Legal
Privacy Policy
What EduZen AI collects, who it reaches, and how long it stays. Short answer: what the app needs to teach you, and nothing to sell.
- Last updated 6 September 2026
- Effective 6 September 2026
The short version
- We never train AI on your material. Not your notes, files, recordings or conversations. Neither do our providers.
- Analytics, not advertising. Google Analytics measures visits and engagement and may set analytics cookies. We do not send it your account identity or study material, use Google Signals, or share data for advertising.
- We collect what running the app needs — your account, what you study, and how much storage and voice time you have used.
- Your files are private. They sit in a private bucket and are opened with links that last minutes and are minted only after we check it is you asking.
- Ask and it is gone. One email to [email protected] deletes your account and what is in it.
This summary is here to be read. It is not the agreement — the numbered sections below are.
Who we are
EduZen AI is operated by Linkintel, Inc., which is the data controller for the personal data described here. This policy explains what we collect when you use EduZen AI, why, who else sees it, and what you can tell us to do about it. It applies to the website, the app and our emails.
For anything on this page, write to [email protected].
What we collect
Your account
Your email address, your name if you give one, your chosen language and time zone, and — if you sign in with Google — your Google account identifier and profile picture. If you set a password we store a one-way hash of it, never the password itself.
What you study
The material and work the app exists to hold: files you upload, notes you write or generate, folders, audio you record and its transcript, lessons and the steps in them, quizzes and flashcards, your answers and marks, your study plan and sessions, the gaps we name for you, and your conversations with the voice tutor.
Your onboarding answers
What you tell us when you set up — your subject, your exam date, how much time you have, where you feel you are starting from. If you answer before you make an account, those answers are kept against a random identifier your browser generates, and the account claims them when you sign up or sign in to an unfinished account, including with Google. This includes your starting topic, what you want help with, and how you would like the tutor to explain things. We use these as preferences you shared, not as a test of your ability.
Usage and metering
How much storage you are using and how many voice minutes you have spent in your current allowance period, plus taught lessons and AI-created quiz or flashcard sets in the last 24 hours when those Free allowances apply. Also your streak, your study days and when you last studied, because the app shows them back to you.
Payment
If you subscribe, we store your Stripe customer identifier, your plan and its status. We never see or store your card number — that goes straight to Stripe and stays there.
How the app is used
So we can tell which parts of EduZen AI work and which are failing, our own server records a short line each time something meaningful happens — a lesson taught, a file brought in, a set of flashcards made, a request that was refused and the reason it was. Each line holds the name of the thing that happened, whether it worked, and your account. It never holds what you wrote: not the question you asked, not the title of your note, not a file name. These lines are deleted after six months.
Which link brought you here
The first time your browser opens EduZen AI we record the campaign parameters that were already in the address bar (the utm_ values on a link we shared), the site that linked to you — youtube.com, not the page — and which of our pages you landed on. It tells us which of our own posts and ads reach people. It is recorded once, by our own server, against the same random identifier your browser already generates for onboarding, and the account claims it when you sign up. This first-party record itself sets no cookie and does not rely on Google Analytics.
Website visits and engagement
We use Google Analytics 4 to understand visits and how people move through the website and app. Its default measurement includes page views, session statistics, approximate location, and browser and device information. Google uses the IP address during collection, including to derive approximate location; its handling then depends on the visitor’s region. The tag may set first-party analytics cookies such as _ga to distinguish a browser and session.
We do not send Google Analytics your name, email, account ID, questions, notes, file names, recordings, transcripts, or lesson content. Google Signals and advertising personalization are disabled in our tag. This browser-level measurement is separate from our own server’s feature and first-touch records above.
Technical
Our servers log ordinary request information: IP address, browser and device type, the page or endpoint requested, and the time. We use it to keep the service up, find bugs and stop abuse.
When you contact us
Your name, email address, subject and the message you send through our contact form. The form keeps short-lived one-way hashes derived from the address, IP address and submission to limit repeated and duplicate messages; it stores no copy in the app database. The queued email passes temporarily through Redis on its way to the support inbox.
Recordings and the microphone
Your browser asks before it ever opens the microphone, and it only opens when you start a recording or a voice conversation. Nothing is listened to in the background.
When you record, the audio is sent to our servers and on to the speech model that turns it into text. The transcript is saved to your note so you can read what was actually said, and the recording itself is kept in your library until you delete it. A voice conversation with the tutor is streamed through our API rather than from your browser straight to a model provider, so no provider credential and no tool access ever enters the page.
The words of a conversation with Wolfie are kept, as text, so the next call in it can pick up where you left off; the audio of the conversation is not kept. Each conversation is listed in the Wolfie panel and you can delete it there, which removes its words. The record that a call happened, when, and which actions it took stays, for safety.
