Distill Privacy Policy

Last updated: April 8, 2026

Setout Labs ("Distill", "we", "us") operates the Distill applications for iOS and Android (the "Service"). Distill lets you read book summaries from our curated library and turn YouTube videos into swipeable learning cards. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data, and outlines the choices and rights available to you.

We align this Policy with the privacy requirements published by Apple App Store Review Guideline 5.1 and Google Play User Data policies. By using the Service, you agree to the practices described here. If you do not agree, please discontinue use of Distill.


Third-Party AI Services and Your Consent

Distill uses third-party AI services to turn the YouTube videos you submit into summary cards. Before any of your data is sent to these services, Distill asks for your explicit permission. You can still read pre-generated book summaries and browse the library without enabling AI processing.

What Data Is Sent and to Whom

  • AI Card Generation (OpenAI and Google): When you submit a YouTube URL or ask Distill to summarize a video, the fetched transcript and related metadata (such as video title and channel name) is sent to OpenAI and/or Google (Gemini) to generate the summary cards and key ideas that Distill returns to you.
  • YouTube Transcripts: When you submit a YouTube URL, Distill fetches the public transcript from YouTube's public data interfaces and processes that text to build the summary cards. We do not download or store the video itself.

How We Obtain Your Permission

During onboarding, Distill presents a consent step that identifies each third-party AI service, describes the data that will be shared, and asks you to agree before AI-powered features are enabled. You may decline, and the AI-powered features will not be used.

How These Providers Protect Your Data

Each third-party AI provider processes your data under a data-processing agreement with us that requires them to use your data only to perform the requested service, apply appropriate security measures, and not retain your data beyond what is needed to fulfill the request. They are not authorized to use your content to train their AI models. We require that each provider offers protections for your personal data that are the same as or equivalent to those described in this Privacy Policy.


Data We Collect

We collect the minimum personal data needed to provide Distill and keep your library in sync across your devices.

Account and Authentication

When you create or sign in to a Distill account we process your name (if provided), email address, authentication tokens, profile photo, timezone, and preferences. If you sign in with Apple or Google we receive the identifier, name, and email they confirm for you.

Library Content You Add

We store the book summaries you save, the YouTube videos you submit or follow, your saved ideas and highlights, reading progress, tags, and collections so that they stay synced across your devices. This also includes metadata such as timestamps and source URLs.

YouTube Imports and Creator Follows

If you submit a YouTube video to summarize, we store the URL, the fetched transcript, and the resulting summary in your library. If you follow a YouTube creator, we store the channel identifier so that we can poll YouTube for new videos and generate summaries when new content is published. As described in the "Third-Party AI Services and Your Consent" section above, we ask for your permission before sending any content to our AI provider.

We do not sell your content and we do not use it to train our own models. We do not authorize our AI provider to use your content for training.

Shared Content via Share Extension

If you share a YouTube URL to Distill from another app using the share sheet, we receive only the URL you share and treat it the same as a URL you paste directly into the app. We do not receive the content of other apps, your browser history, or any unrelated data.

Device and Usage Data

We automatically collect device type, operating system version, app version, language, IP address, time zone, unique identifiers generated by us, and interactions with product features to secure the Service and understand performance.

Diagnostics, Analytics, and Logs

We use analytics and error-monitoring tools to understand feature usage and capture crashes and performance diagnostics. These services receive device identifiers and event metadata; they do not access the contents of your library.

Purchases and Subscriptions

If you buy a subscription, Apple App Store, Google Play, and RevenueCat share transaction identifiers, product selections, subscription status, and country information with us so that we can activate your benefits. We do not receive your full payment card details.

Support and Communications

When you contact support, respond to surveys, or submit feedback we collect the information you provide together with any attachments, timestamps, and contact details so we can respond.

Push Notifications

If you enable push notifications we store a device token provided by Apple Push Notification service or Firebase Cloud Messaging so we can tell you when a video you submitted has finished processing, when a creator you follow publishes something new, or when there are important account messages. You can disable notifications at any time in your device settings.

We do not intentionally collect precise geolocation, contacts, or sensitive personal data unless you include it in your content or choose to share it with us.


How We Use Personal Data

We use personal data to:

  • Provide, maintain, personalize, and improve the Service, including syncing your library across devices.
  • Authenticate you, manage your account, and deliver the features you request.
  • Generate summary cards and key ideas from the YouTube videos and transcripts you submit.
  • Poll YouTube for new videos from creators you follow and notify you when new summaries are available.
  • Process purchases, manage subscriptions, and communicate billing or entitlement updates.
  • Send important notices such as security alerts, transactional emails, and policy updates.
  • Provide customer support and respond to feedback or feature requests.
  • Monitor usage, perform analytics, and develop new features while balancing product performance and user experience.
  • Protect against fraud, abuse, and technical issues and enforce our Terms of Service.
  • Comply with applicable laws, regulations, and legal processes.

