Legal

Privacy Policy

Effective: June 30, 2026 · Last updated: June 30, 2026

Controller: Shyngys Tursynkhan, an individual

Summary

This summary is not a substitute for the full policy below. The full text controls.

  • We collect your email address (via Google OAuth) to create and secure your account.
  • We process the book files you upload and the AI-generated passages and images derived from them so you can use the Service.
  • We collect typing and behavioral data (keystrokes, speed, accuracy, progress) to run the typing experience and track your learning.
  • We record achievements and progress tied to your account.
  • We measure usage with PostHog, a cookieless, EU-hosted analytics tool. It does not set tracking cookies, does not fingerprint your device, and is never used for advertising.
  • One AI text model we use, DeepSeek, is based in China. We send it only public-domain, openly licensed, or TypeCram-original book text. We never send it your private uploads and never send it your personal data.
  • We do not sell or share your personal information for cross-context behavioral advertising.
  • Books you upload are processed for you alone. They are never made public automatically, and the original file is deleted after processing.
  • You have rights to access, correct, delete, and export your data.

1. Who We Are

TypeCram is a typing-based reading and learning tool. We turn public-domain books and books you upload into short passages that you type to read and absorb. References to "TypeCram," "we," "us," and "our" mean the legal entity listed below.

Controller / BusinessShyngys Tursynkhan, an individual
Registered addressOskemen, East Kazakhstan Region, Kazakhstan (full mailing address available on request by email)
Privacy contact emailhello@typecram.com
Data Protection OfficerNot appointed
EU representative (GDPR Art. 27)Not applicable at this time
UK representative (UK GDPR Art. 27)Not applicable at this time

2. Information We Collect

2.1 Information you provide

  • Account. Your email address, name, and profile picture from Google OAuth when you sign in.
  • Profile. A display name and username you choose.
  • Uploaded books. The book or document files you choose to upload for private processing.
  • Communications. Any message you send to our support or feedback channels.
  • Payment. Page pack purchases are processed entirely by Dodo Payments (our Merchant of Record). We receive only a confirmation of payment and the product purchased, not your card or bank details.

2.2 Information generated by the Service

  • Derived content. AI-generated passages, summaries, and scene images created from your uploads or from public-domain titles, linked to your account.
  • Typing data. Your keystrokes, typing speed, accuracy rates, combo counts, and session durations recorded during each reading session.
  • Progress records. Your level completions, streak data, and reading history.
  • Achievements. Badges and titles earned within the Service.

2.3 Information collected automatically

  • Usage analytics. Page views, feature interactions, session lengths, and referral sources, collected by PostHog in cookieless mode. No fingerprinting. No advertising identifiers.
  • Technical information. Browser type, device category, operating system, and approximate country (from IP, not stored in granular form).
  • Server logs. Standard web server logs (IP address, request path, timestamp, HTTP status code) retained for security and operational purposes.

We do not intentionally collect sensitive personal data (health, financial, racial or ethnic origin, political opinions, religious beliefs, biometric data, or sexual orientation). Please do not include such data in any uploads or support communications.

3. How and Why We Use Your Information

3.1 To provide the Service

We use your account data, uploaded content, derived content, and typing data to run the core typing experience, track your progress, deliver your reading library, and maintain your account.

3.2 To process content through our AI pipeline

When you import a book, we transmit the text to our AI processing pipeline to generate condensed passages and scene images. Public-domain and openly licensed titles may pass through DeepSeek (a China-based model) for text processing. Your private uploads are processed only through services hosted in regions you consent to below. Your personal data is never sent to any AI model as part of this pipeline.

3.3 To operate, maintain, and improve

We use aggregated, anonymized analytics to understand how people use the Service, detect bugs, and prioritize improvements.

3.4 To communicate with you

We use your email to send transactional messages (account confirmations, purchase receipts, security notices). We do not send marketing emails unless you opt in separately.

3.5 For security and legal compliance

We use data to detect and prevent fraud, abuse, and unauthorized access; to comply with legal obligations; and to enforce our Terms of Service.

3.6 Content visibility model

Books you upload are private by default and are never placed on public surfaces of the Service without your explicit action. Content on public surfaces of TypeCram is limited to public-domain, openly licensed (CC-BY/CC0), or TypeCram-original material.

