Claryfied is used by students, many of them children, so it handles information that deserves care: the questions they type, the homework they photograph, and the lessons they watch. This page says exactly what we do with each of them — including what we keep and what, like the photographs, we never store.
If you are a parent or guardian, the sections headed “Children and parents”, “Our minimum age, and what we ask of parents” and “What a parent or guardian can do at any time” are the ones written for you. They are the direct notice to parents that the law in several countries requires, and you can read them on their own.
The short version
- We collect what we need to run a tutor and to bill for it: your account details (your name, email and the education level you give us), the questions you ask and the lessons we build from them, and records of how those lessons are used and what they cost us. Payments run through our merchant of record, Dodo Payments, so all we hold is your plan and a payment reference — never your card number. The full list, item by item, is in “What we collect” below.
- We do not sell, rent or license your information, and we do not build a dataset out of it. There is no advertising on Claryfied and no ad or tracking pixel in the site.
- We do not profile children or target anything at them. No behavioural tracking, no interest categories, no recommendations built from a child's activity.
- Your questions go to the AI provider that generates the lesson. We only use providers that are contractually barred from training their models on what we send.
- The text of a question is erased 12 months after it is asked — except the copy kept as the title of the lesson it produced, which stays in your library for as long as that lesson does. Your library holds your 12 most recent lessons, plus every lesson you bookmark to keep. And you can delete your account, and everything on it, yourself, from your profile page — one button, no email to us, no waiting.
Who is responsible for your information
Nela Kosigi Pranesh, an individual based in India, is the controller of the personal information described here. Contact us about anything on this page at privacy@claryfied.com.
We operate from India and do not offer Claryfied to customers in India. It is available to students in the United States, Canada and Australia; the regional sections further down set out the rules that apply where you live.
Because we operate from India, we handle privacy questions and complaints under India's Digital Personal Data Protection Act, 2023, as well as under the law where you live. Write to us about anything on this page at privacy@claryfied.com and we will deal with it; wherever you live, you can also raise it with your own data protection authority — the routes are listed under “Your rights”.
What we collect
| What | Specifically | Where it comes from |
|---|---|---|
| Account details | First and last name, email address, the education level you tell us, and a password stored only as a cryptographic hash. If you sign in with Google, we receive your name, email address and Google account identifier instead of a password. | You, at signup |
| Age check | A date of birth, asked once at signup to confirm you are at least 13. We keep only the fact that the check was passed and when — never the date of birth itself. | You, at signup |
| What you ask | The text of every question you ask, and any follow-up questions in the same session. This is free text, so it contains whatever you typed. | You, on the board |
| Photographs you upload | Images of homework or textbook problems you attach to a question. These are sent to the AI provider to read the question and are not stored on our servers afterwards. | You, on the board |
| Voice input | If you use the microphone button, your browser converts speech to text. On most browsers this is done by the browser maker's own service — in Chrome, audio goes to Google, not to us. We receive only the resulting text, exactly as if you had typed it. | Your browser |
| Your lessons | The finished board and its narration, saved to your library so you can replay it. | Generated for you |
| Usage and cost records | For each lesson: the question, its length setting, whether a photo was attached, whether it was a follow-up, what it cost us to generate, how long it took, and whether it succeeded. | Our servers |
| Playback records | Whether a lesson was watched to the end, how far through you got, and how long you waited for the first drawing. | Your browser |
| Subscription details | Your plan, its status and renewal date, and a payment reference. We do not receive or store card numbers. | Our payment provider |
| Technical records | IP address, browser type and request logs, kept briefly by our hosting provider for security and debugging, plus aggregate, cookieless page analytics. | Automatic |
| Failure records | When something on Claryfied goes wrong, we record which part of the app failed, a short code for what went wrong, and the error message our own systems produced — plus, where the failure interrupted something you were doing while signed in, your account identifier, so we can tell whose lesson or payment to put right. We do not record your IP address here, and we never record the text of your question. Requests we turn away on purpose — a mistyped password, or an attempt to use a part of the app that needs an account — are kept only as anonymous hourly totals, with nothing in them that points to a person. | Our servers |
We do not ask for and do not want special-category information — health, religion, biometrics — and you should not put it into a question or a photograph. A photograph should show only the homework or problem you are asking about: please keep faces, names, ID documents, addresses and anything else that identifies you or anyone else out of the frame. A photo is sent to the AI provider only to read your question and is never stored — but the safest personal information is the kind you never send in the first place.
