Stripe receives your email address and the card details you enter on their checkout page.
- Cloudflare — bot protection on the sign-in and sign-up screen. It checks that a real browser is submitting the form, and sees only what it needs for that check. It is not used anywhere else in the app and never sees your study material.
- Replicate — generating cover art for a set, if you leave that switched on. It receives a short description of the subject built from the set’s title and a few of its questions, and it returns an image. It does not receive your whole deck, your answers, or your account details, and the finished image is stored by us rather than by them.
- Vercel Blob — storing set cover art and images attached to your study cards, including original images used for cropping. Images are stored at unguessable public URLs; anyone who has one of those URLs can access the image. If you upload your own image we re-encode it in your browser before it is sent, which removes embedded camera data such as GPS location.
- Google Fonts — typefaces used on the website. Your browser fetches them from Google’s font servers on every page, including before you sign in, so Google receives your IP address and which page requested them. No account data and no study material is involved.
- Adobe Fonts — one typeface used for the Reps website wordmark, loaded the same way and with the same footprint as Google Fonts.
- Sentry — error reports, so we find out when something breaks instead of waiting for you to tell us. Reports carry the technical details of the failure and an anonymous account identifier. We deliberately strip your email address, your IP address, and the contents of whatever you were working on before the report is sent. We do not use session recording or replay.
AI and your study material
When you generate cards, the material you provide — pasted text, an uploaded file, or a transcript — is sent to Google’s Gemini API to produce the deck. When you answer a free-response card, your written answer is sent to be graded. Google processes this on our behalf as an API customer; API inputs are not used to train Google’s models.
Two things worth knowing. First, plenty of grading never reaches the AI at all: if your answer matches the expected one, it is graded locally on your device and nothing is sent. Guest study sessions never call the AI. Second, do not paste material you are not allowed to share — someone else’s copyrighted content, confidential documents, or anything containing another person’s sensitive personal information.
Cookies
We set cookies for two purposes: keeping you signed in, and remembering which link first brought you here so we know whether our own advertising works. Neither is shared with anyone. There are no advertising cookies and no third-party tracking cookies. Separately, your browser stores your decks and preferences locally so the app works offline and feels instant; that data stays on your device and you can clear it at any time through your browser settings.
Your choices
- Leaderboards are opt-in. The campus board is off by default.
- Publishing is opt-in and reversible. Unpublishing removes the public copy.
- Export. Your decks can be copied out of the app as plain text.
- Deletion. Settings has a Delete your Reps data button. Your shared Alca login and other Alca apps are kept. It removes your decks, progress, streaks, leaderboard row, published sets and stored images, and cancels your Reps subscriptions. New writes are paused while deletion runs. If a provider is unavailable, retry the operation to finish; your billing references are retained until cancellation and image cleanup succeed. Previously cached or downloaded copies may remain outside our control. We retain a minimal deletion record to prevent stale devices from restoring deleted data and to handle delayed billing events. If you would rather we did it, email erikyaspelin@gmail.com.
Children
Reps is built for college students. It is not directed at children under 13, and we do not knowingly collect their information. If you believe a child has created an account, contact us and we will remove it.
Changes and contact
If we change this policy in a way that materially affects you, we will say so in the app rather than quietly updating this page. Questions, requests, or complaints: erikyaspelin@gmail.com.