Privacy Policy
Version 1.0
Effective date: August 27, 2026
Last updated: August 27, 2026
Academa, Inc. ("Academa," "Company," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit academa.ai, create or watch lectures, use the tutor, interact with the community, subscribe to updates, purchase a plan, or otherwise use our websites, applications, and related services (collectively, the "Service").
By using the Service, you acknowledge the practices described in this Privacy Policy. Our Terms of Use govern your use of the Service.
Scope and definitions
Scope
This Privacy Policy applies to information Academa processes in connection with the Service. It does not apply to a third party's independent processing when you visit that party's site or use a service governed by that party's own terms and privacy notice.
Personal information
"Personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a person or household. The meaning may vary under applicable law. Information that has been aggregated or deidentified so that it cannot reasonably identify you is not personal information.
Roles of other providers
Most providers described in Section 6 process information for us to operate the Service. Some providers may also process information for their own purposes under their terms and privacy notices. For example, Google and GitHub process information when you choose their sign-in services, Cloudflare and GitHub process in-app feedback as described below, Polar acts as the merchant of record for purchases, and Cloudflare processes certain security signals for Turnstile.
Information we collect
We collect information you provide, information generated through your use of the Service, information collected automatically, and information received from other parties.
Account and profile information
When you create or use an account, we may collect:
- your name, email address, profile image, email-verification status, and account identifier;
- the permanent public handle you choose and any other profile information you provide;
- the identity provider you used, that provider's account identifier, the authorization scope, and authentication tokens needed to maintain the connection;
- account creation and update timestamps; and
- session information, including a session token, expiration time, IP address, and user-agent information.
We currently offer sign-in through Google and GitHub. We do not offer a separate password stored by Academa.
When you comment, only your public handle is displayed as your identity; comments do not publicly display your name, profile image, email address, or account identifier. Your handle, name, and profile image may still be public when you publish a lecture or use another public feature that expressly displays them. Your email address is not part of your public Academa profile.
Lecture-creation information
When you ask Academa to create a lecture, we may collect and retain:
- your initial request, interview answers, preferences, instructions, and other prompt content;
- an optional PDF and the text, figures, layout information, and metadata extracted from it;
- the resulting brief, source files, narration, transcript, audiovisual assets, model inputs and outputs, render attempts, technical receipts, and generated lecture;
- whether the lecture is private or public, together with its title, subject, description, tags, publication status, and related metadata; and
- generation usage, timing, model, provider, token, cost, error, and entitlement information.
Before Academa accepts an assignment for production, the current interview and temporary uploads are maintained so the interaction can continue across visits. If you cancel that interview, or choose Try again after an interview or question-limit failure, Academa removes the attempt from your active Composer state and schedules its temporary uploads for deletion. This product-level pruning does not necessarily erase Workflow execution records, logs, AI telemetry, or records held by model and infrastructure providers on the same schedule. See Section 9.
Once Academa accepts an assignment, its prompt, interview provenance, selected uploads, generated materials, and production record become a durable lecture project. They remain part of that project even if generation later fails or you clear the failure from Composer.
Tutor information
When you use the tutor, we may collect and retain:
- your questions, the tutor's answers, the lecture being discussed, and your position in the lecture;
- files or images you attach, including file type, size, identifiers, and content;
- a draft that you have started but not yet sent, so it can persist with the conversation;
- conversation and message identifiers; and
- model, token, cost, latency, error, entitlement, and other generation metadata.
Tutor conversations are associated either with your account or with a pseudonymous guest identifier and the lecture. The tutor may use the lecture's transcript and semantic record as context when answering.
Community and public-content information
We collect content and activity you choose to make public, including generated lectures you publish, comments, reactions, votes, and related timestamps. We also maintain aggregate view counts. The Service records a view after the applicable viewing threshold and uses browser storage to avoid repeatedly counting the same view from the same browser; the server stores the aggregate count rather than a per-viewer view history.