Why we use it
We do not use your information for advertising, we do not build marketing profiles, and we make no automated decisions about you that produce legal or similarly significant effects.
| Purpose | Our basis for it |
|---|---|
| Creating and running your account, generating lessons, saving them to your library | Performance of a contract with you |
| Checking that an account holder is old enough to be here | Compliance with a legal obligation; our legitimate interest in keeping under-13s off a service not built for them |
| Taking payment, issuing receipts, preventing payment fraud | Performance of a contract; compliance with a legal obligation |
| Keeping the service secure and abuse-free | Our legitimate interest in protecting the service and its users |
| Noticing when part of the service breaks, and fixing it | Our legitimate interest in keeping the service working; performance of a contract with you |
| Understanding what a lesson costs and whether it worked, so the product improves | Our legitimate interest in improving the service, balanced by keeping this data server-side and never using it to profile a student |
| Sending service emails — confirmations, one-time codes, billing notices | Performance of a contract |
| Meeting tax, accounting and legal obligations | Compliance with a legal obligation |
Who we share it with
We use a small number of service providers to run Claryfied. Each one is bound by a contract that limits them to processing information on our instructions, and each receives only what it needs.
| Provider | What it receives |
|---|---|
| AI model provider — OpenAI | Your question, any photograph attached to it, and the context of earlier questions in the same session, in order to generate the lesson. Our agreement bars the provider from using this to train its models, and content is retained by them only briefly, for abuse monitoring. |
| DeepInfra (narration) | The text of the narration to be spoken aloud. This is written by the model, but it follows from your question. |
| Supabase | Database, authentication and file storage — account details, saved lessons, cached narration audio. |
| Vercel | Hosting and request logs; cookieless page analytics. |
| Resend | Your email address and the content of service emails we send you. |
| Dodo Payments | Our merchant of record: they sell the subscription to you as the seller, take the payment and handle the tax on it, receiving your name, email, country and payment details, which go to them directly. As the seller, they also send you transactional and service emails about your payment and subscription — such as receipts, renewal reminders, and payment, refund or cancellation notices, and other billing-related messages — to the email address on your account. As a separate controller of that payment data, they process it under their own privacy policy. |
| If you sign in with Google, the sign-in exchange itself. If you use voice input in Chrome, the audio your browser sends for transcription. | |
| Rekomi (affiliate program) | Only if you arrive through an affiliate partner's link. We pass the partner's referral code into checkout, and Rekomi receives the resulting payment and subscription events from Dodo Payments — the referral code, the amount, and your name and email — so the referring partner can be credited and paid a commission. Rekomi does not use this to advertise to you or to track you across other sites. As the payer of record for those commissions, Rekomi collects tax details from the partners, not from you. |
There is one way you can make part of this public yourself: sharing a lesson. If you press Share on a saved lesson and confirm, we create an unlisted web link for it, and anyone who has that link can watch that lesson — including the question you asked, which is the lesson’s title — without an account. Nothing is shared this way unless you ask for it, one lesson at a time. You can stop sharing at any time from the same button, which permanently disables the link; it cannot, of course, undo what someone has already seen or saved. Shared lessons are not listed anywhere on our site and we ask search engines not to index them.
Beyond those, we share information only where we are legally required to — a valid order from a court or authority — or where a business we are part of is sold, in which case the buyer is bound by this policy for information they receive. We have never sold, rented or licensed personal information, and we do not do so.
About the AI providers specifically
This is the part of the pipeline most worth being clear about, because a question is the most personal thing a student gives us.
When you ask a question, its text and any photograph are sent to the AI provider that generates your lesson. We select providers on commercial terms that prohibit training on the content we send and that limit how long they retain it. We do not send your name, email address or account identifier along with a question — the provider receives the question, not the student.
