Who we are
Crypt'd Studios builds local-first applications. HYSM is the holding company and is not the public product brand. Optional network features today run through a service we operate at apps.hysm.org.
This policy covers the Crypt'd website and Crypt'd mobile applications we publish now or later, unless a later app posts a superseding notice. Android is shipping first. iOS is in scope of this policy if and when we publish there.
Privacy and support: support@cryptdstudios.com
1. Core principles
- No account required to do the work. We do not make a login the price of the core feature. We do not track you across apps or sites, do not build a marketing profile, and do not ship advertising SDKs or third-party behavioral analytics.
- Local first. Notes, plans, recordings, transcripts, imports, and settings live on the device. Unless you start a named network action, that content does not leave the device.
- Network is a tap. If something leaves, you can name the button in one sentence.
- Minimum payload. We send the smallest artifact that makes the action work. Text instead of a whole file when text is enough.
- No sale. We do not sell personal information and do not share it for cross-context behavioral advertising.
- No Crypt'd model training on your work. We do not use your content to train a Crypt'd model. We select vendor tiers whose contracts, as we understand them, forbid using that traffic to train the vendor’s public models. Vendor monitoring windows still apply and are named below.
- These pages do not spy. The studio site is static HTML. No cookies. No analytics script.
2. Information we handle
On the device
Typical local store — exact items are in the app notes:
- Content you type, import, record, or generate.
- Files the app copies for your use.
- Preferences.
- Secrets you supply (API keys) in platform-backed storage, not in the APK.
- A device-generated identifier if that app talks to our proxy, used to enforce quotas or entitlements — not to stitch an advertising profile.
Where the OS allows it, we turn off automatic cloud backup of sensitive app data so a platform backup does not quietly copy a recording or a private file into another company’s cloud.
Handled by our proxy (apps.hysm.org)
- Quota and subscription checks. An anonymous device identifier and monthly usage counts, so a free tier cannot be reset by reinstalling and so a paid entitlement can be honored.
- What we do not need to run the apps: username, email, or government ID.
- Website server logs. IP address, user-agent, timestamp — for upkeep, security, and rate limits. Not for ads.
- Support mail. If you write us, we receive the address and the message so we can answer.
- Crash reports. Stored on the device. Sent only if you tap Send Report. (If a build has no such button yet, nothing is sent.)
3. When you tap an AI action
Offline features keep working on whatever is already stored. If you never tap Extract, Ask, Transcribe, Summarize, or a later named action, we do not receive your content.
When you do tap, the device talks to our proxy over HTTPS. The proxy authenticates the app, checks quota, and forwards the submitted text or media to the processor named for that action. It returns the result to the device. We sit in the middle so vendor keys are not baked into a public APK, and so one app is not hardcoded to one raw vendor URL.
DueNext Extract/Ask send text, not the PDF file. A future speech feature may send audio because audio is the work. App notes say which.
Processors we may use, and what their public terms say as of this draft:
| Provider | Purpose | Vendor retention (as represented to us) |
|---|---|---|
| xAI (Grok family) | Extract, ask, summarize | Zero Data Retention on the enterprise path we intend: processed to answer, then discarded. Confirm the exact SKU per build. |
| OpenAI (Whisper / transcription models) | Speech to text, if that tap exists in the build | Zero Data Retention on the enterprise path we intend. Confirm the exact SKU per build. |
| Google (Gemini family) | Summarize or extract, if that tap exists in the build | Not zero retention. Prompts may be kept up to 55 days for abuse and safety monitoring, then deleted. Not used for model training under the tier we would buy. We will not silently route a user to this path. |
Shipped DueNext today: device → apps.hysm.org → xAI. Family ClassReplay builds may still use an on-device key; Settings will say so until those builds move to the proxy.
Ordinary hosting, DNS, and TLS vendors may see IP addresses and connection metadata. We do not grant processors a right to advertise to you from that traffic.