If you delete a comment, we erase its body and related votes. A bodyless thread marker may remain while a live reply needs it to preserve the conversation structure.
Billing and subscription information
Polar Software, Inc. ("Polar") is the merchant of record for paid plans. Polar collects and processes checkout and payment details. Academa receives information needed to create and manage your access, such as your Academa account identifier, email address, Polar customer and subscription identifiers, plan, subscription status, current billing-period end, purchase metadata, and related timestamps. Academa does not receive or store your complete payment-card number.
Creating an Academa account may also create a corresponding customer record with Polar so paid access can later be connected to the correct account.
Newsletter and communications
If you subscribe to updates, we collect your email address and the time you first subscribed. For signed-in users, we may also record whether and when you accepted or declined an invitation to subscribe. If you contact us, participate in a survey, report content, submit a privacy request, or otherwise communicate with us, we collect the information in that communication and the information needed to respond.
In-app feedback
When you submit in-app feedback, we collect your message, the lecture page, and the playback position at which you sent it. A guest may optionally provide an email address. For a signed-in user, we associate the message with the user's Academa account identifier and account email address. We deliver the message and associated information through Cloudflare to a private issue in GitHub that is available only to authorized recipients; it is not posted as a public GitHub issue.
Information collected automatically
When you use the Service, we and our providers may automatically collect:
- IP address; request date and time; requested URL; referring URL; response status; and network, routing, and security information;
- browser, device, operating-system, language, screen, and user-agent information;
- country, region, city, time zone, postal and related approximate-location fields derived from IP address;
- page views and page leaves; navigation paths; feature use; clicks on instrumented controls; scroll and pointer activity; media interactions; and performance measurements;
- campaign and referral parameters, including UTM parameters;
- anonymous, device, session, account, lecture, conversation, and event identifiers;
- errors, stack traces, diagnostic details, feature-flag values, and fraud or abuse signals; and
- cookie, local-storage, and session-storage information described in Section 8.
Information from other parties
We may receive information from:
- Google or GitHub, when you choose that provider to create or access an account;
- Polar, about customers, checkouts, subscriptions, cancellations, refunds, and payment status;
- Cloudflare, about network delivery, security, rate limiting, and Turnstile verification;
- service providers, about delivery, processing, errors, and usage of the services they perform for us; and
- other users or the public, if they interact with your Public Content or send us a report concerning it.
Information we ask you not to provide
Please do not upload or submit government identifiers, financial-account credentials, complete payment-card details, health records, or other highly sensitive personal information unless the feature expressly requests it and you are authorized to provide it. Lecture prompts, PDFs, tutor messages, and attachments are processed by automated systems and providers as described below.
How we collect information
We collect information:
- directly from you when you sign in, create content, upload a file, use the tutor, post a comment, submit feedback, subscribe, purchase a plan, or contact us;
- automatically from your browser, device, and interactions with the Service;
- through cookies and similar technologies;
- from the providers that support authentication, billing, hosting, security, analytics, communications, artificial intelligence, document processing, rendering, and media generation; and
- from public areas of the Service and reports made by other users.
How we use information
We use information for the following purposes:
- Provide the Service. To authenticate you, maintain accounts and sessions, create and render lectures, parse documents, generate narration, answer tutor questions, store drafts and conversations, publish content at your direction, and provide community features.
- Personalize and preserve continuity. To remember settings, associate a guest tutor conversation with the same browser, restore drafts, show account-specific content, and apply plan entitlements and usage limits.
- Process purchases. To initiate checkout, reconcile subscription status, provide a billing portal, prevent duplicate fulfillment, and maintain financial and tax records.
- Communicate. To send account, service, security, purchase, production, and support messages; respond to requests; and send newsletters or other marketing communications where permitted.
- Receive and act on feedback. To review feedback, respond when contact information is available, improve the Service, and document follow-up.
