Last Updated: April 11, 2025
Welcome to SMOTE! This Privacy Policy explains how SMOTE ("we," "us," or "our") collects, uses, shares, and protects information in relation to our web application and related services (the "Service"). By using our Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
We collect the following types of information:
I. Account Information:
When you create an account, we collect information such as your name, email address, password, school affiliation, and chosen terms/courses. If you sign up using a third-party service like Google, we receive information from that service as permitted by your privacy settings on that service.
II. User-Generated Content (UGC):
We collect content you create, upload, or share through the Service. This includes:
- Audio recordings you make within the app for lecture generation.
- Files you upload (images, videos, documents, audio files, YouTube links) as course materials, chat attachments, profile pictures, or for AI processing (like schedule images or lecture audio).
- Content generated during interactions with AI features, including chat history with the AI Tutor and AI-generated summaries/notes derived from your uploads. Chat history is stored to provide conversational context.
- Messages sent within course-specific chats.
III. Device Permissions Data:
With your explicit permission, granted contextually when you use specific features (primarily in our associated mobile application), we may access:
- Microphone: To record audio when you use the recording feature for lecture generation. Recordings are stored locally temporarily and then processed or uploaded as directed by you. Recording may continue in the background if you leave the app during a session.
- Contacts: To allow you to select contacts for inviting them to the app. We only read contact names/emails temporarily for display and selection; we do not store your entire address book. Only selected contact details are used transiently for sending invitations.
- Location (When In Use): To find nearby schools during onboarding. We access your precise location coordinates transiently for this purpose only; it is not stored persistently with your account.
- Media Library (Photos/Videos): To allow you to select images/videos for uploading (e.g., course materials, avatar, chat, schedule image). We only access files you specifically select.
- File Access: The app uses the system file picker (iOS/Android) to allow you to select documents or audio files for upload (e.g., course materials, lecture audio). We only receive access to the files you explicitly choose.
IV. AI Interaction Data:
When you use AI-powered features (like lecture generation from audio/links, AI Tutor), we process the content you provide (e.g., uploaded audio, YouTube links, schedule images, prompts to the AI Tutor) through third-party AI service providers (see Section 3) to generate the requested output (e.g., lecture notes, schedule data, chat responses).
V. Usage and Device Information:
We automatically collect information about how you use the Service, such as features accessed, interaction times, crash logs, device type, operating system, browser type, IP address, and unique device identifiers (or similar identifiers like cookies for web) for analytics and service improvement purposes.
2. How We Use Your Information
We use the information we collect for purposes including:
- To operate, maintain, and provide the features of the Service (e.g., creating your account, storing and displaying your UGC, processing audio/images/links for AI features, enabling invites, finding schools).
- To personalize your experience.
- To communicate with you (e.g., service announcements, support).
- To monitor and analyze usage trends and improve the Service.
- To enforce our Terms of Service and detect/prevent fraud or security issues.
- To comply with legal obligations.
- We do NOT use your personal data or User-Generated Content (including audio recordings, uploaded files, AI prompts, AI Tutor chat history, or feedback) to train or improve AI models, either our own or those of third parties.
3. Sharing of Your Information
We may share your information in the following circumstances:
- Within Courses: User-Generated Content you contribute to a specific course (e.g., uploaded materials, messages within the course chat) will be visible to other users enrolled in that same course.
- Third-Party Service Providers: We share information with vendors and service providers who need access to such information to perform services on our behalf. These include:
- Cloud Hosting & Storage: Supabase
- Authentication: Google (if using Google Sign-In)
- Authentication: Apple (if using Sign in with Apple)
- AI Content Generation: OpenAI
- Speech-to-Text: ElevenLabs
- Analytics & Advertising: Facebook SDK (Meta Platforms, Inc.)
These providers are obligated to protect your data and use it only for the services they provide to us according to their respective privacy policies. Please review their policies for details on their data handling practices:
- With Your Consent: We may share information for other purposes with your explicit consent.
