Intashyo Privacy Policy
Effective date: October 1, 2026
This Privacy Policy explains how the Intashyo iOS app ("Intashyo," "we," "our," or "the app") handles your information. We built Intashyo to help immigrants and refugees in the United States find resources in their own language, and we collect as little data as possible to do that.
On this page
- Summary
- What stays on your device
- Optional account (Sign in with Apple or Google)
- Subscriptions and payments
- AI Chat — what it is and what gets sent
- Voice features — dictation and spoken replies
- Scan a letter
- Service providers — who else handles your data
- Network requests
- Permissions
- This website
- Children and minors
- Changes to this policy
- Contact
Summary
- We do not require an account. You can use the app without signing up. Signing in (with Apple or Google) is optional.
- We do not show ads or use trackers or analytics.
- Your saved resources and the name you type stay on your device. They are stored in iOS UserDefaults and are not sent to us.
- Your city is sent with each AI Chat and Scan request so the answer fits your situation. It is used only to generate that answer and is not stored with your identity (see "AI Chat" and "Scan a letter" below).
- If you choose to sign in, our server stores a small account record: a unique account ID, your name and email address (if your Apple or Google account shares them), and the city and language you set in the app. You can delete it in the app at any time; for Sign in with Apple, deleting your account also revokes the app's access to your Apple ID.
- Messages you send to the AI Chat are forwarded to Google's Gemini API through a server we operate (a Cloudflare Worker) so that Gemini can respond. We keep no record of your conversation on our server (your recent chat is saved only on your phone); we do cache the answers to common first questions for up to 30 days (see "AI Chat" below). Google does not use these requests to train its models, but keeps them for up to 55 days to detect abuse (see "Service providers").
- If you use the voice features, your recording is sent through our server to a speech service (ElevenLabs or Pindo) to turn speech into text, and the assistant's reply text is sent to the same services to produce spoken audio (which may be cached for up to 30 days). Voice is always optional — you can type instead. See "Voice features" and "Service providers" below.
- If you scan a letter, the photo is read on your device and never leaves it. Only the text found on the page is sent through our server to Gemini to be explained in your language, and our server does not store the letter — the one exception is audio you choose to hear, see "Scan a letter" below. (Google keeps API requests for up to 55 days to detect abuse.)
- If you let the app use your location during onboarding, it is used once to find your city name. Your coordinates are never sent to our server and the app never tracks you — see "Permissions" below.
- AI responses are generated by a language model and may be wrong. Always verify important information with a licensed professional or official source.
- The optional subscription is billed by Apple, not by us. We never see or store your card number or billing details — see "Subscriptions and payments" below.
- We do not sell your data.
- We do not track you across other apps or websites.
What stays on your device
When you onboard or use the app, you enter the following information. It is stored locally on your device (in iOS UserDefaults):
- Your name (as you enter it)
- Your city
- Your selected language (Kinyarwanda, French, Swahili, or English)
- Which resources you have bookmarked
During onboarding you can optionally let the app use your location once to fill in your city for you — see "Permissions" below. Only the resulting city name is kept; your coordinates are never stored and never sent to our server.
Your bookmarks and the name you type are never sent to us. Your city and language are sent along with each AI Chat or Scan request (see those sections below) so the answer fits your situation; they are not stored on our server with your identity. If you sign in, your city and language are also saved in your account record (see "Optional account").
Deleting the app from your device removes all of this information. Sign-in tokens kept in the iOS Keychain are also cleared the first time a reinstalled app is opened, so a reinstalled app starts signed out.
Optional account (Sign in with Apple or Google)
You can optionally sign in with Sign in with Apple or Google Sign-In. Signing in is never required — every feature of the app works without an account.
If you sign in, the following is sent to and stored on our server (a Cloudflare Worker with a database, both operated by us on Cloudflare's platform):
- A unique account ID derived from your Apple or Google identity token
- Your name, if your Apple or Google account shares it
- Your email address, if your Apple or Google account shares it (with Sign in with Apple you can choose to hide it)
- Your city and preferred language, if you provided them in the app
If you use Sign in with Apple, our server also keeps the token Apple issues for your sign-in, only so that it can revoke the app's access when you delete your account.
