Privacy policy
Draft v0.1 · 2026-09-12 · Not yet in force. The final text will name the controller (a sole trader registered in Lithuania), the contact e-mail and the effective date.
The short version
- Your Moodle password, session and access token never reach us. They stay in your browser or on your computer.
- Your course files, videos and study content stay on your computer unless you choose the cloud plan for preparing material, and then only for that purpose, described below.
- We keep the minimum for an account: your e-mail, your plan and trial dates, settings you save, and an encrypted copy of your plan and progress that we cannot read.
- No advertising, no selling of data, no tracking across sites. Usage statistics are shared only if you switch them on.
- You can delete everything with one button.
1. Who is responsible
The controller is the provider named in the Terms (a sole trader registered in Lithuania). Your school remains the controller of the data on its Moodle site; we process what you, the student, choose to read from it through your own access, on your instruction (GDPR Article 6(1)(b), performance of the contract with you). We do not act for or on behalf of your school.
2. What we process and where
| Data | Where it is processed | Purpose | Kept |
|---|---|---|---|
| Moodle password | Never with us. The password route sends it to your school's own login endpoint from your device and keeps only the token it returns. | — | — |
| Moodle session / access token | Your browser (extension) or your computer (the local app), file restricted to your user | Reading your courses, deadlines and notifications | Until you disconnect; tokens expire per your school's settings |
| Course materials, videos, transcripts, the study content built from them | Your computer (the local app's workspace folder) | Your private study | Until you delete the folder or disconnect |
| Account e-mail, plan, trial dates, consent choices | Our hosted API (Cloudflare, EU/US edge; contract-based safeguards for transfers, see §5) | Sign-in by e-mail link, subscription, trial limits | Until you delete the account; then removed within 30 days including backups |
| Hashed Moodle identity (a one-way fingerprint of your site + user id) | Our hosted API | One free trial per student | 12 months |
| Plan, progress, settings (cloud sync — not enabled in the pilot) | Our hosted API, encrypted on your device before upload so that we hold ciphertext only (this is how the feature will work when it is switched on; until then these stay on your device) | Using the app on more than one device | Until you delete them or the account |
| Bug and feature reports | Our hosted API | Fixing and improving the app | 24 months |
| Usage statistics (only if you switch "Help improve the app" on) | Our hosted API | Improving the app; event names, counts and error classes only — never your name, school, course content, grades or Moodle identity | 24 months, aggregated |
| Payment data | Our merchant of record (named at checkout), as an independent controller | Billing, tax, invoicing | Per their policy and tax law |
| Country code from your connection | Computed by our API on each request to pick a default language; not stored | Default language | Not stored |
3. The optional cloud plan for preparing material
If you choose the paid plan's cloud preparation, the text of the course material you select is sent to our processing service and to an AI model provider under contract with us, solely to produce your study content, and is deleted from our systems when the job finishes. We tell you which provider is used in the app before you switch it on. If you do not want this, use the local options: the baseline (no AI) or an AI model running on your own computer.
4. Children
If you are under the digital-consent age of your country (14 in Lithuania), a parent or guardian must confirm your account; we send the confirmation link to the parent's e-mail you give us and keep only a record that it was confirmed. We do not profile children for advertising and we show no advertising to anyone.
5. Where data is stored and transfers
Our hosted API runs on Cloudflare's network; account data is stored in their EU-eligible data locations where available, and transfers outside the EU are covered by the EU standard contractual clauses and, for US providers, the EU–US Data Privacy Framework where the provider is certified. Course materials are never transferred by us; they stay on your device.
6. Your rights
You can access, correct, export and delete your data. Deleting your account (Settings → "Delete my account and all its data") removes the account, the encrypted blobs and push subscriptions immediately and from backups within 30 days. Local data is a folder on your computer that you can delete yourself. You may withdraw the usage-statistics consent at any time with the same switch. You can complain to the Lithuanian State Data Protection Inspectorate (VDAI) or your local authority.
7. Security
HTTPS everywhere; sign-in by single-use e-mail links; a strict content-security policy on every page; no third-party scripts; the local app listens only on your own computer; credentials are stored in a file readable only by your user; hosted data is encrypted on your device before upload. Details: the security page of our source repository.
8. Changes
We will announce material changes in the app and by e-mail at least 30 days before they take effect.
Related: Terms · How AI is used