Privacy
Privacy Policy
Last updated
APTO Study turns your lecture slides into study notes. This policy explains what we store to do that, why, and how you can see or delete it. Short version: your slides are yours, we don't sell your data, we don't run advertising trackers, and you can delete a deck and its files at any time.
1.Who we are
“APTO Study”, “we” and “us” mean the operator of the APTO Study website and app, Joseph Abraham. You can reach us about anything in this policy at our support email (coming soon).
2.What we collect
Your account. Your name, your email address and, if you sign up with a password, a scrypt hash of that password (we never store the password itself). You can change your name in Settings.
Google sign-in. If you continue with Google, we ask Google only for your basic profile: your name, your email address and Google's account ID for you (the openid email profile scopes). We do not get access to your Google Drive, Gmail, contacts or anything else in your Google account. The same applies to Google's one-tap “Continue as” prompt: Google hands us a signed token with your name, email address, whether Google has verified that address, your Google account ID and a link to your Google profile photo. We check the token and keep only the name, email address and account ID; we do not store the photo.
Google's sign-in prompt. If you are not signed in, the home page, the log in and sign up pages and shared-notes pages load Google's sign-in script from accounts.google.com so Google can offer that one-tap prompt. Loading it lets Google see that your browser visited the page, under Google's own privacy policy. Nothing is shared with us unless you choose to continue, and you can close the prompt; Google then waits before showing it again. It is never loaded once you are signed in.
What you upload and create. The slide files you upload (PDF, PowerPoint or images, up to 50 MB each) and their original file name, type and size; the text we extract from each slide; slide and figure images we render from the file; and everything the app makes from them or you add to it: notes, summaries, flashcards and your review history, questions you ask about your notes and their answers, classes, calendar events, practice exams and your answers and scores, and cram plans.
Billing. Your plan, its status, billing interval, trial and renewal dates, and the customer and subscription IDs that Stripe gives us. Your card details go to Stripe, not to us, and we never see or store your card number. We also keep counts of how many decks, slides, questions and exports you use each billing period, so we can apply your plan's limits.
Sign-in sessions. For each device you sign in on, a hashed session token, when it was created and last used, and your browser's user-agent string (so a session can be recognised).
Technical information. Your IP address is used briefly, in memory, to limit repeated sign-in and sign-up attempts and repeated error reports. We do not write it to our database. Our hosting provider may keep standard server logs that include IP addresses.
Error reports. When something goes wrong (on our server, in your browser, or while your notes are being made), we record the error so we can fix it: the type of error, a short message of at most 240 characters, the first few lines of the technical trace, the kind of page it happened on (for example “a notes page”, never the address with your deck’s ID or a query string), and which version of the app was running. Before an error is saved, we remove email addresses, passwords, keys and tokens, long IDs, anything in quotation marks or backticks (where a line from your slides could appear), and user names in file paths. We design error reports to exclude your account ID, your IP address, your cookies and what you uploaded; automatic removal is careful but not perfect, so error reports are read only by the APTO Study team and are deleted on the schedule below.
Referrals. Each account has a personal invite link with a random code (it is not made from your name or email). We count how many times a link is first opened, but keep nothing about the person who opened it. When someone signs up through a link, we store which account invited them, and later whether they made a first payment and whether the inviter earned a reward. The inviter sees only counts (invited, joined, paid, months earned), never a friend's name or email. To stop people referring themselves, we compare the two email addresses. About two weeks after the friend first pays, we ask Stripe whether that payment was refunded or disputed and whether the subscription is still running, and we ask Stripe for the card fingerprints on the friend's account and compare them with the inviter's and with the inviter's other invited friends. A card fingerprint is a code Stripe uses to recognise the same card number. It is not the card number, and we don't store it: Stripe keeps it, and we use only the result of the comparison. Until the referral is decided, we keep the Stripe customer, subscription and invoice IDs of the friend's first payment with it; we delete them as soon as the referral is decided, or when the friend's account is deleted. If Stripe tells us a payment was refunded, disputed or credited, we keep the Stripe customer or charge ID from that notice only until we have matched it to a referral, then delete it. We also note, once, the date an account first made a payment, so that credits earned during a free trial can wait for that first payment.