- Legal Requirements: We may disclose information if required by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
- Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction.
4. Third-Party Analytics and Advertising (Facebook SDK)
We use third-party services, specifically the Facebook SDK (primarily in our mobile application, though related analytics may apply to web interactions), for app usage analytics and potentially for advertising purposes in the future. This SDK helps us understand how users interact with our Service and may be used to measure the effectiveness of advertising campaigns or deliver relevant ads.
The Facebook SDK may collect or process certain data as described in their Data Policy, including:
- Device Information: Such as your operating system version, device model, platform, carrier, timezone, and screen size (more relevant in mobile context).
- Usage Data: Information about your interactions with the Service, such as app installs, app launches (sessions), session duration, and specific events or features used (which we may configure the SDK to log).
- Identifiers: On iOS, the Identifier for Advertisers (IDFA) may be collected only if you grant permission through the App Tracking Transparency (ATT) prompt. On Android, the Google Advertising ID (GAID) may be collected unless you have opted out in your device settings. Facebook may also use other pseudonymous identifiers. Browser cookies or similar web technologies may be used for web analytics.
- IP Address: Your IP address may be collected by Facebook.
This data is shared directly with Facebook (Meta) and is subject to their Data Policy (linked in Section 3). We use the aggregated insights from this data for internal analytics to improve the Service and may use it for future advertising relevance.
Your Choices Regarding Tracking:
- iOS: You have direct control over the collection of the IDFA. You can grant or deny tracking permission when presented with the App Tracking Transparency (ATT) prompt within the app.
- Android: You can typically reset your Google Advertising ID or opt-out of personalized advertising through your device's Google settings.
- Web Browsers: You can typically manage tracking preferences through your browser settings, including options to block third-party cookies or enable "Do Not Track" signals, though effectiveness varies.
5. Data Security
We implement reasonable security measures (including HTTPS for data transmission) designed to protect your information from unauthorized access, alteration, disclosure, or destruction. However, no internet-based service is 100% secure.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you the Service. Account information and directly identifying data (such as your name, email, authentication identifiers) are deleted upon your request for account deletion (see Section 7). User-Generated Content you contributed to courses (including messages, uploaded files, and AI-generated content derived from your uploads like lecture notes or chat history) may be retained but anonymized and attributed to a "Deleted User" state after account deletion to maintain the integrity and context of shared course environments for remaining users. We may retain certain usage or anonymized data for longer periods for analytics, security, or legal compliance purposes.
7. Your Rights and Choices
- Access and Correction: You may access or update your account information (such as name or avatar) through your profile settings in the app.
- Permissions: You can manage Microphone, Location, Contacts, and Media Library permissions through your device's operating system settings for the mobile app. Browser permissions (e.g., for microphone access if applicable on web) are managed through browser settings.
- Account Deletion: You can request the deletion of your account and associated personal information directly within the app via the Settings or Account screen. Upon processing your request, your personal identifiable information (including your name, email, authentication details, and any direct link between you and your generated content) will be permanently deleted from our active systems. As noted in Section 6, User-Generated Content shared within courses will be retained but fully anonymized and attributed to a "Deleted User". Please note that some residual data may remain in backups for a limited time before being automatically deleted.
- Communications: You may opt-out of promotional emails by following the unsubscribe instructions in those emails.
8. Children's Privacy
Our Service is not directed to individuals under the age of 13 (or 16 in the European Economic Area). We require users to confirm they meet the minimum age requirement during registration. We do not knowingly collect personal information from children under these ages. If we become aware that we have inadvertently collected such information, we will take steps to delete it.
9. Third-Party Links and Services
The Service may contain links to third-party websites or services (e.g., Google for authentication, Supabase for backend services, OpenAI and ElevenLabs for AI features, Facebook for analytics). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies using the links provided in Section 3 or by visiting their respective websites.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy within the app or through other communication channels. Your continued use of the Service after such changes constitutes your acceptance of the new policy.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at info@howcan.io