Legal

Privacy Policy

Ever Teleprompter is local-first, not server-free. This policy explains what remains on your device and what VanhSoft processes to provide sign-in, paid access, and Contact Us.

Effective and last updated: 25 August 2026 · Ever Teleprompter for Android 1.0.12

Who we are

Ever Teleprompter is provided by VanhSoft (“VanhSoft”, “we”, “us”). This policy applies to the Ever Teleprompter Android app and everteleprompter.com.

Summary

Your scripts, folders, settings, reading progress, raw microphone audio, and recordings are not uploaded to VanhSoft. They remain on your device unless you deliberately export or share them. Account sign-in, limited subscription-verification data, authentication email delivery, and Contact Us messages that you choose to submit are processed online.

We do not sell personal data. The app contains no advertising SDK, behavioural analytics, or developer crash-reporting SDK.

Information processed for accounts and access

InformationPurpose
Verified email address, Supabase user ID, and linked sign-in identity referencesCreate and secure the app account, support Google or email/password sign-in, display the signed-in email, and support account deletion.
Salted password hash for email/password accountsAuthenticate the account. Supabase Auth processes the password over HTTPS and stores its derived hash; VanhSoft does not store or log the plain-text password.
Pseudonymous HMAC account binding and opaque account scopeBind purchases and local app data to the correct verified account without exposing the original Google identifier or email in subscription tables or local-data folder names.
Authentication email address and verification or recovery message metadataSend account confirmation and password-recovery messages through PurelyMail. These messages contain a time-limited account action link.
Random app installation ID and Play Integrity verdict informationVerify that entitlement and purchase requests come from the genuine published app and reduce fraud.
Entitlement status and Free plan identityProvide Free basic access and determine whether paid access is active.
Google Play product, purchase state, paid-through date, renewal/acknowledgement status, introductory-offer eligibility, encrypted purchase token, and hashed order/token referencesVerify Weekly, Annual or Lifetime access, restore purchases, and process introductory trials, renewals, refunds, expiration, and revocation.
RTDN notification identifiers and security/audit eventsProcess Google Play subscription changes once, investigate failures, and protect the service.
IP address, request time, user agent, and security logs generated by hosting providersDeliver and protect the website and subscription service, troubleshoot outages, and prevent abuse.
Contact Us category (including Feature Request) and message, contact ID, submission time, verified account email, and current subscription tierDeliver the message to support, enable a reply to the verified account email, identify the user's current access level, and investigate the request.
Technical problem Contact Us messages only: app version and version code, Android version and SDK level, and device manufacturer and modelDisplay and attach the relevant app and device context so VanhSoft can troubleshoot the reported technical problem.
Contact Us throttle metadata: contact ID, signed-in Supabase user ID, submission time, delivery time when sent, and pending or sent stateEnforce the limit of five accepted Contact Us messages per account in a rolling 24-hour period without retaining the message, category, email, or diagnostics in the throttle record.
Support correspondenceAnswer requests, investigate problems, and complete manual account-deletion requests.

Contact Us messages are submitted while you are signed in. Every category displays and sends the category, message, verified reply email, and current subscription tier (Free, Lifetime, Annual, Weekly, Trial, or None). Feature Requests are available to paid tiers. VanhSoft derives the reply address and subscription tier from the verified account rather than trusting identity or subscription information entered by the app. If you choose Technical problem, the screen also displays and sends the app version and build, Android version and API level, and phone manufacturer and model shown to you, with a short explanation that these values will be sent for troubleshooting. General question, Account or billing, Feedback, and Feature Request send no automatic app or device information. Brevo delivers the identifiable support email to VanhSoft with its contact ID and submission time. After delivery, PurelyMail retains the message in the support mailbox; a user-configured PurelyMail Sieve rule also sends one copy to VanhSoft's owner mailbox. The app backend retains only the content-free throttle metadata described above, not the Contact Us category, message, email, subscription tier, or diagnostics.

Older app builds may still use the legacy Feature Request endpoint. Those submissions remain subject to the separate legacy storage and retention contract until those builds are retired.

Do not enter or send passwords, tokens, purchase tokens, confidential scripts, or unnecessary sensitive data in Contact Us messages or support email.

Information stored only on your device

Scripts, folders, file names, ordering, reading progress, appearance and mode settings, cue-line settings, Camera-Eye and Floating Prompt settings, remote-controller settings, downloaded speech models, and recordings are stored locally. Cross-device content restoration is not provided. Signing out or deleting the online account does not remotely erase these files.

Microphone, speech recognition, and model download

Voice Follow needs microphone permission while it is active. VanhSoft does not receive or store the raw microphone audio.

After you affirmatively approve a download, the installed model processes speech on the device. Model downloads and stored sizes are approximately: English 188/189 MB; Chinese 168/168 MB; Hindi 198/198 MB; Spanish 156/156 MB; French 156/156 MB; German 156/156 MB; Portuguese 156/156 MB; Vietnamese 339/339 MB; Japanese 170/170 MB; and Korean 160/160 MB.