Recording other people is your responsibility: check that you are allowed to where you are.
How we use it
We use what we collect to:
- run the app — explain topics, build plans, make notes, mark practice;
- keep your account working, and let you sign back in;
- answer a message you send to support;
- send you the emails the service needs: confirming your address, resetting a password, receipts, and study reminders if you turn them on;
- meter storage and voice minutes, and take payment for Pro;
- keep the service secure and available — spotting abuse, debugging failures, preventing fraud;
- understand aggregate visits and movement through the service;
- meet our legal and tax obligations.
We do not build advertising profiles, and we do not make decisions about you with legal effects by automated means.
Your material is not training data
Your files, notes, recordings, transcripts and conversations are never used to train, fine-tune or improve any AI model — ours or anyone else’s. The model providers we send requests to process the content to answer that request and are contractually prohibited from training on it.
What we do look at is counts: how many lessons were started, which calls failed, how long something took. Aggregate numbers with nobody in them.
Our legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we rely on these bases under the GDPR:
- Performance of a contract — running your account and everything you asked the app to do.
- Legitimate interests — keeping the service secure and reliable, preventing abuse and fraud, and understanding aggregate usage. We have weighed these against your rights.
- Consent — the microphone, and optional emails such as study reminders. You can withdraw it at any time, in Settings or in your browser.
- Legal obligation — tax and accounting records for payments.
Where your data is
Linkintel, Inc. is a company in the United States, and our providers process data there. If you are outside the United States, using EduZen AI means your data is transferred there. For transfers out of the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), which our providers have signed.
How long we keep it
Your material stays for as long as your account does — the point of it is that your notes are there next term.
- Delete a note, a file or a folder and it goes, including from storage.
- Delete your account and we remove your material and personal data. Copies in routine encrypted backups age out within 30 days.
- Sign-in links and password-reset links are stored only as a hash, are single-use, and expire in hours.
- Server logs are kept for a short period for security and debugging.
- The lines recording how the app is used are deleted after six months. Nothing reads them further back than that.
- Which link brought your browser here is kept for as long as the account, and goes with it when the account goes.
- Google Analytics data follows the retention controls configured in that service. Clearing its cookies stops this browser from carrying the same analytics identifier forward, but does not delete reports already produced; ask us if you want us to handle a data-rights request involving Google Analytics.
- Contact-form rate-limit hashes expire within 24 hours. The message itself stays in our support mailbox for as long as we need it to answer and keep a record of what was resolved.
- Records of payments are kept for as long as tax and accounting law requires, typically seven years. That is invoice data, not your study material.
How we protect it
Everything travels over encrypted connections. Passwords are stored as one-way hashes, so nobody here can read yours. Changing your password ends every other signed-in session immediately.
Your uploads live in a private bucket with no public address. Nothing is served from it directly: when you open a file we check that the file is yours and then mint a signed link that works for a few minutes and then does not. Every upload is identified by its own bytes rather than by what it claims to be.
Links we email you are treated as credentials — random, stored only as a hash, valid once, expiring, and checked for the purpose they were issued for.
No system is perfect. If a breach ever affects your personal data, we will tell you and the relevant regulator as the law requires.
Your choices and your rights
In the app you can, at any time:
- edit or delete any note, file, folder or recording;
- change your name, language, study days and reminders in Settings;
- change your password, which signs other sessions out;
- manage or cancel a subscription in Settings → Manage billing.
Depending on where you live, you also have the right to ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent. Write to [email protected] from the address on your account and we will answer within 30 days. We will not treat you worse for asking.
If you are in the EEA or the UK and you think we have got it wrong, you can complain to your local data protection authority. We would rather you told us first.
If you are in California
Under the CCPA/CPRA you may request the categories and specific pieces of personal information we have collected about you, ask us to correct or delete it, and be free from discrimination for asking. We do not sell personal information and we do not share it for cross-context behavioural advertising — there is no opt-out link because there is nothing to opt out of. Requests go to [email protected], and an authorised agent may make one on your behalf with written proof.
Children and family use
EduZen AI is a learning platform and anyone can learn on it, including children studying with a parent, guardian or teacher. Where a child uses it, we collect only what running the service needs; we do not profile them, advertise to them, or use their work for anything beyond teaching them.
A parent, guardian or teacher can write to [email protected] to see what a child’s account holds, correct it, have it deleted, or withdraw permission for us to keep it, and we will act on that request. If we learn that a child’s account was created without the consent their local law requires, we will delete it.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change matters — a new provider, a new purpose — we will tell you by email or in the app before it takes effect, rather than leaving you to notice.