Referate - Privacy Policy
Last updated: September 22, 2026
This Privacy Policy applies to the mobile application Referate, published by Elmvick Software. For privacy questions or data requests, contact us at support@elmvick.com.
1. Who We Are
Referate helps users create academic materials such as reports, essays, presentations, bachelor's theses, and master's dissertations using AI assistance, online research, and export formats such as DOCX, PDF, and PowerPoint.
2. Data We Collect
We collect and process only the data needed to operate the app, generate academic materials, sync projects, and manage subscription access. We may collect the following categories of data:
- Account identifiers. An anonymous Firebase user identifier, authentication tokens, and technical information needed to maintain the session.
- Academic project data. Project title, work type, language, generation mode, user requirements, requested export formats, sources, generated drafts, summaries, and study questions.
- User-provided content. Any text the user enters into the app for content generation. If the user includes personal data or sensitive information in requirements, that information may be processed as part of generation.
- Subscription data. The Google Play product purchased, subscription status, expiry date, renewal state, hashed purchase token, and limited information returned by Google Play to verify the subscription. We do not store payment card numbers or full payment details.
- Technical and operational data. Server logs, errors, Cloud Functions call information, and metadata needed for security, abuse prevention, and debugging.
The app does not currently request access to the camera, microphone, contacts, SMS, call history, or precise location.
3. How We Use Data
The current app also processes the following data when the corresponding features are used:
- Saved accounts: email address, Google profile name/photo, sign-in providers and password-reset requests. Firebase Authentication manages passwords; we cannot read them.
- Selected files and media: source PDF, DOCX, TXT, Markdown and images; institution logos; presentation images, MP4 clips (including their audio tracks), thumbnails and generated exports. Files are selected using the system picker; separate audio uploads are not supported.
- One-time credit purchases and subscriptions: purchase history, renewal, expiry, refund/revocation, credit use, transaction identifiers and protected purchase tokens used for verification, acknowledgement, deduplication and recovery. We do not receive payment card details.
- Diagnostics and security: Firebase Installation ID, App Check/Play Integrity information, release-build Crashlytics reports, operation status/duration/counts, and IP address/user-agent processed by infrastructure. Diagnostic events are designed to exclude manuscript text, purchase tokens, API keys and private download URLs.
- Support and compliance: generated-content reports, deletion requests and the information necessary to verify and handle them.
These data support the requested generation, source extraction, media placement, export, purchase recovery and account-management features, as well as abuse prevention and fault diagnosis.
We use data to create and save academic projects, generate drafts, sources, summaries, study questions, and export-ready materials; verify subscriptions through Google Play Billing; protect access to projects and premium functionality; prevent abuse; diagnose issues; improve app stability; and comply with legal obligations and platform rules.
We do not sell personal data and we do not use user data for behavioral advertising.
4. AI Processing and Third-Party Providers
To generate academic content, Referate sends relevant project information to OpenAI services through our Firebase backend. This information may include the title, work type, language, requirements, export formats, and instructions entered by the user. OpenAI may process API inputs and outputs to provide the service and monitor abuse according to its applicable policies.
The app infrastructure uses Google Firebase and Google Cloud services, including Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase, and Cloud Functions. Subscriptions are processed through Google Play Billing. Payment details such as card numbers are processed by Google Play and are not stored by us.
The main third-party providers used by the app are Google Firebase and Google Cloud, Google Play Billing, and OpenAI.
5. Storage, Security, and Transfers
Where a requested feature requires it, relevant uploaded images or content extracted from files are also sent to OpenAI for generation or analysis. Google Cloud services process source documents for extraction/OCR. Firebase App Check and Crashlytics support security and diagnostics. The app does not claim that AI processing is performed only on your device or that provider retention is zero.
Data is transmitted using secure connections. Access to projects is controlled through Firebase rules so that an authenticated user can access only data linked to their own account. Backend API keys are stored as server secrets, not inside the app installed on the device.
Data may be stored and processed in Google Cloud, Firebase, and OpenAI infrastructure, including in regions outside the user's country, depending on provider configuration and service availability. For Firebase services that we configure, we use European regions where applicable.
No electronic transmission or storage method is completely risk-free, but we use reasonable measures to protect data against unauthorized access, loss, or misuse.
6. Retention and Deletion
We keep project data for as long as needed to provide the app or until the user requests deletion. Subscription data and technical logs may be retained longer when needed for security, fraud prevention, accounting, dispute resolution, or legal compliance.
To request deletion of your app account or associated data, contact support@elmvick.com. We may ask for additional information to safely identify the anonymous account and associated projects. After verification, we will delete or anonymize applicable data except for data we must retain for legal, tax, security, or anti-fraud reasons.
7. User Choices and Rights
You can also request deletion in Account > Account and Data Deletion. Delete app data only preserves sign-in, subscriptions and purchased credit rights while deleting app content. Delete account and data also removes the authentication account and remaining in-app rights. Requests are verified and processed through a resumable deletion workflow, not necessarily immediately.
Minimal restricted transaction, antifraud and deletion evidence may be retained, rather than academic projects or uploaded media. The documented financial-evidence ceiling is five years under the applicable fiscal-year calculation unless a different legal period applies; active purchase lifecycles require a separate retention review. Provider backups and technical logs follow their configured retention cycles. See account and data deletion for the request methods and retained data.
Deleting a Referate account does not cancel a Google Play subscription. Manage it separately in Google Play subscriptions.
Depending on applicable law, users may have the right to request access to personal data, correction of inaccurate data, deletion of data, restriction of or objection to certain processing, export of data in a portable format, and withdrawal of consent where processing is based on consent.
To exercise these rights, contact us at support@elmvick.com.
8. Sensitive Information and User Responsibility
Referate is intended for general academic assistance. We recommend that you do not enter sensitive information in project requirements, such as medical data, financial data, passwords, identification codes, official documents, or personal data about other people, unless it is strictly necessary and you have the right to use it.
9. Children and Minors
The app is not intended for children under 13 and is not designed as a child-directed service. If a minor uses the app, they must comply with applicable legal requirements and, where required, obtain consent from a parent or legal guardian.
10. Changes to This Policy
We may update this Privacy Policy when we change the app, providers, processing practices, or legal requirements. The updated version will show the latest update date. Continued use of the app after changes are published means the updated policy applies from the date indicated.
11. Third-Party Privacy Resources
12. Contact
If you have questions about this Privacy Policy, contact support@elmvick.com.
Elmvick Software © 2026. All rights reserved.