Privacy Policy
for FirstPass

Effective date: July 28, 2026

FirstPass is a scholarly paper reader that also helps you find, save, and organize papers. This Privacy Policy explains what information FirstPass stores, what may be sent to FirstPass or other services, and the choices available to you.

FirstPass is operated by Fernando Flores, an individual developer. In this Policy, “FirstPass,” “we,” “us,” and “our” refer to the developer, the FirstPass app, and related server-side services.

Contact: support@getfirstpass.app

Summary

FirstPass is designed to be local-first. We do not require an account, sell personal information, use advertising networks, or use cross-app advertising tracking.

Most reading and library data stays on your device or, if iCloud sync is enabled, in your private iCloud database. This includes saved and liked papers, reading history and progress, searches, highlights and notes, open and pinned papers, local AI output, preferences, and cached paper files.

Some information is sent when needed for server-backed features such as search, feeds, recommendations, paper lookup, citation metadata, Radar, smart folders, embedding requests, and model downloads.

If you expressly choose to share optional product analytics, FirstPass sends limited category-level usage events to TelemetryDeck. These events never include paper identifiers or content, searches, notes, highlights, links, account or purchase data, location fields, or a lasting user or device identifier.

Opening paper files, publisher pages, citation links, exports, or other external content may connect your device to third-party services governed by their own privacy policies.

Information We Do Not Collect

FirstPass does not currently require or provide user accounts.

We do not intentionally collect your name, email address, phone number, payment card information, street address, Apple Account password, or other account credentials through the app. If you contact us, we receive the address and contents of your message.

We do not sell personal information, use third-party advertising networks, or use data for cross-app advertising tracking.

We do not intentionally build permanent server-side profiles of the papers you read, save, like, highlight, or search for. Necessary feature requests, limited operational records, and optional category-level analytics are described below.

FirstPass never sends paper identifiers or content, search text, notes, highlights, or links as analytics fields.

Information Stored on Your Device

FirstPass stores app data locally so the app can work, remember your choices, and provide cached or offline features. Local data may include:

Library and reading activity. Saved and liked papers, folders, pins, currently open papers, reading history and state, recent searches, feed choices, Radar entries, smart folders, author follows, acknowledged results, and related timestamps or status data.

Paper and reader data. Paper identifiers, titles, abstracts, authors, categories, URLs, citation and recommendation metadata, related-paper results, highlights, notes, highlight anchors and embeddings, reader mode, scroll or page position, zoom, and appearance settings.

Cached content. Paper metadata, PDFs, HTML, figures, model files, embeddings, related-paper data, and other files used for reading, offline access, or performance.

On-device AI data. Local Briefs, Guided Skim state, context explanations, suppression records, and other local AI inputs or outputs needed by the feature.

Purchase and Plus access state. Purchase or subscription status, Plus trial timing and integrity records, and related entitlement state needed to unlock features and prevent repeated trials.

Analytics state. Your analytics consent choice, pending events awaiting delivery, and local category-level dates, counters, and milestones used to limit or avoid duplicate analytics events. No analytics event is recorded for delivery before consent is granted.

Preferences and service state. Theme, haptics, caching, notifications, export choices, local AI settings, onboarding state, and other app preferences.

You can delete some local data from inside the app, including paper caches and user-created items. You can also delete the app to remove data stored by iOS, although app-group, Keychain, iCloud, or other system-managed data may follow Apple’s own retention behavior.

iCloud Sync and Plus Trial Eligibility

FirstPass offers iCloud sync for some Plus features. If sync is enabled, FirstPass uses Apple CloudKit to keep supported data available across devices signed in to the same Apple Account.

Synced data may include saved papers and folders, liked papers, reading history and position, reader mode and appearance, highlights and notes, pinned papers, saved feeds, Radar entries, smart folder data, and related preferences. Highlight sync may include highlighted text, notes, anchors, and locally computed embeddings.

When you deliberately request a Plus feature while eligible, FirstPass may check or create a record in your private CloudKit database to coordinate a one-time 14-day Plus trial across devices. The record contains trial timing and status information and whether verified purchase activity has consumed trial eligibility. The trial requires internet access and iCloud, does not require payment, and does not renew automatically.

