Privacy Policy
Last updated: 20 September 2026
Effective: on first publication in the app
Draft — not yet reviewed by a lawyer.[[BRACKETED]]items are yours to decide. Two of them — where your Supabase project is hosted, and which email provider sends sign-in codes — are facts to look up, not choices, and this document is wrong until they are filled in. Seedocs/legal-open-questions.md.
This policy explains what the cram app (the "App") collects, why, who else sees it, and what you can make us do about it. It is written to be read, not to be survived.
PYC Software Inc. is the organisation responsible for this information. Reach us at [[CONTACT EMAIL]].
The short version
- We ask for a university email, a handle you choose, and — if you want to — your programme and the courses you have taken.
- We do not ask for your legal name, your student number, or your address.
- We do not sell your data or use advertising trackers. Configured production builds may send limited crash diagnostics to Sentry to help fix failures.
- Your notes are stored privately and are readable only by you and by people who acquired them.
- If you sell notes, Stripe collects identity and banking details directly. We never see them.
- You can delete your account from inside the App. Some things survive on purpose, and the section on deletion says exactly which.
1. What we collect
To sign you in. Your university email address. We check that its domain belongs to a supported university — that check is the only thing standing between this App and the open internet. We send a six-digit code to that address each time you sign in. We store no password, because there is none.
Your public identity. The handle you choose. It appears on your listings, your reviews, and your profile.
What you tell us about your studies, if you choose to. Your programme (major, minor, level) and the courses and terms you have taken. This drives the home feed and your public profile. It is optional; the App works without it, and you can clear it at any time.
What you post. Listings — course, instructor, term, title, description, price, format — and the note files themselves. We render the first few pages into preview images, as many as your listing offers.
What you do here. Notes you acquire, reviews you write, ratings you give, and accounts you follow. Purchases are stored as a record of what you paid and when, plus an identifier for the payment.
Technical necessities. Your session token, held in your device's secure storage so you stay signed in. Our infrastructure providers keep ordinary server logs, including IP addresses, for security and debugging.
What we do not collect. No legal name. No student number. No date of birth. No location. No contacts or device identifiers for advertising. We do not run advertising or session replay SDKs.
Saved notes and safety. We store notes you bookmark, accounts you block, and reports or support requests you submit. Reports and support messages are visible to you and authorised support staff. Staff responses appear in your inbox.
Notifications. Your inbox contains request answers, sales, course updates, and support responses. If you enable mobile push notifications, we store a push token for that device and your notification preferences. Expo and the device's push provider deliver notifications; you can disable them in the inbox or your device settings. Notification previews may appear on your lock screen.
Local drafts and downloads. Draft fields and attachments are saved on your device or in your browser, scoped to your account. Downloaded notes and a cached profile allow mobile offline reading. Signing out removes offline downloads and the cached profile. Drafts remain for the same account unless cleared or the app/browser data is removed. Keep your device and browser account secure.
Crash diagnostics. When Sentry is configured in a production build, it receives error stack traces and technical app/device information. We disable session replay, performance tracing, and automatic session tracking, and strip user identity, request details, breadcrumbs, and exception messages from crash events. Diagnostic collection is disabled when no Sentry destination is configured.
2. If you sell notes
Selling requires being payable, and being payable requires identity verification. That happens through Stripe, inside a Stripe-operated form shown in the App.
What Stripe collects directly from you, under Stripe's privacy policy and not this one: your legal name, date of birth, address, bank or card details, and — where Canadian law requires it for identity verification or tax reporting — a government identifier. This information goes from your device to Stripe. It does not pass through us and we cannot retrieve it.
What we store about your selling account: the Stripe account identifier, and whether your account is able to receive transfers and payouts. That is enough to know whether to show you a price field, and nothing more.
3. Why we are allowed to have it
Under Canadian privacy law (PIPEDA) we rely on your consent, given when you create an account and when you choose to fill in optional fields. Where you are covered by the GDPR or UK GDPR, our bases are: performance of our contract with you (running your account, delivering what you bought, paying you); our legitimate interests (keeping the marketplace safe and free of abuse); legal obligation (tax and accounting records); and consent for anything optional.
You can withdraw consent by clearing the optional fields or deleting your account. Withdrawing it does not undo what was already done.
