Legal
Privacy Policy
Effective 18 August 2026
1. Who we are
Islet (the “app”, “we”, “us”) is operated by samko labs, s. r. o., registered at Trnková 451/12, 040 14 Košice - mestská časť Košická Nová Ves, Slovakia, company registration number (IČO) 53928881, VAT number (DIČ) 2121532600.
We are the data controller for the personal data described in this policy. You can reach us at [email protected] for any privacy question or to exercise the rights described in section 9.
2. What we collect
Account data
When you first open Islet, we create an anonymous account so the app works before you sign up. That account holds only a generated identifier and an authentication token stored on your device.
If you sign in, we additionally store:
- Email address — if you sign in with an email one-time code. We also store the codes themselves briefly so they can be verified.
- Apple account identifier, and your name and email address if you choose to share them — if you use Sign in with Apple. Apple provides your name only on the first authorization. We also keep an Apple refresh token so we can verify and, on request, revoke the connection.
- Web account credentials — if you use the web app: a hashed password, and, if you enable them, two-factor authentication secrets, recovery codes and registered passkeys.
Signing in with an anonymous account in place upgrades that account rather than creating a new one, so the content you already made is preserved.
Content you give us
- Documents you upload — the file itself, its filename, type and size, plus the text extracted from it, which we split into passages and store together with numeric representations (embeddings) used to find the relevant passage.
- Text you share for a suggestion — the message or passage you send from the iOS share sheet, and the suggestion generated in response.
- Your instructions and preferences — the tone and custom instructions you set for how Islet should reply.
Technical data
Our servers record standard request logs — IP address, device and app version, and timestamps — which we use to operate the service, debug failures and detect abuse.
Islet displays no advertising inside the app. It does, however, include software from Meta and from RevenueCat that collects data about your use of the app, which is described in the next two subsections and in section 4.
Subscription data
Subscriptions are billed by Apple and managed on our side by RevenueCat. RevenueCat receives your Islet account identifier, the purchase and renewal history of your subscription, and device and app identifiers generated by its own software. We never receive your payment details.
Advertising and measurement data
We run acquisition campaigns on Meta and TikTok, and we need to know which of them lead to an install or a subscription. The Meta SDK in the app collects, and sends to Meta:
- app events — that the app was launched, that it was opened for the first time, and similar product interaction events;
- an anonymous identifier that Meta generates for your installation of the app;
- device and app information such as the device model, operating system version and app version;
- the advertising identifier (IDFA) assigned to your device by iOS — only if you allow tracking when iOS asks you.
We do not send your email address, your documents, your questions or the answers to Meta, to TikTok or to any other advertising network.
3. How we use it
- To provide the service: authenticating you, storing your documents and generating reply suggestions.
- To keep your account secure and to prevent abuse of the service, including rate limiting.
- To send you transactional messages such as sign-in codes and account notices.
- To manage your subscription and check whether it is active.
- To fix problems and improve reliability.
- To measure how well our advertising works and how the app is used, as described in section 4.
We do not sell your personal data. Your content — the documents you upload, the text you share, your questions and the answers — is never used for advertising, and never used to train AI models, neither ours nor our providers'.
4. Advertising and measurement
Islet shows you no ads. We do advertise Islet elsewhere, on Meta (Facebook and Instagram) and on TikTok, and the app includes the Meta SDK so that installs and subscriptions can be attributed to the campaign that produced them. That is measurement of our own advertising, and Apple counts it as tracking.
The App Tracking Transparency prompt
Shortly after you first open the app, iOS asks whether Islet may track you across apps and websites owned by other companies. That prompt is your consent, and nothing happens before you answer it.
- If you allow it, the Meta SDK may read your device's advertising identifier (IDFA) and send it to Meta with the app events listed in section 2, so a subscription can be matched to an ad you saw.
- If you decline, the advertising identifier is not read and not sent. App events and Meta's own anonymous install identifier are still sent, but without the cross-app identifier that would link them to your activity in other apps. The app itself works exactly the same either way — nothing is withheld, and no feature depends on your answer.
You can change your answer at any time in Settings → Privacy & Security → Tracking on your device, or turn tracking off for every app there. Withdrawing permission stops the advertising identifier being collected from that point on; it does not undo measurement that already happened.
