Back

Privacy Policy

How we collect, use, share, and protect your information

Last updated August 29, 2026

1. Who we are and what this policy covers

This Privacy Policy explains how the operator of Nebulearn("Nebulearn," "we," "us," or "our") collects, uses, discloses, and protects personal information. It applies to nebulearn.app and www.nebulearn.app, the Nebulearn iOS and Android apps, the Nebulearn Chrome extension, our APIs, and related features (together, the "Service").

Nebulearn is operated from Canada. We handle personal information in line with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where they apply, other laws such as GDPR, UK GDPR, and U.S. state privacy laws. This policy describes our practices. It is not legal advice and does not create rights beyond those the law already gives you.

Our Terms of Service govern use of the Service. If you do not agree with this policy, do not use the Service.

2. Information we collect

We collect information you provide, information created when you use the Service, and information from third parties that help us operate it.

Account and profile

Username, email address, password (stored in hashed form if you use email sign-up), Google or Apple account identifiers if you sign in that way, email-verification and password-reset tokens, signup method, optional profile fields such as bio, country, and avatar, role (for example student or teacher), referral codes, and preferences such as marketing-email unsubscribe status.

We do not collect a legal name as a required account field. If you type a name into a contact form, profile, or study content, we will store what you submit.

Study content and learning data

Folders, flashcards, quizzes, rich text, tags, notes, explanations, answer choices, photos attached to cards (stored in Amazon S3), import/export files, study-session results, spaced-repetition data, confidence ratings, streaks, ELO-style ratings, achievements, tutor chat threads, and similar learning records.

Files you submit for AI features

Text, images, PDFs, audio, and similar files you upload or paste so we can generate questions, transcribe audio, autofill cards, power the study tutor, or run related AI tools. Temporary copies on our servers are deleted after processing. Content sent to Google Gemini is handled under Google's terms (see Section 4).

Authentication and device data

Session cookies and tokens (including an httpOnly authentication cookie, a logged-in flag cookie, and a short-lived session cookie), JWTs stored in the browser, native app, or Chrome extension, OAuth tokens needed to keep you signed in, IP address, browser and device type, app version, and approximate security/usage signals used to run and protect the Service. We use Google reCAPTCHA on some sign-up and sign-in flows.

Payments

Subscription tier and status, billing provider, trial and renewal dates, Stripe customer and subscription IDs for web purchases, RevenueCat / App Store / Google Play identifiers for mobile purchases, and related transaction IDs. We do not receive or store full payment card numbers. Stripe, Apple, or Google process those.

Communications

Emails you send us, contact-form messages (processed by Formspree), support correspondence, and records of transactional emails we send (verification, password reset, security, and similar). If you receive optional product or marketing email, we store related preference and delivery information.

Usage, diagnostics, and acquisition

Feature use, pages viewed, referral or acquisition source, device and app surface (web, iOS, Android, or Chrome extension), in-app notification records (generally kept for a limited period), and aggregated product analytics. On the website we also use Google Analytics and, on some pages, Google AdSense (not in the native apps).

Information we do not intentionally collect

We do not require government ID, precise GPS location, or health records. Do not put sensitive personal information (health, financial account numbers, government IDs, or information about children under 13) into study content or AI uploads.

3. How we use information

We use personal information to:

  • Create and maintain your account, authenticate you, and sync content across devices.
  • Provide study features, spaced repetition, collaboration, publishing, and exports.
  • Run AI features you request, including sending necessary content to Google Gemini.
  • Process subscriptions, trials, storage add-ons, and restore purchases.
  • Send transactional email (verification, security, password reset, important account notices).
  • Send optional product or marketing email if you have not unsubscribed.
  • Provide customer support and respond to contact-form messages.
  • Prevent fraud, abuse, spam, and security incidents, and enforce our Terms.
  • Understand how the Service is used, fix bugs, and improve features. This includes aggregated metrics and, when needed to debug or support an account, looking at that account's usage.
  • Comply with law, respond to lawful requests, and protect our rights and users.

We do not sell your study materials as a product to other companies. We do not use your private decks to train our own machine-learning models.

4. Artificial intelligence

Nebulearn uses Google's paid Gemini Developer API (server-side API key; we pay Google for usage) for features such as generating questions and flashcards, autofill, chat, audio transcription, distractors, and the study tutor. This is not the consumer Gemini app. Some image-occlusion processing (for example OCR) may run on our own servers instead of Gemini.

When you use an AI feature, we send Google the material needed to fulfill your request. That can include prompts, uploaded or pasted files, selected webpage text or snips from the Chrome extension, card text, explanations, choices, study statistics, tutor chat history, and photos attached to cards. Files may also be uploaded to Google's Gemini Files API so the model can read them.

