Weavr

Privacy Policy

Weavr is a “save anything” app. You share a link, a screenshot, a note or a document into it, and Weavr turns that into a structured, searchable object you can act on later. Doing that means reading your content, sending parts of it to AI and lookup services, and storing what comes back. This policy explains exactly what that involves, in the order it happens.

1.Introduction

What Weavr is

Weavr is a mobile application and its supporting backend service. You save content into Weavr — a social media link, a web page, a screenshot, a PDF, or a note you type yourself. Weavr then attempts to extract the useful information from it, classify what kind of thing it is (a recipe, a workout, a place, a watchlist, a checklist, and so on), pull out structured fields, and present it as something you can search, organise, share into a Space with other people, and act on.

Who operates Weavr

Weavr is operated by Ryonkai (“Weavr”, “we”, “us”, “our”), registered at Uttar Pradesh, India. For the purposes of applicable data protection law, Ryonkai is the controller (or, under Indian law, the Data Fiduciary) for personal data processed through Weavr.

What this policy covers

This policy covers the Weavr mobile app, the Weavr backend API, and any website we operate that links to this policy. It does not cover third-party services you reach from Weavr — for example the original social platform, website or map listing a saved link points to. When you open one of those, that service's own privacy policy applies.

Relationship to our Terms

This Privacy Policy forms part of, and should be read alongside, our Terms of Service (#terms). Where this policy describes how we handle information and the Terms describe the rules for using the service, this policy governs on privacy matters.

How to reach us about privacy

Privacy questions, requests and complaints go to ryonkai.devs@gmail.com. Full contact details, including the grievance contact for users in India, are in section 22.

2.Information we collect

We group information into three categories: what you give us, what is collected automatically as the service runs, and what Weavr generates from your content. The third category is unusually large for an app like this, so it has its own subsection.

A. Information you provide

Account information

  • Email address — required to create an account. Accounts are created and authenticated through Supabase Auth (see section 5).
  • Password — chosen by you at sign-up. It is handled by our authentication provider; we do not receive or store your password in Weavr's own database.
  • Display name — the name you enter at sign-up, shown to other members of any Space you join.
  • Username — a unique handle you choose. It must be unique across all Weavr users, so it is stored in a form that lets us check that.

We do not ask for your phone number, date of birth, postal address, government identifiers, or a profile photo. There is no profile picture upload anywhere in the app; member avatars are drawn from initials.

Content you save

Weavr accepts five kinds of source material, and this is the core of what we process:

  • Links (URLs) — shared from another app via the system share sheet, or pasted from your clipboard.
  • Text notes — typed directly into the app.
  • Images and screenshots — chosen from your photo library, or shared into Weavr from another app.
  • PDF documents — where a saved link points to a PDF.
  • Audio — where a saved link points to media with an audio track that we transcribe (see section 4).

Content you create inside Weavr

  • Spaces — their names, types, and who you invite. Invitations are issued as codes.
  • Comments — on individual saves and on merged “entities” inside a Space. Visible to the other members of that Space.
  • Votes and pins — signals you attach to shared items.
  • Progress and status — checklist ticks, watch status and ratings, exercise completion, lifecycle status (“planned”, “started”, “completed”), favourites and archive flags.
  • Shopping lists — items generated from a saved recipe, plus your ticks and edits. A shopping list can be personal or shared inside a Space.
  • Organisational overrides — where you rename or merge a collection or an item, we store that instruction.
  • Notes attached to a save, and search queries you type.

Device permissions you grant

  • Photo library — requested only when you choose to attach an image. We receive only the image you pick, not your library.
  • Clipboard — read only at the moment you tap “Paste link”. We do not monitor your clipboard in the background.
  • Share sheet — on Android, Weavr registers to receive shared text and images. We receive only what you deliberately share into Weavr.