Starting the Plus trial enables FirstPass content sync. You may turn content sync off afterward. The separate private trial-eligibility record may still be checked or retained to enforce one-time eligibility and prevent the trial from repeating.

Local trial integrity records may include a one-way digest derived from the iCloud identity token available on the device and a device-only Keychain marker. FirstPass does not retain the raw identity token or send it to the FirstPass server.

CloudKit is provided by Apple. Data in a private CloudKit database is available only through the user’s iCloud account and is subject to Apple’s privacy policy, iCloud settings, and system behavior. FirstPass does not receive your Apple Account password or payment card information. Apple may use remote notifications to tell FirstPass that synced records changed.

Disabling sync or deleting the app from one device may not immediately delete records already stored in iCloud or present on other devices. Deleting records in FirstPass may also delete synced copies, depending on the feature and Apple’s sync behavior.

Information Sent to FirstPass or Its Server

FirstPass uses a backend service to provide paper metadata, search, feeds, recommendations, citation metadata, model files, and related features. Requests may include:

Search, feed, Radar, and smart folder requests. Search text, author or category filters, date filters, sort choices, saved criteria, seed or acknowledged paper identifiers, lookback settings, pagination cursors, limits, and lists of paper identifiers when searching within results.

Recommendation and paper requests. Paper identifiers for liked-paper feed ranking, paper lookup, related-paper results, citation metadata, author suggestions, or paper embeddings. We use these inputs to answer the request and do not intentionally use them as account, advertising, or tracking identifiers.

Highlight embedding requests. A limited portion of highlighted passage text may be sent so the server can compute a numerical representation used for related-highlight and personal paper-connection features. The text is processed for the request and is not intentionally retained or logged afterward. Notes are never sent to the embedding server.

Content shared to FirstPass. When you share text or a URL to FirstPass, FirstPass examines the shared item on your device for a supported arXiv link. If it finds one, it may send the paper identifier or related lookup candidates to our server to retrieve paper metadata or related-paper results. The complete text or URL you shared is not sent as analytics data.

Model downloads. If Local Briefs is enabled and its model is not installed, the app may download the model artifact from the FirstPass server, including automatically over Wi-Fi on a new installation.

Technical connection information. Like other internet services, the server necessarily receives information needed to deliver a response, such as an IP address, request time, and basic request metadata.

Support and privacy messages. If you contact us, we receive your email address and message contents and use them to respond and handle the request.

We use this information to provide requested features, operate and secure the service, prevent abuse, troubleshoot problems, and maintain reliability. We do not use it for advertising or sell it.

We do not intentionally keep permanent logs containing ordinary search text, liked or saved paper lists, highlighted passage text, smart folder seeds, or reading activity. Hosting, security, error, and infrastructure logs may temporarily contain technical metadata needed to operate, protect, or troubleshoot the service. We design requests and logs to avoid paper-interest data where practical.

Optional Product Analytics

FirstPass offers optional product analytics only after you expressly choose “Share Analytics.” You may decline without losing ordinary app features and may change the choice later in Settings. The choice applies to both the FirstPass app and its Share Extension.

When enabled, FirstPass sends events directly to TelemetryDeck, operated by TelemetryDeck GmbH in Germany. Events describe broad product interactions such as a feature category being used, a supported action succeeding, a reader being opened from a broad source or mode, or a category-level return milestone.

Events may include a coarse UTC calendar day, month, or both without the time of day; a short-lived random session identifier that resets after inactivity and is not written as a lasting user or device identifier; the app version and build; the operating-system name and major-minor version; and the broad action, feature, surface, reader origin, or reader mode relevant to the event. TelemetryDeck also receives ordinary server-side receipt information needed to process the event.

FirstPass intentionally sends an empty user-identifier field. It does not send a stable installation identifier, paper identifiers or content, search text, notes, highlights, links, account or purchase data, location, country, or region fields, or full device-model details.

Your IP address is necessarily used to deliver the network request. TelemetryDeck states that it does not store IP addresses in its database or logs. TelemetryDeck states that its analytics servers are hosted in the European Union.

