Privacy Policy
Submate is operated by Small Big Brands LLC ("we", "us"). This Privacy
Policy explains what information we collect when you use the Submate
mobile app and related services (together, the "Service"), why we
collect it, and what we do with it.
We try to keep this short and honest. If anything's unclear, email us
at any address ending in @submate.app — they all reach
the same inbox.
1. What we collect
Account information
When you sign in with Google or Apple, we receive the email address, name (when provided), and provider-issued user identifier associated with that sign-in. We use these to create your account so your saved flashcards sync across devices. We do not receive your Google or Apple password.
Content you save
When you star a subtitle in the app, we record the YouTube video ID, the source-language and translated text, the timestamps of that line, and the corresponding audio clip extracted from the public YouTube video. This is what becomes your flashcard for spaced-repetition review.
Usage data
We log the actions you take inside the app — videos watched, flashcards reviewed, daily activity minutes — so we can show you your streak and so we can fix bugs and improve the app.
Web funnel and acquisition data
If you use the web player or onboarding flow, we record the quiz answers you provide, funnel steps reached, coarse device and country information, and campaign parameters in the link that brought you to Submate. We use this first-party data to operate and improve the onboarding and purchase experience. We do not use a cross-site advertising identity SDK.
Feedback you submit
If you send feedback through the app, we receive your message, your email address (if you provide one), and any photos or videos you attach.
Technical data
Standard server logs (IP address, timestamps, request paths, app version) for operational and security purposes. These rotate every 14 days. We resolve your IP address to a country code for pricing and statistics; the country code is kept with usage events, the IP address itself is not.
Cookies and data stored on your device
The Service stores, accesses, and collects information on your device, including by placing and reading cookies and similar technologies (such as browser localStorage), and allows the third parties listed below to do the same. Specifically:
- Session cookie (get.submate.app): keeps you signed in to your account on the web. Deleted when you log out.
- Guest-usage cookie (submate.app): if you use the web player without an account, a cookie records that this browser used its daily free subtitle generation. It contains a date and a video ID — no personal information — and expires within two days.
- Preferences (localStorage): your interface language, subtitle language choices, layout, and similar settings, stored in your browser so they persist between visits.
- Visitor identifier (localStorage): a randomly generated ID used to measure how the web player is used (pages reached, subtitles loaded, errors). It is not derived from and cannot be tied back to your name, email, or any other identity unless and until you create an account in the same browser.
- Advertising measurement (third party): our onboarding pages at get.submate.app load the Google tag (gtag.js), which places and reads cookies on your device so Google can measure whether an ad click led to a sign-up or purchase. Google's handling of this data is described in the Google Privacy Policy.
- Sign-in and payment providers (third party): Google and Apple set cookies during their sign-in flows, and Stripe during checkout, on their own domains under their own policies.
- Mobile app storage: the iOS app stores your sign-in token, settings, and cached content on the device so the app works offline and you stay signed in.
We do not use cross-site advertising identity SDKs, and we do not place cookies for any purpose other than those listed above. You can clear cookies and site data in your browser at any time; the Service keeps working, though you'll be signed out and preferences reset.
YouTube API Services
Submate uses YouTube API Services to look up publicly available video information (title, duration, available caption languages) and captions for the videos you choose to watch. By using Submate you also agree to the YouTube Terms of Service. Google's handling of data in connection with YouTube is described in the Google Privacy Policy.
These lookups involve no YouTube account: we never ask for, receive, or store your YouTube credentials, watch history, or any other data from a YouTube account. Requests are made for the public video you selected and are not tied to your identity. The video metadata and caption files we retrieve are public, video-level data — they contain no information about you — and are cached on our servers for a limited time (metadata up to 7 days) so the next viewer of the same video gets subtitles faster. What is tied to your account is what you explicitly save: starring a subtitle stores that video ID and text in your flashcards, as described above.
2. What we don't collect
- We do not collect your contacts, location, microphone audio, or any data outside what the app explicitly does.
- We do not show ads. We have no advertising SDKs.
- We do not sell, rent, or share your personal data with third parties for marketing.
- We do not use third-party analytics SDKs that build profiles across other apps.
3. Third parties we use
Submate relies on a few external services to function. Each receives the minimum data needed to do its job:
- Google: for account sign-in (Google OAuth). Receives your sign-in flow only.
- Apple: for account sign-in and, where applicable, App Store purchases.
- OpenAI and similar AI providers: for word definitions, subtitle translation, and reading the 12-digit pairing code from camera photos. They receive only the specific text or image being processed — public video captions, or the word you tapped — with no name, email, or account identifier attached; provider API policies do not retain inputs for model training.
- YouTube API Services: we fetch publicly available video metadata and captions for the videos you choose (see the YouTube API Services section above). No YouTube account credentials are involved, and requests are not tied to your identity. Use of YouTube data is also subject to the YouTube Terms of Service and the Google Privacy Policy.
- Google (advertising measurement): the Google tag on our onboarding pages reports ad-conversion events (e.g. "a sign-up happened") with Google's cookie identifiers — not your name or email. See the Google Privacy Policy.
- Stripe: processes direct web subscriptions and provides billing management. Stripe receives the payment and billing information required to do that; we do not receive your full card details.
- RevenueCat: connects subscription status from Stripe or an app store to your Submate account so Pro access works across supported devices.
- Google Play: processes purchases made through Google's in-app purchase system.
4. Where your data lives
Your account information, saved flashcards, audio clips, and feedback are stored on a server we operate. Server backups are encrypted and retained for 30 days. We're a small team and we don't move your data off this server.
5. How long we keep it
- Account + flashcards: as long as your account exists. Delete your account in Settings to erase them.
- Server logs: 14 days.
- Feedback messages: indefinitely, so we can refer back. Email us if you'd like a specific message removed.
6. Your rights
You can:
- Access: see all your saved flashcards in the app.
- Delete: remove your account and all associated data via Settings → Delete account, or by emailing us.
- Export: request a JSON export of your data by emailing any address at
@submate.app. We'll send it within 14 days. - Object / restrict: if you're in the EU, UK, or California, you have additional rights under GDPR / CCPA. Contact us and we'll comply.
7. Children
Submate is not directed at children under 13 (or 16 in the EU). We don't knowingly collect personal data from children. If you believe a child has signed up, contact us and we'll delete the account.
8. Security
We protect your data with industry-standard precautions: HTTPS for all network traffic, server access restricted to authenticated keys, and encrypted database backups. No system is perfectly secure, and we can't guarantee absolute security. If we ever discover a breach affecting your data, we'll notify you within 72 hours.
9. Changes to this policy
If we materially change this policy, we'll update the date at the top and notify users via the app. Continued use after a change means you accept the updated terms.
10. Contact
Submate is operated by Small Big Brands LLC.
For questions, concerns, or requests about this policy or your data,
email privacy@submate.app.
In fact, any address ending in @submate.app reaches the
same human-monitored inbox (support works too), and we
respond to privacy requests within 14 days.