B. Information collected automatically

Weavr contains no analytics SDK, no advertising SDK, and no third-party crash-reporting SDK. We do not build behavioural profiles, and there is no event-tracking pipeline in the app. What is collected automatically is limited to what running a networked service necessarily involves:

Automatically collected information and why
WhatWhy it exists
IP address and standard request metadata (approximate origin, request time, user agent, response status) Processed by our hosting, database and authentication providers as an inherent part of routing and serving network requests, and for their own abuse prevention and security. We do not record IP addresses in Weavr's own application database.
Server logs Our backend writes operational logs (which job ran, whether it succeeded, error codes and messages). These can include a saved URL or an error string derived from your content, because that is what failed.
Authentication session data Our authentication provider issues and refreshes session tokens and keeps its own records of sign-in activity for security purposes.
Processing and usage counters We count saves and conversions per account per period, to apply fair-use limits and manage capacity. We record per-request AI metadata — which model ran, token counts, a confidence score, and whether it succeeded — but not the content of the request.
Connectivity state The app checks on-device whether you are online, so it can queue work while you are offline. This check stays on your device.

We do not collect precise device location. Where a saved place has an address or coordinates, those describe the saved place — not where you are.

C. Information Weavr creates from your content

This is derived data: information that did not exist until Weavr processed something you saved. It is stored alongside the original and is treated as your personal data wherever the source content is.

  • Extracted text — captions and subtitles published with a video, page text from a link, text from a PDF, a transcript of an audio track, and text read from video frames or screenshots by optical character recognition.
  • A knowledge type — the classification of what the save is (recipe, movie, place, workout, article, product, book, checklist, itinerary, course, code repository, recommendation list, and similar), plus a confidence score.
  • Structured fields — the type-specific data pulled out of the content: ingredients and quantities, exercises with sets and reps, an address, a synopsis, a list of recommended titles with the reason each was recommended, and so on.
  • Enrichment data — facts fetched from external catalogues to fill gaps the content itself left empty (see section 5).
  • Embeddings — a numeric vector representing the meaning of a save, used for semantic search and for spotting when two members of a Space have saved the same thing. It is generated from the structured fields, not from the raw source text.
  • Search indexes — a full-text index built from the structured fields, held both on our servers and on your device.
  • Collections and groups — a derived organisation of your library. These are computed on demand from your saves rather than stored as a fixed structure.
  • Weekly digest — a short AI-written summary of the week's saves, generated only when you actually open the screen that shows it, and then cached for that week.
  • A thumbnail link — where a source platform publishes a thumbnail, we store the URL of that image. We do not copy the image itself.

What we deliberately do not keep

To extract text, our servers may temporarily download audio or a low-quality copy of a video into scratch storage on the processing machine. That material is deleted when the job finishes, whether it succeeded or failed. Weavr does not retain, host or re-publish downloaded videos or audio.

3.How we use information

Purposes, the data each uses, and the basis we rely on
Purpose Data used Legal / business reason
Creating and authenticating your accountEmail, password (via our auth provider), display name, usernamePerformance of our contract with you
Storing the content you saveSaved links, notes, images, documentsPerformance of contract
Extracting text and understanding contentSaved content, extracted text, transcripts, video framesPerformance of contract
Classifying and structuring a saveExtracted text and selected frames, sent to an AI providerPerformance of contract
Enriching a save with missing detailsA title, name or place string derived from your content, sent to a lookup servicePerformance of contract
Search — keyword and semanticStructured fields, embeddings, your search queryPerformance of contract
Organising your library into collectionsStructured fields of your savesPerformance of contract
Weekly digestTitles and structured fields of that week's savesPerformance of contract
Collaboration in SpacesSaves you place in a Space, comments, votes, pins, progress, display name and usernamePerformance of contract
Duplicate detection inside a SpaceEmbeddings of saves in that SpaceLegitimate interests — making a shared library usable
Offline use and synchronisationA copy of your library and queued changes, held on your devicePerformance of contract
Fair-use limits and capacity managementPer-account counts of saves and conversions; per-request AI metadataLegitimate interests — keeping a shared, capacity-limited service available to everyone
Reliability, debugging and securityServer logs, error codes, job outcomesLegitimate interests — operating a secure and functioning service
Preventing abuse and enforcing our TermsAccount information, activity recordsLegitimate interests; legal obligation where applicable
Responding to your support and privacy requestsWhatever you send us, plus account information needed to identify youPerformance of contract; legal obligation
Subscription management, if and when paid plans launchAn entitlement record and a payment-platform customer identifierPerformance of contract
Complying with lawAs required by the requestLegal obligation

We do not use your content or activity for advertising, ad targeting, or profiling for marketing. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

4.AI processing

AI is not an optional add-on in Weavr — it is how a saved link becomes a usable object. This section explains what it does, what leaves our systems, and what the limits are.

