Legal
Privacy Policy
Last updated:
Mobeera is private-first and local by default. This page explains in detail how Mobeera handles information across our apps.
Overview
Mobeera builds native productivity apps for Apple platforms and Android, including Stuff, WordPilot, and PDF Max. This Privacy Policy describes how we handle information when you use our apps and website.
The short version: our apps are private-first and local by default. Currently available AI features run locally on your device. If we introduce optional cloud AI features, they will be clearly labeled and used only when you choose them.
Stuff Library and iCloud Sync
Stuff keeps a working copy of your saved text, images, links, screenshots, documents, files, voice notes, and associated metadata on your device. When iCloud is available, Stuff synchronizes that library through the private CloudKit database associated with your Apple account so it can appear on your Apple devices. Mobeera does not operate that private database.
OCR, full-text and semantic search, embeddings, transcripts, and optional local intelligence run on your device. Search indexes, downloaded model files, and embeddings remain device-local and are not uploaded to Mobeera for processing.
Stuff Connected Services
Stuff creates an anonymous Firebase Authentication identity with a stable random identifier and no email address, name, or password. Mobeera uses that identifier to secure and meter the optional link-reading service. Firebase App Check uses App Attest on supported Apple hardware, with DeviceCheck as a fallback, to provide app and device-integrity signals intended to distinguish genuine copies of Stuff from abusive clients.
When you opt into reading a public link, Stuff sends its address to a Mobeera Firebase Cloud Function. Mobeera sends the address to Jina Reader to produce article text; Jina receives the address and technical network information from Mobeera's server, not your Stuff library or Firebase identifier. The request includes DNT: 1, which asks Jina not to retain the request or use it for training. DNT is a request to Jina, not a guarantee made by Mobeera about Jina's systems.
Mobeera separately caches the canonical URL and returned article output in Firestore for up to 30 days so repeated reads can reuse the result. This shared cache is keyed by a hash of the URL identity and is not stored under your Firebase identifier. Capability-style and private share links are refused by both the app and service.
Stuff uses RevenueCat to provide subscription status, purchases, restoration, and subscription-management features. RevenueCat receives the Firebase anonymous identifier as Stuff's app user ID, together with store purchase and entitlement information needed to provide Stuff Pro. RevenueCat and Apple process information under their own privacy terms.
Stuff Model Downloads and Shared Weights
When you choose to download a Gemma model, Stuff downloads the selected model files from Hugging Face. Hugging Face may receive ordinary request information such as your IP address and request metadata under its privacy policy. Gemma inference and your prompts remain on your device.
When you choose to download Stuff's speech transcription model, FluidAudio's model download mechanism retrieves the required Parakeet model files. The provider hosting those files may receive ordinary download request information. Recordings and transcription run on your device and are not sent with the model download.
Stuff stores Gemma weights in an Apple app-group container that can also be used by other installed Mobeera apps with access to that group. Sharing is limited to downloaded model files so those apps can avoid duplicate multi-gigabyte downloads; Stuff library content, prompts, embeddings, and transcripts are not stored there. Removing one app may not remove shared weights while another authorized Mobeera app still uses the container.
Data Stored On Your Device
Documents you create, open, edit, or annotate — including their text, images, formatting, and embedded content — are stored locally on your device and in storage locations you choose, such as iCloud Drive, Google Drive, or another document provider. In local workflows, Mobeera does not receive or transmit this content.
WordPilot and PDF Max may keep working files or recovery snapshots on your device to protect against data loss. On macOS and iOS, protected recovery snapshots use hardware-bound keys through the device's Secure Enclave. On Android, PDF Max keeps its working and recovery files in app-private storage and relies on Android's application sandbox and the device's storage protection; PDF Max does not separately encrypt every Android recovery file.
Local and Optional Artificial Intelligence
Currently available AI features — including Dr. Proof document review, WordPilot AI writing assistance, grammar suggestions, translation, and summarization — run locally on your device. We use efficient local models (such as Google's Gemma via LiteRT) and, where available, native Apple Intelligence.
Because these current features use local inference, the text of your documents is not sent to Mobeera or any third-party server to perform them.
If optional WordPilot Pro AI cloud features are introduced, they will be presented as a separate choice. Cloud AI requests will be sent only when you choose to use that mode.
Camera, Microphone, and Device Services
PDF Max for Android asks for camera access only when you choose a scanning workflow. Captured pages are processed on the device and remain in the document or storage location you choose.
PDF Max asks for microphone access only when you choose to record a Voice Note. Audio and supported transcription are processed on the device and stored with the document. Mobeera does not receive the recording or transcript through that workflow.
You can deny either permission and continue using features that do not need it. Some optional Android capabilities use Google Play services or download language and recognition models from their providers; those downloads are governed by the provider's privacy terms.
Optional Connected Features
PDF Max for Android can offer stock-image search through Pexels and Pixabay. When you use it, your search terms are sent to the selected provider and the chosen image is downloaded from that provider or its delivery network. Those services may receive technical network information such as your IP address under their own privacy policies. PDF Max does not send the document you are editing with the search request.
