Privacy Policy
Last updated: July 13, 2026
CruxPack (“CruxPack,” “we,” “us,” or “our”) turns lecture files and pasted text into study notes, flashcards, practice problems, and cheat sheets. This Privacy Policy explains what information we collect, how we use it, the lawful basis for using it, who we share it with, how long we keep it, and the choices you have. It applies to the CruxPack website and related services (the “Service”). CruxPack is the data controller for the Service and is operated from Massachusetts, United States.
1. Information we collect
We collect the following categories of information:
- Account information. When you sign in with Google OAuth, we receive your name, email address, and profile picture from Google. We use these to create and identify your account.
- Content you provide. The lecture files you upload (PDF, PPTX) or text you paste, and the study packs we generate from them (notes, flashcards, practice problems, cheat sheets).
- Study activity. Basic progress data, such as which study packs you have opened, so the Service can show your activity.
- Plan and usage data. Your subscription plan and a count of how many study packs you generate each month, used to enforce plan limits.
- Device and connection data. When your browser or app talks to our servers we automatically receive ordinary technical data, including your IP address, browser and device type, and the pages or API endpoints you request. This is a normal part of how the web works and is used to run, secure, and debug the Service.
- Server and API logs. We keep short-lived logs of requests to our Service (for example, the endpoint called, a timestamp, response status, and the originating IP) to operate the Service, investigate errors, and detect abuse.
- Analytics and error data. With privacy-respecting analytics (PostHog) we record product events — such as pages viewed and actions like creating or exporting a pack — tied to your account identifier. If something goes wrong, our error-monitoring provider (Sentry) receives diagnostic details about the error and the request that triggered it. See “Third-party processors” and “Cookies and analytics” below.
- Cookies. The cookies described in the Cookies section below.
2. How we use your information
- To provide, maintain, and improve the Service.
- To generate study packs from the content you submit.
- To authenticate you and keep your account secure.
- To enforce plan limits and process subscriptions and billing.
- To understand how the Service is used and improve it, through aggregate product analytics.
- To monitor, diagnose, and fix errors, and to keep the Service reliable and secure.
- To communicate with you about the Service, including service-related notices.
- To comply with legal obligations and to detect, prevent, and address fraud or abuse.
3. Lawful basis for processing (GDPR)
If you are in the EU, EEA, or UK, we process your personal data under the following lawful bases in Article 6 of the General Data Protection Regulation (GDPR):
- Performance of a contract (Art. 6(1)(b)). To create your account, generate the study packs you ask for, run exports you initiate, and provide and bill for the Service you signed up to use.
- Legitimate interests (Art. 6(1)(f)). To keep the Service secure, prevent fraud and abuse, maintain server and API logs, and understand and improve how the Service is used — balanced against your rights and interests.
- Consent (Art. 6(1)(a)). Where required, for non-essential analytics and similar cookies. You can withdraw consent at any time; withdrawing it does not affect processing that already took place.
- Legal obligation (Art. 6(1)(c)). To meet accounting, tax, and other legal requirements, and to respond to lawful requests.
4. How uploaded content is processed
To generate your study materials, the content you upload or paste is sent to Google’s Gemini API for processing. That content is transmitted to and processed by Google subject to Google’s applicable terms and privacy practices, including Google’s own policies on whether submitted content may be used to improve its models. We do not control Google’s data-use practices for content submitted to its APIs; please review Google’s privacy documentation and Gemini API terms for details.
Please do not upload content you do not have the right to share, or that contains other people’s confidential, sensitive, or personal information. You are responsible for the content you submit.
5. AI processing and third-party data sharing
We want to be clear about how the content you submit is handled when we generate study materials:
- What is sent. The lecture files and text you provide are sent to a third-party AI provider (Google Gemini) to generate notes, flashcards, practice problems, and cheat sheets. We do not use your content to train our own models, and we do not sell it or share it with advertisers.
- Google’s handling of your content. Content sent to the Gemini API is processed subject to Google’s own applicable terms, which govern whether it may be used to improve Google’s models. We do not control Google’s data-use practices for content submitted to its APIs; please review Google’s privacy documentation for details.
- How long it is kept. Your uploaded content and generated study packs are stored in your account so you can keep studying with them. We keep them until you delete them or close your account; see “Data retention and deletion” below.
- Your control. You can export or delete your data at any time from your account settings. Deleting a study pack removes it from your account.
We do not control Google’s own data practices for its APIs; please review Google’s privacy documentation for details on how Google processes data submitted to Gemini.
6. Third-party processors
We rely on a small number of trusted service providers (“processors”) to operate the Service. Each processes data only as needed to perform its function, on our instructions, and under a data-processing agreement where applicable:
- Stripe — payment and subscription processing. Stripe handles your card details directly; we never receive or store full card numbers.
