Cathedra — Privacy Policy
Last updated 12 September 2026
Your lecture recordings never leave your iPhone. The audio of a lecture is never uploaded, never synced and never sent to any service. There is no analytics, no telemetry and no advertising anywhere in Cathedra.
Three things do leave the device, and each one is something you switch on. Your transcripts and timetable sync through your own private iCloud, which we cannot read. If you make an account, a copy of your courses and transcripts is kept on our server so you can read them on the web — never the audio. And if you use the AI features, what you are asking about is sent to be answered — only when you ask, and only after you have separately agreed to it.
The sections below spell out exactly which is which, because a privacy claim is only worth anything if you can check it.
Who holds it
Cathedra is made and run by Remzi Atasagun Poyrazoğlu, who is the data controller for everything described here. Anything on this page — a question, a request to see or delete what we hold, a complaint — goes to support@cathedra.study and is answered by a person.
What the app stores, and where
Everything Cathedra creates lives in the app's own storage area on your device:
- Audio recordings of lectures you choose to record, as files on the device.
- Transcripts produced from those recordings.
- Your timetable — terms, courses, class times, rooms, exams and deadlines.
Audio stays on the device that recorded it. A term of lecture audio is several gigabytes, and the app is built so it never goes anywhere — not to us, not to iCloud. Transcripts and your timetable sync to your own private iCloud database so your library follows your Apple Account to your other devices; Apple gives developers no access to a user's private database, so we cannot read any of it.
The AI features, if you use them
These are the only parts of Cathedra that send anything to another company, so each one is described in full. None of them runs unless you have subscribed and agreed, on a screen that names the service and the destination, to send content off your device. Declining leaves every other part of the app working exactly as before.
- Finding announcements — exam dates, assignments, room changes — runs on Apple's on-device model. Nothing is sent anywhere, and it works with no connection.
- Asking a question about a lecture sends the text of that lecture's transcript to DeepSeek, an AI service outside your country, so it can answer you. Asking a question about a whole course sends the transcripts of that course's lectures, together with their titles, their dates and the course name. Your audio recording is never sent.
- Describing a photograph — a slide, a whiteboard — sends that photograph, and reading a syllabus sends the document or screenshot you chose. Only what you picked, and only when you ask.
- Speaking a question instead of typing it sends those few seconds of your voice to Groq, a speech-to-text service outside your country, so the words can be understood in any language. The text comes back; the audio is not kept.
- Fixing misheard terms sends a short list of phrases from the transcript, with a few words around each, so the model can judge whether they were misheard.
- Requests pass through a small service we operate on Cloudflare. It holds our API key, checks with Apple that your subscription is active, and counts how many questions the subscription has asked this month. To do that it keeps, for a few hours, the subscription's original transaction identifier and whether it was active, and the month's count — nothing else. It stores no transcript, photograph or document, and writes no content to any log.
- Your subscription is handled by Apple. We never see your name, email or payment details.
Your account, if you make one
You can use every part of the app without an account. An account exists for Cathedra on the web, and you can walk past the offer when the app first asks and sign in later from Settings, or never.
- An account is your email address and nothing else — no name, no password. You sign in by typing a six-digit code we email you; the code works for ten minutes.
- We keep the address, when the account was made and last used, and a record of each signed-in device (which kind, when it signed in, when it was last seen), on a database we operate on Cloudflare in Western Europe. The sign-in code and the session are stored only as hashes.
- If you sign in on your iPhone, your courses, your lectures' titles and dates, their transcripts, and your questions and answers are copied to your account on our server (Cloudflare, Western Europe), so the website can show them and Cathedra AI can answer from them there. Recordings are not copied. Signing out stops the copying; deleting the account deletes the copy.
- The only email we send is the sign-in code. Nothing else, and never to anyone else.
- Signing out ends that device's session. Deleting the account — in the app under Settings › Account, or on the website — removes the address and every session; it asks for a fresh code first. Your lectures, transcripts and timetable are not part of the account and stay where they are.
Deleting things
Deleting the app removes all of it, and the app lets you delete any recording, any transcript, any course or any term individually at any time.
The microphone
Cathedra asks for microphone access so it can record lectures. Recording only ever starts when you start it — from the app, from a reminder's Start Recording button, or from the Lock Screen card. iOS does not permit an app to open the microphone on its own, and Cathedra has no way to do so. iOS shows its own recording indicator whenever the microphone is live.
Speech-to-text
Transcription runs on your device, using the speech recognition built into iOS. Your audio is not sent to us, to Apple, or to anyone else in order to be transcribed.
One thing does involve the network, and it is worth being precise about: the first time you transcribe a lecture in a language you have not used before, iOS downloads that language's speech model from Apple. That download is a request to Apple for a model file. It carries no audio, no transcript and nothing about your lectures. After it completes, transcription in that language works with the network switched off entirely.
