Privacy Policy
How we protect and use your information
Last updated August 11, 2025
Nebulearn (nebulearn.app) is an AI-powered flashcard and spaced repetition study platform operated from Toronto, Ontario, Canada. This Privacy Policy explains how we collect, use, store, and protect the personal information and study data of students using our service. We are committed to GDPR-compliant and PIPEDA-compliant privacy practices. Create a free account or contact our support team with any privacy questions.
What Information We Collect
Account Information: When you create an account, we collect your name, email address, and encrypted password. We also store your subscription plan and preferences.
Study Content: We store the quizzes, flashcards, folders, and study materials you create. Each question stores performance statistics (correct/incorrect answers, confidence levels, review dates) that our spaced repetition algorithms use to recommend optimal study timing.
Uploaded Files: When you upload content for AI question generation, files are temporarily stored, sent to our AI service for processing, then immediately deleted. Only image files that you attach to specific questions are permanently stored as part of your study materials.
Usage Data: We track your study sessions, progress metrics, ELO ratings, streaks, and learning analytics to provide personalized recommendations and track your improvement.
Authentication Data: We store secure authentication tokens (like Google OAuth tokens) to keep you logged in and sync your account across devices.
Technical Information: We automatically collect browser type, device information, and usage patterns to ensure security and improve our service.
Payment Information: Payment details are processed securely by Stripe. We only store subscription status and billing history, never full payment card information.
How We Use Your Information
Provide Our Service: We use your data to generate AI questions, power spaced repetition algorithms, sync your content across devices, and provide personalized study recommendations.
Improve Nebulearn: We analyze anonymized, aggregated usage patterns to enhance features, fix bugs, and develop new functionality. Individual user data is never used for this purpose.
Communication: We send important account notifications, security alerts, and optional product updates (you can unsubscribe from marketing emails anytime).
Customer Support: When you contact us, we use your information to provide helpful assistance and resolve issues.
Security: We monitor for suspicious activity, prevent fraud, and protect against unauthorized access.
Our Privacy Promise
Your content is completely private. We never share, sell, or make public your study materials, quiz questions, or personal learning data. Your information belongs to you, and we're committed to keeping it secure and confidential.
We only share data when legally required or with your explicit consent. Third-party services we use (listed below) have strict data protection agreements and cannot access your personal study content.
Third-Party Services
Nebulearn uses trusted services to operate effectively:
AI Processing: Processes your uploaded content to generate questions using fine-tuned language models, but files are immediately deleted after processing.
Stripe: Handles all payment processing securely. We never see your full payment card details.
Google Analytics & Vercel Analytics: Help us understand how users interact with Nebulearn through anonymized usage statistics. No personal study content is shared.
Google Ads: We may use Google Ads for marketing. Google may collect anonymized data about your visit for advertising purposes.
Cloud Hosting: Our servers and databases are hosted on secure cloud infrastructure with enterprise-grade security.
Each service has its own privacy policy and data protection measures. We carefully vet all partners to ensure they meet our privacy standards.
Data Security
We protect your information using industry-standard security measures including encryption in transit and at rest, secure servers, access controls, and regular security audits. While no system is 100% secure, we continuously monitor and improve our security practices.
Your password is encrypted and never stored in plain text. We recommend using a strong, unique password and enabling two-factor authentication when available.
Your Rights and Controls
Access Your Data: You can view and download all your study content from your account dashboard.
Delete Your Account: You can permanently delete your account and all associated data from your settings. This action cannot be undone.
Export Your Content: Download your quizzes, flashcards, and study materials in various formats anytime before deleting your account.
Email Preferences: Unsubscribe from marketing emails while still receiving important account and security notifications.
Data Correction: Update your account information, correct errors, or modify your study content anytime.
Cookies and Tracking
Essential Cookies: We use necessary cookies to keep you logged in, remember your preferences, and maintain your session security. These are required for the service to function.
Analytics Cookies: We use Google Analytics and Vercel Analytics to understand how users interact with Nebulearn through anonymized usage statistics. This helps us improve the platform.
Advertising Cookies: Google Ads may place cookies for marketing and advertising purposes when you visit our site.
You can control cookie settings in your browser, though disabling essential cookies will prevent you from using Nebulearn effectively. You can opt out of Google Analytics tracking and advertising cookies through your browser settings or Google's opt-out tools.
Children's Privacy (COPPA)
You must be 13 or older to use Nebulearn. COPPA (Children's Online Privacy Protection Act) is a US federal law that requires special protections for children under 13. We don't knowingly collect personal information from children under 13.
If we discover that someone under 13 has created an account, we'll immediately delete it and all associated data. Parents who believe their child under 13 has used Nebulearn should contact us immediately.
Data Retention
We keep your account and study data as long as your account is active. If you delete your account, we permanently remove all your personal data within 30 days, except where required by law for security or legal purposes.
Anonymized analytics data may be retained longer to help improve Nebulearn, but cannot be linked back to you personally.
International Users
Nebulearn is operated from Canada. If you're using our service from outside Canada, your information may be transferred to and processed in Canada and other countries where our service providers operate. We ensure appropriate safeguards are in place to protect your privacy regardless of location.
Policy Changes
We may update this privacy policy to reflect changes in our practices or applicable laws. We'll notify you of significant changes via email or in-app notification. The “Last updated” date at the top shows when this policy was last modified.
Privacy Questions?
If you have questions about this privacy policy or how we handle your information, please contact us: nebulearn.app@gmail.com
See also our Terms of Service.