  • Local-model delivery: depending on the selected language, files are delivered by Hugging Face and its content-delivery providers, everteleprompter.com/model infrastructure protected by Cloudflare, or GitHub-hosted release infrastructure. Those providers receive ordinary request metadata such as IP address and user agent.
  • Other device languages or fallback: Android's selected speech-recognition service may transmit audio or transcripts to its provider. That processing is controlled by the provider and your Android settings, not by VanhSoft.
  • Time and Manual modes: do not require speech recognition.

Camera, audio recordings, video, and documents

Video Record Mode saves a front-camera MP4. Audio Record Mode saves an M4A when video is off, or adds microphone audio to the MP4 when both modes are enabled. Video-only recording is silent. Media is saved through Android MediaStore and can be played, renamed, shared, trashed, or deleted locally.

When you import, export, or share a document or video, Android's system picker or share sheet sends only the file you select to the provider you choose. VanhSoft does not receive it.

Floating Prompt uses Android's display-over-other-apps permission and an ongoing notification while you run it. The script remains on the device and is not uploaded to VanhSoft. Camera-only streams normally omit the overlay, but full-display sharing, mirroring, or screen recording may expose it to viewers.

Service providers

  • Google: Google Sign-In, Google Play Billing, Play Integrity, Android Publisher API, and Pub/Sub purchase notifications.
  • Supabase software on VanhSoft infrastructure: email/password and Google authentication and subscription-verification APIs at api.vanhsoft.com. A separate development environment is used only for development/testing.
  • Cloudflare: DNS, transport security, content delivery, abuse protection, and associated network logs.
  • Hugging Face, GitHub, Cloudflare, and VanhSoft model infrastructure: optional local Voice Follow model delivery, depending on the selected language.
  • PurelyMail: delivery of account verification and password-recovery messages from [email protected], support email storage, and the user-configured Sieve copy from the support mailbox to VanhSoft's owner mailbox. PurelyMail processes ordinary mail metadata and service logs under its published privacy and security practices.
  • Brevo: separate email processing for identifiable Contact Us delivery, including the Feature Request category, and legacy Feature Request delivery to VanhSoft with the verified account email as the reply address. Brevo is not used to send authentication emails.
  • Your Android speech, storage, document, and sharing providers: only when you select or use those services.

Retention

  • Auth account, verified email, linked identities, password hash, sessions, profile, and installation records: deleted from active systems when account deletion completes.
  • Introductory-offer eligibility and entitlement records: retained only as needed to verify Google Play access and prevent abuse.
  • Lifetime purchase/restoration records: retained while VanhSoft must honour Lifetime restoration, refunds, or revocations.
  • Ended Weekly or Annual purchase records, encrypted purchase tokens, RTDN events, and audit/security events: retained for up to 24 months after the relevant end or event.
  • Infrastructure logs controlled by VanhSoft: normally up to 30 days. Providers may retain their own logs under their published policies.
  • Authentication email delivery metadata and service logs: retained by PurelyMail as needed to deliver and protect the mail service under its published practices. Deleted message copies may remain in PurelyMail's daily backups for one month.
  • Legacy Feature Request database records: deleted 12 months after submission. Notification emails and any related replies are support correspondence and follow the period below.
  • Contact Us throttle metadata: sent records become eligible for deletion after 24 hours and are removed by the next scheduled cleanup; pending reservations expire after ten minutes and are likewise removed by scheduled cleanup. Expired records no longer count toward the submission limit. These records contain no category, message, email, or diagnostics.
  • Contact Us messages and other support correspondence: normally until the request is resolved plus 24 months, or longer when required for an unresolved dispute or legal obligation. This correspondence is not automatically removed by account deletion. When VanhSoft deletes a transactional message, Brevo says deletion of its logs and email previews may take up to 72 hours. PurelyMail says its daily deleted-message backups are retained for one month, after which the deleted copies expire from those backups.
  • Encrypted disaster-recovery backups: expire within 90 days and are not used for ordinary processing.

Account deletion and your choices

Delete your account in Options → Account & Privacy or from Delete your Ever Teleprompter account. The in-app flow optionally erases app-managed local content; the website cannot reach files on your devices.

For legacy feature requests, account deletion nulls the linked user ID and email in the private database. The request text, request ID, submission time, subscription tier, anonymization time, and notification delivery state remain until the record is deleted 12 months after submission. Account deletion does not immediately remove notification emails or related support correspondence, including the verified email and any personal information that you typed into the message.

Account deletion removes Contact Us throttle metadata linked to the account, but it does not automatically remove Contact Us messages, replies, or other support correspondence already delivered by email. That correspondence follows the retention period above, including any personal information you typed in the message and, for Technical problem messages, the displayed app and device diagnostics.

Account deletion does not cancel a Google Play subscription. Cancel separately in Google Play's subscription centre. Uninstalling, signing out, or clearing local data also does not cancel a subscription.

If self-service deletion fails, email [email protected] from the verified email used in the app. Manual requests are completed within 30 days. Never send a password, access token, or purchase token.

Security

VanhSoft uses HTTPS, access controls, forced row-level security, pseudonymous identity binding, encrypted purchase tokens, restricted server ports, log rotation, and encrypted off-server backups. No system can be guaranteed perfectly secure; contact us if you believe your account or data is at risk.

Age

Ever Teleprompter is designed and marketed for adults aged 18 and over. It is not directed to children.

Contact and policy changes

Questions or privacy requests: [email protected]. Material policy changes will be posted here with a revised effective date.