← Back
1. What data do we collect
1.1 Account information
- Username and email address
- Password (encrypted/hashed, never readable by us)
- When signing in via Google: your name and email address as provided by Google
1.2 Study profile
- Your country of study, and for Belgium also the region (Flanders, Brussels or Wallonia). We use this to determine whether we can show you a course list and whether we can process your payment
- University or college, program, phase, and study year — only if you study in Flanders or Brussels; if you study elsewhere we don't ask for this
- The courses you follow and for which you upload documents or join group chat
1.3 Documents and AI functionality
- The documents you upload yourself, and the text extracted from them
- Technical representations ("embeddings") that make your documents searchable
- Your questions to the AI assistant and the answers given
- Quizzes and practice exams you create, and your answers to them
The AI assistant looks for the answer in your own documents. If it can't find everything there, it may supplement its answer with the language model's general knowledge; that part is marked as such in the answer. Quizzes and practice exams are built exclusively from your own documents.
1.4 Course group chat
- Messages and attachments you post in a course's group chat
Note: messages and attachments in group chat are visible to other users following the same course.
1.5 Usage, subscription, and marketing preferences
- Usage statistics and subscription data
- Payment-related identifiers linked to Stripe — for your subscription, we do not store card or bank account details ourselves (see 1.6 for the founder program exception)
- Whether you gave consent for marketing emails, and when
- Your language preference (Dutch/English/French), so we can, for example, send emails in the right language
- Per AI call (question, quiz, exam, text recognition): which model, how much text ("tokens") and what it cost us — to apply your usage limits and track our costs; never the content itself
1.6 Founder/affiliate data
- Your founder number and founder code
- Who referred you and who you referred, and the commissions resulting from that
- Only if you take part in the affiliate program and want to receive a commission: your bank account number (IBAN) and the account holder's name, solely to be able to pay out your commission. This data is stored encrypted and never shown in full, not even to you — only the last 4 characters of your IBAN are visible
- If you change your bank account number, we log that (who, when, and the last 4 characters of the old and new number), so there's a record in case of a dispute about a payment
1.7 Technical data
- Your IP address, for security only: after repeated failed login attempts on an account we temporarily lock that account; after many failed attempts from one IP address (for example a shared campus network) a cool-down applies to wrong attempts — with your correct password you can always log in. We also limit how often an account can be created, a password reset or a confirmation email re-requested from one IP address
- Your IP address also appears in our hosting provider's technical logs; those are overwritten automatically after a short time and we don't use them
2. Why and on what basis we process this data
- Account, AI functionality, group chat, subscriptions and payments — necessary for performance of the contract
- Account verification and functional emails — necessary for performance of the contract, no separate consent required
- Marketing emails — only with your explicit, voluntary consent, revocable at any time
- Security and abuse prevention — legitimate interest
3. Who we share your data with
We never sell your data. We only share data with parties that help us provide the service, under a data processing agreement:
- Render (Render Services, Inc.) — hosts the application, the database (account data, the text of your documents, chat messages) and the cache/sessions; the servers are located in Frankfurt, Germany
- Cloudflare (Cloudflare, Inc.) — stores the files themselves: your uploaded documents and the attachments from the group chat (R2 storage service, Western Europe region)
- Anthropic (Claude) — answers your questions and generates quizzes and practice exams; for that it receives the relevant passages from your documents and your question
- OpenAI — makes your documents searchable ("embeddings") and reads the text of scanned pages: for a scanned document, the pages are sent to OpenAI as images to extract the text (text recognition)
- Stripe — processes payments (SEPA direct debit)
- Brevo — sends account verification, functional, and (if permitted) marketing emails
- Google — only if you sign in via Google (we then receive your name and email address)
- Have I Been Pwned — when you choose a password, we check whether it appears in a known data breach; for that we send only the first 5 characters of an encrypted derivative (hash) of your password, never the password itself
Render, Cloudflare, Anthropic, OpenAI, Stripe and Google are US companies; even though the servers are in Europe, they may process data outside the EEA (e.g. the United States), with appropriate safeguards such as EU Standard Contractual Clauses.
4. Retention periods
- Account data and documents: for as long as your account is active
- Text messages in group chat (without attachment): automatically deleted after 1 year
- Attachments in group chat: automatically deleted after 2 years, unless marked as "old exam questions"
- Billing data: legally required accounting retention period (typically 7 years in Belgium)
- IBAN and account holder name (founders): for as long as you take part in the affiliate program, and afterwards for as long as the law requires us to keep payment records
- AI logs (per call: model, tokens, cost): automatically deleted after 90 days; after that only a monthly total per account remains
- Login-block records (IP address, email address, number of failed attempts): the per-account counter expires after 24 hours without a new attempt, the per-IP counter after 1 hour; the record is automatically deleted 30 days after the last attempt
- Desktop app connections (if you choose "Continue with Google" in the app, the app signs you in through your regular browser): for each connection we keep which account was connected and when, solely to complete that connection; the record is automatically deleted after 1 day
- Rate limits per IP address (account creation, password reset, confirmation email): counters of at most 1 hour
- Sessions: at most 7 days ("remember me"), otherwise until 3 hours after your last activity
4.1 What stays behind if you delete your account
If you delete your account, your documents, your chat messages, your
profile and your AI logs all go. Of your AI usage, only an anonymous,
aggregated monthly cost figure remains (all deleted accounts together),
which can no longer be traced back to you. If you were a founder, your
founder profile is removed completely as well — name, email address, bank
account number and the log of account changes — unless a commission
was ever paid out to you: in that case we keep your name, your
email address and your bank account number in our commission records,
together with the commissions themselves. If someone else earned a
commission because you took a yearly plan via their code, your name and
email address stay in that commission record, as proof of payment for that
founder.
The reason is accounting: a payment without a name is not usable proof of
payment. Without those two details we can no longer show afterwards who we
paid what, and the law requires us to be able to do that. This data is not
used for anything else, and it disappears once the legal retention period
for those payments has passed.
5. Your rights
- Access, correction, erasure ("right to be forgotten"), restriction, objection, and data portability
- Deletion and data requests can be made directly via your account settings
- You can withdraw consent at any time, without affecting your continued use of the service
- You can file a complaint with the Belgian Data Protection Authority — www.dataprotectionauthority.be
To exercise these rights, see the contact details on the last page of this document.
6. Security
- Encrypted connections (HTTPS)
- Passwords are never stored in readable form; at least 10 characters and checked against known data breaches
- Temporary block after repeated failed login attempts
- Founders' bank account numbers are stored encrypted
- File uploads are checked for type and content
7. Cookies
We only use functional cookies (such as your login session). No analytics or advertising cookies, so no cookie banner is required.
8. Changes
We may amend this statement; in case of significant changes, we will inform you via the app or by email.