1. Scope
This Privacy Policy explains how MySummaries Pty Ltd (ABN 75 545 287 502), a company registered in Victoria, Australia ("MySummaries", "we", "us"), collects, uses, discloses and protects personal information when you use mysummaries.app, portal.mysummaries.app, the MySummaries mobile apps and the services reachable through them (the "Service"). It is written to meet the Australian Privacy Act 1988 and the Australian Privacy Principles, the EU General Data Protection Regulation and UK GDPR, and the California Consumer Privacy Act as amended by the CPRA. Where those laws give you particular rights, the sections below say so. It forms part of our Terms of Service.
For the personal information described here, MySummaries Pty Ltd is the controller (or, in California terms, the business). Our contact details are in section 13. We have not appointed a representative in the European Union or the United Kingdom; contact us directly at the address in section 13.
2. What we collect
- Account information. Email address, the name you give us, your sign-in provider identifier (for Google sign-in), a hashed password (for email sign-in, held by our authentication provider — we never see it), and the study profile you set up: what you are studying, which examiner persona you chose, exam dates, the name you want the examiner to use, and the language you choose for the app and for what the AI writes. Your account also keeps your pomodoro timings, so that the timer starts from the same ones wherever you sign in, and which of the app's tips you have already been shown, so that a tip shown on one device is not offered again on another. When you sign up on the web we also record which language the site was in at that moment, and use it only to count sign-ups by language, so that we know which languages to support. It is kept with your account and deleted with it.
- Your Content. Everything you put into the Service: notes, scratchpad text, uploaded documents (PDF and Word files are converted in your browser to text and page images, and those are what we store), images, flashcards, typed exam answers, audio recordings of spoken answers and the transcripts made from them, and the outputs the Service generates from all of that — cards, papers, marks, lectures, examiner transcripts and feedback.
- Acceptance records. When you accept the Terms and this Policy we record the versions accepted, the time, your IP address and browser user-agent string, so we can show what you agreed to.
- Usage and billing. Which features you use, when, with which model, and what each call cost (to meter your plan); your plan, subscription and credit balance; and the customer and subscription identifiers our payment provider assigns you. We never receive or store your full card number.
- Technical and security information. IP address, device and browser type, app version, request logs, error reports, and the signals our bot-protection service (reCAPTCHA Enterprise / App Check) returns. If you file a bug report from inside the Service, it includes the description you write and a short trail of the screens and calls that preceded it.
- Messages. Anything you send us through the contact form or by email.
- Referral information. If you arrive through an affiliate link, a cookie holding that affiliate's code is set for 60 days so that a signup or purchase can be attributed to them. The affiliate sees a masked form of your email address, never the full address or any of Your Content.
- Analytics. We use Google Analytics 4 on the marketing site, the web app and the affiliate portal. It records the pages you view, an approximate location worked out from your IP address (Google derives the location and does not store the address itself), your device and browser type, and the actions you take in the Service as event names and counts. It never receives the content of your notes, cards, exam answers or recordings, and never your name or email address. In the EEA, the UK and Brazil it runs with analytics storage denied by default: no analytics cookie is set, and Google receives cookieless pings instead. Everywhere else it sets the two cookies described in section 11.
We do not collect information from data brokers, and the Service carries no advertising trackers.
3. Sensitive information, and information about other people
We do not ask for sensitive information (health, racial or ethnic origin, political or religious views, sexual orientation, genetic or biometric data, criminal history). Your own study notes may nonetheless contain some — a medical student's notes about their own condition, for example. If you choose to enter sensitive information about yourself, we process it only to provide the Service to you, on the basis of your explicit choice to include it, and you can remove it at any time by editing or deleting the content.
The Terms prohibit uploading personal information about anyone else that you are not authorised to disclose, and in particular any information about a patient, client or other identifiable individual. We do not want it, do not knowingly process it, and have no agreement with you to act as your processor or service provider for it. If you upload it anyway, you are the party responsible for it under privacy law. If we become aware of it we may delete it and suspend the account, and we will cooperate with any affected person or regulator. If you believe information about you has been uploaded by someone else, contact us and we will investigate.
4. Why we use it, and our legal bases
Under the GDPR and UK GDPR we need a legal basis for each use. They are:
- To provide the Service you asked for (performance of our contract with you) — storing and displaying Your Content, sending it to our AI providers to generate cards, papers, marks, lectures and oral examinations, transcribing your recordings, syncing between the web and mobile apps, sharing with people you choose, metering your plan, and billing. AI processing is inseparable from the Service, which is why it is a term of the contract rather than a separate consent you can withdraw while keeping the Service.