We use this only to recognize your account across sign-ins. We do not use it for marketing, we do not sell it, and we do not share it with anyone. Sign-in credentials (session tokens) are stored on your device in the iOS Keychain; our server keeps a record of each active session (its expiry and the app's user-agent string, e.g. app version and iOS version) so it can be signed out. Signing out or deleting your account removes them, and they are cleared automatically the first time the app is opened after being deleted and reinstalled.
Deleting your account: Open Profile → Delete account. This permanently removes your account record from our server and, for Sign in with Apple, revokes the app's access to your Apple ID (it disappears from "Apps Using Apple ID" in your iPhone settings). Deleting your account also clears your name, city, saved places and chat from this phone. You can also email us (address below) and we will delete it for you.
Subscriptions and payments
The resource directory and emergency numbers are free. The AI features (chat, letter scanning, and voice) are free for your first 30 days of using the app; after that they require a monthly subscription. The exact price in your local currency is always shown in the App Store before you confirm.
The free month needs nothing from you. You do not sign up, enter a payment method, or cancel anything — the AI features simply work for 30 days from when you first use the app. When the free month ends, the AI features ask whether you'd like to subscribe; nothing is ever charged unless you choose to subscribe through Apple. The directory and emergency numbers stay free forever.
Apple handles all payment. Subscribing happens through Apple's In-App Purchase system, using the payment method on your Apple Account. We never see, collect, or store your card number, bank details, or billing address. Apple's handling of your payment information is governed by Apple's privacy policy (https://www.apple.com/legal/privacy/).
What we learn: only whether the subscription is active, so the app knows what to unlock. This comes from Apple as an anonymous entitlement on your device — it does not include your name, your Apple ID, or any payment details, and we do not link it to an account or your identity.
A subscription renews automatically each month until you cancel. Apple shows the price and the renewal terms before you confirm, and sends the billing receipts.
Cancel any time in your device's Settings → your name → Subscriptions (or in the App Store app). Canceling stops all future charges; the subscription keeps working until the end of the period you already paid for. Deleting the app does not cancel a subscription — it must be canceled in Settings.
Refunds are handled by Apple at https://reportaproblem.apple.com, per App Store terms.
AI Chat — what it is and what gets sent
The AI Chat feature uses Google Gemini (a third-party generative AI model from Google) to answer your questions. We host a small server (a Cloudflare Worker) that forwards your messages to Google's Gemini API. We do this so that no API credentials live on your device.
AI responses are generated automatically by a language model. They may be inaccurate, incomplete, or out of date. For anything important — especially legal, medical, or immigration questions — verify what the AI tells you with a licensed professional or the relevant agency before acting on it.
When you send a message in AI Chat, the following information leaves your device:
- The chat message you typed (or spoke, if you used voice)
- The recent message history of the current chat (so the assistant can respond in context)
- Your selected language (used to set the response language)
- Your city, if you provided one during onboarding (used to give location-aware responses)
- If you are asking a follow-up question about a scanned letter, the text recognized from that letter, so the assistant knows what the letter says (see "Scan a letter" below); these requests are never cached
Your city is used only to generate the answer; it is not stored with your identity (the anonymous answer cache below is filed under it, never under you). We do not send your name, and we keep no record of your conversation linked to you or your device. Your chat history is saved only on your phone: the last 50 messages, unreadable while the phone is locked and left out of iCloud and computer backups. Starting a new chat erases it, and so does deleting your account.
Answer caching. So that common questions load quickly and reliably, when the first message of a conversation produces an answer, our server may keep that answer (and its spoken-audio version) for up to 30 days, filed under the question text itself together with the city and language it was asked for — never under your identity, account, or device. Someone else asking the same first question in the same city and language may receive the same cached answer. Follow-up messages in a conversation are never cached. If you'd rather a question not be cached, ask it as a follow-up rather than as the first message of a new chat.
Google's handling of Gemini API requests is governed by Google's Privacy Policy (https://policies.google.com/privacy) and the Gemini API terms (https://ai.google.dev/gemini-api/terms). We use Google's paid API service, so Google does not use our requests to improve its products or train its models; it keeps them for up to 55 days only to detect and prevent abuse.
Safety filters. We configure Gemini to block responses in Google's "sexually explicit" and "dangerous content" categories at the medium-or-above severity level, and in the "harassment" and "hate speech" categories at the high severity level (the lower setting wrongly blocked ordinary Kinyarwanda and Swahili answers about everyday paperwork). If the filter blocks a reply, you'll see a short message with emergency numbers and can try again or rephrase.
