Privacy Policy
Effective September 14, 2026 · Contact: legal@notekit.net
Who operates NoteKit
What we collect
- Your email address, used to create your account and send you sign-in links.
- A derived, pseudonymous account identifier (not your email itself) under which your data is stored.
- The PDFs you upload.
- The study kits we generate from them.
- Usage counters: your plan and how much of it you have used, so we can run the service and monitor our own API costs.
- Anonymous page-view records: which page was opened, roughly where from, and on what kind of device and browser. They set no cookie and are not linked to your account. They are listed in full under “Analytics” below.
- If you subscribe to a paid plan: which plan you are on, the identifiers that link your account to your subscription at our payment provider, the dates your subscription started, renews or was cancelled, and its current status. We never see or store your card number. Your card details go straight to the payment provider and never reach NoteKit.
- For sign-in security only: a one-way hash of your email address and of the IP address used to request a sign-in link, kept to limit abuse.
- When you turn on the optional exam-focus setting for a subject, the per-lecture practice tallies worked out from your self-grades: small counts of how many questions you got right, got wrong, or never opened in each lecture. This is off unless you enable it.
- If you arrived at NoteKit from a link or an advert: the web address that referred you, and any campaign tags in the link you followed (the utm_source, utm_medium, utm_campaign, utm_term and utm_content parameters). We record this once, when you first request a sign-in link, and keep it on your account record so we know which channels bring people to NoteKit. It is not used to advertise to you, and it does not follow you to other sites.
Your self-grade answers themselves stay on your device (in your browser’s localStorage). When the exam-focus setting above is on, only the per-lecture tallies (counts of got, missed, and never-opened questions, with no question or answer text) are sent, used once to build that subject exam kit, and not stored by us.
Where your data lives
Your uploaded files, kits, and account record are stored per-account in Vercel Blob storage in the United States, and the application itself is hosted by Vercel.
We also set two strictly-necessary cookies and a small amount of on-device storage so the app can recognise you and remember your study progress. These are listed by name in the next section.
What we store on your device
Two cookies, both httpOnly and sameSite: lax, both strictly necessary for the service to work:
nk_magiclasts 15 minutes and binds your sign-in link to the browser that requested it, so a link forwarded to someone else can’t be used to sign in. It is deleted the moment you sign in.nk_sessionis a signed token that lasts 30 days and keeps you logged in.
On-device study state is kept in your browser under the nk: localStorage prefix, for example your per-question self-grades, how many questions you have shown in each kit, and whether you've seen the first-time tour, saved per account (not per browser). This never leaves your device unless you turn on the optional exam-focus setting described above, and you can clear it any time from your browser.
Those two cookies and the nk: localStorage entries are everything NoteKit puts on your device, and all of it is strictly necessary. We do count page views (see “Analytics” below), but that count sets no cookie and neither writes to nor reads anything from your device. There is no tracking pixel and no advertising anywhere in NoteKit, and nothing here follows you to other sites. Because nothing non-essential is stored on or read from your device, you do not see a cookie banner.
AI processing
To build your study kit, we send your uploaded PDFs (your lecture file and, if you attach one, your past exam or tutorial file) and the kit we generate from them to a third-party AI model provider for processing. When the exam-focus setting is on, the per-lecture practice tallies are included inside the prompt sent to the provider for that one subject exam kit. Only one provider is active at a time. The provider we currently use is OpenAI (OpenAI OpCo, LLC, United States). If we ever change provider, we will update this page and the effective date above.
Under OpenAI’s standard API terms, data sent through the API is not used to train or improve its models unless the customer opts in. This policy relies on those provider terms; it does not make a separate guarantee about training.
The file we upload to the provider is held there for processing and is deleted once your kit has been generated. As a backstop in case that deletion request itself fails, the file also auto-expires on OpenAI’s side within 1 hour regardless (an expiry we set explicitly on every upload), so the file is never left there indefinitely. OpenAI is a United States company, but it gives standard API accounts like ours no single-country processing commitment: regional data residency is an approval-only option we do not have, and OpenAI’s published sub-processor list shows that OpenAI and its content-moderation vendors may process API content outside the United States. So your data is processed in the United States and may also be processed outside the United States (see “International transfer”).
