Privacy

What our servers hold, what passes through them, and what never arrives. This page restates our data-handling design of record (written 2026-08-24, last ruled on 2026-08-31); when that changes, this page changes.

Never on our servers

Transits, never stored

When you use the class chat without your own AI key, your prompt passes through our server to the AI provider and back. It is never written down: our usage ledger records only your account, a timestamp, the model, token counts, and cost. There is no column a prompt or a reply could land in, and prompt logging is never enabled at the provider.

The shared AI has daily limits per account and product-wide; when one is reached you are told in plain words and it resets at midnight UTC. Using your own OpenRouter key in Settings means your prompts never touch our server at all.

Stored when you sync

If you create an account, the app state you choose to sync — marks, overrides, syllabi, Class Memory, projects and chats, study tools, briefs, plans, reviews, drafts, and the files you upload to a project — is stored per account so it can follow you to another device. What may sync is a fixed list on both the app and the server; grades and the Canvas token are on neither. Uploaded files count against a per-account storage quota. Data is stored in the United States (AWS us-east-2).

Deleting your account

Settings → Account → Delete account removes every synced row, every uploaded file, every signed-in device, the usage ledger, and the account itself. The promise extends into our backups: the database replica ages out within 72 hours and the nightly file backup deletes what you deleted, so a deleted account leaves the backup within days. Signing out on its own deletes nothing remotely.

Questions

Write to grahamlmcwilliams@gmail.com.