- To run the Service safely and improve it (our legitimate interests, balanced against yours) — security, fraud and abuse prevention, debugging, capacity planning, aggregate usage statistics, reviewing model performance, and paying affiliates for signups they referred (the 60-day first-party referral cookie records only the affiliate's code and is used for nothing else). Where we look at Your Content for these purposes it is to investigate a specific problem or report, not routinely.
- To meet legal obligations — tax and accounting records, responding to lawful requests, and data-breach notification.
- With your consent — optional study reminders or product updates by email. You can withdraw consent at any time; every optional email carries an unsubscribe link that takes effect immediately.
We do not use Your Content to train AI models, do not sell personal information, and do not make decisions about you that have legal or similarly significant effects by automated means. AI marking is feedback for your own use; it is not reported to any examining body.
5. Who we share it with
We share personal information only with the service providers that run the Service on our behalf, each bound by contract to use it only for that purpose:
- Google Cloud / Firebase (United States) — authentication, database, file storage, hosting, serverless compute and bot protection. All of Your Content is stored here.
- Google Analytics (Google LLC, United States) — the analytics described in section 2, processed on our behalf under the Google Ads Data Processing Terms and Google's privacy policy. We do not use it for advertising.
- OpenAI, Anthropic and Groq (United States) — the AI models. The parts of Your Content needed for a request are sent to the one that answers it and the output comes back; we attach no name, email address or account id. As a safety check, OpenAI's moderation service also receives the start of the text in a request, and the words of a picture search, whichever provider answers. Groq turns recorded speech into text and runs the fast text tools — explaining a highlight, the section toolbar's complete, lengthen, shorten and format, and translating a selection. It receives the audio being transcribed and, for a recording dropped onto a board, that board's title and headings to help spelling; or the passage or section text a single request needs. OpenAI also builds the search index over your notes, so it receives their text for that. Under their API terms none of the three may use your data to train their models. OpenAI: up to 30 days — it may keep API inputs and outputs that long for abuse monitoring, and it stores a long generation that runs in the background so that we can collect the result. Anthropic and Groq may each keep API inputs and outputs for a limited period under its API terms. Which provider serves a feature is an operational setting and may change.
- SerpApi (SerpApi, LLC, United States) — the picture search on a board. It receives the words you search for and the board's language, sent from our servers with no name, email address or account id attached, and runs the search on Google. SerpApi keeps each search for 31 days, then deletes it. The previews in the results load straight from Google's image servers, so Google receives your IP address and browser details for them, under its own privacy policy. A picture you choose is downloaded by our servers, so the site hosting it sees our servers rather than you, and it is stored with Your Content like any other picture, along with the address of the page it came from.
- Stripe (United States and local entities) — payments and billing.
- Amazon Web Services (United States) — sending transactional email.
- Apple and Google — distribution of the mobile apps and their crash and install statistics, under their own policies.
We may also disclose personal information where the law requires it, to protect the rights, safety or property of any person, to enforce the Terms, or to a successor if the Service is acquired or merged (we would tell you first). We do not sell personal information and we do not share it for cross-context behavioural advertising.
6. International transfers
MySummaries is operated from Australia, and the providers above store and process data in the United States. If you are in the EEA, the United Kingdom or Switzerland, your personal information is therefore transferred outside your region. We rely on the EU–US Data Privacy Framework, its UK Extension and the Swiss–US Data Privacy Framework where the recipient is certified under them, and otherwise on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), incorporated into our agreements with those providers. You can ask us for a copy of the relevant safeguards.
7. Security
Data is encrypted in transit and at rest. Access to each account's content is restricted by per-user security rules at the database and storage layer; staff access to production data is limited to what is needed to operate the Service and investigate problems. Our AI providers receive only what a request needs, and the API keys for them never leave our servers. No system is perfectly secure, so we also ask you to use a strong, unique password — we check new passwords against known breach lists — and to tell us at once if you think your account has been compromised. If a data breach is likely to result in serious harm to you we will notify you and the relevant authority as the law requires (within 72 hours to a European supervisory authority where the GDPR applies).
8. How long we keep it
- Your Content stays until you delete it or delete your account, with the exceptions below, which a nightly job enforces.
- Recordings. The audio of a recorded spoken answer, and the spoken feedback on it, is deleted 90 days after the attempt. The transcript, the marks and the written feedback stay.
- Boards and subjects. A board you archive is removed 90 days later, and so is a subject you schedule for deletion. Restore points — the earlier versions of a board kept so that you can go back — are deleted after 30 days. Scratchpad items that have already been merged into a board are deleted 30 days after they were captured. An invitation to share a subject with an address that never signs up is deleted after 90 days.
- Notifications, job records and exports. In-app notifications and background generation job records are deleted after 30 days; data-export files after seven days.