Separately from that file: our current provider, OpenAI, may itself retain the prompt and the generated kit text for up to 30 days to provide the service and to monitor for abuse. This is OpenAI’s own standard retention for API usage and applies regardless of the no-store setting we request on every call; we cannot turn it off from our side. After 30 days that copy is removed from OpenAI’s systems, unless longer retention is required by law or is reasonably necessary to protect OpenAI’s services or others from harm. We have not requested, and do not have, OpenAI’s zero-data-retention program, which would remove this window entirely.
Bring your own key
You can choose to run your kits on your own API key with OpenAI, Google Gemini, or Anthropic Claude, instead of using ours. This is optional. If you have not added a key, nothing in this section applies to you, and the rest of this policy describes what happens to your data.
What we store: the key you paste, encrypted with AES-256-GCM before it is written down, using an envelope key that we hold and that is kept apart from the encrypted record. That record sits in your own account area, in the same place as your uploads and kits. We never display the key back to you, not even partly masked: once it is saved, the settings page can only tell you that a key exists and which provider it belongs to, because the server has no way to hand it back. The key is never written into a log, an error message, or an email. If a stored key cannot be read back (for example after the record was altered, or after we rotate the envelope key), we record that the failure happened, against your account identifier only and never any part of the key itself.
Where your material goes: when you generate a kit with your own key, our servers send your uploaded PDFs and the generated kit to whichever of OpenAI, Google (Gemini), or Anthropic (Claude) you chose, authorised with your key instead of ours. The work is therefore carried out under your own account and your own agreement with that provider, and that provider bills it to you, not us. Your own key can be used with one provider at a time: the one you chose when you saved it. Saving a new key for a different provider replaces the old one, it does not add a second active provider. If we ever change which providers are supported here, we will update this page and the effective date above.
Training and retention on this path sit between you and the provider you chose, not us. What “AI processing” says about OpenAI’s no-training default for API data, about its 30-day abuse-monitoring window, and about our not having OpenAI’s zero-data-retention program, describes our own OpenAI account on the platform path, not yours. When your own key is used, the terms, data controls and retention settings on your own account with that provider are what apply, including any training or data-sharing option you have turned on there. Anthropic’s standard commercial API terms do not use your prompts to train its models. Google’s Gemini API works the same way only on a paid AI Studio key: on a free-tier Google API key, Google’s Unpaid Services terms allow it to use the prompts and files you send, including your uploaded course material, to improve its products, and may have them reviewed by a human. That is your agreement with Google on the key you chose to use, not a setting NoteKit controls or can turn off for you; if you want your material excluded from Google’s training, use a paid Gemini key. What NoteKit does with the file is not identical across providers: with an OpenAI key, it is uploaded to OpenAI’s file storage for processing, deleted once your kit has been generated, and carries the same 1-hour expiry we set on every upload as a backstop. With a Gemini or Claude key, your PDF rides inside the same request that asks for your kit, and the provider does not create a separate stored file for it on our side to expire or delete. Whatever the provider itself retains in its own logs beyond that (Anthropic’s standard commercial API terms describe a 30-day retention window; Google’s retention on a free-tier key is described above) is governed by your own agreement with that provider, not by NoteKit.
What we record on our side: how much you generate, because your plan limits and our anti-abuse rate limits still apply, and an internal running total of estimated model cost that is not linked to your account. We do not record against your account what you spend with your own key. What that key has cost you is shown on your own billing page with the provider it belongs to, OpenAI, Google, or Anthropic, not in NoteKit.
How long we keep it: the encrypted key stays until you remove it from the settings page, or until you delete your account, in which case it is erased along with everything else stored under your account (see “Keeping and deleting your data”).
Analytics
We count page views so we can see how much NoteKit is used and which pages people actually reach. We do this with Vercel Web Analytics, provided by Vercel Inc. (United States), the same company that hosts NoteKit. The measuring script is served from NoteKit’s own address and reports back to it; nothing is loaded from, or sent to, an advertising or tracking network.
