Privacy Policy
Last updated August 2, 2026
Information we collect
This is everything we collect, and nothing more:
- Account information: the name and email you sign up with (via Firebase Authentication), and an optional profile photo and short bio if you add them in Account settings.
- Project content: everything you create while using the Service — outlines, the manuscript you write, sources you search for or import, citations, notes and any files you upload with them, spreadsheet data, slides, comments, and messages sent through a connected chat integration.
- Usage and diagnostic data: basic technical information (like error logs) needed to keep the Service running and to fix problems.
- School library setup, if you add one: the library name and link prefix you configure so source links open through your institution's access. We never see or store your school login password — we never ask for it.
What we never collect: we don't ask for or store your school library login credentials — the library-access feature works by wrapping a source link with a proxy prefix you paste in yourself (published on your library's own website), so you authenticate directly with your school, never through us. We don't collect payment card details ourselves (a payment processor, if you're on a paid plan, handles that directly).
How we use it
To operate the features you use — generating an outline, finding and citing sources, checking grammar/style/voice/facts, real-time collaborative editing, exporting or importing documents, generating flashcards or slides — to maintain your account, to let you collaborate with people you choose to share a project with, and to respond to support requests sent through our Contact page. We don't use your project content for advertising, and we don't sell your data to anyone.
Third-party services we use
The Service is built on these providers, each processing only what a feature needs:
- Google Firebase (Authentication, Firestore, Storage) — sign-in, database, and file storage. This is where your account and project data actually lives.
- Anthropic's Claude API — powers outline generation, grammar and style suggestions, voice/fact-checking, and source summarization. Relevant text is sent to Anthropic to generate a response; per Anthropic's API terms, content sent through their commercial API is not used to train their models.
- LanguageTool — real-time grammar and spell-checking as you type.
- Pexels — stock images you can optionally insert into slides or the manuscript.
- Academic source databases (Semantic Scholar, CrossRef, OpenAlex, Open Library) and general web search — queried when you search for sources; your search terms are sent to whichever database(s) you have selected.
Shared and collaborative projects
If you share a project or accept an invitation to one, your name, profile photo (if set), and contributions to that project become visible to the other people on it, according to the role you've been given. This is inherent to how collaboration works and isn't something we can selectively hide from other project members.
Your choices and rights
You can edit or delete your project content at any time. Any project owner can permanently delete an entire project — including everyone's contributions to it — from that project's Settings page; this happens immediately and can't be undone. You can remove a configured school library at any time from Account Settings. To have your account and any remaining associated data deleted entirely, reach us through Contact.
Children's privacy
The Service is intended for users aged 13 and older and isn't directed at children under 13; we don't knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, contact us and we'll delete it.
Data retention
We keep your account and project data for as long as your account is active, so the Service works the way you'd expect (your projects are there when you come back). When you delete a project or your account, associated data is removed from our active systems; backups are cycled out over time thereafter.
Security
Connections to the Service are encrypted in transit. Access to your data is governed by database security rules scoped to your account and the projects you're a member of; server credentials and API keys live in a server-only location no client, including our own front-end code, can read directly. No system is 100% secure, and we can't guarantee absolute security, but we take reasonable, industry-standard steps to protect your information.
A note on legal review
This policy describes, plainly and accurately, what the Service actually does with your data today. If you have specific compliance requirements — for example, a school district's data privacy agreement, FERPA, or a regional data-protection law like GDPR — please reach out through Contact so we can work through what you need.
Changes to this policy
We may update this policy from time to time; we'll update the date at the top of this page whenever we do.