Privacy Policy
1. Who We Are
TeachPaper ("we", "us", "our") operates the website teachpaper.com and provides AI-powered learning tools for scientific publications.
Contact: privacy@teachpaper.com
2. What Data We Collect
2.1 Account Data
- •Email address (for registration and login)
- •Name (optional)
- •Authentication provider data (if using Google Sign-In)
2.2 Uploaded Content
- •PDF files of scientific publications that you upload
- •Generated learning materials (quizzes, flashcards, summaries) derived from your uploads
2.3 Usage Data
- •Pages visited, features used, time spent
- •Quiz scores and flashcard review progress
- •Device type, browser, operating system
- •We use PostHog with cookieless tracking (no tracking cookies are set)
2.4 Payment Data
- •Payments are processed by Stripe. We do not store your credit card details.
- •We receive: transaction ID, subscription status, billing email.
2.5 Voice Conversations
- •Voice interactions with the AI Tutor are processed in real-time by ElevenLabs.
- •We do not record or store voice conversation audio.
- •Conversation transcripts may be temporarily stored to provide session continuity.
3. How We Use Your Data
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide the service (generate quizzes, flashcards, etc.) | Contract performance |
| Process payments | Contract performance |
| Send transactional emails (password reset, subscription) | Contract performance |
| Analyze usage to improve the product | Legitimate interest |
| Prevent abuse and enforce rate limits | Legitimate interest |
We do not:
- •Sell your personal data to third parties
- •Use your uploaded papers to train AI models
- •Share your data with advertisers
4. AI Processing
Your uploaded PDFs are sent to OpenAI's API (GPT-4o) for analysis and content generation. This means:
- •OpenAI processes the text of your documents to generate quizzes, summaries, flashcards, and other learning materials.
- •According to OpenAI’s API data usage policy, API inputs and outputs are not used to train their models.
- •We send only the text content — no personal metadata is attached to API requests.
- •Voice interactions are processed by ElevenLabs under their data processing terms.
5. Data Storage & Security
- •Hosting: Vercel (servers in the EU/US)
- •Database: Neon Serverless Postgres with encryption at rest
- •Encryption: All data transmitted over HTTPS (TLS 1.3)
- •Access control: Role-based, minimum privilege principle
6. Data Retention
| Data | Retention |
|---|---|
| Account data | Until you delete your account |
| Uploaded PDFs | Until you delete them, or 30 days after account deletion |
| Generated content (quizzes, flashcards) | Until you delete them, or 30 days after account deletion |
| Usage analytics | 24 months (aggregated, non-identifiable) |
| Payment records | As required by tax law (typically 5–7 years) |
7. Your Rights (GDPR)
If you are in the EU/EEA, you have the right to:
- •Access your personal data
- •Rectify inaccurate data
- •Delete your account and all associated data
- •Export your data in a portable format (JSON/CSV)
- •Object to processing based on legitimate interest
- •Withdraw consent at any time (where consent is the legal basis)
To exercise these rights, email us at privacy@teachpaper.com. We will respond within 30 days.
8. Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| OpenAI | AI text processing | openai.com/policies/privacy-policy |
| ElevenLabs | Voice AI conversations | elevenlabs.io/privacy-policy |
| Stripe | Payment processing | stripe.com/privacy |
| Vercel | Hosting | vercel.com/legal/privacy-policy |
| PostHog | Analytics (cookieless) | posthog.com/privacy |
| Sentry | Error monitoring | sentry.io/privacy |
10. Children
TeachPaper is not directed at children under 16. We do not knowingly collect data from children. If we learn we have collected data from a child, we will delete it promptly.
11. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or an in-app notice. The "Last updated" date at the top reflects the most recent revision.
12. Contact
For privacy-related inquiries:
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.