Privacy Policy

Last updated: April 26, 2026

Summary

We collect the minimum data needed to run the Service. Your whiteboard drawings stay on your device. Your messages, screenshots, and voice audio are processed by our AI service providers so the tutor can respond. We do not sell your data.

1. Data We Collect

Account data: email address, display name, and a hashed password (stored using industry-standard cryptographic hashing — we never see or store your password in plain text).

Usage data: number of AI responses, subscription tier, device type (user agent), timestamps of sessions, number of characters sent to text-to-speech, and learning-progress events (which math concepts you practiced and outcomes — for the in-app progress tracker).

Content data: text of messages you send and AI responses, screenshots of your whiteboard (sent to our AI provider for context), audio recordings of your voice (sent for speech-to-text transcription, then discarded). Full conversation history and your handwritten drawings are stored on YOUR device (IndexedDB). Text-only summaries may be cached briefly on our servers to support streaming responses and progress tracking.

2. What Stays On Your Device

The following is stored only on your device (browser IndexedDB) and never uploaded to our servers:

Clearing your browser data or using a different device will reset this content.

3. Service Providers

To provide the Service, we share limited data with vetted service providers acting as data processors on our behalf. These providers fall into the following categories:

All processors are bound by data-processing agreements limiting use of your data to providing the Service. We do not sell or share your data for advertising or other commercial purposes.

4. Legal Basis for Processing

We process your data to fulfill our contract to provide the Service (GDPR Article 6(1)(b)). Analytics data is processed on the basis of legitimate interest (GDPR Article 6(1)(f)).

5. Data Retention

Account data is retained as long as your account exists. Usage logs are retained for 90 days for operational and billing purposes, then deleted. Server-side conversation caches expire after 30 minutes of inactivity.

6. Your Rights

You have the right to:

7. Children's Privacy

The Service is not intended for children under 13. If we learn we have collected data from a child under 13 without parental consent, we will delete it.

8. Security

We use HTTPS for all connections, encrypted password hashing, and database access controls. However, no system is fully secure. You are responsible for keeping your account password private.

9. Cookies and Tracking

We use browser localStorage to keep you signed in. We do not use tracking cookies or third-party analytics that identify you across the web.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via the Service or by email.

11. Contact

For privacy questions or data requests, contact us at support@try-chalk.com.

← Back to Chalk