Profiling
We do not build advertising profiles ourselves and we make no automated decisions about you that have legal or similarly significant effects. Meta may combine what it receives with data it holds about you, as its own controller, under Meta's privacy policy.
5. Legal basis (GDPR)
- Performance of a contract (Art. 6(1)(b)) — for everything needed to give you the service you asked for: your account, your documents, the suggestions you request, and managing your subscription.
- Legitimate interests (Art. 6(1)(f)) — for security, abuse prevention and service reliability.
- Legal obligation (Art. 6(1)(c)) — for accounting and tax records relating to purchases.
- Consent (Art. 6(1)(a)) — for the advertising and measurement described in section 4. Your answer to the App Tracking Transparency prompt is that consent; we do not rely on legitimate interests for advertising. You may withdraw it at any time in your device settings, and withdrawal does not affect processing that already took place.
6. Who we share it with
We share data with the providers we need to run and to advertise the service. All of them are bound by a contract with us; all except Meta process the data only on our instructions, which is noted where it applies:
- AI providers — OpenAI, OpenRouter, Google, Anthropic and Mistral. The text you share, the relevant passages from your documents and your instructions are sent to one of these providers to generate a suggestion. They process it to return the result and do not use it to train their models.
- Apple — for Sign in with Apple, and for App Store purchases. Payments are handled entirely by Apple; we never see your payment details, only whether a subscription is active.
- Our hosting and infrastructure provider — which stores the database and uploaded files on our behalf.
- Our email delivery provider — for sign-in codes and account emails.
- RevenueCat — which manages subscriptions on our behalf. It receives your Islet account identifier, your purchase and renewal history and device identifiers, and tells the app whether your subscription is active.
- Meta Platforms — which receives the app events, install identifier and, with your permission, the advertising identifier described in section 4, so that our advertising can be measured. Unlike the providers above, Meta is not acting only on our instructions: it is an independent controller for what it receives and also uses it for its own purposes.
We may also disclose data where we are legally required to, or where necessary to establish or defend legal claims.
7. International transfers
Some of the providers above process data outside the European Economic Area, primarily in the United States. Those transfers are covered by the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism.
8. How long we keep it
- Account data — until you delete your account.
- Documents and their indexed passages — until you delete the document. Deleting a document removes its extracted passages and embeddings in the same operation.
- Sign-in codes — minutes; they expire shortly after being issued.
- Server logs — a rolling short retention window, kept only for debugging and security.
- Accounting records — for the period required by Slovak law.
- Purchase records held by RevenueCat — for as long as we use RevenueCat to manage subscriptions, since a purchase must remain restorable and the record supports the accounting obligation above. Deleting your Islet account does not by itself delete it there; write to us and we will have it deleted.
- Advertising and measurement data — held by Meta under its own retention rules, which we do not control. We keep no copy of it ourselves.
Deleting your account removes your profile, documents and indexed passages from our systems. Backups are overwritten on their normal rotation.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy of it;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to certain processing;
- receive your data in a portable, machine-readable format;
- withdraw consent, where processing is based on it.
The quickest way to exercise the last of these is the tracking switch in your device settings, described in section 4: turning it off withdraws your consent to the advertising identifier being collected, with no need to contact us.
You can delete your account and its data directly in the app. For anything else, write to [email protected] and we will respond within one month.
If you believe we have handled your data improperly, you may lodge a complaint with the Slovak supervisory authority, the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava), or with the authority in your country of residence.
10. Security
Data is encrypted in transit. Authentication tokens are stored in the iOS Keychain on your device and are never written to shared storage. Every query against your documents is scoped to your account at the database level, so one account's content cannot surface in another's answers. No system is perfectly secure, but we take these measures seriously and will notify you and the supervisory authority of a breach as required by law.
11. Children
Islet is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We will update this page when our processing changes, and revise the effective date above. For material changes we will notify you in the app or by email before they take effect.
13. Contact
samko labs, s. r. o.
Trnková 451/12, 040 14 Košice - mestská časť Košická Nová Ves, Slovakia
[email protected]