What AI does in Weavr

  • Decides what kind of thing you saved, and how confident it is about that.
  • Pulls structured fields out of unstructured content — ingredients, exercises, addresses, ranked recommendations and their stated reasons.
  • Transcribes speech from a saved video or audio track, when no published captions exist.
  • Reads on-screen text from video frames and screenshots.
  • Produces the numeric representation used for semantic search and duplicate detection.
  • Writes your weekly digest summary.
  • Normalises a recipe's ingredient lines into shopping-list products, quantities and aisles.

How processing works, step by step

  1. You save something. It is recorded and queued for background processing.
  2. Our server tries the cheapest text sources first: captions or subtitles the platform already publishes, then the post's own title, description and metadata, then readable text from a web page or a PDF.
  3. If none of that yields usable text, we escalate — downloading only the audio and transcribing it, or sampling a small number of video frames and reading them with optical character recognition on our own servers.
  4. Only if local text-reading fails or produces low-confidence output do we send images to an AI vision model.
  5. The assembled text (and, in the fallback case, a handful of frames) is sent to our AI provider in a single request, which returns the classification and the structured fields.
  6. We fill remaining gaps from external catalogues, generate the search embedding, and store the result on your account.
  7. The finished object appears in your library, and syncs to your device.

Scratch files created during steps 3 and 4 are deleted when the job ends. The result of steps 5 to 7 is stored.

AI and lookup providers we use

The providers below are the ones actually integrated in Weavr today. Their role and what reaches them is set out in section 5.

  • Google (Gemini API) — classification and extraction, vision fallback, digest writing, shopping-list normalisation, and embeddings.
  • Groq — speech-to-text transcription, using a Whisper model.

We do not train our own models on your content

Weavr does not train, fine-tune or develop machine-learning models of its own, and does not use your content to do so. Where third-party AI providers are involved, their handling of the data sent to them is governed by their own terms and privacy commitments — including, on Google's free tier, the model-improvement use described above.

Limits of AI output

AI-generated results can be wrong. Classification can pick the wrong type, extraction can miss or misread a field, transcription and text recognition make mistakes, and enrichment lookups can match the wrong title or place. Weavr marks fields it could not determine rather than guessing at them, and enrichment only ever adds to what your content said — it never overwrites it. Even so:

Do not rely on Weavr's output for anything consequential without checking the original. That applies especially to ingredients and quantities, allergen information, medical or fitness guidance, dosages, addresses, prices, and anything with a safety implication. Every save keeps a link back to its source so you can verify it.

5.Third-party services and data sharing

We share information with the service providers below because Weavr cannot function without them. Each processes data on our instructions for the purpose described, under its own terms.

Service providers (processors and infrastructure)

Providers integrated in Weavr, and what reaches each one
Provider Purpose Data potentially processed
Supabase Authentication, application database, file storage Email address, password credentials, session tokens, your entire saved library and everything derived from it, uploaded images, request metadata including IP address
Render Hosting for the Weavr backend and processing pipeline All API traffic in transit, request metadata including IP address, server logs
Google — Gemini API Content classification and extraction, vision fallback, digest writing, shopping-list normalisation, embeddings Text extracted from your saved content; in the vision fallback, selected video frames or your screenshot; titles and structured fields for digests and embeddings
Google — Places API Filling in details for a saved place A place name or address string derived from your content
Groq Speech-to-text transcription A short audio excerpt extracted from media you saved
Google — Books API Filling in book details A title string, and an author name where your content already stated one, derived from your content
TMDB (The Movie Database) Filling in film and television details A title string, and optionally a year, derived from your content
RapidAPI (YouTube metadata provider) Fetching public metadata and caption tracks for a saved YouTube link The video identifier from the URL you saved
RevenueCat Subscription entitlement records A customer identifier and subscription status. No purchase flow exists in the app today — this integration is inactive until paid plans launch.