3.7 No profiling on book topics

We do not build profiles about your reading interests or inferences derived from the topics of books you read or upload. Your reading content is not used to serve advertising.

3.8 Automated decision-making

We use automated processing to calculate your typing speed, accuracy, level progress, and achievements. These calculations affect your in-app experience. You may contact us to request a manual review of any automated outcome that significantly affects you. We do not use automated processing for decisions about your legal rights or for producing legal or similarly significant effects outside the Service.

4. Sub-Processors and Data Sharing

We share your data only with the sub-processors below, and only to the extent necessary to operate the Service.

Sub-processorRoleData sentLocation
SupabaseDatabase, auth, storageAccount data, typing data, progress, derived contentSupabase's managed cloud; specific region available on request
Fal.aiAI image generationBook passage text (public-domain and openly licensed only) to generate scene imagesFal's managed cloud; specific region available on request
DeepSeekAI text processingBook text (public-domain, openly licensed, and TypeCram-original only). Never private uploads, never personal data.China (PRC)
PostHogAnalyticsAnonymised usage events, no personal identifiersEU (Frankfurt)
Dodo PaymentsMerchant of Record / payment processingPurchase confirmation; payment card data stays with Dodo onlyGlobal (Dodo)
Email providerTransactional emailYour email address and name for delivery of account and purchase notificationsSupabase Auth's built-in email service (account emails only)

4.2 Other disclosures

  • Legal requirement. We may disclose data if required by a valid court order, subpoena, or applicable law, and where legally permitted we will notify you first.
  • Business transfer. If TypeCram is acquired or its assets transferred, your data may be part of that transfer under the same or stricter protections. We will notify you before transfer and give you the option to request deletion.
  • With your consent. For any other purpose, only with your explicit consent.

5. International Data Transfers

TypeCram is operated from Kazakhstan. Your data may be transferred to and processed in countries outside your own, including countries whose data protection laws may differ from yours.

  • PostHog analytics stays within the EU (Frankfurt), so usage data does not leave the EEA.
  • DeepSeek is based in China. We mitigate the risk by ensuring it never receives personal data or private uploads, only public-domain text. We rely on the GDPR Article 49 derogations for occasional transfers for these transfers.
  • For all other sub-processors, we use Standard Contractual Clauses (SCCs) where required and, for UK data transfers, the International Data Transfer Agreement (IDTA) or UK Addendum to the SCCs.

6. Cookies and Analytics

We use only cookies that are strictly necessary to operate the Service (your authenticated session). We do not use advertising or tracking cookies.

For analytics, we use PostHog in cookieless mode. PostHog collects: anonymised events (page views, feature interactions), session duration, referral source, browser type, device category, and approximate country derived from IP (not stored). PostHog does not set tracking cookies, does not fingerprint your device, does not use advertising identifiers, and is never used for targeted advertising. Data stays on EU-hosted servers.

You can opt out of analytics entirely by enabling the "Do Not Track" signal in your browser. We honor DNT signals.

7. Legal Bases for Processing (GDPR / UK GDPR)

If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases:

PurposeLegal basis
Creating and managing your accountContract (Art. 6(1)(b))
Providing the typing and reading experienceContract (Art. 6(1)(b))
Processing book imports through the AI pipelineContract (Art. 6(1)(b))
Sending transactional emails (purchase receipts, security notices)Contract (Art. 6(1)(b))
Processing paymentsContract (Art. 6(1)(b)), via Dodo Payments as Merchant of Record
Improving and securing the Service (analytics, logs)Legitimate interests (Art. 6(1)(f)): we have assessed that our interest in operating a safe, improving service does not override your interests
Complying with legal obligationsLegal obligation (Art. 6(1)(c))

8. Your Privacy Rights

8.1 GDPR / UK GDPR rights (EEA and UK residents)

  • Access. Request a copy of the personal data we hold about you.
  • Rectification. Ask us to correct inaccurate or incomplete data.
  • Erasure. Ask us to delete your personal data, subject to legal retention obligations.
  • Portability. Receive your data in a machine-readable format and transfer it to another provider.
  • Restriction. Ask us to limit how we process your data while a dispute is resolved.
  • Objection. Object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds that override your interests.
  • Withdraw consent. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
  • Lodge a complaint. You have the right to lodge a complaint with your local data protection authority. In the EU, the lead supervisory authority is the data protection authority of the EU country where you are based (TypeCram has no EU establishment). In the UK, contact the ICO at ico.org.uk.