Study-content signals and feedback. Short topic signals from the decks you generate, and any flags, votes and self-check marks you give on knowledge-base items. See Improving the study content for exactly what is kept.
Free-trial checks. To give one free trial per person, we keep one-way scrambled codes (salted SHA-256 hashes) of the email address, of the browser or device (from the apto_dev cookie described under Cookies) and of the payment card used for a trial. The card codes come from Stripe's card fingerprint and from the card's last four digits, expiry month and year and billing postal code. A hash can't be turned back into your email or card number, and it isn't linked to your account. We keep these codes for 24 months, including after you delete your account, so that deleting and re-creating an account does not give a second trial. If a trial is refused because the card was already used, we note that against your account so Settings can tell you; that note is deleted with your account.
We do not use third-party analytics or advertising tools, and we do not collect your location or contacts. The only device identifier we use is the trial-check cookie described under Cookies.
3.How we use it
- To run the service: make your notes, flashcards, answers to your questions, exams and study plans, and show them to you.
- To keep you signed in and keep your account secure, including limiting abuse such as repeated sign-in attempts.
- To take payment through Stripe, apply your plan and its limits, and handle trials, renewals and cancellations.
- To answer you when you contact us.
- To meet legal obligations, such as tax and accounting records.
We do not sell your personal information, and we do not use it for advertising.
4.Your slides and AI
Your notes are built by APTO Study's own study engine and knowledge base, which run on our servers. We do not send your slides, your notes or your questions to outside AI providers, and we do not use your uploads to train AI models. The app has no connection to any AI model service.
People at APTO Study do not look at your uploads or notes unless you ask us to (for example, for help with a problem) or the law requires it.
5.Improving the study content
APTO Study's knowledge base is the library of explanations, memory tricks, test traps and self-check questions that appears in your notes. To find out where it needs work, we collect the following. The app never sends any of it to an AI model. Only the weekly totals described below, which contain no account information, inform study content we write offline.
- Topics we don't cover yet (every plan). When you generate a deck, we record which knowledge-base topics it matched, and short terms from its headings and key terms that matched none. Each term is shortened to at most 5 lower-case words and 60 characters, letters only. We drop any word containing a digit, common words and course-admin words (such as “lecture” or “quiz”), and we drop the whole term if it contains an email address, a web address, a personal title such as Dr or Prof, or what looks like a person's name (a capitalised word in the middle of an otherwise lower-case heading). These filters are careful but not perfect, so we treat the records as personal data, as described next. At most 20 headings and 40 terms are kept per deck. We never keep your slide text, notes, file names, deck titles, course name, account ID, email address or IP address for this.
- Raw records, and how they become totals. Each raw term record carries a weekly code made from your account ID with a secret key kept outside the database, and a code for the deck it came from. The account code changes every week and is used only to count how many different accounts sent a term. Because we could link these codes back to your account, raw records are pseudonymous, not anonymous: we delete them after 30 days, when you delete the deck they came from, or when you delete your account, whichever comes first. A term is kept in our weekly totals only if at least 5 different accounts sent it that week. The weekly totals, and counts of how many decks were generated and how many matched each topic, contain no account or deck information and are kept for 104 weeks.
- “This is wrong” flags. Where knowledge-base items are shown in your notes, you can flag one as wrong, with an optional note of up to 280 characters. Notes are read only by the APTO Study team to fix content. They are never sent to an AI model and never included in the material used to write new content.
- Helpful votes and self-check marks. You can mark a memory trick helpful or not helpful, and mark your answer to a self-check question “Got it” or “Missed it” (only your first try counts).
Flags, votes and self-check marks are stored with your account ID for two reasons only: so each account counts once, and so they are deleted when your account is deleted. They are kept for 365 days. The people and tools that write new study content see only item and topic IDs, counts, and the weekly topic totals. They never see your account, your decks or your notes on a flag.