TelemetryDeck keeps data available for queries according to the applicable plan’s retention period and states that older data may remain in cold storage. Because FirstPass sends no lasting user or installation identifier, FirstPass generally cannot isolate all analytics events belonging to one person for individual access or deletion.

Turning analytics off stops new events and removes pending events that have not yet been sent. FirstPass retains your opt-out choice and may retain local category-level dates, counters, or milestones so the app can enforce the choice and avoid duplicate events if analytics is later enabled again.

We use analytics only to understand broad feature use, successful actions, and app reliability. We do not use analytics for advertising, tracking across other companies’ apps or websites, or paper-level interest profiles.

On-Device AI Features

FirstPass offers several AI-assisted features designed to run on your device:

Local Briefs. FirstPass uses a modified Gemma 3 model to generate short summaries of paper abstracts. On new installations, Local Briefs may be enabled by default and the model may download automatically from the FirstPass server over Wi-Fi. Abstracts and generated Briefs are processed on your device and are not sent to the server for summary generation. You can disable Local Briefs and delete the model.

Guided Skim. Guided Skim uses bundled on-device models to score and highlight parts of paper text. The text analyzed for Guided Skim is not sent to FirstPass or TelemetryDeck.

Context explanations. On supported devices, FirstPass may use Apple’s on-device Foundation Model to explain selected text using surrounding section context. The selected text, context, and generated explanation remain on the device and are not sent to FirstPass or TelemetryDeck.

Generated AI output may be wrong, incomplete, or misleading and should be checked against the original paper. AI inputs, outputs, settings, and suppression records may be stored locally until cleared or removed with the app. This section does not change the separate highlight-embedding request described above.

arXiv, ar5iv, Publisher Sites, and Other Third-Party Content

FirstPass helps you read papers from arXiv, ar5iv, and other sources and may show metadata derived from services such as OpenAlex.

When you open an arXiv or ar5iv page, PDF, HTML version, DOI or publisher page, citation link, figure, or a link inside the reader, your device may connect directly to that third party. The service may receive an IP address, browser or device information, the requested page or file, cookies or local storage, referring information, and other data described in its own privacy policy.

FirstPass does not control these services. The in-app web reader is intended to use an ephemeral web-data store where practical, but third parties still receive technical connection information while their content is open. Links opened outside FirstPass may be handled by Safari or another app with its own privacy behavior.

PDFs, HTML, Sharing, and Exports

FirstPass may download paper PDFs, HTML, figures, or related files from arXiv or another source. If caching is enabled, files may be stored locally for faster or offline reading. You can disable supported caches and clear them from the app. Temporary downloads may still be needed to display content when persistent caching is off.

When you export or share a paper, Markdown file, highlight, note, link, or other content, FirstPass gives the item to the destination you choose, such as Files, another app, or a third-party service. That destination may receive and retain the exported content under its own privacy policy and terms.

How We Use Information

We use information to provide and personalize app features; operate search, feeds, paper lookup, recommendations, embeddings, sync, reading, exports, and paid access; store local preferences and app state; provide on-device AI; respond to messages; understand optional category-level product use; and maintain, debug, secure, and improve FirstPass and its server-side services.

We may also process information to comply with applicable law or respond to lawful requests.

Where data-protection law requires a legal basis, we process information as needed to provide FirstPass and features you request, perform our agreement with you, operate purchases and Plus access, and take steps at your request. We rely on your consent for optional product analytics. We may rely on legitimate interests to secure and maintain the service, prevent abuse, troubleshoot failures, respond to support, and improve necessary service operation, provided those interests are not overridden by your rights. We may also process information to comply with legal obligations.

Optional analytics is not required to use ordinary FirstPass features. You may withdraw analytics consent at any time in Settings without affecting the lawfulness of processing that occurred before withdrawal. Information needed for a requested network feature must be transmitted for that feature to work; you can avoid the transmission by not using that feature.

FirstPass does not use personal information to make automated decisions that produce legal or similarly significant effects.

How We Share Information

We do not sell personal information or share it with advertising networks.

Hosting providers. Infrastructure providers may process technical information needed to host FirstPass services, store server files, and deliver responses.