Each page view records:
- the time, and the address of the page you opened: its path, the route pattern behind it (for example
/chapter/[id]), and any query string that address carries. The address is sent exactly as it appears in your browser. Vercel describes the query parameters it stores as “filtered” but does not publish what that filter removes, so we do not claim any particular part of an address is dropped. - the site you arrived from, if you came from another site. Moving between pages inside NoteKit is not recorded as a referral.
- an approximate location worked out from your connection: country, region and city, never a street address.
- your device type (mobile, tablet or desktop), operating system and browser, with version numbers.
- the version of the analytics script itself.
No cookie is set for this and nothing is stored on or read from your device. Vercel recognises a visit using a hash it computes from the incoming request instead of an identifier kept in your browser, and states that this hash is discarded after 24 hours, that the records are anonymous and aggregated, and that it collects nothing that would let anyone rebuild your browsing across different sites or identify you. This policy relies on Vercel’s published description of its product; it does not add a separate guarantee of our own. We do not send Vercel your email address, your uploads, or your kit text through analytics, and we do not join these records to your account.
Vercel stores these records in the United States and keeps them for the reporting window of the plan we are on, currently 12 months, and says it may hold them for longer than that window. Because they are not tied to your account, deleting your account does not remove them and we cannot single yours out to delete (see “Keeping and deleting your data”).
Error monitoring
When something goes wrong in NoteKit, a crash or a bug, we automatically send an error report to GlitchTip, an error-tracking service operated by Burke Software and Consulting LLC (a New York, United States company). A report is sent only when an error actually occurs, never on a schedule. It contains the error message and stack trace, the page or route where it happened, browser and operating-system metadata, and a timestamp. Your browser sends these reports directly, so GlitchTip also sees the internet (IP) address your browser connects from, in the same way any website you visit does.
Before a report leaves NoteKit we scrub it. On our side we redact email addresses, sign-in tokens and the request URL’s token parameter, all authentication headers (including cookies and authorization), and the entire request body, and we drop console breadcrumbs entirely. Your notes, uploads, kit text, and account content are never part of an error report.
We use this only to detect and fix crashes so the service stays reliable. GlitchTip automatically deletes error data after 90 days. Our GlitchTip instance is hosted in New York, in the United States, so error reports are transferred to and processed in the United States under the Standard Contractual Clauses and, for UK users, the UK International Data Transfer Addendum, in Burke Software’s Data Processing Agreement. See “International transfer”.
Separately, we send operational logs to Better Stack, Inc. (a Delaware, United States company), our log-monitoring provider, through its Sentry-compatible ingest. These record service events such as a sign-in attempt or a rate limit being reached, identified only by a one-way hash, never by your email address or your IP address. Better Stack stores them for 90 days, in EU data centres by default (ISO/IEC 27001-certified). Some of Better Stack’s sub-processors are in the United States, so log data may be transferred to the US under the EU-US Data Privacy Framework and Standard Contractual Clauses, and Better Stack’s Data Processing Agreement (auto-incorporated at betterstack.com/dpa).
Who we share data with
We do not sell personal data, and we do not share it for advertising.
These companies process data on our behalf, on our instructions, so we can run the service:
- Vercel Inc. (United States), hosts the application, stores your uploaded PDFs and generated kits (Vercel Blob), and runs the cookieless page-view counting described under “Analytics”.
- OpenAI OpCo, LLC (United States), the AI provider we currently use; it receives your uploaded PDF and generated kit text to produce your study kit.
- Resend (United States), receives your email address to deliver the sign-in link you request.
- GlitchTip (Burke Software and Consulting LLC) (New York, United States), receives the scrubbed error reports described under “Error monitoring” when a crash or bug occurs, so we can detect and fix problems. It receives no notes, uploads, or account content.
- Better Stack, Inc. (Delaware, United States), receives the operational logs described under “Error monitoring”. These carry service events and one-way hashes only, and no notes, uploads, or account content.
Paid subscriptions are sold by a separate company, which decides for itself how it handles the payment side, so it is not simply acting for us:
- Dodo Payments (Dodo Payments Inc., a Delaware corporation in the United States, together with its group companies) is the merchant of record for every paid subscription, which means it is the legal seller. When you subscribe it receives your email address, your billing details and country, your card details, and the plan you chose. It uses them to take the payment, to work out and pay the sales tax or VAT due where you live, to send you your receipt, to prevent fraud, and to keep the tax and accounting records the law requires of it. Because it decides those purposes itself, it is responsible for that data in its own right, under its own privacy policy at dodopayments.com, and not only as a provider acting for us. What comes back to us is limited to your subscription status, plan, renewal date and the identifiers we need to match the subscription to your account. Your card number never reaches us.