Enrichment lookups (Google Places, Google Books, TMDB) are optional per installation and are disabled when no credential is configured. Transcription is likewise only used when earlier, cheaper text sources produced nothing.

Source platforms

When you save a link, our servers fetch that URL to read its text — the same thing a browser does. The site or platform you saved from therefore sees a request from our server, not from your device, and may log it under its own policies. We only ever fetch content you have chosen to save. We do not crawl, scrape in bulk, or re-publish downloaded media.

Other Weavr users

Spaces are collaborative by design. When you add a save to a Space, or comment, vote or pin in one, the other members of that Space can see it, along with your display name and username.

One consequence worth knowing about

Progress markers such as “watched” are recorded against your account globally, not per Space. If a Space contains an item you already marked as watched from your own private library, other members of that Space will see it as watched by you. The app repeats this notice wherever another member's status is shown.

Independent third parties

We do not sell personal information, and we do not share it with advertisers, data brokers, or any third party for their own independent marketing purposes.

Legal disclosures

Separate from the above, and covered in section 20.

6.Connected services and imported content

Weavr does not connect to your third-party accounts. There is no “connect your Instagram”, no calendar or email integration, no OAuth link to another service, and no import of your account history from anywhere. Weavr has no access to any account of yours other than the Weavr account itself.

The only route content takes into Weavr is one you take deliberately, each time: sharing an item via your device's share sheet, pasting a link, typing a note, or picking an image. Because there is no persistent connection to another service, there is nothing to disconnect, and no background import to stop.

Saving a public link does not give us access to your account on the platform that link came from. Content that platform makes available only to signed-in users may simply fail to process.

7.Cookies and similar technologies

In the mobile app

The Weavr app does not use advertising cookies, advertising identifiers, or cross-app tracking. It does not request permission to track you across other companies' apps and websites, because it does not do so. It uses the following on-device storage, all of it essential:

  • Authentication storage — your session tokens, kept so you stay signed in.
  • A local database — a copy of your library, so the app opens instantly and works offline.
  • A pending-changes queue — changes made offline, held until they can be sent.
  • Preferences — theme, accent, font, haptics, and whether the app opens when you share into it.
  • A small share-handoff file — on Android, so the background share handler can identify your account and upload what you shared.

All of this is removed when you sign out or uninstall the app.

On this page and any Weavr website

This policy page sets no cookies, loads no external fonts, scripts or trackers, and makes no third-party requests. Where we operate other web pages, any use of cookies beyond what is strictly necessary will be described there. No marketing website exists at the time of this policy.

8.Data storage

On our servers

  • Database — a managed PostgreSQL database provided by Supabase, in the region ap-northeast-1 (Tokyo, Japan). It holds your account record, your saves, everything derived from them, your Spaces and collaboration data.
  • Backend service — hosted on Render in the United States (Oregon region). This is where the processing pipeline runs.
  • File storage — images you upload are stored in a Supabase Storage bucket.

On your device

Weavr keeps a local copy of your library so the app works without a connection. That copy lives in the app's private storage area, protected by your device's own app sandboxing and, on most modern devices, by full-disk encryption. It is removed when you sign out or uninstall.

Encryption

All traffic between the app, our backend and our providers uses HTTPS/TLS. Our database and storage providers encrypt data at rest as part of their managed platforms. We do not additionally encrypt individual fields within the database, and Weavr is not end-to-end encrypted — our servers necessarily read your content in order to process it.

Backups

Backups are those provided by our managed database platform, on that platform's schedule and retention terms. We do not maintain a separate backup system of our own. See section 9 for what this means for deletion.

