Privacy Policy
Effective August 6, 2026 · Contact: legal@notekit.net
Who operates NoteKit
What we collect
- Your email address — used to create your account and send you sign-in links.
- A derived, pseudonymous account identifier (not your email itself) under which your data is stored.
- The PDFs you upload.
- The study kits we generate from them.
- Usage counters — your plan and how much of it you have used — so we can run the service and monitor our own API costs.
- For sign-in security only: a one-way hash of your email address and of the IP address used to request a sign-in link, kept to limit abuse.
Your self-grade answers are kept only in your browser (localStorage) and are never sent to us.
Where your data lives
Your uploaded files, kits, and account record are stored per-account in Vercel Blob storage in the United States, and the application itself is hosted by Vercel.
We set two strictly-necessary cookies, and no others (no analytics or advertising cookies): when you request a sign-in link, a short-lived cookie (15 minutes) binds that link to your browser, so a forwarded link can’t be used to sign in anywhere else; it is deleted the moment you sign in. Once signed in, a session cookie — a signed token — keeps you logged in.
AI processing
To build your study kit, we send your uploaded PDFs (your lecture file and, if you attach one, your past exam or tutorial file) and the kit we generate from them to a third-party AI model provider for processing. Only one provider is active at a time. The provider we currently use is OpenAI (OpenAI, L.L.C., United States). Our service can also run on Google (the Gemini API, Google LLC, United States), which we keep available as an alternative; if we switch to it, we will update this page and the effective date above.
Under the standard terms of both providers’ paid/business API tiers, data sent through the API is not used to train or improve their models unless the customer opts in. This policy relies on those provider terms; it does not make a separate guarantee about training.
The file we upload to the provider is held there for processing and is deleted once your kit has been generated. As a backstop in case that deletion request itself fails, the file also auto-expires on the active provider’s own schedule regardless: within 1 hour on OpenAI (which we set explicitly), or within about 48 hours on Google’s Gemini API (its own default) if we are using that provider instead — so the file is never left there indefinitely either way. Both providers process this data in the United States (see “International transfer”).
Separately from that file: our current provider, OpenAI, may itself retain the prompt and the generated kit text for up to 30 days to provide the service and to monitor for abuse — this is OpenAI’s own standard retention for API usage and applies regardless of the no-store setting we request on every call; we cannot turn it off from our side. After 30 days that copy is removed from OpenAI’s systems, unless longer retention is required by law or is reasonably necessary to protect OpenAI’s services or others from harm. We have not requested, and do not have, OpenAI’s zero-data-retention program, which would remove this window entirely.
Who we share data with
We do not sell personal data, and we do not share it for advertising. We use a small number of service providers who process data on our behalf:
- Vercel Inc. (United States) — hosts the application and stores your uploaded PDFs and generated kits (Vercel Blob).
- OpenAI, L.L.C. (United States) — the AI provider we currently use; it receives your uploaded PDF and generated kit text to produce your study kit. Google LLC (United States) is kept available as an alternative provider for the same purpose.
- Resend (United States) — receives your email address to deliver the sign-in link you request.
We update this list when it changes.
Why we process your data, and on what basis
- Creating and running your account, storing your uploads, and generating study kits — this is the service you asked for, so we process this data to perform our contract with you.
- Limiting sign-in attempts and daily usage — our legitimate interest in keeping the service secure, available, and abuse-free.
- Keeping cost and usage records — running our business and meeting accounting obligations.
- Where the law where you live requires consent for any of the above (including guardian consent for minors), we rely on the consent you give at sign-in.
Your rights
You can ask us to: tell you what data we hold about you and how we use it; give you a copy of it; correct it if it is wrong or incomplete; delete it; or stop or limit a particular use. Email legal@notekit.net and we will respond within 30 days. Deleting your chapters or your whole account yourself (see below) is usually faster.
If you are in Saudi Arabia, you can complain to the Saudi Data & AI Authority (SDAIA). If you are in the UK or the EU, you can complain to your national data protection authority.
What we don’t do
International transfer
NoteKit is operated from Saudi Arabia and our service providers are in the United States, so wherever you use NoteKit from, your personal data is transferred to and processed in the United States.
Before making these transfers we carry out a transfer risk assessment, and we rely on the data-protection terms each provider publishes for the plan we are on. You can ask us for details of the safeguards that apply by emailing legal@notekit.net.
Keeping and deleting your data
Most of what we collect — your uploads, your generated kits, your account record, and your usage counters — we keep for as long as your account exists, until you delete it or ask us to.
The one-way hashes of your email and IP address used ONLY for sign-in abuse prevention (see “What we collect”) — not the account identifier your data is stored under, which is covered separately below — are not part of your account. We delete a given email or IP address’s older abuse-prevention records when that same email or IP is next used to request a sign-in link; a record for one that is never used again may also be removed by a periodic internal cleanup.
You can delete your data yourself: remove a single chapter and its kit from your account at any time, or delete your entire account and everything in it. If you need help, or would like us to delete something for you, contact us at legal@notekit.net.
Deleting a single chapter permanently removes its uploaded file, generated kit, and chapter record from our storage. If you’ve also created a subject-wide synthesis kit from several chapters, deleting one of those source chapters does NOT remove or update that already-generated synthesis kit — it keeps whatever content was generated from the deleted chapter until you delete the synthesis kit itself, the same way you delete any chapter.
Deleting your whole account removes every chapter, kit, and synthesis kit, plus your account record itself, and resets your plan to free — except we keep one minimal replacement record: a marker that revokes any sign-in still active on another device, and the date of deletion. That record holds no file, kit, or other content of yours. The deletion date is cleared from it the next time the record is accessed after 30 days have passed (self-cleaning on next use, not a fixed schedule) — long enough that any signed-in session from before your deletion would already have expired on its own; the record itself continues to exist afterward, holding only what’s needed for a later re-registration under the same email to work correctly. This 30-day clearing does not apply to an account terminated for repeat copyright infringement (see our Terms) — that record is kept for as long as the termination stands. Re-registering with the same email always works and starts with a clean free-plan quota. Neither chapter nor account deletion reaches content already sent to our AI provider: the uploaded file is deleted automatically once your kit finishes generating and expires automatically within an hour regardless (above), and the provider’s own up-to-30-day abuse-monitoring copy of the prompt and generated text (above) is on the provider’s schedule, not ours. Deletion also does not cover records we must keep for legal or accounting reasons, or backups that overwrite on their normal cycle.
AI accuracy
Age
NoteKit is for users aged 13 and over. When you sign in, you confirm — as its own separate checkbox — that you are at least 13 and, if you are under 18, that a parent or guardian has agreed to your use of NoteKit. We keep a record of that confirmation and of the policy version you accepted. We rely on your own confirmation; we do not verify your age.
It is your responsibility to obtain a parent or guardian’s agreement before using the service if you are under 18; we do not check whether you have it. If you believe a child under 13 has given us personal data, contact us at legal@notekit.net and we will delete it.
Changes to this policy
Questions about privacy? Email legal@notekit.net.
See also our Copyright and Takedown Policy.