- Unconfirmed sign-ups. An account whose email address is never confirmed is deleted seven days after sign-up, so that a mistyped address is not held — unless it already holds a plan or an affiliate application.
- Account deletion runs after a seven-day recovery window, then removes Your Content, your stored files, your profile, subscription projections and your authentication account. It also cancels any subscription and deletes your customer record and saved card at Stripe, which keeps the invoices as a financial record. The database is backed up nightly and each backup is kept for 30 days, so a copy of what was deleted rolls off within a further 30 days. One thing is kept: a one-way, salted hash of the email address you signed up with, together with the count of free-plan items that address has used. It identifies nobody, cannot be turned back into an address, and is not included in a data export — it exists only so that deleting an account and signing up again does not hand out a second free allowance.
- Billing, usage and acceptance records are kept for as long as tax, accounting and consumer law require — generally up to seven years — and then deleted or anonymised.
- Emails and contact messages — the queue of emails we send on your behalf or about your account, and messages you send us through the contact form, are deleted 30 days after they are written.
- Security logs are kept for up to 12 months unless needed for an ongoing investigation.
9. Your rights and controls
Wherever you live, the Account page lets you export a structured copy of your data, edit your profile, manage your subscription and schedule deletion of your account, and every board lets you edit or delete its content directly.
Depending on where you live you also have rights under law to:
- access the personal information we hold about you and be told how we use it;
- have inaccurate information corrected;
- have your information deleted;
- receive it in a portable, machine-readable form;
- object to, or ask us to restrict, particular processing;
- withdraw consent where consent is the basis (this does not affect processing already done);
- not be discriminated against for exercising any of these rights; and
- complain to a supervisory authority.
To exercise a right that the Account page does not cover, email [email protected] from the address on your account, or use the contact form while signed in, so that we can verify the request. We respond within one month (45 days for California requests), or tell you if we need longer and why. We will not charge for a request unless it is manifestly unfounded or excessive. If you are unhappy with our response you can complain to the Office of the Australian Information Commissioner (oaic.gov.au), the UK Information Commissioner's Office (ico.org.uk), your local EU data protection authority, or the California Attorney General.
10. California residents
This section supplements the rest of the Policy for California residents under the CCPA/CPRA. In the preceding 12 months we have collected the following categories of personal information, from you directly and from your device, for the purposes in section 4, and disclosed them for a business purpose to the service providers in section 5: identifiers (name, email, account and customer IDs, IP address); customer records and commercial information (plan, purchases, credits); internet and electronic activity (feature use, logs, bug-report trails); audio information (recordings you make); the content you upload and the outputs generated from it; inferences limited to study scheduling (which cards are due); and sensitive personal information limited to account credentials and any health or other sensitive information you choose to include about yourself in your notes. We use sensitive personal information only to provide the Service you requested and for security, which are permitted purposes, so no "Limit the Use of My Sensitive Personal Information" control is required. We do not sell personal information, do not share it for cross-context behavioural advertising, and have no actual knowledge of selling or sharing the personal information of anyone under 16. You have the rights to know, access, correct, delete and port your information and not to be discriminated against, exercisable as described in section 9, including through an authorised agent with written permission from you. Retention periods are in section 8.
11. Cookies and local storage
The Service uses only what it needs to work: a sign-in token kept by our authentication provider, your display preferences (theme, fonts, pomodoro timings, country filter) stored in your browser, a language cookie, bot-protection tokens, and — on the marketing site only, if you arrived through an affiliate link — the 60-day referral cookie described in section 2. The pomodoro timings are also saved on your account, as section 2 describes. The language cookie, "ms_lang", holds only the language you chose, so that the marketing site and the web app both open in it. It is set only when you pick a language, or when the web app applies the language saved on your account, and lasts a year. Google Analytics adds two analytics cookies, "_ga" and "_ga_" followed by our measurement id; they hold a randomly generated identifier for your browser and last up to two years — except in the EEA, the UK and Brazil, where analytics storage is denied by default and neither is set. There are no advertising cookies. You can clear all of these from your browser settings, and refuse the analytics ones there or with Google's opt-out browser add-on, which turns off Google Analytics on every site you visit. Clearing the sign-in token signs you out.
12. Children
The Service is not directed at children under 16 and we do not knowingly collect personal information from them. If you are under 18 a parent or guardian must agree to the Terms for you. If you believe a child under 16 has created an account, contact us and we will delete it.
13. Changes and contact
When this Policy changes we publish it with a new "Last updated" date. For changes that matter we also give it a new version, ask you to accept it in the Service before you continue, and tell you by email where we can. Questions, requests and complaints about privacy go to [email protected] or the contact form. Please include enough detail for us to identify your account and understand the request.