9.Data retention

We have not fixed a numeric retention period for every category, and we would rather say so than publish a number we do not enforce. What we can state precisely is the rule each category follows:

Retention by category
CategoryRetained
Account record (email, name, username)For as long as your account exists. Deleted when you delete your account.
Saves and everything derived from themUntil you delete the save, or delete your account. There is no automatic expiry — a save you keep, we keep.
Uploaded imagesWith the save they belong to.
Comments, votes, pins, Space activityWith the Space they belong to, or until deleted.
Downloaded audio, video and framesDeleted as soon as the processing job ends — within minutes, and never persisted.
Weekly digestsCached per week; regenerated rather than accumulated.
Usage counters and AI request metadataUsage counters are tied to your account and removed with it. AI request metadata records no content, and is retained for capacity and cost management. Retained for up to 12 months, then deleted.
Server logsRetained on our hosting platform's default schedule, which is short and rolling. Retained on a short rolling basis by Render (typically 7 days). Not accessible to Weavr.
Authentication recordsHeld by our authentication provider for as long as the account exists.
BackupsOn our database platform's backup retention schedule. Deleted data can persist in a backup for a limited period after deletion, and is overwritten as backups roll forward.
Data sent to AI providersGoverned by that provider's own retention terms, not ours. See section 4.

Where no fixed period is set, we decide how long to keep something by weighing:

  • whether it is still needed to provide the service to you;
  • whether it is needed to keep the service secure or to prevent abuse;
  • whether a law requires us to keep it, or a dispute makes it necessary; and
  • whether an aggregated or de-identified form would do instead.

10.Account deletion

How to delete your account

In the app: Settings → Danger Zone → Delete account. You will be asked to confirm twice, including by typing the word DELETE. Deletion begins immediately once confirmed.

Without the app: email ryonkai.devs@gmail.com from the address on your Weavr account and ask for deletion. We will verify the request and action it.

What deletion actually does

  1. Every Space you own is deleted. Its members are notified that it is gone, and lose access to it.
  2. Every save you own is deleted — including saves you had placed in someone else's Space. Everything attached to a save goes with it: extracted text, structured fields, embeddings, comments, votes, progress and uploaded images.
  3. You are removed from Spaces owned by others.
  4. Your profile record is deleted, which cascades to your subscription record, usage counters, digests, saved progress and organisational overrides.
  5. Your authentication account is deleted at our authentication provider. You can no longer sign in, and the email address is released.
  6. On the device you deleted from, the local copy of your library is wiped and you are signed out.

In normal operation this completes within minutes. If a step fails partway, the process is safe to retry and will finish from where it stopped.

What is not immediate, and why

  • An already-issued sign-in token stays valid until it expires. Our backend verifies session tokens cryptographically rather than checking a database on every request, so a token issued shortly before deletion remains technically valid for its short remaining lifetime. The app signs you out and wipes local data immediately, which closes this on the device you used. We do not claim instant global session revocation.
  • Backups roll forward. Deleted data can remain in a database backup for a limited period before being overwritten.
  • Content in another member's Space that they created — their comments, their saves — is theirs and stays. What was yours is removed.
  • Data already sent to an AI provider is subject to that provider's retention and deletion terms. We cannot delete on their behalf.
  • Records we must keep — for example to meet a legal obligation or resolve a dispute — are retained only for as long as that reason lasts.

11.Data export

Weavr does not currently offer a self-service export. There is no “download my data” button in the app, and we would rather say that than describe a feature that does not exist.

You can still exercise your right to portability where it applies: email ryonkai.devs@gmail.com from your account address and we will provide the personal data we hold about you in a structured, commonly used, machine-readable format. We will confirm receipt and respond within the time applicable law allows.

The export will cover your account record, your saves and their extracted and derived fields, your Spaces and collaboration data, and your uploaded images. It will not include another member's content, or internal operational logs.

12.Your privacy rights

Depending on where you live, you may have some or all of the rights below. Not every right applies to every user, and some are subject to conditions and exceptions under the law that grants them.