The model does not evaluate you, score you or decide anything about your education. It draws an explanation and it forgets: each question is generated fresh, and the only memory in a session is the earlier questions on the same board, which are sent along so a follow-up makes sense.
How long we keep it
| What | How long |
|---|---|
| Account and profile | Until you delete your account. There is no expiry we apply to it. |
| Saved lessons (your library) | Your library keeps your 12 most recent lessons, plus every lesson you bookmark to keep — there is no limit on bookmarks. Each time you generate a new one, the oldest lesson you have not bookmarked drops off automatically; a bookmarked lesson stays until you remove the bookmark or delete it. Because each lesson is titled by the question that produced it, this is also how long that copy of the question lasts. Deleting your account removes them all at once. |
| Shared lessons | A lesson you have chosen to share stays readable by anyone holding its link until you stop sharing it, or until you delete the lesson or your account — whichever comes first. Sharing also bookmarks the lesson, so it is kept in your library rather than ageing out while its link is live. Stopping disables the link permanently. |
| Questions | The text of a question is permanently erased 12 months after it was asked, by a job that runs every day. Deleting your account erases the text of every question on it immediately. What remains afterwards is an anonymous record of what a lesson cost us and whether it worked, with no way back to you. |
| Playback records | Erased 12 months after the lesson was watched. Deleting your account unlinks them from you immediately, leaving anonymous statistics. |
| Photographs you upload | Not stored. They are passed to the AI provider to generate the lesson and discarded when the request finishes. |
| Cached narration audio | Held while the lesson can still be replayed, keyed by a hash of the text rather than by user. |
| One-time codes for email changes | The code itself stops working 10 minutes after we send it, and is stored only as a hash — never as the code. The record of the request is deleted the moment the change completes; one that was started and then abandoned is deleted within 2 days by the same daily job. |
| Payment and tax records | Held by our merchant of record, Dodo Payments, who is the seller on your receipt and keeps the transaction and tax records for as long as tax and accounting law requires. We keep only a minimal mirror of your charges so you can see your billing history in the app, and we delete our copy when you delete your account — the merchant of record's records remain with them, as the law requires. |
| Server and security logs | Up to 30 days. |
| Failure records | Erased 90 days after the failure, by the same daily job. Deleting your account unlinks them from you straight away, leaving an anonymous record of what broke. The hourly totals of refused requests hold nothing about you at any stage. |
Children and parents
This section is written for parents and guardians, and it is the part of this policy worth reading if you read nothing else. It also serves as the notice to parents required by the Children's Online Privacy Protection Act in the United States.
Claryfied has a minimum age of 13, and we ask for a date of birth at signup to enforce it. It is not built for younger children, we do not knowingly collect anything from them, and if we learn that an account belongs to one we close it and delete what is on it — tell us at privacy@claryfied.com if you believe that has happened.
Between 13 and 18 a student is still a child in the eyes of the law in most of the world. Everything in the tables above applies to their account. What follows is what changes because it is a child's.
- No advertising, ever. There is none in Claryfied, and there is no ad or tracking pixel in the site.
- No profile of your child. We do not build interest categories, we do not track across other sites, and we do not target anything at a student based on their behaviour.
- Nothing about your child is sold, rented or licensed. Not their name, email address, age, photograph, or any record of what your child in particular has asked — and not the questions themselves — to anyone, at any price.
- No training on your child's questions. Our agreements with the AI providers prohibit it.
- Nothing public. There is no feed, no profile page, no chat with other users, and no way for anyone else to reach your child through Claryfied.
- No photographs kept. A photograph of a homework problem is passed to the AI provider to be read, then discarded. It is never stored.
- No more than the service needs. We ask for a name, an email address, an education level, and the questions themselves. No phone number, no address, no location, no contacts, and no photograph of your child.
One thing that is not a privacy point but belongs in the part a parent reads: every lesson is generated by AI at the moment it is asked for, and it can be confidently wrong. Claryfied is a study aid, not a teacher and not a source of record — and it is at its best when you watch a lesson back with your child.