We only send marketing communications with your consent, and you can unsubscribe at any time.


How We Share Personal Data

We do not sell or rent your personal data. We share it only with trusted service providers that help us operate Distill:

  • Supabase, which hosts our database, authentication, and sync services and stores the library content you choose to add.
  • OpenAI and Google (Gemini), which process the YouTube transcripts and related metadata you submit to generate summary cards and key ideas. Your content is sent only after you grant permission.
  • YouTube Data API and related public interfaces, which we use to fetch video metadata and transcripts for videos you submit or for creators you follow.
  • RevenueCat, together with Apple App Store and Google Play billing, to process subscription purchases and verify your entitlement status.
  • Apple Push Notification service and Firebase Cloud Messaging, to deliver push notifications to your devices.
  • Analytics and error-monitoring services, to measure product usage trends and capture crashes and performance issues so we can improve the Service.
  • Vendors that provide hosting, logging, customer support, and email services under contractual confidentiality obligations.

All third-party service providers listed above operate under agreements that require them to protect your personal data with safeguards that are the same as or equivalent to those described in this Privacy Policy.

We may disclose information to comply with law, defend our legal rights, prevent harm, or in connection with a corporate transaction such as a merger or acquisition.

We may publish aggregated or de-identified insights that do not identify you.


Legal Bases for Processing (EEA/UK)

If you live in the European Economic Area or the United Kingdom, we process personal data under the following legal bases:

  • Contract: to provide the Service you request, including syncing your library and processing purchases.
  • Legitimate interests: to maintain, improve, and secure Distill when those interests are not overridden by your rights.
  • Consent: for sharing data with our third-party AI providers (card generation from YouTube transcripts), optional analytics, marketing communications, or when you connect a third-party account.
  • Legal obligations: to comply with accounting, tax, and regulatory requirements.
  • Protection of vital interests or legal claims.

Data Retention and Storage

We retain personal data only for as long as necessary to provide the Service, meet legal obligations, resolve disputes, and enforce our agreements.

Your saved book summaries, video cards, highlights, and related metadata remain while your account is active. When you delete content, we remove it from active systems and schedule it for deletion from backups within a reasonable timeframe.

Server logs and analytics summaries are kept for a limited period to secure the Service. Aggregated or anonymized data that no longer identifies you may be retained longer.


International Data Transfers

We store and process data in the United States and other countries where our service providers operate.

When personal data is transferred internationally we rely on safeguards such as Standard Contractual Clauses, contractual commitments, and technical controls to protect your information.

By using Distill you understand that your data may be transferred to jurisdictions with different data-protection rules than your home country.


Your Rights and Choices

Depending on where you live, you may have the right to:

  • Access, review, or obtain a copy of the personal data we hold about you.
  • Request corrections or updates to inaccurate or incomplete information.
  • Request deletion of certain personal data, subject to legal exceptions.
  • Object to or request restriction of processing in certain circumstances.
  • Withdraw consent or change your marketing and analytics preferences.
  • Receive your information in a portable format.
  • Opt out of sale or sharing of personal data; we do not sell personal data and we only share it to deliver the Service.

To exercise these rights, use the in-app controls described below or contact us at hello@dstl.cc. We may request information to verify your identity and authorized agents may submit requests for California residents with proof of authority.


Account Deletion and Data Management

You control your account and content at any time:

  • In the Distill app, open Settings and tap "Delete account" to permanently delete your account in compliance with Apple and Google requirements.
  • Deleting your account removes your saved library, submitted videos, highlights, creator follows, and device tokens from active systems within a reasonable period (usually within 30 days) unless we must retain certain records for legal obligations.
  • Signing out or uninstalling the app removes the locally cached data on that device. To clear offline copies on other devices, sign out or uninstall Distill there as well.

You can also delete individual saved summaries or highlights directly inside the app. For additional help, or to request deletion of your account and associated data if you no longer have access to the app, email us at hello@dstl.cc.


Children's Privacy

Distill is not directed to children under 13, and we do not knowingly collect personal data from children. If we learn that a child under 13 (or the minimum age in your jurisdiction) has provided personal data, we will delete it. Parents or guardians who believe a child has provided data should contact us.


Security

We use administrative, technical, and physical safeguards, including encryption in transit, access controls, secure development practices, and continuous monitoring, to help protect personal data.

No security controls are perfect, and we cannot guarantee absolute security. Please keep your account credentials confidential and notify us immediately if you suspect unauthorized access.


Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements.

If we make material changes, we will provide notice through the app, by email, or other appropriate means before the updated policy becomes effective. The "Last updated" date at the top of this page reflects the most recent revision.

Please review this Privacy Policy regularly. Continuing to use Distill after changes take effect means you accept the revised policy.


Contact Us

Setout Labs is the controller of your personal data.

If you have unresolved privacy or data-use concerns, you may contact your local data protection authority.