- Analyze and improve. To understand how the Service is used, diagnose errors, evaluate model and product quality, measure performance, develop features, and improve lectures, tutor responses, accessibility, security, and reliability.
- Protect the Service and others. To verify that requests are made by people rather than bots, enforce usage limits, prevent fraud and abuse, investigate security incidents, moderate content, enforce our Terms, and protect rights, safety, and property.
- Comply with law. To meet legal, tax, accounting, reporting, and recordkeeping obligations; respond to lawful process; and establish, exercise, or defend legal claims.
- Carry out transactions. To evaluate or complete a financing, merger, acquisition, reorganization, sale of assets, or similar corporate transaction.
We may aggregate or deidentify information and use it for any lawful purpose. We will not attempt to reidentify information that we maintain as deidentified except to test whether our deidentification measures work, where the law permits.
Artificial intelligence and automated processing
The Service uses artificial intelligence and other automated systems to interview you about a lecture, select relevant examples, parse documents, write and render lectures, synthesize narration, and answer tutor questions.
Information sent for AI processing
Depending on the feature, model inputs may include your prompt, interview transcript, uploaded-document text and figures, tutor conversation and attachments, the lecture transcript and semantic record, current video position, instructions supplied by Academa, and related metadata. Outputs may include interview questions, briefs, lecture source, narration, audiovisual content, and tutor answers.
The providers used for a request depend on the feature and availability. They may include:
- OpenRouter, which routes requests to model-hosting providers;
- Google Cloud Vertex AI and Google Gemini models;
- Amazon Web Services Bedrock and Anthropic models;
- Modal, where Academa runs document-parsing and rendering workloads;
- Fal and ElevenLabs for text-to-speech narration; and
- PostHog for AI observability and evaluation, as described below.
Provider availability and routing can change. A fallback provider may process a request if a preferred provider is unavailable.
AI telemetry
Academa records detailed AI telemetry in PostHog to operate, evaluate, and improve AI features. Unlike ordinary session replay, this telemetry may contain the complete text visible to a model, including system instructions, your prompts and interview answers, extracted document text, tutor conversation context, and model output. It also includes provider, model, settings, token counts, cost, latency, identifiers, and errors.
Binary attachments and signed media URLs are omitted or redacted from this telemetry where implemented, but file metadata, hashes, identifiers, counts, sizes, extracted text, or other model-visible representations may still be recorded. Tutor AI telemetry may be linked to the same analytics session as the corresponding browser session replay.
Training and evaluation
Academa does not currently train its own foundation model on your content. We do use inputs, outputs, ratings, errors, and related telemetry to evaluate and improve the Service and the way it uses models. Model and hosting providers may retain or use inputs and outputs as allowed by our account settings, arrangements with them, and their applicable terms and policies. Because those practices differ by provider and endpoint, do not submit information that you are not comfortable having processed by the providers needed to perform the feature.
No significant automated decisions
Academa does not use these systems to make decisions that produce legal or similarly significant effects about you, such as decisions about employment, credit, housing, insurance, or access to essential services.
How we disclose information
We may disclose the categories of information described in Section 2 as follows.
Service providers and contractors
We disclose information to providers that perform services for us, including:
- Cloudflare for content delivery, networking, Workers, databases, object storage, durable state, security, rate limiting, and Turnstile;
- PostHog for product analytics, session replay, error diagnostics, feature flags, and AI observability;
- Google and GitHub for account authentication;
- Cloudflare and GitHub to deliver in-app feedback to Academa's private issue inbox;
- Polar for customer creation, checkout, payment processing, subscriptions, refunds, taxes, and the billing portal;
- OpenRouter, Google Cloud, AWS, and model suppliers such as Google and Anthropic for AI inference and routing;
- Modal for document parsing and lecture-rendering compute;
- Fal and ElevenLabs for narration generation;
- Resend for transactional email delivery; and
- professional advisers and vendors that support security, legal, accounting, insurance, and business operations.
