What we collect, how we use it, and how to delete it
A plain-language explanation of how LearnByAi handles the documents, messages, and account data you share with us. No legal boilerplate, no vague commitments.
Last reviewed July 2026
Summary
The short version
If you only read one section, read this one. The rest of this page explains each of these points in detail.
Anonymous by default
You can upload and analyze documents without creating an account. We generate a session token in your browser so your workspace stays private to your device.
Your documents, your data
We do not claim ownership of the files or conversations you create. You retain full rights to everything you upload.
Not used for AI training
Your files and chat messages are sent to OpenAI only to answer your questions. They are not used to train any model.
Encrypted in transit
Every connection between your browser, our servers, and our storage and AI providers uses TLS encryption.
Deleted on request
Ask us to delete your data and we remove it from file storage, the vector index, and the database. Most deletions complete immediately.
Never sold or shared
We do not sell your data and we do not share it with advertisers or data brokers. The only third parties involved are the providers required to run the platform.
Data Collection
What we collect and why
We collect only what is necessary to run the service. Here is a complete list.
Session tokens
When you use LearnByAi without signing in, we generate an anonymous session token stored in your browser. This token ties your documents and chat history to your device without capturing your name, email, or identity.
Uploaded files
The documents you upload (PDF, DOCX, TXT, and other supported formats) along with their extracted text content. We process these files to answer your questions and store them for as long as your session or account is active.
Chat history
The questions you ask and the answers you receive during a session. This history is kept so you can continue a conversation without re-uploading your document.
Account information (if you sign up)
If you create an account, we store your email address and a hashed password. We do not collect your name, phone number, or payment card details. Payment amounts are handled by our third-party processor.
Usage records
Basic usage counts, such as how many messages you have sent or how many documents you have uploaded, used to enforce tier limits and calculate wallet balances. These records do not contain the content of your documents.
Data Use
How your information is used
The data we collect is used for three purposes only.
01
Answering your questions
Document content and chat history are used to retrieve relevant passages and generate accurate, grounded answers.
02
Running the platform
Usage records let us enforce tier limits, calculate wallet balances, and keep the service stable for all users.
03
Communicating with you
If you have an account, we may use your email to send transactional messages such as password resets or billing receipts. No marketing email without your consent.
Third-Party Providers
Who else handles your data
Running LearnByAi requires a small number of infrastructure and AI providers. Each one handles a specific part of the pipeline and nothing more.
OpenAI
Generates embeddings and chat responses. Only the passages from your document needed to answer your specific question are sent, not your entire file or conversation history. Under OpenAI's API terms, data submitted through the API is not used to train their models.
Cloudinary
Stores your uploaded files. Files are accessed only through signed, expiring URLs generated by our backend. Cloudinary is SOC 2 Type II certified.
Supabase
Manages account data, session metadata, and usage records in a Postgres database. Authentication runs through Supabase Auth with password hashing and secure session tokens.
Qdrant
Stores the vector embeddings generated from your document text. Every query is filtered by owner ID, so a request can only ever return your own content.
Retention and Deletion
How long we keep your data
We keep your data for as long as it is useful to you and no longer.
Anonymous sessions
Documents and chat history tied to an anonymous session token are retained while the session is active and cleaned up automatically once the session goes idle.
Signed-in accounts
Documents and history persist until you delete them or close your account. Nothing is auto-deleted while your account is active.
Usage records
Aggregate usage counts are retained to support billing, audit trails, and service integrity. These do not contain document content.
Backups
Deleted data may remain in encrypted backups for up to 30 days before those backups are cycled out.
Deletion Process
What a deletion request triggers
When you delete a document or request account deletion, a cascading removal runs across every system that touched your data.
Files removed
File deleted from Cloudinary storage
Vectors wiped
Embeddings deleted from Qdrant
Records cleared
Database rows removed from Supabase
Logs flushed
Session and activity logs purged
Your Rights
What you can ask us to do
Regardless of where you are located, you can exercise the following rights by emailing security@learnbyai.app.
Access
Ask what data we hold about you and receive a copy of it.
Correction
Ask us to correct inaccurate information associated with your account.
Deletion
Request that we permanently delete your data from our systems.
Portability
Ask for a machine-readable export of your account data where technically feasible.
Objection
Object to specific uses of your data, such as receiving any communications from us.
Restriction
Ask us to temporarily stop processing your data while a dispute is being resolved.
FAQ
Privacy questions
Contact
Privacy inquiries
For data access requests, deletion requests, or any question about this policy. We aim to respond within one business day.
See it work with your own document
Upload a file and ask a question. No account required, and your document stays private to your session.