  • Access — to know whether we process your personal data and to obtain a copy.
  • Correction — to have inaccurate or incomplete data corrected. Your name, username and saved content are editable in the app.
  • Deletion — to have your personal data erased. See section 10.
  • Portability — to receive your data in a machine-readable format. See section 11.
  • Restriction — to ask us to limit how we process your data in certain circumstances.
  • Objection — to object to processing based on legitimate interests.
  • Withdrawal of consent — where we rely on consent, you may withdraw it at any time. This does not affect processing already carried out.
  • Non-discrimination — we will not degrade the service because you exercised a privacy right.
  • Complaint — to lodge a complaint with your data protection authority.

To exercise a right, email ryonkai.devs@gmail.com. We may need to verify your identity — normally by confirming you control the email address on the account — before acting, and we will not use verification information for any other purpose.

13.India — Digital Personal Data Protection Act, 2023

Where applicable, Weavr processes personal data in accordance with applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023 and the rules or regulations issued under it. Where that Act applies, Ryonkai acts as the Data Fiduciary and you are the Data Principal.

Notice and consent

This policy, together with the consent you give when creating an account, is intended to serve as the notice describing the personal data we process, the purposes for which we process it, and how you may exercise your rights and make a complaint. We ask for personal data only where it is needed for the purposes set out in section 3.

Withdrawing consent

You may withdraw your consent at any time by emailing ryonkai.devs@gmail.com or by deleting your account. Withdrawal is as easy as giving consent. Because processing your saved content is how Weavr works, withdrawing consent generally means we can no longer provide the service to you, and your account will be closed.

Your rights as a Data Principal

  • The right to access a summary of the personal data we process and the processing activities undertaken.
  • The right to correction, completion, updating and erasure of your personal data.
  • The right to nominate another individual to exercise your rights in the event of your death or incapacity.
  • The right of grievance redressal, described below.

Grievance redressal

If you are dissatisfied with how we have handled your personal data or a request, contact our grievance contact:

Grievance officer / privacy contact
Grievance Officer, Ryonkai
Grievance email
ryonkai.devs@gmail.com

We will acknowledge and respond to grievances within the period required by applicable law. If you remain dissatisfied, you may escalate to the Data Protection Board of India.

14.International users and transfers

Weavr is operated from India and its infrastructure is not confined to any one country. In particular:

  • Our backend service runs in the United States (Render, Oregon region).
  • Our database, authentication and file storage run on Supabase in the region ap-northeast-1 (Tokyo, Japan).
  • Our AI and lookup providers process data on their own global infrastructure.

If you use Weavr from outside those countries, your personal data will be transferred to and processed in them. Laws there may differ from those in your own country.

Where a transfer requires a legal safeguard, we rely on the mechanisms our providers make available — typically standard contractual clauses incorporated into their data processing terms. Each provider listed in section 5 maintains Standard Contractual Clauses or equivalent transfer mechanisms. See each provider's own privacy policy for details.

15.Additional information for users in the EEA and UK

This section applies if you are in the European Economic Area, the United Kingdom or Switzerland, and supplements the rest of this policy.

Controller

Ryonkai, Uttar Pradesh, India, contactable at ryonkai.devs@gmail.com, is the controller of your personal data.

Legal bases

The table in section 3 sets out the basis for each purpose. In summary, we rely on:

  • Performance of a contract — for everything needed to give you the service you signed up for: your account, storing and processing your saves, search, Spaces, and synchronisation.
  • Legitimate interests — for security, abuse prevention, debugging, fair-use limits and capacity management. We have considered these against your rights and consider them proportionate; you may object at any time.
  • Legal obligation — where the law requires us to retain or disclose information.
  • Consent — where we ask for it specifically, such as device permissions you grant.

Your rights

The rights listed in section 12 apply, including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. There is no automated decision-making producing legal or similarly significant effects on you. AI classification of your saved content organises your library; it does not make decisions about you.

Data Protection Officer and representative

We have not appointed a Data Protection Officer. Ryonkai does not currently maintain a formal EU/UK Article 27 representative. Privacy enquiries from EEA or UK users should be directed to ryonkai.devs@gmail.com. Privacy enquiries should be directed to ryonkai.devs@gmail.com.

