Vestige

Privacy Policy

Effective 5 September 2026 · Version 1.3

Who we are

Vestige is published by Hiel Digital, a one-person business in Purmerend, the Netherlands (Sem Hiel, Dom Helder Camarastraat 132, 1447 ZM Purmerend, Chamber of Commerce 42134222). We are the data controller for everything described here. Questions, or a complaint: sem@hiel.digital. The full policy, with every processor named, is published at learnvestige.app/privacy.html.

What we collect

An account needs an email address and a password, or the identity Apple shares when you use Sign in with Apple. Optionally you may add a display name, a short bio and an avatar photo. As you use Vestige we store the interests you selected, articles you save and collect, your reading progress and history (only while its toggle is on), and your recent searches. If you explicitly allow notifications, we also store an Expo device push token linked to your account so the categories you select can reach that device.

What we use it for

Most data we store exists to run your archive: signing you in, syncing your reading across devices, personalising your discovery feed, remembering where you left off, and delivering notifications you opted into. Notification access and each category can be turned off from Profile; turning off device notifications deactivates its push token and cancels scheduled reminders. With your iOS tracking permission, we also use limited app events to measure whether a Vestige advertisement on TikTok led to an install. We never sell or rent personal data, and we never send TikTok your account, purchases, searches, saved stories or reading activity.

Legal grounds

Under the GDPR we rely on three grounds. A contract, for running your account, your library and a Vestige Plus membership — without that data there is no service to deliver. Legitimate interests, for keeping the archive secure and for knowing in aggregate which parts are read, so we know what to write next; you may object at any time. And consent, for your photo library when you choose an avatar, for the interests you volunteer, and for TikTok advertising measurement where iOS asks for tracking permission. You may withdraw consent whenever you like.

Where it lives

Your account and reading data are stored with Supabase on servers in the European Union (eu-west-1, Ireland), protected by row-level security so that only your signed-in session can read your private records. Four outside services are worth naming: Apple and Google act as independent controllers when you sign in with them; Apple handles a Plus payment; RevenueCat — established in the United States — checks the receipt behind that membership and receives your account identifier and purchase, never anything you read; and TikTok receives the limited advertising-measurement data described below. Where data crosses the European Economic Area, the transfer is protected by the safeguards in the provider’s applicable data terms, including Standard Contractual Clauses where required. Narrated audio and artwork are editorial content, not personal data.

TikTok advertising measurement

If you allow tracking in the iOS permission prompt, the TikTok App Events SDK reports only that Vestige was installed, opened, or opened again the next day. For attribution the SDK also sends a device identifier, IP address, timestamp, app version and basic device information to TikTok. TikTok may use these signals to measure and improve delivery of our ads and to associate the event with activity on TikTok. Automatic purchase tracking and enhanced data postback are disabled: TikTok does not receive what you buy, read, search, save or type in Vestige. If you decline permission, iOS blocks requests to TikTok’s tracking domain; Apple’s privacy-preserving SKAdNetwork may still provide aggregated campaign results.

Optional usage statistics

Share usage statistics is off by default and separate from reading history and advertising permission. If you turn it on in Profile, Vestige receives basic onboarding, story-open/completion, series and purchase-screen events, a random flow identifier, app build and a limited link-source category. Events contain no story titles, subjects, searches, reading text, email address or advertising identifier. They are linked to your account on our own backend for up to 14 days to prevent duplicates and measure return after seven days, then kept as anonymous daily totals for up to 90 days. A small account marker remembers whether your first-return cohort has already started while consent remains on; it contains no story or return timestamp. Turning sharing off deletes identifiable usage events and the marker, stops sending and clears the device queue. If the device is offline, local sending stops immediately and the server change is retried when you save the setting online. Previously anonymised totals cannot be linked back to you. We rely on your consent for this optional measurement.

Series reminders

A reminder for tomorrow is scheduled locally on your device only after you choose a time and allow notifications. It does not require a remote push token. You can cancel it in Profile. Turning reading-history tracking off, clearing history, or changing the signed-in account cancels the series reminder on that device.

Server logs

Like nearly every online service, our infrastructure provider writes standard server logs when the app talks to it: an IP address, a timestamp and the endpoint called. These logs exist only to keep the service secure and running — abuse prevention, fault diagnosis — and are kept briefly. They are never used for advertising, profiling or personalisation.

Sign in with Apple

When you use Sign in with Apple, Apple shares a verified identity and, if you allow it, your name and email address (or a private relay address). We use these only to create and secure your account. We never receive your Apple ID password.

Subscriptions

If you subscribe to Vestige Plus, Apple handles payment through your App Store account. We do not receive your card or bank details. RevenueCat verifies access and provides subscription product, store environment, transaction status, purchase/expiry times and, where available, price and currency. We use these records to provide your membership and reconcile charges, cancellations and refunds. Sandbox tests, introductory trials, editorial grants and verified paid subscriptions are reported separately. Detailed reporting records are retained for up to 90 days; minimal subscription evidence remains while needed to classify active access. Aggregate totals contain no account identifiers. Purchase verification is part of providing the paid service and does not depend on optional usage-statistics consent.

Sharing with others

A collection you explicitly share becomes visible — title and description included — to people who hold its share link. Nothing else you write or read is visible to other readers. We share data only with the providers named in this policy and only for the purposes described here.

Your controls

In your profile you can turn reading-history tracking off, clear your reading history, export a copy of your data as a file, and delete your account. In iOS Settings → Privacy & Security → Tracking you can change TikTok advertising-measurement permission at any time. Deletion is immediate and permanent: it removes your account and all private synchronized data from our servers.

Retention

We keep your data for as long as your account exists. When you delete your account, private records are deleted with it; anonymised editorial attributions (for example a review record) are detached, not kept under your name.

Your rights

Under the GDPR you may request access, correction, deletion or a portable copy of your personal data, and you may lodge a complaint with the Dutch supervisory authority (Autoriteit Persoonsgegevens). The in-app export and delete controls answer most requests instantly; for anything else, email us.

Age

Vestige is intended for readers aged 16 and up. We do not knowingly collect data from younger children; if you believe a child has created an account, contact us and we will remove it.

Changes

If this policy changes in a way that matters, the app will say so before the change applies. The date above always names the version you are reading.