Reporting an AI response. Tap and hold any AI message and choose "Report" to email us about a problematic response. We review reports and adjust the system prompt or safety settings as needed.
Your consent, and withdrawing it. The first time you use an AI feature (AI Chat, Scan a letter, a microphone button, or voice mode), the app asks for your permission before anything you type, say or scan is sent. You can withdraw that permission at any time in Profile → Stop sharing with AI; after that, nothing more is sent until you agree again. To also erase what is stored, start a new chat (erases the chat on your phone) or delete your account (erases your account record on our server).
If you do not want to share any data with Google or our speech partners, do not use AI Chat, Scan a letter, the microphone buttons, or the speaker (listen) buttons. All other features (Resources, Emergency, Profile) work without sending any personal data off the device — the listen button on a resource listing sends only that listing's public text to the speech service, and signing in, if you choose to, contacts our server.
Voice features — dictation and spoken replies
Voice is optional everywhere it appears. The microphone is used only while you are actively recording (you tap to start and tap to stop; recordings are capped at 60 seconds), and iOS shows the standard microphone indicator whenever it is on.
Speech to text (dictation and voice chat). When you speak instead of typing, the app records a short audio clip and sends it through our server to a speech-recognition service to turn it into text:
- ElevenLabs (elevenlabs.io) for English, French, and Swahili
- Pindo (pindo.ai) for Kinyarwanda
The clip is deleted from your device as soon as it has been transcribed, and our server does not store it. The speech providers process the audio to produce the transcript; how they handle it is described under "Service providers" below and in their own privacy policies (https://elevenlabs.io/privacy and https://pindo.ai/privacy-policy). We may add or switch speech providers to improve accuracy for our languages (for example, a provider specialized in East African languages); if we do, we will update this policy.
Text to speech (spoken replies). When a reply or a scan summary is read aloud, its text is sent through our server to the same services (ElevenLabs for English/French/Swahili, Pindo for Kinyarwanda) to generate the audio. Because the same reply is often requested many times, the generated audio may be cached on our server for up to 30 days, filed under a fingerprint of the exact text — never under your identity, account, or device. This includes the audio of a scan summary or follow-up answer that you choose to listen to (see "Scan a letter" below).
What our server logs about voice requests: only operational metadata — language, provider, success/failure, duration, and size. Never the audio, never the transcript, never the reply text.
Scan a letter
This feature lets you photograph a piece of mail and read it in your own language.
The photograph never leaves your device. The text on the page is recognized on the phone itself, using Apple's on-device text recognition. No image is uploaded to us or to anyone else, and no image is saved by the app.
What is sent. Only the text recognized on the page, together with your selected language and (if you provided it during onboarding) your city, so the explanation fits your situation. That text goes through our server to Google Gemini, which returns a short summary in your language: what the letter is, its main point, what you need to do and by when, and the key details. The app does not show a full translation of the letter; you can ask questions about any part of it instead (see "Follow-up questions" below). Your name is not sent.
Follow-up questions. If you ask a question about a scanned letter on the scan screen, your question and the letter's recognized text are sent through our server to Gemini, exactly like an AI Chat message. These requests are never cached, and the letter text still isn't stored anywhere.
We don't store your letter. Unlike AI Chat answers, scans are never cached on our server — a letter is unique to you and carries your name, address and case numbers. The scan also is not saved on your phone: when you close the scan screen, the text, the summary and any follow-up answers are gone. Scanning the same letter again produces a fresh result.
If you listen to a scan. Tapping the speaker button sends the summary (or a follow-up answer) to the speech service to be read aloud, like any spoken reply (see "Text to speech" above). The generated audio may be kept on our server for up to 30 days, filed under a fingerprint of that exact text — never under your identity, account, or device — so it can only be found again by someone sending exactly the same text. If you'd rather no audio be kept, read the summary instead of listening to it.
What our server logs about a scan: only operational metadata — the language, how many characters were on the page, whether it succeeded, and how long it took. Never the text of your letter.
It can be wrong. The recognition can misread faint or handwritten print, and the explanation is generated by a language model. For court, immigration, legal or medical papers, confirm what the letter says with a person — a legal aid office, your resettlement caseworker, or the agency that sent it. The app shows this warning with every scan.