We do not use your content to train Nebulearn's own models. Under Google's current Gemini API Additional Terms for Paid Services, Google states that it does not use paid-API prompts (including files and system instructions) or generated responses to improve Google products. Google may still log prompts and responses for a limited time for abuse, safety, and legal compliance, and may process that data in countries where Google or its processors operate. Google's terms can change. If usage were ever on unpaid API quota, Google's unpaid terms could allow Google to use content to improve its services. We intend to keep these features on paid API usage.

Temporary copies stored on our servers for generation are deleted after processing. We cannot control how long Google retains API logs or Files API uploads under its own policies. Treat anything you send to an AI feature as visible to Google.

AI output can be wrong. See the Terms of Servicefor your responsibility to verify it.

5. Public profiles, publishing, and collaboration

Private folders stay in your account unless you share or publish them. If youpublish a folder, other users may browse, copy, like, and export it, including photos. If you share a folder with another user, they can access it according to the permission you grant. Public profiles may show your username, avatar, bio, country, stats, and published decks.

Copies that others have already made are not automatically removed if you later unpublish or delete the original. Do not publish personal information you are not willing to make public.

6. Who we share information with

We share personal information with service providers that process it for us, when you ask us to (for example publishing or sharing a deck), when required by law, or to protect rights and safety. We do not sell your personal information for money.

Current categories of recipients include:

  • Google — sign-in (OAuth), paid Gemini Developer API, Analytics, AdSense (website), reCAPTCHA, and fonts loaded from Google.
  • Apple — Sign in with Apple, and App Store billing for iOS in-app purchases.
  • Stripe — web payments and the customer billing portal.
  • RevenueCat — mobile subscription entitlements connecting our apps to Apple and Google billing.
  • Google Play — Android in-app purchases.
  • Amazon Web Services — file storage (S3 for photos) and email delivery (SES).
  • MongoDB Atlas — primary database hosting.
  • Redis — sessions and rate limiting, when enabled.
  • Vercel and our API hosts — website and application hosting.
  • Formspree — contact-form submissions.
  • Chrome / browser storage — extension authentication and local preferences on your device.

Providers may change as we operate the Service. Each provider's own privacy policy also applies to what they process. We require providers we contract with to use personal information only to provide their services to us, except where they act as independent controllers (for example Google acting on its own Analytics or Ads terms, or Apple and Google acting as stores).

We may also disclose information if we believe it is reasonably necessary to comply with law or legal process, enforce our Terms, or protect Nebulearn, users, or the public. If we sell or reorganize the business, personal information may be transferred as part of that transaction, subject to this policy or a successor policy.

7. Analytics and advertising

On the website we use Google Analytics 4 to understand how the Service is used (pages, devices, general location derived by Google, and similar). The Chrome extension may also send limited Analytics events with a stored client identifier.

On some website pages we use Google AdSense to show ads. Google and its partners may use cookies or similar identifiers for advertising, including to measure ads and, where permitted, to personalize them. Native iOS and Android apps do not load Google Analytics or AdSense in the app shell.

You can control Google Analytics and ads through your browser settings, Google's ad settings, and industry opt-out tools such as the Digital Advertising Alliance. Blocking cookies may limit some website features.

8. Cookies and similar technologies

We and our providers use cookies, local storage, and similar technologies:

  • Essential: authentication (authToken), logged-in state (loggedIn), and short-lived session (nebulearn_session). The Service will not work properly without these.
  • Preferences: theme and similar settings stored locally.
  • Analytics and advertising: Google Analytics and AdSense cookies on the website, as described above.
  • Security: reCAPTCHA and related Google cookies on some auth flows.

The native apps store authentication and preferences on-device (for example local storage or app preferences) rather than website cookies. The extension stores a login token and some preferences in Chrome storage.

9. Payments

Web billing is handled by Stripe. Mobile subscriptions and some add-ons are handled by Apple or Google through RevenueCat. Those companies collect payment details under their own policies. We keep subscription status and identifiers needed to provide paid features, cancel, or restore purchases.

10. Native apps and Chrome extension

iOS and Android

The apps may store a login token and preferences on your device, schedule local study reminders you turn on (these are not sent through our servers as push notifications), and process in-app purchases via RevenueCat / the stores. Social login uses Google and/or Apple.

Chrome extension

If you use the extension, it can access page content you choose to capture (selected text, generate-from-page actions, or a screen snip) on websites you visit, and send that content to Nebulearn, including to AI features. It may read and write the clipboard when you use capture features. It stores a login token locally and may sync AI-instruction profiles through Chrome sync storage. We do not use the extension to collect your full browsing history.