8.How long we keep it
- Your uploads and everything made from them are kept until you delete the deck or your account. Deleting a deck stops any notes still being made from it, then removes its original file, slide images, extracted text, notes, flashcards, question history, share links and raw topic records straight away. If a file can't be removed at that moment, we keep retrying until it is. A file that fails to become notes, or that you cancel, is deleted as soon as that happens.
- Your account is kept until you delete it in Settings (see below).
- Referral records are kept while the inviting account exists, so its months earned and its progress toward the next one stay correct. If the invited friend deletes their account, the link to it is removed and only the inviter's counts remain; we also keep, for one year, a one-way code made from the friend's email address (not the address itself), so the same address can't join through an invite link again and earn a second reward. Deleting the inviting account deletes its code, its referral records and its rewards. A credit already added to a Stripe balance is part of Stripe's billing records.
- Usage counts (how many decks and questions you used in a period) are kept after a deck is deleted, so plan limits stay accurate. They contain no slide content.
- Free-trial codes (the one-way hashes of email, device and card described under Free-trial checks) are deleted 24 months after they were made, even if you delete your account sooner. They can't be turned back into your email or card number.
- Billing records are kept by us and by Stripe for as long as the law requires for tax and accounting.
- Study-content signals: raw topic records for 30 days, or until you delete the deck or your account if that is sooner; the weekly totals (no account information) for 104 weeks; your flags, votes and self-check marks for 365 days, or until your account is deleted if that is sooner.
- Error reports: only the most recent 5,000 from our server and notes generation, and the most recent 1,000 from browsers, are kept. Older ones are deleted automatically.
- Backups: every night, and before each update of the app, we back up the database and the uploaded files so we can restore the service if something breaks. We keep the newest backup from each of the last 7 days and from each of the 4 weeks before that, and delete older ones automatically. Something you delete can therefore remain in a backup for up to about five weeks, until that backup is deleted. Backups are used only to restore the service.
9.Your choices and rights
- Delete a deck from the app at any time. Its files and content are removed as described above.
- Turn off a share link from the deck's Share menu.
- Cancel a subscription from Settings. See the Terms for how cancellation works.
- Delete your account in Settings, under Account. You confirm with your password (or, if you sign in with Google, your email address). Any subscription is cancelled straight away, with no refund for the rest of the period (see the Terms), and anything still being made is stopped. Then we delete your account, your decks and their files, your notes, flashcards, exams, classes, calendar, share links, sessions, study history, raw topic records, and your flags, votes and self-check marks. The weekly topic totals described above stay, because they contain no account information; the referral code described above stays for one year if you joined through an invite link; the free-trial codes described above stay for their 24 months; copies in backups are deleted on the schedule above; and we keep only what we must by law, such as billing records, which Stripe also keeps.
- Get a copy of your data: email our support email (coming soon) from the address on your account.
Depending on where you live, you may have further rights, such as the right to access, correct, delete or move your information, to object to some uses, or to complain to a data-protection authority. We honour these rights for every user, wherever you live. We never sell or “share” personal information for cross-context advertising.
10.Children
APTO Study is for students aged 13 and over. It is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, contact us at our support email (coming soon) and we will delete it. If you are under 18, please use APTO Study with a parent or guardian's permission, and ask them before buying a subscription.
11.Security
Passwords are stored only as scrypt hashes. Session tokens are stored only as hashes and the session cookie cannot be read by page scripts. Uploaded files are never published on the open web: they are served only to their owner, or through a share link the owner created. Cookies are sent only over HTTPS in production. No system is perfectly secure, so please use a strong, unique password.
12.Where your data is stored
APTO Study's database, uploaded files and backups are stored with our hosting provider (details coming soon). If you use APTO Study from another country, your information is transferred to and processed there.
13.Changes to this policy
We will update this page when what we collect or how we use it changes, and change the “Last updated” date at the top. If a change is significant, we will tell you in the app or by email before it takes effect.
14.Contact
Questions or requests about your privacy: our support email (coming soon).
See also: Privacy Policy · Terms of Service · Attributions