We update these lists when they change.
Why we process your data, and on what basis
- Creating and running your account, storing your uploads, and generating study kits. This is the service you asked for, so we process this data to perform our contract with you.
- Limiting sign-in attempts and daily usage: our legitimate interest in keeping the service secure, available, and abuse-free.
- Keeping cost and usage records: running our business and meeting accounting obligations.
- Counting page views so we know how much the service is used and which pages people reach: our legitimate interest in understanding and improving NoteKit, measured without cookies and without linking anything to your account.
- Recording, once, how you first reached NoteKit (the referring web address and any campaign tags in the link you followed), so we know which channels bring people to the service. This is our legitimate interest in understanding how NoteKit is found and spending our effort sensibly. You can ask us to erase it from your account record at any time.
- Taking payment for a paid plan and running your subscription, which is necessary to perform our contract with you. Keeping the billing and tax records that go with it is a legal obligation we have.
- Where the law where you live requires consent for any of the above (including guardian consent for minors), we rely on the consent you give at sign-in.
Your rights
You can ask us to: tell you what data we hold about you and how we use it; give you a copy of it; correct it if it is wrong or incomplete; delete it; or stop or limit a particular use. Email legal@notekit.net and we will respond within 30 days. Deleting your chapters or your whole account yourself (see below) is usually faster. You can also ask us for a copy of the data you gave us in a portable, machine-readable form, or object to a use we base on our legitimate interests. Where we rely on your consent for something, you can withdraw it at any time, and withdrawing it does not affect anything we did lawfully before you did.
If you are in Saudi Arabia, the rights above are those given to you by the Personal Data Protection Law, and you can complain to the Saudi Data & AI Authority (SDAIA). If you are in the UK or the EU, they are your rights under the UK GDPR or the GDPR, and you can complain to your national data protection authority.
Who is responsible for your personal information
The person responsible for the protection of personal information at NoteKit is Ali Almuhaysh, founder of Taweed Establishment. Quebec’s Law 25 requires us to publish who that person is (section 3.1). He is the same person who answers privacy questions from anywhere else, and the one who handles the requests described above.
You can reach him at legal@notekit.net.
What we don’t do
International transfer
NoteKit is operated from Saudi Arabia and our service providers are in the United States, so wherever you use NoteKit from, your personal data is transferred to and processed in the United States. That includes the page-view records described under “Analytics”, which Vercel processes and stores in the United States. Our AI provider, OpenAI, is a United States company, but OpenAI and its content-moderation vendors may process API content outside the United States, so what we send for AI processing may also be processed outside the United States (see “AI processing”).
Dodo Payments, which sells and bills paid subscriptions, is a United States company and processes your payment data in the United States and wherever its group companies operate, under its own safeguards and its own privacy policy. See “Who we share data with”.
Before making these transfers we carry out a transfer risk assessment, and we rely on the data-protection terms each provider publishes for the plan we are on. You can ask us for details of the safeguards that apply by emailing legal@notekit.net.
Error reports sent to GlitchTip are stored on its United States instance in New York, under the Standard Contractual Clauses and, for UK users, the UK International Data Transfer Addendum, in Burke Software’s Data Processing Agreement. Operational logs sent to Better Stack, Inc. are stored in its EU data centres by default, but some of its sub-processors operate in the United States, so log data may also be transferred to and processed in the US under the EU-US Data Privacy Framework and Standard Contractual Clauses, and Better Stack’s Data Processing Agreement. We do not claim EU-only processing for either.
Keeping and deleting your data
Most of what we collect: your uploads, your generated kits, your account record, and your usage counters. We keep these for as long as your account exists, until you delete it or ask us to. The per-lecture practice tallies are the exception: we do not keep them at all. They are used inside the one request that builds your subject exam kit and then discarded, so there is nothing of them to delete or export.