These providers receive information appropriate to the service they perform. For example, Resend receives a verified email address and message content for a transactional email, while Academa retains a delivery identifier and an event ledger to prevent duplicate sends.
At your direction or in public areas
We disclose information when you direct us to do so, authorize a connection, complete a transaction, or publish content. Information you make public is available to anyone, including search engines and people who are not signed in. See Section 7.
Legal, safety, and enforcement reasons
We may disclose information if we believe in good faith that disclosure is necessary to comply with applicable law, regulation, legal process, or a valid governmental request; enforce agreements; investigate fraud, abuse, or security incidents; protect the rights, property, or safety of Academa, our users, or others; or establish, exercise, or defend legal claims.
Corporate transactions
We may disclose information in connection with an actual or proposed financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction. A recipient will be permitted to process personal information only in a manner consistent with this Privacy Policy unless it gives you notice of a different policy as required by law.
Affiliates
We may disclose information to entities under common control with Academa, if any, for purposes consistent with this Privacy Policy.
No sale or behavioral-advertising sharing
We do not sell personal information for money. We do not disclose personal information to third parties for cross-context behavioral advertising or targeted advertising, and we do not use third-party advertising networks on the Service. We may disclose information to service providers for analytics and the other business purposes described above.
Public information
When you make a generated lecture public, the lecture and associated public information may be visible worldwide and indexed by search engines. Public information may include the generated audiovisual lecture, title, subject, summary, transcript, metadata, publication time, the publishing account's public handle, profile name and image, comments, reactions, and aggregate engagement.
When you comment, the comment, related timestamps and vote counts, and your public handle may be visible worldwide. Academa does not publicly display your name, profile image, email address, or account identifier as comment-author information.
Unless the Service expressly indicates otherwise, your original lecture prompt, interview answers, uploaded PDF, source files, and tutor conversations are not made public merely because the resulting lecture is public. Historical content may follow the visibility setting in effect when it was published.
You should have no expectation of privacy for information you choose to make public. Other people may view, save, copy, quote, or redistribute Public Content outside Academa's control. Search-engine caches, third-party copies, and material reshared by others may remain after you make content private or ask us to remove it.
Cookies, local storage, and analytics
The Service uses cookies and browser storage for essential functions, preferences, analytics, and product improvement.
Essential cookies and identifiers
We use authentication cookies to keep you signed in across Academa subdomains and to protect account actions. We may also remember the sign-in provider you most recently used.
For visitors who use the tutor without signing in, Academa sets an academa_viewer cookie containing a random browser credential. The cookie is generally set for one year and may work across Academa subdomains. The raw credential is not stored with the conversation; Academa derives a cryptographic digest that identifies the guest conversation and related usage. Deleting the cookie breaks the browser's ability to return to that same guest identity but does not itself delete server-side conversation or usage records.
Cloudflare may use cookies or similar signals that are necessary to provide networking, security, and Turnstile bot detection.
Local and session storage
We use local storage to remember player preferences and whether a browser has already contributed a qualifying view for a lecture. We may use session storage to keep a stable identifier for a guest tutor message during the browser session. PostHog may also use cookies or browser storage for anonymous, device, and session identifiers.
PostHog analytics and replay
We use PostHog in the United States for product analytics, session replay, feature flags, error diagnostics, and AI observability. PostHog may collect page and navigation activity, referrer and campaign data, device and browser data, IP-derived location, performance measurements, clicks on instrumented controls, pointer and scroll activity, media interactions, session and device identifiers, and diagnostic details.
When you are signed in, we associate analytics with your Academa account identifier and may attach your name and public handle. We do not send your email address as a PostHog person property.
Session replay can reconstruct the page structure and interactions from a browsing session. Academa configures replay to mask form inputs and marked sensitive text, block attachment elements, strip network request and response bodies and headers, remove URL fragments, and redact sensitive query parameters. These replay protections do not apply to the separate full-content AI telemetry described in Section 5.2.
