Skip to content
TextbookOS

Privacy Policy

How TextbookOS handles your data — in plain language.

Last updated: 15 August 2026

This policy is published by the operator of TextbookOS ("we", "us") — an individual-run study app currently in private beta, not yet a registered company (a company will take over as publisher once formed, post-traction). Contact: support@textbookos.com.

Plain-English version: this explains what TextbookOS collects, why, and what you (or your parent/guardian) can do about it.

1. Who this is for, and who's in charge of the account

TextbookOS is a study app for students. You can sign up yourself if you meet Google's own minimum age for holding a personal Google Account (13 in many places, sometimes higher depending on local law) — we rely on that gate rather than running a separate age-verification system.

If you're under 13: you can still use TextbookOS, but a parent or legal guardian must create and manage the account. That parent/guardian is the Account Holder — the person responsible for the account, its content, and (once paid plans exist) any payments on it. A parent or guardian is also welcome to manage the account for an older teen if they'd rather handle it themselves.

2. What we collect

In short: your Google sign-in info, what you put into TextbookOS, and basic usage counts to keep the free plan fair.

  • Account info — your name, email address, and profile photo, from signing in with Google.
  • Your content — the notes you write, PDFs you upload, chats you import, and your conversations with the AI tutor.
  • Browser extension activity — if you use the TextbookOS Chrome extension (currently in private developer beta), it only captures content when you actively trigger it — never in the background.
  • Usage counts — how many tutor questions, PDF pages, and note approvals you've used today, so we can apply plan limits fairly and honestly.
  • Basic technical info — IP address and device/browser details, collected automatically by our infrastructure (Cloudflare) for security and to keep the service running.
  • Payment info (only once a paid plan is available) — handled directly by our payment processor, Razorpay. We never see or store your full card number.

We do not collect more than we need to run the app, and we do not buy data about you from anyone else.

3. Who we share it with

We don't sell your data, and we don't share it with advertisers — see Section 5. We use a small number of service providers to run TextbookOS, each only for the job below:

Provider What they handle
Google Sign-in (via Supabase Auth)
Supabase Our database and authentication infrastructure (hosted in Mumbai, India)
OpenAI, Anthropic See note below.
Google (Gemini) Reads scanned or photographed PDFs that contain no selectable text — nothing else. These files go to Google's paid Gemini API. Under Google's paid-service terms, Google does not use your prompts or files to improve its products. Google logs prompts and responses for a limited period, solely to detect abuse of its service and to meet legal obligations; that data may be stored or cached in any country where Google operates. Google's paid terms do not address human review either way, so we make no promise about it. Importing a scan is a paid feature (Starter, Focus or Deep) — on Trial or Free the import is refused and nothing is sent to Google. A PDF that already contains real text never reaches Google at all.
Cloudflare Domain, content delivery, and security/rate-limiting
Cloudflare Turnstile Checks that a waitlist signup is a person and not a bot. Your IP address is sent to Cloudflare for that check.
Razorpay Payment processing, once a paid plan is available

OpenAI, Anthropic - Power the AI tutor, pull notes out of PDFs and chats, make your notes searchable, and write practice questions about them.

Google (Gemini) - Reads scanned or photographed PDFs that contain no selectable text — nothing else. These files go to Google's paid Gemini API. Under Google's paid-service terms, Google does not use your prompts or files to improve its products. Google logs prompts and responses for a limited period, solely to detect abuse of its service and to meet legal obligations; that data may be stored or cached in any country where Google operates. Google's paid terms do not address human review either way, so we make no promise about it. Importing a scan is a paid feature (Starter, Focus or Deep) — on Trial or Free the import is refused and nothing is sent to Google. A PDF that already contains real text never reaches Google at all.

This includes notes you write yourself. Whenever a note is saved, or its text is edited, that note is sent to be indexed for search and to have a few practice questions written about it - not only notes brought in from a PDF or a chat.

Notes, text PDFs, written text, and chat prompts sent through OpenAI and Anthropic are strictly private and never used to train public AI models, per their commercial API terms.

Can we see your notes ourselves? We can read your notes in our database when we support you or verify the product works; we do not browse them otherwise, and no employee other than the operator has access today.

TextbookOS is not a password manager or a vault. Do not put passwords, card or bank details, or other secrets in notes: notes are sent to our AI providers to be searched and questioned, and we can read them.

Voice input uses your browser's own speech recognition. Recording continues until you tap Stop — it does not end just because you pause. On Chrome and Edge the audio is sent to Google or Microsoft for recognition; on Safari it mostly stays on your device. TextbookOS receives the text only and never stores a recording.

4. How long we keep it, and how to delete it

We keep your account and content for as long as your account is active, so your notebook is there when you come back.

Trash. Notes you delete go to your Trash, and so do images that no note uses any more. Nothing in the Trash is gone until you empty it. Emptying the Trash permanently deletes those notes and the stored image files, including the smaller copies we make for display.

On your computer — the Chrome extension's capture buffer. When you capture something with the extension, it waits in a buffer on your computer until it is sent to your notebook. That buffer holds up to 20 waiting captures — the text you saved, or for a screenshot the picture itself, along with the address of the page it came from. It stays there until it is sent: there is no time limit, and nothing you capture is quietly discarded for being old. If all 20 slots are full and they cannot be sent, the extension refuses the new capture and tells you, rather than dropping anything you already have. The buffer never leaves your machine on its own — it is local storage, not synced to Google or to us, and nothing reads it except the TextbookOS side panel on that computer. You can clear it three ways: send the captures to your notebook, remove them one at a time in the side panel, or uninstall the extension, which deletes the buffer with it.

Deleting your data: today, deleting your account is a manual process — email support@textbookos.com from the account's sign-in email (or have your parent/guardian do so, if they're the Account Holder), and we'll delete your account and content.

Some records (like payment records, once payments exist) may need to be kept longer to meet legal/tax requirements.

5. Advertising

TextbookOS does not show ads, does not build advertising profiles from your data, and does not share your data with ad networks. If that ever changes, we'll update this policy first and tell you clearly — not bury it in a settings toggle.

6. If you're in the European Union (GDPR)

TextbookOS isn't specifically built for the EU market today, but if you use it from there: the age at which you can consent to an online service on your own varies by country (13 to 16, set by each EU member state). If you're below that age where you live, a parent or guardian needs to consent on your behalf — the same parent-managed-account approach as Section 1. You have the usual GDPR rights (access, correction, deletion, portability) — contact support@textbookos.com to use them.

7. Security

We use industry-standard practices to protect your account (Google-backed sign-in, encrypted connections, access controls on our database) — but no system is perfectly unbreakable, and we can't guarantee absolute security.

8. Changes to this policy

If we make a meaningful change to this policy, we'll post the update here and, where required, let Account Holders know directly.

9. Contact

Questions, deletion requests, or anything else: support@textbookos.com.

© 2026 TextbookOS. All rights reserved. Home · Terms