If you have the summary read aloud, its text is sent to our speech partners exactly as described under "Voice features" above.
Service providers — who else handles your data
We share your information only with the companies below, only what each feature needs, and only so that they can provide that feature to us. We never give them your name or your account details.
- Cloudflare hosts our server, database and answer cache. It processes this data for us under its data processing terms (https://www.cloudflare.com/cloudflare-customer-dpa/), which limit it to providing the service and require it to keep the data secure.
- Google (paid Gemini API) receives your chat messages, the text of letters you scan, and your city and language. Under Google's terms for paid API customers (https://ai.google.dev/gemini-api/terms), Google processes this data for us under its data processing terms and does not use it to improve its products or train its models. It keeps these requests for up to 55 days, only to detect and prevent abuse, and they may be reviewed for that purpose.
- ElevenLabs (voice in English, French and Swahili) receives your voice recordings and the text you ask to hear. Its terms (https://elevenlabs.io/privacy) let it keep this content in our account's history and, unless that option is switched off, use it to improve its services.
- Pindo (voice in Kinyarwanda) receives your voice recordings and the text you ask to hear. Its privacy policy (https://pindo.ai/privacy-policy) lets it keep this content as long as its service needs it and use it to improve its speech recognition.
These providers protect your information as this section describes. We will update this section if their terms change, and stop using a provider that no longer meets it. If you'd rather not share your voice with ElevenLabs or Pindo, type instead of speaking and read instead of listening — every feature works without voice.
Network requests
The app makes the following network requests:
- AI Chat: requests to our backend proxy (a Cloudflare Worker), which forwards to Google Gemini.
- Voice: requests to the same proxy, which forwards audio to ElevenLabs or Pindo (speech-to-text) and reply text to the same services (text-to-speech).
- Scan a letter: requests to the same proxy carrying the text recognized on the page (never the photo), which forwards to Google Gemini.
- Sign-in (optional): requests to the same Cloudflare Worker to create or verify your account.
- Tapping a "Call" button opens the iOS Phone app to dial the number.
- Tapping "Directions" opens the iOS Maps app.
- Tapping a resource address opens Maps to that location.
Our server keeps no content from these requests beyond the caching described above. To keep the service available and prevent abuse, our server enforces daily request limits per internet connection; for this it briefly stores a hashed (unreadable) form of the connecting IP address for up to 48 hours. Cloudflare, which hosts our server, also processes IP addresses as part of operating its network (https://www.cloudflare.com/privacypolicy/).
Permissions
The app requests three iOS permissions, and only when you first use the feature that needs it:
- Microphone — requested the first time you tap a microphone button (after you agree to the AI permission described above), so you can speak instead of typing. If you decline, everything else in the app keeps working; you can type instead. You can change this any time in iOS Settings → Intashyo.
- Camera — requested the first time you scan a letter, so you can photograph the page. The photo is read on your device and never uploaded. If you decline, the rest of the app keeps working, and you can still pick an existing photo instead.
- Location (while using the app) — offered during onboarding as a shortcut so you don't have to type your city. If you allow it, the phone finds your approximate position once and turns it into a city name using Apple's geocoding service; only that city name is kept. Your coordinates are never sent to our server, the app never uses your location in the background, and you can always just type your city instead.
Choosing an existing photo uses the iOS photo picker, which hands the app only the picture you select — the app is never granted access to your photo library.
The app does not request contacts access. If a future version adds a permission, we will update this policy and request the permission only with a clear in-app explanation.
This website
This policy also covers our website, intashyo.app. The website does not use cookies, analytics, or trackers, and it does not load anything from other companies' servers: every page, font, and image comes from intashyo.app itself. Cloudflare, which hosts the website, processes standard request data, such as IP addresses, to deliver the site and protect it from abuse (https://www.cloudflare.com/privacypolicy/).
Children and minors
Intashyo is not directed at children under 13. It is intended to help adults navigate resources after arriving in the US. We do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and believe your child has provided information to us, please email us and we will help.
If you are between 13 and 17, please use the app together with a parent, guardian, or trusted adult — particularly when asking the AI about legal, medical, or immigration matters.
Changes to this policy
If we change this policy, we will update the "Effective date" at the top and post the new version at https://intashyo.app/privacy.
Contact
If you have questions about this policy, email iradukuunda@gmail.com.