Your browser controls
Most browsers let you delete or block cookies and storage. Blocking essential cookies may prevent sign-in, guest tutor continuity, billing return flows, or other features from working. Deleting local storage may reset player preferences and allow a later view to be counted again. The Service does not currently provide a separate in-product control that disables PostHog while preserving all other functionality.
Retention
We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, preserve the integrity and provenance of generated lectures, meet legal and accounting obligations, resolve disputes, enforce agreements, and protect the Service. Retention depends on the category and context.
Accounts and authentication
We generally retain account and profile information while your account is active and for a reasonable period afterward. Authentication sessions are configured to expire, but expiration does not necessarily cause immediate deletion of the underlying session row or provider-account record. We may retain security, fraud-prevention, consent, and account-history records after account closure where needed.
Lecture projects and generated assets
Accepted lecture requests, interview turns, briefs, selected uploaded documents, generated source, render attempts, receipts, transcripts, media, semantic records, and publication records form part of the durable production and provenance history of a lecture. We may retain them for the life of the project and afterward for continuity, reproducibility, safety, dispute resolution, and legal or business records. An accepted project remains durable if a later production stage fails.
Before acceptance, the active interview and attachment metadata are stored as the current Composer attempt and uploaded bytes are temporary. Canceling an active interview or choosing Try again after an intake failure removes that attempt from the active Composer state and schedules those temporary bytes for deletion; Academa does not retain it as a Catalog production or intake-history row. Workflow execution records, infrastructure logs, AI telemetry, and model-provider records may remain for their separately configured or provider-controlled retention periods, as described elsewhere in this Policy.
If content has been made public, we may retain the publication record and copies needed to preserve public links, community context, ownership, licensing, safety, or legal records. Third-party caches and copies are outside our control.
Tutor conversations
Tutor messages, attachments, and drafts are stored durably so a conversation can continue across visits. The Service may limit the number of messages kept in the active conversation, but it does not promise deletion after a fixed period. Entitlement, generation, and cost records may remain after conversation content is removed because they are used to account for usage and prevent duplicate charges or grants.
Community information
Public comments remain until deleted or moderated. When a comment is deleted, its body and votes are removed; a blank marker may remain temporarily or for as long as a live reply depends on the thread path. Reactions and votes may remain until changed, removed, or no longer needed for the public tally and integrity of the feature.
Billing, communications, and legal records
We retain subscription, transaction, event-delivery, tax, accounting, support, privacy-request, and dispute records for the periods required or permitted by law and reasonably needed for audit, fraud prevention, enforcement, and legal claims. We may retain an opt-out or suppression record so we can honor a communications choice.
Feedback records
Feedback messages and any associated guest email address or signed-in account identifier and email address are retained in Academa's private GitHub issue inbox for as long as reasonably needed to review the feedback, respond, improve the Service, document follow-up, and meet legal or security obligations. Cloudflare may temporarily retain records needed to deliver the private issue, and GitHub may retain provider records under its terms, policies, and our settings.
Analytics and provider records
Analytics, replay, AI telemetry, infrastructure logs, and records held by providers are retained according to our settings, operational needs, contracts, and applicable law. Providers may maintain their own security, abuse-prevention, transaction, or legal records under their policies.
Deletion and backups
When information is deleted, it may remain for a limited period in backups, caches, logs, legal holds, or systems designed to prevent accidental loss. We may retain information that is required to comply with law, protect safety and security, prevent fraud, maintain billing and entitlement integrity, resolve disputes, enforce agreements, or exercise legal rights. Where appropriate, we may deidentify information instead of deleting it.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These include access controls, transport encryption, separation of public and private storage, signed access to private media, authentication and authorization checks, bot and abuse protections, and provider security controls.
