We collect the minimum data needed to run the Service. Your whiteboard drawings stay on your device. Your messages, screenshots, and voice audio are processed by our AI service providers so the tutor can respond. We do not sell your data.
Account data: email address, display name, and a hashed password (stored using industry-standard cryptographic hashing — we never see or store your password in plain text).
Usage data: number of AI responses, subscription tier, device type (user agent), timestamps of sessions, number of characters sent to text-to-speech, and learning-progress events (which math concepts you practiced and outcomes — for the in-app progress tracker).
Content data: text of messages you send and AI responses, screenshots of your whiteboard (sent to our AI provider for context), audio recordings of your voice (sent for speech-to-text transcription, then discarded). Full conversation history and your handwritten drawings are stored on YOUR device (IndexedDB). Text-only summaries may be cached briefly on our servers to support streaming responses and progress tracking.
The following is stored only on your device (browser IndexedDB) and never uploaded to our servers:
Clearing your browser data or using a different device will reset this content.
To provide the Service, we share limited data with vetted service providers acting as data processors on our behalf. These providers fall into the following categories:
All processors are bound by data-processing agreements limiting use of your data to providing the Service. We do not sell or share your data for advertising or other commercial purposes.
We process your data to fulfill our contract to provide the Service (GDPR Article 6(1)(b)). Analytics data is processed on the basis of legitimate interest (GDPR Article 6(1)(f)).
Account data is retained as long as your account exists. Usage logs are retained for 90 days for operational and billing purposes, then deleted. Server-side conversation caches expire after 30 minutes of inactivity.
You have the right to:
The Service is not intended for children under 13. If we learn we have collected data from a child under 13 without parental consent, we will delete it.
We use HTTPS for all connections, encrypted password hashing, and database access controls. However, no system is fully secure. You are responsible for keeping your account password private.
We use browser localStorage to keep you signed in. We do not use tracking cookies or third-party analytics that identify you across the web.
We may update this policy from time to time. Material changes will be communicated via the Service or by email.
For privacy questions or data requests, contact us at support@try-chalk.com.
← Back to Chalk