Notifications
Class reminders and exam reminders are scheduled locally by your iPhone from the timetable you entered. They are not push notifications; nothing about your schedule is sent anywhere. If you decline notification permission, the rest of the app works normally.
What we do not do
- No password. An account is an address and a code sent to it, so there is no password to store, to leak, or to reset.
- No name, no phone number, no date of birth. Nothing is asked for that the app does not use.
- No analytics, telemetry, crash reporting or usage tracking.
- No advertising and no advertising identifiers.
- No third-party SDKs of any kind are included in the app. Every service above is reached over an ordinary web request to our own address; no outside company's code runs inside Cathedra.
- Nothing is ever sold. Nothing is shared with anyone except the companies named above, each doing one job we asked them to do.
- We never receive the audio of a lecture. Not on our server, not on the way to anywhere. The only sound that ever leaves is the few seconds of your own voice when you choose to speak a question instead of typing it.
- We do not read your library for our own purposes. What is on our server is there so the website can show it to you and answer your questions from it, and for nothing else — not to train a model, not to build a profile, not to look at.
Recording other people
This part is about your responsibility rather than ours, and it matters more than anything else on this page.
A lecture recording contains someone else's voice — usually your lecturer's, sometimes other students'. Whether you may record it is decided by the law where you are and by your university's rules, not by this app. Many institutions permit recording for personal study and prohibit sharing; some require the lecturer's permission first; some prohibit it outright. Rules differ between countries and between universities in the same country.
Please check before you record, ask when in doubt, and do not publish or distribute a recording of someone who did not agree to it. Cathedra keeps your recordings private on your device by default; what you choose to export or share afterwards is up to you.
Children
Cathedra is intended for university and college students and is not directed at children. It collects no personal information from anyone, including children.
Why we are allowed to hold it, and for how long
Under the GDPR every piece of personal data has to have a reason. Ours:
- Your email address, your sessions, and the copy of your library on our server — to give you the service you asked for when you made the account. Kept while the account exists. Delete the account and they go with it, immediately and completely.
- A sign-in code — the same reason. Stored only as a hash and gone after ten minutes, used or not.
- Sending lecture text, a photograph or a few seconds of your voice to be answered — your consent, given on a screen that names the service and what it receives. You can withdraw it in Settings; the rest of the app keeps working. Nothing sent is stored by us, and the services we send it to do not keep it either.
- Your subscription's identifier and this month's question count — to check that a subscription is live and to keep a fair-use ceiling, which is our legitimate interest in not being billed for somebody else's use of a leaked identifier. The identifier is kept for a few hours at a time; the count for the month it belongs to.
Who else sees any of it
Four companies, each doing one job, and none of them given anything for its own purposes:
- Cloudflare — runs our server and holds the account and the copy of your library, in Western Europe.
- DeepSeek — answers a question, from the text sent with it. Outside the European Union.
- Groq — turns a spoken question into words. Outside the European Union.
- Apple, and Paddle if you subscribed on the website — sell the subscription and tell us only whether it is live. Neither gives us your payment details.
One page on this site, the payment page, loads Paddle's checkout script from Paddle's own servers and shows Paddle's payment form inside it. What you type there goes to Paddle, not to us, and what Paddle keeps is described in Paddle's privacy policy. No other page here runs a script.
The two that sit outside the European Union receive text or a photograph you have chosen to send, at the moment you send it, under the consent described above. Nothing is sent to either of them in the background, and nothing about you is sent with it beyond what the question needs.
If you are in Türkiye, that transfer is why the app asks for your explicit consent separately (KVKK madde 9) rather than folding it into anything else.
Your rights
Data protection law — including the GDPR in the European Union — gives you the right to see what is held about you, to have it corrected, to have it deleted, to take it elsewhere, to object to it being held, and to withdraw a consent you gave. You can use any of them by writing to support@cathedra.study, and we answer within a month.
Most of it you can do yourself, without asking anyone. Deleting your account — in the app under Settings › Account, or on the website — erases the address, every session and the whole copy of your library, and it happens as you watch. Signing out stops the copying. Withdrawing AI consent in Settings stops anything being sent.
Your recordings are on your own device, under your own control: the app can play, export in several formats, and permanently delete any of them, and deleting the app removes everything at once. We could not give you those or delete them for you if we wanted to — we have never had them.
If you think we have handled your data wrongly, tell us first and we will try to put it right. You also have the right to complain to a data protection authority — in the Netherlands the Autoriteit Persoonsgegevens, and otherwise the one for the country you live in.
Changes
If this policy changes, the updated version will be posted at this address with a new date at the top. Material changes will also be described in the App Store release notes for the version they take effect in.
Contact
Questions about this policy, or about the app: support@cathedra.study