Scrubbed error reports sent to Better Stack (see “Error monitoring”) are kept by Better Stack for 90 days and then removed. They hold no notes, uploads, or account content.
Page-view records held by Vercel (see “Analytics”) are kept for its reporting window, currently 12 months on our plan, and Vercel says it may keep them longer. They hold no notes, uploads, or account content, and they are not linked to your account, so deleting a chapter or your whole account does not reach them, and there is nothing in them we could identify as yours to delete or export.
The one-way hashes of your email and IP address used ONLY for sign-in abuse prevention (see “What we collect”), not the account identifier your data is stored under, which is covered separately below, are not part of your account. We delete a given email or IP address’s older abuse-prevention records when that same email or IP is next used to request a sign-in link; a record for one that is never used again may also be removed by a periodic internal cleanup.
The record of how you first reached NoteKit is kept on your account record for as long as your account exists, and is deleted when you delete your account. If you request a sign-in link and never complete sign-in, the temporary record holding that information (stored under a one-way hash of your email, not your email itself) is deleted after 30 days at the latest, whether or not you come back.
You can delete your data yourself. Remove a single chapter and its kit from your account at any time, or delete your entire account and everything in it. If you need help, or would like us to delete something for you, contact us at legal@notekit.net.
Deleting a single chapter permanently removes its uploaded file, generated kit, and chapter record from our storage. If you’ve also created a subject-wide synthesis kit from several chapters, deleting one of those source chapters does NOT remove or update that already-generated synthesis kit. It keeps whatever content was generated from the deleted chapter until you delete the synthesis kit itself, the same way you delete any chapter.
Deleting your whole account removes every chapter, kit, and synthesis kit, plus your account record itself, and resets your plan to free, except we keep one minimal replacement record: a marker that revokes any sign-in still active on another device, and the date of deletion. That record holds no file, kit, or other content of yours. The deletion date is cleared from it the next time the record is accessed after 30 days have passed (self-cleaning on next use, not a fixed schedule): long enough that any signed-in session from before your deletion would already have expired on its own; the record itself continues to exist afterward, holding only what’s needed for a later re-registration under the same email to work correctly. This 30-day clearing does not apply to an account terminated for repeat copyright infringement (see our Terms): that record is kept for as long as the termination stands. Re-registering with the same email always works and starts with a clean free-plan quota, unless your account was terminated for repeat copyright infringement. Neither chapter nor account deletion reaches content already sent to our AI provider: the uploaded file is deleted automatically once your kit finishes generating and expires automatically within an hour regardless (above), and the provider’s own up-to-30-day abuse-monitoring copy of the prompt and generated text (above) is on the provider’s schedule, not ours. Deletion also does not cover records we must keep for legal or accounting reasons, or backups that overwrite on their normal cycle.
AI accuracy
Age
NoteKit is for users aged 14 and over. When you sign in, you confirm, as a separate checkbox, that you are at least 14 and, if you are under 18, that a parent or guardian has agreed to your use of NoteKit. We keep a record of that confirmation and of the policy version you accepted.
Please do not use NoteKit if you are under 14. If you are under 18, you must have a parent or guardian’s agreement before you use the service, and the confirmation you give at sign-in is your statement that you have it. If you believe someone under 14 has given us personal data, contact us at legal@notekit.net and we will delete it.
Security incidents and breach notification
If we discover a security incident that has or is likely to have resulted in a breach of your personal data, for example, unauthorized access to our systems, or data being exfiltrated or decrypted by someone who should not have it. We assess the risk to you. Where that risk is likely to result in a high risk to your rights and freedoms (for example, identity theft or fraud), we will notify you without undue delay, using the email address on your account. That notification will describe what happened, what data we believe was affected, and what we are doing about it. Where we are required to notify a supervisory authority (for example, under the GDPR, within 72 hours of becoming aware of a personal-data breach that poses a risk), we will do so on the same timeline. We do not charge you for any breach notification we are required to send you.
This commitment is separate from any limitation of liability in our Terms of Service, and nothing in these Terms limits it. Your statutory rights around breach notification are not affected.
Changes to this policy
Questions about privacy? Email legal@notekit.net.
See also our Copyright and Takedown Policy.