Privacy

Privacy Policy

Last updated July 20, 2026

Calyxa is an AI math tutor that runs as a browser extension. This policy explains exactly what we collect, why, how long we keep it, and how you can see or delete it. We built the product so that the most sensitive things are never collected in the first place: your voice is never stored, the pages you visit are recorded only as a one-way hash, and our usage metrics carry no personal content.

Calyxa offers a free plan with monthly limits and a paid Pro subscription.

What we collect, and why

  • Account email and password

    To create and secure your account. Authentication is handled by our provider (Supabase); we do not store your raw password. If you join the waitlist before signing up, we keep only your email until you either sign up or ask us to remove it.

  • Birth year

    To confirm you meet the minimum age to use Calyxa. We store the year only — not a full date of birth — alongside a flag that the age check passed.

  • Consent record

    A timestamp and version marking the privacy terms you agreed to at signup, so we have a record of the consent you gave (GDPR).

  • Your learning profile

    The heart of the tutor: an estimate of what you've mastered, the misconceptions you've shown, and when each topic is due for review. This is what lets Calyxa adapt to you instead of repeating a script.

  • Session transcripts (text only)

    The text of your tutoring turns — what you typed or said, and the tutor's replies — so a session has memory and your progress is scored. This is TEXT ONLY. Your microphone audio is transcribed in real time and never stored (see below).

  • A hashed page identifier

    So the tutor knows you're working on the same problem across a session, we record a one-way HMAC hash of the page's domain — never the full URL, never the page contents. We cannot recover the site you were on from the hash.

  • Product telemetry

    A small set of strictly-typed events (e.g. a session started, a turn's latency, an onboarding completed) so we can tell whether the beta is working. By design these events carry NO free text, NO transcript, NO URL, and NO audio — only counts and timings.

  • Feedback you choose to send

    If you use the in-app feedback control, we keep the message and rating you wrote so we can fix issues. This is the one field where you type free text for us on purpose.

  • Generated study materials

    When a session produces a study kit — notes, practice problems, flashcards — we store it so you can come back to it. It is generated from your own session's text and is covered by the same export and delete rights as everything else.

  • Personal notebooks

    For each concept you practice, Calyxa keeps a short study notebook — a running summary, reminders, and explanations — that it updates after your sessions. It is generated from your own session's text and is covered by the same export and delete rights as everything else.

  • Saved worked-problem snapshots

    When the tutor marks up a problem during a session — highlighting a step, labelling what to notice — we save those annotations (the short problem spans it points at, plus its notes) so you can revisit the worked problem later. This is the tutor's own markup on text you were already working through; we still never store a screenshot, the page's URL, or the page's contents.

  • Billing and subscription status

    If you subscribe to Pro, our payment processor (Stripe) handles your card — we never see or store your card number. We keep only your subscription tier and status, a Stripe customer reference, and processing bookkeeping, so your account reflects what you've paid for.

  • A monthly voice-usage counter

    On the free plan, premium voice has a small monthly budget. We keep one number per month — an estimate of that spend in cents — so we know when to switch you to the free browser voice. It contains no audio, text, or page data.

  • A hashed signup network identifier

    When you create an account, we record a one-way HMAC hash of your network (IP) address — never the address itself — solely to limit how many accounts can be created from one network (abuse prevention). We cannot recover your IP from the hash, we never use it for location, and it is deleted with your account.

  • Referral data

    If you share your invite link, we keep your referral code, which accounts joined through it (so we can credit your bonus sessions), and — if you signed up through someone's link — a reference to who invited you.

What we never collect, and never do

  • We never store your microphone audio. Voice is streamed for real-time transcription and discarded — no recording is ever written to disk.
  • We never store the URLs or contents of the pages you visit. Only a one-way hash of the domain, which cannot be reversed.
  • Our metrics carry no personal content. Telemetry is a fixed set of typed events with no room for a transcript, question, or URL.
  • We never sell your data or use it for advertising.
  • No AI keys or secrets ever ship in the extension. All calls to AI, speech-to-text, and text-to-speech go through our own server.

Who we share it with

We do not sell your data and we do not share it with third parties for their own purposes. To deliver the tutor, your data is processed by service providers acting only on our behalf (processors), under our server-side control:

  • OpenAI — the AI model that generates tutoring replies and study materials (receives your session text, never audio), and real-time speech-to-text for voice input (transcribes audio in the moment; no recording is retained).
  • Anthropic — a backup AI provider we can switch tutoring replies to (same session text, never audio); not used by default.
  • Stripe — payment processing for Pro subscriptions. Your card details go directly to Stripe and never touch our servers.
  • ElevenLabs — text-to-speech so the tutor can speak replies aloud.
  • Supabase — our database and authentication, where your account and learning profile are stored.
  • Vercel — hosting for our website and server.

How long we keep it

Your account and learning data are kept until you delete them. Microphone audio is never persisted at all. When you delete your account, everything tied to it — sessions, mastery history, misconceptions, reinforcement schedule, telemetry, feedback, generated study materials, personal notebooks, the voice-usage counter, and our record of your subscription status — is queued for permanent deletion and removed after a short grace window. (Stripe retains its own transaction records as required for financial compliance.)

Your data is yours — export and delete

You can download everything Calyxa holds about you as a JSON file, or permanently delete your account and all associated data, at any time from your account settings.

Manage your data in account settings →

Age

Calyxa checks your age at signup and is not intended for children under the minimum age we enforce there. If we learn we have collected data from someone under that age, we will delete it.

How we protect it

All data is encrypted in transit (HTTPS/TLS) to our server and database. Access to your rows is isolated per account at the database level, and all provider API keys live only on our server — never in the extension you install.

Changes to this policy

If we change what we collect, we will update this page and the “Last updated” date above before the change takes effect.

Contact

Questions about your privacy? Email us at calyxasupport@gmail.com.