Our minimum age, and what we ask of parents
A student aged 13 to 17 needs their parent or guardian's permission to use Claryfied, and our Terms require them to confirm they have it. Asking a question and generating a lesson requires a paid subscription, so in practice the parent or guardian who pays is already in the loop before a student asks anything — a free account can only replay the public sample lessons, which anyone can watch without signing up at all. We would rather that real involvement than a box ticked by a fourteen-year-old on their own.
If you are a parent or guardian and you did not give that permission, write to privacy@claryfied.com from any address and we will close the account and erase it, no questions asked and no proof required. The same applies if you simply want it closed.
We do not require a separate consent step from parents today. If we introduce one, we will say so here first, and we will not quietly start collecting parents' contact details without telling you.
What a parent or guardian can do at any time
| You want to… | How |
|---|---|
| See what your child has asked | Sign in to the account. Its library holds the recent lessons — the 12 most recent, plus every one bookmarked — each titled by the question that produced it and replaying exactly as it was taught. Sit down and watch them together. |
| Delete the account and all of it | The delete button on the profile page cancels any subscription on the account, then removes the account, the profile, the saved lessons and the text of every question asked on it. It is immediate, nothing further is charged, and it cannot be undone. |
| Refuse any further collection | Email privacy@claryfied.com. In practice this means closing the account, since asking questions is the whole service — we will say so plainly rather than pretend otherwise. |
| Complain | Write to us first at privacy@claryfied.com — most things we can sort out directly. If we can't, you can escalate to your data protection authority: in Australia, the OAIC; in Canada, the Office of the Privacy Commissioner; in the United States, the FTC or your state attorney general. |
Where your information goes
The database that holds your information is hosted in the United States, and most of our providers are there too. We are based in India, so our own team there may access your information to operate the service; and some providers, such as our hosting and content-delivery network, may process it in other countries where their infrastructure runs. Your information therefore crosses borders, and we remain responsible for it wherever it is processed; we put contractual and technical protections in place before a provider is used.
We assess each provider before using it and bind it by contract to protect your information to the standard the law where you live requires. The country-specific rules for Canada and Australia are set out in the regional sections further down.
Your rights
Wherever you live, you can ask us to give you a copy of what we hold about you, correct it, delete it, or stop a particular use of it. You can object to processing based on our legitimate interests, ask for your data in a portable format, and — where processing rests on consent — withdraw that consent at any time.
The fastest route to two of these needs no email at all: your profile page lets you correct your details and delete your account and everything on it. For anything else, write to privacy@claryfied.com from the address on the account. We respond within 30 days, and we will not charge you or make you justify the request.
If you think we have got it wrong, you can complain to a data protection authority: the Office of the Privacy Commissioner of Canada (or the Commission d'accès à l'information du Québec), or the Office of the Australian Information Commissioner. In the United States, you can contact the FTC or your state attorney general. We would appreciate the chance to fix it first.
How we protect it
- Everything travels over encrypted connections, and our database encrypts data at rest.
- Passwords are never stored — only a one-way hash, handled by our authentication provider.
- Our analytics tables have row-level security enabled with no access policies at all, which means no browser, signed in or not, can read them. Only server code holding a secret key can, and that key never reaches the browser.
- There is no path for one user's browser to write to another user's records; every write that matters goes through server code that checks who is asking.
- Access to production data is limited to the people who run the service, and we keep that number at the minimum a company our size can operate with.
- If a breach happens that puts you at risk, we will tell you and the relevant regulator within the deadlines the law sets where you live — including, in Australia, the Notifiable Data Breaches scheme.
Cookies, and why there is no banner
Most cookie sections are long because most sites carry advertising networks and trackers that follow you across the web. Claryfied carries none of that, so this is short and complete.