- Google — sign-in (Google OAuth) and AI study-pack generation (Gemini API).
- PostHog — product analytics (pages viewed and in-app actions), used to understand and improve how the Service is used.
- Sentry — error and performance monitoring, used to detect, diagnose, and fix problems in the Service.
These providers may process data in the United States and other countries; see “International data transfers” below.
8. Abuse-prevention device signal on content reports
When you use the “Report this deck” feature on a shared study pack, your browser computes a device signal (a combination of properties such as screen size, time zone, language, and graphics capabilities) that we store only as a salted, one-way hash — never in a form that directly identifies your device. We use it, together with a hash of your network address, solely to detect duplicate or throwaway-account reports, so that a small number of bad-faith reports cannot trigger action that is meant to require several independent people. It is not used for advertising, is not shared for cross-site tracking, and does not rely on cookies or similar browser storage.
PLACEHOLDER — UNDER LEGAL REVIEW. The lawful basis for this signal (likely legitimate interest in fraud and abuse prevention) and how it reconciles with the “Do Not Track” commitment and the “no advertising or cross-site tracking” statement in the Cookies section above are still being finalized with counsel and may change. This paragraph is a placeholder and is not a final statement of our practices.
9. Data retention and deletion
We keep personal data only for as long as we need it for the purposes described in this policy. In particular:
- Account data and study packs. Retained for as long as your account is active. Your uploaded content and generated packs stay until you delete them or close your account.
- Server, API, and error logs. Retained for approximately 90 days, then deleted or anonymized, except where a specific log must be kept longer to investigate an incident or meet a legal obligation.
- Backups. When you delete your account, your data is removed from our live systems promptly and purged from routine backups within approximately 30 days as those backups age out.
- Legal holds. We may retain limited information longer where required for legal, accounting, tax, or fraud-prevention purposes.
You can delete individual study packs from within the app at any time. See “What happens when you delete your account” below for the full picture.
10. Your rights
Depending on where you live, you may have rights under laws such as the EU/UK General Data Protection Regulation (GDPR, Articles 15–21) or the California Consumer Privacy Act (CCPA/CPRA), including the right to:
- Access the personal data we hold about you (GDPR Art. 15).
- Portability — export your study packs and account data in a machine-readable format (GDPR Art. 20). You can do this yourself anytime with Download my data in settings.
- Correct inaccurate information (GDPR Art. 16).
- Delete your data and close your account (GDPR Art. 17). You can do this yourself anytime with Delete my account in settings.
- Object to or restrict certain processing (GDPR Arts. 18, 21).
- Withdraw consent where processing is based on consent, and complain to a data-protection supervisory authority (GDPR Art. 77).
We do not sell your personal information. To exercise any of these rights, use the tools in your account settings or contact us using the details below.
11. What happens when you delete your account
Deleting your account is permanent and cannot be undone, except where we are required by law to preserve specific information (for example, content subject to a legal hold or an active investigation) — in that narrow case we retain only what the law requires, for as long as it requires, and delete the rest. When you confirm deletion in account settings:
- We permanently delete your account and all associated data — your study packs and figures, folders, memberships, feedback, and study activity.
- Internal usage/cost records (kept only for aggregate reporting on how the Service is used) are anonymized rather than deleted outright — we remove the link to your account, not the underlying aggregate statistics.
- We cancel any active paid subscription so you are not billed again.
- We clear your session, ending your signed-in state on this and any other device.
- Your data is removed from routine backups as they age out (about 30 days), and any residual logs age out on the schedule above. Content already sent to third-party processors (such as Google Gemini) is governed by their retention practices, which we do not control.
12. Children's use
CruxPack is intended for college and university students. It is not directed to children, and we do not knowingly collect personal information from anyone under the age of 13 (or under 16 where a higher age applies under local law). If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
13. Security
We use reasonable technical and organizational measures to protect your information, including encrypted connections and access controls. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. Please use a strong, unique account at your identity provider and notify us promptly if you suspect unauthorized access.
14. International data transfers
We and our service providers may process and store your information in countries other than the one in which you live, including the United States. Those countries may have data-protection laws that differ from yours. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.
15. Changes to this policy
By agreeing to this Privacy Policy, you agree to be bound by future revisions we make to it as well. We may update this Privacy Policy from time to time; when we do, we will revise the “Last updated” date above and, for material changes, take additional steps to notify you where appropriate (for example, by email or an in-app notice). Your continued use of the Service after an update takes effect — with no further action required on your part — means you accept it.
16. Contact us
If you have questions about this Privacy Policy, or to exercise your data rights, contact us at privacy@cruxpack.io (CruxPack, Massachusetts, United States).