11. How long we keep information

We keep account and study data while your account is active. If you delete your account, we delete or de-identify associated personal data within about 30 days, except:

  • information we must keep for law, accounting, dispute, or security purposes (kept only as long as needed for those purposes);
  • backup copies, which age out on our backup cycle;
  • content you published or shared that other users have already copied;
  • anonymized or aggregated analytics that cannot reasonably identify you;
  • information our processors retain under their own legal requirements (for example Stripe records or Google API safety logs).

In-app notifications are generally retained for a limited period (currently about 90 days). Transactional email logs and security logs are kept as reasonably needed to operate and protect the Service.

12. Security

We use reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit (HTTPS), hashed passwords, access controls, and hosting with reputable providers. No method of transmission or storage is completely secure. You are responsible for using a strong unique password and for activity on your account.

We do not currently offer two-factor authentication. Protect your email account, because it can be used to reset access.

13. International transfers

We operate from Canada. Your information may be processed in Canada, the United States, the European Union, and other countries where we or our providers (including Google, Amazon, MongoDB, Stripe, Apple, and hosting partners) have facilities. Those countries may have privacy laws that differ from the laws where you live. Where required, we rely on appropriate safeguards such as contractual commitments with providers.

14. Children

The Service is not directed to children under 13. You must be at least 13, and at least the minimum age required in your country if that age is higher (for example 16 in some EEA countries). We do not knowingly collect personal information from children under 13.

If you believe a child under 13 has created an account, contact us. We will delete the account and associated personal information. Parents or guardians of users under the age of majority should supervise use of the Service.

15. Your rights and choices

Depending on where you live, you may have some or all of the following rights:

  • Access and correction: view and update account and study content in the Service, or ask us for a copy of personal information we hold.
  • Deletion: delete your account in Settings, which removes associated data as described in Section 11. You can also email us to request deletion.
  • Export: download your materials using in-app export tools (such as spreadsheet, document, or Nebulearn package formats) before you delete your account.
  • Email: unsubscribe from optional marketing email using the link in those emails or your email preferences. You will still receive transactional and security messages.
  • Consent withdrawal: stop using optional features (AI uploads, publishing, marketing email, local reminders). Essential processing needed to run an account continues until you delete the account.
  • Complaints: you may complain to us and, if you are in Canada, to the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner. EEA/UK users may complain to their local supervisory authority.

To make a request, email nebulearn.app@gmail.com. We may need to verify your identity. We will respond within the time the applicable law requires (PIPEDA generally expects a response within 30 days).

16. California and other U.S. state privacy rights

If you are a consumer in California or another U.S. state with a comprehensive privacy law, you may have rights to know, access, correct, delete, and obtain a portable copy of personal information, and to opt out of certain "sales" or "sharing" of personal information for targeted advertising, and from certain profiling, subject to legal exceptions.

We do not sell personal information for money. On the website, Google Analytics and Google AdSense may use cookies and similar identifiers in ways that some state laws treat as "sale" or "sharing" for cross-context behavioral advertising. Native apps do not load those website ad/analytics tags. To opt out of that kind of advertising, use Google's ad settings, your browser's cookie controls, or industry opt-out pages. You may also email us to request that we record an opt-out preference for your account.

We do not knowingly sell or share the personal information of consumers under 16. We will not discriminate against you for exercising privacy rights.

Categories of personal information we collect, sources, and purposes are described in Sections 2–7. We disclose those categories to the service providers listed in Section 6. We do not use sensitive personal information to infer characteristics about you.

17. Additional information for the EEA, UK, and Switzerland

If European data-protection law applies, Nebulearn is the controller of personal data processed to provide the Service to you. Our legal bases typically include:

  • Contract: creating an account, providing the Service you request, billing, and support.
  • Legitimate interests: securing the Service, preventing abuse, understanding aggregated usage, and improving features, where those interests are not overridden by your rights.
  • Consent: optional marketing email, and non-essential analytics or advertising cookies where consent is required. You may withdraw consent at any time without affecting prior processing.
  • Legal obligation: tax, accounting, and responding to lawful requests.

You may have rights of access, rectification, erasure, restriction, objection, and data portability, and the right to withdraw consent. AI features process content you choose to submit; they are not used to make legal or similarly significant decisions about you without human involvement.

18. Security incidents

If we become aware of a breach of security safeguards involving personal information that creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as PIPEDA requires, and we will notify others as other applicable laws require.

19. Changes to this policy

We may update this policy to reflect changes in the Service, providers, or the law. We will revise the "Last updated" date. For material changes we may also notify you by email or in the Service. Continued use after an update means you accept the revised policy. If you do not agree, stop using the Service and delete your account.

20. Contact

Privacy questions, access or deletion requests, and complaints: email the operator of Nebulearn. This address is our privacy contact for PIPEDA purposes.

Support: support@nebulearn.app · Contact form · Terms of Service