No method of transmission or storage is completely secure. We cannot guarantee that information will never be accessed, used, disclosed, altered, or destroyed without authorization. You are responsible for protecting access to your identity-provider account and devices and for notifying us promptly if you suspect unauthorized use of your Academa account.
Your choices and privacy rights
Product and communications choices
Depending on the feature, you may:
- choose whether a generated lecture is private or public;
- edit your public profile information, subject to the rules for permanent handles;
- delete your own comments, which removes their body as described in Section 2.4;
- change player settings or clear browser cookies and storage;
- manage or cancel a paid plan through the billing portal;
- unsubscribe through a link when one is included in a marketing message or contact us to opt out; and
- disconnect Academa in Google or GitHub, although doing so does not by itself delete the corresponding Academa account or content.
Privacy requests
Depending on where you live and subject to legal exceptions, you may have the right to:
- confirm whether we process your personal information and access it;
- know the categories and specific pieces of personal information we collected, the categories of sources, our purposes, and the categories of recipients;
- correct inaccurate personal information;
- delete personal information;
- receive a portable copy of certain information;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- opt out of a sale, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling;
- limit certain uses of sensitive personal information;
- appeal our decision on a request; and
- receive equal service and pricing without unlawful discrimination for exercising a privacy right.
As stated in Section 6.6, Academa does not currently sell personal information or use it for cross-context behavioral advertising.
How to exercise a right
Email founders@academa.ai with the subject "Privacy Request" and describe your request. You may also write to the address in Section 16. To protect you and others, we may ask for information reasonably necessary to verify your identity and authority. We will use verification information only for that purpose.
An authorized agent may submit a request where applicable. We may ask for proof of authorization and may require you to verify your identity directly. If we deny a request, you may appeal by replying to our decision and stating that you are appealing it.
Some information cannot be deleted or provided because of another person's rights, legal restrictions, security, fraud prevention, billing integrity, a legal obligation, or another applicable exception. We will explain the basis for a denial where required.
EEA, UK, and Swiss users
Where European data-protection law applies, our legal bases include performing our contract with you; our legitimate interests in providing, securing, analyzing, and improving the Service; complying with legal obligations; and consent where we request it. You may also have the right to complain to your local supervisory authority. Contact us first if you would like us to try to resolve a concern.
Children
The Service is intended only for people who are at least 18 years old. We do not knowingly collect personal information from children under 13, or knowingly permit anyone under 18 to create an account or use features that require acceptance of our Terms.
If you believe a child has provided personal information to us, contact founders@academa.ai. We will investigate and take appropriate steps, including deletion where required by law.
International processing and transfers
Academa is based in the United States, and the Service is operated from the United States using providers that may process information in the United States and other countries. Those countries may have data-protection laws different from the laws where you live.
Where required, we rely on appropriate transfer mechanisms, such as contractual protections, adequacy decisions, or another lawful basis for international transfers. Some routing and infrastructure features may process a request in more than one region depending on provider availability.
Third-party sites and services
The Service may link to or integrate with third-party sites and services. Their privacy practices are governed by their own notices, not this Privacy Policy, when they process information independently. This includes identity-provider authorization screens, Polar checkout and billing pages, linked resources in public content, and sites reached through user comments or generated materials.
Review the privacy terms of a third party before providing information to it. Academa is not responsible for a third party's independent privacy or security practices.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the revised policy at this location and change the "Last updated" date.
If a change materially reduces your rights or materially expands how we use personal information already collected, we will provide additional notice, such as by email or a prominent notice on the Service, at least 30 days before the change takes effect where reasonably practicable. We may make a change effective sooner when required by law or reasonably necessary for security, fraud prevention, or the integrity of the Service.
Your continued use of the Service after an updated policy becomes effective means that the updated policy applies to information processed after that time, to the extent permitted by law.
Contact us
For privacy questions, requests, or complaints, contact:
Academa, Inc.
1111B S Governors Ave, STE 37781
Dover, DE 19904
United States
founders@academa.ai