8.2 CCPA rights (California residents)

  • Know. Request the categories and specific pieces of personal information we collected about you, the sources, the business purposes, and the categories of third parties we share it with.
  • Delete. Request deletion of personal information we collected from you, subject to exceptions.
  • Correct. Request correction of inaccurate personal information.
  • Opt out of sale/sharing. We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is required, but you may contact us to confirm.
  • Non-discrimination. We will not discriminate against you for exercising any CCPA right.

8.3 Other US state rights

Residents of Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws have similar rights to access, correct, delete, and port personal data, and to opt out of targeted advertising (which we do not conduct). We respond to these requests using the same process as CCPA.

8.4 How to exercise your rights

Email us at hello@typecram.com with the subject line "Privacy Request." Include your name and the email address associated with your account. We will respond within 30 days (GDPR) or 45 days (CCPA), and may request identity verification before processing your request.

You may also delete your account directly from your account settings at any time. Deleting your account triggers deletion of your personal data per the retention schedule in Section 10.

9. California CCPA Disclosures

In the past 12 months, we have collected the following categories of personal information from California consumers:

CategoryCollected?Sold or shared?
Identifiers (name, email, user ID)YesNo
Internet / network activity (usage events, log data)YesNo
Commercial information (purchase history)Yes (via Dodo Payments)No
Inferences drawn from personal informationYes: typing speed, progress, achievementsNo
Geolocation (precise)NoN/A
Financial information (card numbers, bank accounts)No (Dodo Payments handles this)N/A
Biometric or health informationNoN/A
Sensitive personal informationNoN/A

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

10. Data Retention

Account data (name, email, profile)Until you delete your account, then deleted within 30 days
Typing data, progress, achievementsUntil you delete your account, then deleted within 30 days
Uploaded book files (originals)Deleted immediately after the import pipeline finishes processing
AI-derived content (passages, images)Until you delete the title or your account, then deleted within 30 days
Purchase records7 years for tax and accounting compliance
Server and security logs90 days
Analytics events (PostHog)Anonymised, not subject to individual deletion. Retained per PostHog's standard schedule.

Where we are required by law to retain data longer (for example, financial records), we apply strict access controls and retain only what is necessary.

11. Security

We use industry-standard security measures including encrypted connections (TLS), hashed credentials, row-level security on our database, and access controls scoped by role. Payments are handled entirely by Dodo Payments and never touch our systems in raw form.

No method of electronic transmission or storage is 100% secure. If we become aware of a data breach that is likely to result in high risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.

12. Children

TypeCram is not intended for children under 13. We do not knowingly collect personal information from children under 13 years of age. If you believe a child under 13 has provided us personal information, please contact us immediately and we will delete it.

The minimum age to use the Service is 16 (or the minimum age of digital consent in your country if higher). Users between 13 and 15 may use the Service only with verifiable parental consent.

13. Contact Us

For privacy requests, questions, or complaints:

Emailhello@typecram.com
Mailing addressOskemen, East Kazakhstan Region, Kazakhstan (full mailing address available on request by email)
Response timeWe aim to respond within 5 business days and will resolve requests within 30 days (GDPR) / 45 days (CCPA).

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top and notify you by email or prominent in-app notice before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

We will not retroactively change the policy in ways that significantly reduce your rights over data we have already collected without your consent.

15. Note on Uploaded Books

When you upload a book to TypeCram, that file is transmitted over an encrypted connection to our servers, passed through our AI pipeline to generate condensed passages and scene images, and then the original file is permanently deleted. Only the derived passages and images remain, stored privately to your account.

We do not read your private uploads for any purpose other than generating the derived content. We do not share the content of your uploads with any third party other than the processing sub-processors listed in Section 4, and only to the extent necessary to produce your derived content. The content of private uploads is never used to train AI models.

Public-domain books that appear on the shared library surfaces of TypeCram are sourced from publicly available texts (Project Gutenberg and similar) and are not linked to any individual user's upload.