4. Payments
If we sell a subscription, billing runs through Apple App Store or Google Play. We do not collect card numbers, bank accounts, or billing addresses. Store receipts may be checked locally or through official store APIs so we can honor an entitlement.
5. Permissions
Each app asks only for what a feature needs (microphone to record, a picker to open a file you choose, notifications if you opt in). Refusing a permission turns that feature off. The rest should still work on data already on the device.
6. Retention, deletion, export, and loss
On the device. You hold the store. Use the in-app delete control, then uninstall if you want the app gone. Export only what you mean to let out.
On our proxy. Request bodies are kept only long enough to finish the job and debug a failure you report. Quota rows (device id, timestamps, counts) may last longer so free tiers cannot be reset by reinstalling. Write support with the device id shown in Settings if you want those rows removed. Counsel should lock a numeric window before a store listing ships.
Loss is yours. We do not keep a spare copy of your planner, recordings, or files that we can restore onto a new phone. Uninstall, Delete all, a wiped device, or a refused platform backup can make that content gone. That loss is on the user of the app, not on Crypt'd. Make your own export if you need a spare.
7. Children and other people’s voices
Apps are aimed at adults and at families helping college-age students. They are not directed at children under 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If that happens through a network action, tell us and we will delete server rows we can find.
A file or recording can contain other people. You are responsible for having the right to process that material. Some places require all-party consent to record. Many schools restrict recording without permission. Crypt'd is not a school’s FERPA official.
8. EEA and UK
Legal basis. Device quota identifiers and server logs: legitimate interests in running a service that is not abused, and in answering mail you send. AI transmission: your direction when you tap the action.
Rights. Access, rectification, deletion, objection, restriction. Because we do not keep accounts, verifying a quota row may require the anonymous device id from Settings.
Transfers. Processors may handle data in the United States under standard contractual clauses or an equivalent framework. You may lodge a complaint with your local authority.
10. California
We do not sell personal information and do not share it for cross-context behavioral advertising.
In the prior 12 months we may collect standard network activity (server logs) and a unique device identifier for quota. California residents may request to know or delete that server data, subject to legal exceptions. We will not discriminate for asking.
11. Security
HTTPS to our proxy. Vendor keys for public builds live on our side of that proxy, not in the APK. Bring-your-own-key builds keep those keys in the platform keystore. No transmission is perfect. Do not paste secrets into a title field.
12. Changes
When we add an app, a payment rail, a processor, or a new kind of data that leaves the device, we update this page and the date. New apps inherit the studio rules. Differences appear as a labeled note — not as a silent change.
13. App notes
If a note conflicts with a studio rule, the note wins for that app and version, and we will say so.
DueNext · com.cryptd.duenext
Planner
On the phone: terms, courses, tasks, study suggestions, extracted text, and any local copy of a file you import.
What leaves, only if you tap: Extract sends text (not the original PDF), a device id, and a year/term hint to apps.hysm.org. Ask sends your question plus a short excerpt. Quota check sends the device id. The proxy calls xAI and returns the result.
Delete: Settings → Delete all local data. Uninstall removes the rest.
ClassReplay · com.cryptd.classreplay
Recorder
On the phone: audio, transcripts, summaries, titles, labels, timestamps, and any keys you paste.
What leaves, only if you tap: Family builds may still send Transcribe audio and Summarize text with a key on the device. Public builds are expected to follow the proxy path. Export leaves only if you share the file. Recording and playback of what is already stored still work offline.
Delete: Settings → Delete all lectures. Clearing keys is separate.
Rooms: ask before you record. A summary is not harmless if it quotes people who did not agree.
14. Apps not shipped yet
A future Crypt'd app is covered by the studio rules the day it ships under this name or the com.cryptd root.
We will add a note: what lives on the device, which tap sends what, where it goes, and where Delete lives.
Until that note exists, assume nothing leaves unless the in-app copy says it does.
The next app does not have to be a planner or a recorder.
15. Contact
Crypt'd Studios
Austin, Texas, United States
support@cryptdstudios.com