Store billing, model delivery, crash reporting when enabled, and document providers you choose can also require a network connection. Core document editing and output do not require Mobeera to upload your document to a server.
Data We Do Not Collect
We do not sell the content of your documents.
We do not collect or transmit document content from local editing and local AI workflows.
We do not require you to create an account to use the core features of our apps.
We do not use your document content to train our models or any third-party models.
We do not track your reading or editing activity across other companies' apps or websites.
Diagnostics and Crash Reports
When diagnostics are enabled in a distributed build, we may receive crash reports and limited product signals through Sentry to diagnose problems and understand actions such as a paywall being shown or a workflow completing. Reports can include technical details such as device model, operating system version, app version, error messages, stack traces, and fixed-category feature or outcome labels.
These reports are configured without a Mobeera user identifier, default personal information, screenshots, view hierarchies, document names, folder paths, document content, page text, transcripts, or signature images. If you contact us for support, we may ask you to choose and share relevant log excerpts separately.
Website Analytics
The Mobeera website uses Google Analytics 4 to understand page visits and product actions such as opening a product page, starting a Stuff demo, joining the Stuff waitlist, or following an App Store link. Google may process technical information associated with the visit under its own privacy terms.
Mobeera does not send the email address entered in the Stuff waitlist form, document content, or other form contents to Google Analytics. Waitlist analytics record only the result and the page placement of the action.
Stuff Early-Access List
If you join the Stuff early-access list, we collect the normalized email address you submit, the signup time, the page placement that led to the signup, and the version of the consent notice you accepted. We use this information only for Stuff early-access opportunities and launch updates.
Waitlist records are stored in a Neon Postgres database connected to the website through Vercel. The waitlist does not store your IP address, browser user agent, or raw referrer. We do not sell the list or use it for unrelated product newsletters.
You can ask us to remove your waitlist email at any time by contacting hello@mobeera.ai. Unless you separately choose to receive ongoing communication, we delete remaining waitlist records within 90 days after Stuff's public launch communications end.
Purchases
Purchases and subscriptions are processed by the store through which you obtained the app, such as Apple's App Store or Google Play. The store processes your account and payment details. The app receives the receipt, signed purchase data, product identifier, and subscription status needed to verify and maintain your entitlement; Mobeera does not receive your full payment-card details.
For Stuff, RevenueCat processes the store purchase and entitlement information described above. Cancelling or changing an Apple-billed subscription must be done through Apple's subscription-management controls; deleting a Stuff service identity does not cancel Apple billing.
Third-Party Services
You may choose to open or save files through a third-party cloud storage provider such as iCloud Drive, Dropbox, or Google Drive. When you do, that transfer is governed by the provider's own privacy policy, not this one. Mobeera does not intermediate or observe those transfers.
Apple, Firebase, RevenueCat, Jina Reader, Hugging Face, FluidAudio's model host, Google Play, Google Play services, Pexels, Pixabay, Sentry when enabled, and any storage provider you select process information under their own terms and privacy policies when you use their services.
Our apps may link to external websites for your convenience. Once you leave our app, the linked site's privacy policy applies.
Children's Privacy
Our apps are not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
Security
Local-by-default document processing limits exposure to server-side breaches. Protection for local files depends on the platform and workflow: supported Apple recovery snapshots use hardware-bound encryption, while Android working and recovery files use app-private storage and the device's operating-system storage protections. You remain responsible for securing the device and any external storage location you select.
Data Retention
Document content, working files, and recovery data remain on your device until you delete them, the app removes temporary data, or you uninstall the app. Content retained by iCloud, Google Drive, or another provider remains subject to that provider's storage and deletion controls.
Diagnostic information received by Mobeera is retained only as long as reasonably needed to diagnose issues, maintain security, and improve stability, then deleted or aggregated. Purchase records remain subject to the retention rules of Apple or Google; the app keeps local entitlement state only as needed to provide and restore purchased access.
Stuff's canonical URL and article-output cache expires after up to 30 days. Account deletion does not delete an entry from this shared cache because it is not stored under or owned by the anonymous account.
Stuff waitlist records are retained only for early access and launch communication, then deleted within 90 days after that communication ends unless you separately opt into something else.
Your Privacy Rights
For local workflows, most privacy requests are fulfilled directly on your device — you can delete documents, disable recovery snapshots, or uninstall the app at any time.
You may ask Mobeera to delete Stuff service-account data associated with the app's anonymous Firebase identity, including its per-install link quota and Mobeera entitlement mapping, by contacting us at the email below. Deleting this service identity does not delete your local Stuff library, content in your private CloudKit database, shared model weights, Apple's purchase records, or the shared URL/article cache, and it does not cancel an active Apple subscription. Delete local or iCloud content and manage Apple billing separately. A waitlist email is also separate and must be identified in your request if you want it removed.
If you have shared diagnostic information with us and wish to request its deletion, or if you have other privacy requests, contact us at the email below. We may need information sufficient to locate the records you are asking about.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the 'Last updated' date at the top of this page. We encourage you to review this page periodically.
Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at hello@mobeera.ai.