Mestrio Teleprompter Privacy Policy

Effective date: August 20, 2026
Last updated: August 20, 2026

Welcome to Mestrio Teleprompter (Android package com.mestrio.teleprompter, the “App”). This Privacy Policy explains how the individual developer and operator, Robin Wang (“we,” “us,” or “our”), processes information when you use the App.

The App is primarily an on-device teleprompter. Scripts, reading state, imported resources, settings, and downloaded speech models generally remain on your device. The App does not currently provide an account, script cloud sync, or cloud backup. Network processing occurs when you choose AI generation or model downloads, and when the App performs product analytics and crash diagnostics as described below.

1. Scope

This Policy applies to script creation and editing, file import, full-screen and overlay prompting, speech follow, speech-model downloads, AI generation, product analytics, crash diagnostics, and support communications in the App.

Third-party services reached through the App have their own privacy practices. This Policy does not control information that a third party obtains directly from you or your device.

2. Information We Process

2.1 Local scripts, resources, and settings

The App may store the following in its private app storage:

We do not normally receive this content. Android backup, a storage provider you select, or a device-manufacturer service may retain copies according to your system settings.

2.2 Microphone and on-device speech follow

When you enable speech follow and grant microphone permission, the App reads microphone audio and processes it on your device using sherpa-onnx and voice-activity-detection models. Recognition results are used to match your progress through the script.

Your operating system, keyboard, other apps, and connected audio hardware may have separate behavior outside our control.

2.3 AI script generation

Only after you request generation does the App send the topic, scenario, target duration, language, tone, audience, and key points that you entered over HTTPS to the Mestrio AI service. That service runs on Cloudflare Workers and sends the content needed for generation to Google Gemini. The generated draft returns to the editor and is not added to your local script library until you save it.

The Mestrio AI Worker is designed not to log topics, prompts, key points, generated lines, credentials, or Gemini response bodies. When a request fails, it may log a random request ID, normalized error code, and HTTP status for security and troubleshooting. Responses use no-store, and requests sent to Gemini specify that the interaction should not be stored. Cloudflare and Google may nevertheless process IP address, request time, network and security logs, and service data under their own terms.

Do not submit passwords, access tokens, identity documents, financial or medical information, trade secrets, or other sensitive data that is unnecessary for generation. AI generation may be unavailable in some builds, regions, quota states, or service conditions.

2.4 Firebase Analytics and Crashlytics

The App uses Google Firebase Analytics and Firebase Crashlytics. They are currently enabled by default to understand basic feature use, device compatibility, and application stability.

Analytics events that we intentionally send are limited to app version, version code, build type, standalone-app marker, Android-version bucket, device-performance bucket, locale, orientation, a random session ID, and a screen enum such as library, resources, or settings. We do not intentionally send script titles or text, AI input or output, recognized text, filenames, file paths, email addresses, or access tokens as analytics event fields.

When a crash or nonfatal error occurs, Crashlytics may process stack traces, thread state, app version, device model, operating system, memory state, crash time, installation or instance identifiers, and diagnostic keys. Our diagnostic keys should describe only subsystem, operation type, and severity, not script content.

Firebase SDKs may also generate app-instance identifiers and automatically process network, device, and application technical information. We disable advertising-ID collection, ad-personalization signals, and Firebase automatic screen reporting. The App does not use Firebase data for advertising or cross-app tracking.

2.5 File import and speech-model downloads

When you import a file, the App uses the Android system picker or, on older Android versions, its permission-gated file browser to read the file you selected. Supported formats are TXT, Markdown, and DOCX, currently up to 10 MB. Extracted text is copied into private app storage. Removing an imported resource does not necessarily remove the original file.

When you request a speech model, the App downloads a model archive from a predefined GitHub Releases or Mestrio resource address, verifies its integrity, and installs it in private app storage. The download host processes IP addresses, request times, and ordinary network logs under its own policy. Removing a model deletes the corresponding files from private app storage.