Complaints

You may lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office; in the EEA, the authority for your country of residence, place of work, or where the alleged infringement occurred. We would appreciate the chance to address your concern first.

16.Children's privacy

Weavr is a general-audience product intended for adults. It is not designed for, directed to, or marketed to children, and it contains no features aimed at children.

You must be at least 13 years old to create a Weavr account. Where local law sets a higher age for consenting to data processing, that higher age applies.

We do not knowingly collect personal data from children below the applicable age. If we learn that we have, we will delete the account and its data promptly. If you believe a child has created an account, contact ryonkai.devs@gmail.com and we will act on it.

We do not claim COPPA compliance, because Weavr is not directed to children under 13 and we do not knowingly collect their data.

17.Security

We implement reasonable technical and organisational safeguards designed to protect your information. In practice that means:

  • Encrypted transport — all communication between the app, our backend and our providers uses HTTPS/TLS.
  • Encryption at rest — provided by our managed database and storage platforms.
  • Authenticated access — every API request is authenticated with a short-lived, cryptographically signed session token issued by our authentication provider.
  • Server-side authorisation — every request is checked against the authenticated user's own identity on the server. Access to a Space is checked against membership, and access to a save against ownership or Space membership, on every request. The client is never trusted to assert what it may read.
  • Credential handling — passwords are handled by our authentication provider and are never stored by Weavr. Service credentials are held as environment configuration, never in our source code.
  • Least-privilege storage on device — local data lives in the app's private, sandboxed storage.
  • Ephemeral processing — media downloaded for processing is written to scratch storage and deleted when the job ends.
  • Monitoring — we monitor service health and error rates, and review logs when something fails.

Please also note the two limitations stated plainly elsewhere in this policy: uploaded images are stored at unlisted but publicly reachable URLs (section 8), and an already-issued session token remains valid until it expires (section 10).

No method of transmission over the internet, or method of electronic storage, is completely secure. We cannot guarantee absolute security, and we make no such guarantee. You also play a part: use a strong, unique password and keep your device secure.

18.Security incidents

If we become aware of a security incident affecting personal data, we will investigate, take steps to contain and remediate it, and assess what data and which users are affected.

Where required by applicable law, we will notify the relevant supervisory authority and affected users, within the timeframes that law prescribes. Notice to users will describe, as far as we know it, what happened, what data was involved, what we are doing about it, and what you can do.

We will not promise a fixed notification time here, because the applicable deadline depends on the law that applies to you and on when an incident is confirmed.

To report a suspected vulnerability or incident, email ryonkai.devs@gmail.com.

19.Business transfers

If Weavr is involved in a merger, acquisition, financing, reorganisation, bankruptcy, receivership, sale of assets, or transition of service to another provider, your information may be transferred as part of that transaction.

We will require any acquirer or successor to continue to handle personal data in a manner consistent with this policy, or to give you notice and, where the law requires it, a choice before your information becomes subject to a materially different policy.

21.Changes to this policy

We may update this policy as Weavr changes — for example if we add a feature, change a provider, or move to a different AI service tier. When we do, we will update the “Last updated” date at the top and increment the version number.

For material changes — a new category of data, a new purpose, a new recipient, or a change in how AI providers may use your content — we will give notice before the change takes effect, by in-app notice or by email to the address on your account, and where the law requires it we will ask for your consent.

Continuing to use Weavr after a change takes effect means you accept the updated policy, except where applicable law requires your explicit consent instead. If you do not agree with a change, you can delete your account (section 10).

Earlier versions are available on request from ryonkai.devs@gmail.com.

22.Contact us

Privacy questions and requests
ryonkai.devs@gmail.com
Legal entity
Ryonkai
Registered address
Uttar Pradesh, India
Grievance contact (India)
Grievance Officer, Ryonkai
ryonkai.devs@gmail.com

To request account deletion without using the app, email ryonkai.devs@gmail.com from the address on your account. See section 10 for what deletion covers.