There is no consent banner on Claryfied. Almost everything we store in your browser is either strictly necessary to sign you in or a setting you asked for yourself. The one exception is an affiliate referral cookie, described below, which we set only if you reach us through a partner's link; it is a first-party cookie, is not used for advertising or to track you across other sites, and under the privacy rules that apply in the countries we serve it needs no consent. We would rather have no banner than one that trains people to click through it.
| What | Why | How long |
|---|---|---|
| Session cookies (sb-…) | Keep you signed in and refresh your session. Set by our authentication provider, Supabase. Without them you would be logged out on every page. | Until you sign out, or the session expires |
| Sign-in state cookies | Two short-lived cookies set while you sign in with Google — one carries a security token that prevents a forged sign-in, the other remembers the page to return you to. | A few minutes |
| Lesson length preference | Stored in your browser's local storage, not a cookie. Remembers whether you last chose a short, balanced or detailed lesson, so the picker opens where you left it. | Until you clear your browser data |
| Affiliate referral | Set only if you arrive through an affiliate partner's link. It stores a referral code so that, if you later subscribe, we can credit the partner who referred you and pay their commission. It is a first-party cookie, is not used for advertising, and does not track your browsing on other websites. Managed by our affiliate provider, Rekomi. | The referral window — a limited period, then it expires |
Apart from the affiliate referral cookie above, that is the entire list: no advertising cookie, no social media pixel, no session recording, no cross-site tracker. The affiliate cookie is first-party and records only a partner referral for commission — it does not follow you between sites or build a profile of you. Our page analytics, from Vercel, sets no cookies and stores no persistent identifier, so it cannot follow you between sites or recognise you on a later visit.
You can block or delete cookies in your browser settings. Blocking the session cookies means you cannot stay signed in, so Claryfied will not work while you are logged out — a technical consequence, not a penalty. Blocking the affiliate cookie simply means a partner will not be credited if you subscribe; nothing about your lessons works differently. We do not use advertising or cross-site tracking cookies, and if we ever added a cookie that required consent under the rules in the countries we serve, we would ask for your consent before setting it.
Regional details — United States
We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are used in California and other state privacy laws. We do not use or disclose sensitive personal information beyond what is needed to provide the service. There is nothing here to opt out of, because we don't do it.
Because we do not sell or share personal information — for advertising or anything else — there is nothing for a browser opt-out signal such as Global Privacy Control to act on. There is no sale or sharing to switch off, so none is needed to protect your data here.
Residents of California and of the growing list of states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Florida, Delaware, New Jersey and New Hampshire, among others — have the right to know, delete, correct and obtain a portable copy of their information, and to be free from discrimination for exercising those rights. Use the profile page or write to privacy@claryfied.com; an authorised agent may act for you with written proof.
Claryfied is not directed to children under 13 and we do not knowingly collect personal information from them, as those terms are used in the Children's Online Privacy Protection Act. We ask for a date of birth at signup and refuse accounts below that age. If you believe a child under 13 has given us information, write to privacy@claryfied.com and we will delete it and close the account.
Regional details — Canada
We handle personal information in line with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for residents of Quebec, the province's Law 25. We rely on the consent you give when you create an account and ask questions, and you may withdraw consent to any use that is not essential to providing the service.
You may ask us for access to the personal information we hold about you, for its correction, and — where the law allows — for its deletion, at privacy@claryfied.com. We do not make decisions about you based solely on automated processing.
Because our providers are outside Canada, your information is stored in the United States and processed there and in other countries where our service providers operate; and because we are based in India, our team there may also access it. We remain accountable for it under PIPEDA and require, by contract, that it receive a comparable level of protection. You can complain to the Office of the Privacy Commissioner of Canada, or, in Quebec, to the Commission d'accès à l'information du Québec.
Regional details — Australia
We handle personal information in line with Australia's Privacy Act 1988 and the Australian Privacy Principles (APPs). You may ask us for access to the personal information we hold about you and for its correction, at privacy@claryfied.com.
Because our providers are overseas, your information is stored in the United States, disclosed to and processed in other countries where our service providers operate, and may be accessed from India, where we are based. Under APP 8 we remain accountable for how those providers handle your information and take reasonable steps to ensure they meet Australian standards.
If a data breach happens that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as the Notifiable Data Breaches scheme requires. You can complain to us first at privacy@claryfied.com, and then to the OAIC.
Regional details — elsewhere
If you use Claryfied from a country not covered above, your local privacy law still applies where it gives you more than this policy does. Write to privacy@claryfied.com and we will honour the rights your law gives you.
Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we use information we already hold — a new category of data, a new purpose, a new kind of provider — we will email account holders before it takes effect, and where the change requires consent under the law that applies to you, we will ask for it rather than assume it.