2.6 Support communications

If you contact us by email, we process the email address, message, and attachments you provide to respond, troubleshoot, or handle a complaint. Do not send passwords, tokens, full scripts, or unrelated sensitive information. We retain support correspondence only as long as reasonably needed to resolve the request, meet legal obligations, and maintain necessary records.

3. Permissions and System Features

Permission or feature Purpose
Internet AI generation, speech-model downloads, Firebase Analytics, and crash diagnostics.
Microphone On-device speech follow after you enable it.
Display over other apps The floating teleprompter panel that you explicitly start.
Foreground service Keeps the visible floating prompting task stable.
File access Reads files selected through Android; Android 9 and earlier may use a permission-gated legacy browser.
Keep screen awake Prevents automatic sleep during prompting according to your setting.

Refusing a permission affects only features that need it. You can revoke permissions or overlay access in Android settings.

4. Purposes of Processing

We process information only to:

5. Service Providers and Disclosure

We do not sell or rent personal information and do not use script content for targeted advertising. Information may be processed by the following providers only as needed for a selected feature, diagnostics, or legal compliance:

Provider Purpose Information that may be processed
Cloudflare Workers Mestrio AI routing, security, and error handling AI request and result, request ID, and network/security metadata
Google Gemini Generate a script at your request AI input, generated result, and service-operation metadata
Google Firebase Analytics Product analytics Non-content events, app/device technical data, and instance identifiers
Google Firebase Crashlytics Stability diagnostics Crash reports, app/device technical data, and instance identifiers
GitHub Releases / Mestrio resource hosting Speech-model downloads Model request and network metadata

These providers may process data outside your country or region. Review the privacy policies and terms of Cloudflare, Google, Firebase, and GitHub.

We may disclose information where required by law, court order, or the protection of users and lawful rights. Because we do not host your local script library, we ordinarily cannot provide or restore that content from a server.

6. Retention and Deletion

You can delete scripts, resources, and speech models in the App, or clear data and uninstall through Android settings. Deletion may be irreversible. Uninstalling does not remove an original imported file and does not necessarily immediately delete diagnostics or aggregate data already sent to a provider.

The current version does not offer a separate in-app Analytics or Crashlytics switch. If you object to this processing, stop using and uninstall the App, or contact us with a request available under applicable law. We may request enough information to verify a request but will not ask for a password or access token.

7. Security

We use Android app sandboxing, HTTPS, request-size limits, model hash verification, controlled document parsing, sensitive-header redaction, and minimized telemetry to reduce risk. AI provider keys remain on the server and should not be written to the app repository or ordinary logs.

No device, network transmission, service provider, or software is absolutely secure. Protect your device, review scripts before sharing, and act promptly if you believe a device or account has been compromised.

8. Your Rights and Choices

Depending on applicable law, you may have rights to notice, access, correction, deletion, restriction, withdrawal of consent, portability, and complaint. You can normally manage on-device data directly in the App or Android settings. Exercise rights for data obtained directly by a provider through that provider's process.

Contact robinxdroid@gmail.com for assistance. Because we do not control your device or local script library, we cannot remotely inspect, restore, or delete scripts stored on your device.

9. Children

The App is not designed specifically for children under 14. Minors should use it with guidance from a parent or guardian, particularly before submitting AI content, importing files, or enabling an overlay. A guardian who believes a minor supplied inappropriate information may contact us.

10. Changes to This Policy

We may update this Policy for changes in features, SDKs, providers, law, or security. We will provide reasonable notice of material changes and update the date above. Before adding accounts, cloud sync, advertising, subscriptions, or a new content-processing service, we should update this Policy and any required consent flow.

11. Governing Law and Contact

Unless mandatory law provides otherwise, this Policy is governed by the laws of mainland China. Users elsewhere retain rights that cannot be waived under their local law.