4. Who else sees it
We do not sell your personal information, we do not rent it, and we do not share it for advertising. It reaches exactly these parties:
| Who | What they get | Why |
|---|---|---|
| Other students at your university | Your handle, listings, previews, reviews, ratings, follows, and any programme or course history you filled in | The marketplace only works if these are visible. Row-level security scopes them to your own university — students elsewhere cannot see them. |
| People who acquire your notes | The note file itself | It is what they came for. |
| Supabase | Everything in the database and file storage; it is our hosting provider | Database, file storage, authentication, and server functions. Hosted in the United States (AWS us-east-2, Ohio). |
| Stripe | Payment and payout information, plus the identity details described in section 2 | Processing payments and paying sellers. Stripe also uses device and transaction signals for fraud prevention. |
[[EMAIL PROVIDER]] | Your email address and the sign-in code | Delivering the code that signs you in. |
| Expo, Apple, and Google | Push token and notification payload when you enable push | Delivering mobile notifications. |
| Sentry, when configured | Limited crash diagnostics described above | Finding and fixing application failures. |
| Law enforcement or a court | Only what a valid legal order compels | We require lawful process, and we will tell you unless we are prohibited from doing so. |
If the App is ever sold or merged, information may transfer with it. We would tell you first, in the App, before that took effect.
Your information is stored and processed outside your province and outside Canada. Our database, file storage and server functions run in the United States, and our payment processor operates internationally. It is subject to the laws of those places, including lawful access by their governments.
5. How long we keep it
- Your account and profile: until you delete it.
- Listings and note files: until you take them down or delete your account — with the exception in section 7 for notes other people have paid for.
- Purchase records:
[[7 years]], because they are financial records and Canadian tax law requires us to keep them. Stripe keeps its own copies under its own retention rules. - Sign-in codes: minutes. They expire quickly and are not stored after use.
- Server logs: as our providers retain them, typically weeks.
6. Your rights
You can:
- See what we hold. Most of it is already visible in the App; email us for the rest.
- Correct it. Your programme, courses, and listings are editable in the App. Your handle can be changed. Email us about anything else.
- Delete it. From the App — see section 7.
- Take it with you. Ask and we will send your profile, listings, reviews and purchase history in a machine-readable file.
- Complain. To us first, at
[[CONTACT EMAIL]]. If we do not resolve it, to the Office of the Privacy Commissioner of Canada, or to your local supervisory authority if you are in the UK or the EEA.
We answer within [[30 days]]. We may need to confirm you control the account's email address before acting.
7. What deleting your account actually does
Deletion is not a single erase, and pretending otherwise would be a lie you could catch us in. Here is precisely what happens.
Removed immediately and permanently:
- your account and sign-in credentials;
- your handle, programme, and course history;
- your follows, and who follows you;
- the record of notes _you_ bought;
- listings nobody has bought, and their files.
Kept, deliberately:
- Listings other people paid for. They stay in those buyers' libraries and stay downloadable. They come off sale, and your name comes off them — the author becomes anonymous. Someone who paid for notes should not lose them because the author left.
- Reviews you wrote, anonymised rather than deleted. Removing them would silently change every note and course rating that had already counted them, which would quietly move other people's scores.
- Purchase records for the sales you made, as financial records, for the retention period in section 5. Buyer identity stays attached because it is their receipt.
If that is not what you want, take your listings down and wait until nobody holds a purchase of them before deleting your account.
8. Security
Note files sit in a private bucket. They are never public: every download is a signed link, generated only after the database has confirmed you are the author or that you acquired the notes. Preview images are gated the same way — a free preview is free to students at your university, not free to the open internet.
Row-level security runs on every table, so what you are allowed to read is enforced by the database rather than by the app asking nicely. Connections are encrypted in transit. Sign-in tokens live in your device's secure storage.
No system is perfect. If a breach ever creates a real risk of significant harm to you, we will notify you and the Privacy Commissioner, as Canadian law requires.
9. Children
The App is for university students. It is not directed at children, and we do not knowingly collect information from anyone under 16. The university email requirement makes it unlikely, but if you believe a child has an account, email us and we will remove it.
10. Changes
If we change this policy in a way that materially affects you, we will tell you in the App at least [[14 days]] before it takes effect and update the date at the top. Older versions are in this repository's history.
11. Contact
Questions, requests, or complaints: [[CONTACT EMAIL]] [[LEGAL ENTITY, MAILING ADDRESS]]
Support records may remain after account deletion for handling abuse or purchase issues; their direct account reference is removed. Inbox items, bookmarks, blocks, push tokens, and notification preferences are deleted with your profile. Do not include sensitive personal information in support messages.