Privacy Policy

Last updated: 20 September 2026

Effective: on first publication in the app

Draft — not yet reviewed by a lawyer. [[BRACKETED]] items are yours to decide. Two of them — where your Supabase project is hosted, and which email provider sends sign-in codes — are facts to look up, not choices, and this document is wrong until they are filled in. See docs/legal-open-questions.md.

This policy explains what the cram app (the "App") collects, why, who else sees it, and what you can make us do about it. It is written to be read, not to be survived.

PYC Software Inc. is the organisation responsible for this information. Reach us at [[CONTACT EMAIL]].


The short version

1. What we collect

To sign you in. Your university email address. We check that its domain belongs to a supported university — that check is the only thing standing between this App and the open internet. We send a six-digit code to that address each time you sign in. We store no password, because there is none.

Your public identity. The handle you choose. It appears on your listings, your reviews, and your profile.

What you tell us about your studies, if you choose to. Your programme (major, minor, level) and the courses and terms you have taken. This drives the home feed and your public profile. It is optional; the App works without it, and you can clear it at any time.

What you post. Listings — course, instructor, term, title, description, price, format — and the note files themselves. We render the first few pages into preview images, as many as your listing offers.

What you do here. Notes you acquire, reviews you write, ratings you give, and accounts you follow. Purchases are stored as a record of what you paid and when, plus an identifier for the payment.

Technical necessities. Your session token, held in your device's secure storage so you stay signed in. Our infrastructure providers keep ordinary server logs, including IP addresses, for security and debugging.

What we do not collect. No legal name. No student number. No date of birth. No location. No contacts or device identifiers for advertising. We do not run advertising or session replay SDKs.

Saved notes and safety. We store notes you bookmark, accounts you block, and reports or support requests you submit. Reports and support messages are visible to you and authorised support staff. Staff responses appear in your inbox.

Notifications. Your inbox contains request answers, sales, course updates, and support responses. If you enable mobile push notifications, we store a push token for that device and your notification preferences. Expo and the device's push provider deliver notifications; you can disable them in the inbox or your device settings. Notification previews may appear on your lock screen.

Local drafts and downloads. Draft fields and attachments are saved on your device or in your browser, scoped to your account. Downloaded notes and a cached profile allow mobile offline reading. Signing out removes offline downloads and the cached profile. Drafts remain for the same account unless cleared or the app/browser data is removed. Keep your device and browser account secure.

Crash diagnostics. When Sentry is configured in a production build, it receives error stack traces and technical app/device information. We disable session replay, performance tracing, and automatic session tracking, and strip user identity, request details, breadcrumbs, and exception messages from crash events. Diagnostic collection is disabled when no Sentry destination is configured.

2. If you sell notes

Selling requires being payable, and being payable requires identity verification. That happens through Stripe, inside a Stripe-operated form shown in the App.

What Stripe collects directly from you, under Stripe's privacy policy and not this one: your legal name, date of birth, address, bank or card details, and — where Canadian law requires it for identity verification or tax reporting — a government identifier. This information goes from your device to Stripe. It does not pass through us and we cannot retrieve it.

What we store about your selling account: the Stripe account identifier, and whether your account is able to receive transfers and payouts. That is enough to know whether to show you a price field, and nothing more.

3. Why we are allowed to have it

Under Canadian privacy law (PIPEDA) we rely on your consent, given when you create an account and when you choose to fill in optional fields. Where you are covered by the GDPR or UK GDPR, our bases are: performance of our contract with you (running your account, delivering what you bought, paying you); our legitimate interests (keeping the marketplace safe and free of abuse); legal obligation (tax and accounting records); and consent for anything optional.

You can withdraw consent by clearing the optional fields or deleting your account. Withdrawing it does not undo what was already done.

4. Who else sees it

We do not sell your personal information, we do not rent it, and we do not share it for advertising. It reaches exactly these parties:

WhoWhat they getWhy
Other students at your universityYour handle, listings, previews, reviews, ratings, follows, and any programme or course history you filled inThe marketplace only works if these are visible. Row-level security scopes them to your own university — students elsewhere cannot see them.
People who acquire your notesThe note file itselfIt is what they came for.
SupabaseEverything in the database and file storage; it is our hosting providerDatabase, file storage, authentication, and server functions. Hosted in the United States (AWS us-east-2, Ohio).
StripePayment and payout information, plus the identity details described in section 2Processing payments and paying sellers. Stripe also uses device and transaction signals for fraud prevention.
[[EMAIL PROVIDER]]Your email address and the sign-in codeDelivering the code that signs you in.
Expo, Apple, and GooglePush token and notification payload when you enable pushDelivering mobile notifications.
Sentry, when configuredLimited crash diagnostics described aboveFinding and fixing application failures.
Law enforcement or a courtOnly what a valid legal order compelsWe require lawful process, and we will tell you unless we are prohibited from doing so.

If the App is ever sold or merged, information may transfer with it. We would tell you first, in the App, before that took effect.

Your information is stored and processed outside your province and outside Canada. Our database, file storage and server functions run in the United States, and our payment processor operates internationally. It is subject to the laws of those places, including lawful access by their governments.

5. How long we keep it

6. Your rights

You can:

We answer within [[30 days]]. We may need to confirm you control the account's email address before acting.

7. What deleting your account actually does

Deletion is not a single erase, and pretending otherwise would be a lie you could catch us in. Here is precisely what happens.

Removed immediately and permanently:

Kept, deliberately:

If that is not what you want, take your listings down and wait until nobody holds a purchase of them before deleting your account.

8. Security

Note files sit in a private bucket. They are never public: every download is a signed link, generated only after the database has confirmed you are the author or that you acquired the notes. Preview images are gated the same way — a free preview is free to students at your university, not free to the open internet.

Row-level security runs on every table, so what you are allowed to read is enforced by the database rather than by the app asking nicely. Connections are encrypted in transit. Sign-in tokens live in your device's secure storage.

No system is perfect. If a breach ever creates a real risk of significant harm to you, we will notify you and the Privacy Commissioner, as Canadian law requires.

9. Children

The App is for university students. It is not directed at children, and we do not knowingly collect information from anyone under 16. The university email requirement makes it unlikely, but if you believe a child has an account, email us and we will remove it.

10. Changes

If we change this policy in a way that materially affects you, we will tell you in the App at least [[14 days]] before it takes effect and update the date at the top. Older versions are in this repository's history.

11. Contact

Questions, requests, or complaints: [[CONTACT EMAIL]] [[LEGAL ENTITY, MAILING ADDRESS]]

Support records may remain after account deletion for handling abuse or purchase issues; their direct account reference is removed. Inbox items, bookmarks, blocks, push tokens, and notification preferences are deleted with your profile. Do not include sensitive personal information in support messages.