TelemetryDeck. If you opt in, TelemetryDeck GmbH processes the limited analytics events described above on our behalf.

Apple services. Apple processes App Store purchases and provides StoreKit status used to unlock paid features. Apple also operates iCloud and CloudKit for sync and private Plus trial eligibility. We do not receive your full payment-card details from Apple.

Paper and metadata sources. Your device may contact arXiv, publishers, DOI destinations, citation links, and other sites directly. The FirstPass server may query sources such as arXiv and OpenAlex using public paper identifiers or metadata needed for app features.

Destinations you choose. Files, apps, websites, or services you select for sharing or export receive the content you choose to send.

Legal and safety reasons. We may disclose information if required by law or if we reasonably believe disclosure is necessary to protect rights, safety, security, or the integrity of the service.

Business transfer. If FirstPass is transferred, merged, or reorganized, relevant information may transfer as part of that transaction. We would expect the recipient to honor this Policy or provide notice of material changes.

Data Retention

Local and iCloud-synced data remains until it is cleared, evicted, removed by iOS or iCloud, deleted through the app, or removed when the app or relevant records are deleted. Some caches, searches, and reading-state records have size or time limits.

The private CloudKit record used for Plus trial eligibility may remain after the trial ends or after content sync is turned off so FirstPass can enforce one-time eligibility.

Feature-request inputs such as liked-paper identifiers, highlighted passage text sent for embedding, and paper-identifier lists are processed to provide the response and are not intentionally retained as permanent user profiles. Limited operational, security, error, and infrastructure logs may be retained as needed to operate and protect the service.

Optional analytics retention follows the TelemetryDeck practices described above. Disabling analytics stops future collection but does not automatically remove events already delivered to TelemetryDeck.

Support and privacy correspondence may be retained as reasonably needed to answer the request, keep business records, resolve disputes, or comply with law.

Privacy Rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, or portability of personal information, or to object to or restrict certain processing.

Because FirstPass does not use accounts and most data stays on your device or in your private iCloud database, we may not be able to identify or access that data from our server. You can manage local data through app features where available, by changing iCloud settings, or by deleting the app.

Because optional analytics has no lasting user or installation identifier, we generally cannot identify one person’s already delivered analytics events. We can still stop future analytics collection when you turn it off.

To make a privacy request about support correspondence or server-side operational records that we can identify, contact support@getfirstpass.app. Where applicable, you may also lodge a complaint with the data-protection supervisory authority where you live or work or where you believe a violation occurred.

Your Choices

You can use FirstPass without creating an account.

You can accept or decline optional product analytics and change the choice later in Settings.

You can enable or disable FirstPass content sync where available, although private CloudKit trial-eligibility checks may still be needed to start or validate a Plus trial.

You can enable or disable supported Local Briefs, Guided Skim, caching, notification, reader, and export options, and delete the downloaded Local Briefs model.

You can clear supported caches and delete saved papers, folders, liked papers, highlights, notes, open or pinned papers, Radar entries, smart folders, author follows, and other app data through app features where available.

You can delete the app to remove data stored by iOS, subject to Apple’s behavior for iCloud, Keychain, app-group, and other system-managed storage.

Security

We use reasonable technical and organizational measures to protect FirstPass and its server-side services. No method of transmission or storage is perfectly secure, but we design FirstPass to reduce unnecessary collection and keep most reading and library activity local or in the user’s private iCloud database.

International Users

FirstPass server-side services may be operated from servers in the United States or another location chosen by the developer or hosting provider. Optional analytics is processed by TelemetryDeck on servers it states are located in the European Union.

If you use FirstPass from another country, information may be processed in countries with privacy laws different from those where you live.

Children’s Privacy

FirstPass is not directed to children under 13, and users under 13 should not use it. We do not knowingly collect personal information from children under 13.

If you are a parent or guardian and believe a child under 13 provided information to FirstPass, contact support@getfirstpass.app. We will take reasonable steps to delete information we can identify.

FirstPass provides access to scholarly papers and external links that are not curated for children.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date and provide notice in the app or through another reasonable method. The updated Policy applies after it becomes effective.

Contact

For privacy questions, requests, or concerns, contact:

Fernando Flores
support@getfirstpass.app