Legal
Privacy Policy
Intoola Study ("Study," "intoola," "we," "our," or "us") is a product of INTOOLA LLC. This Privacy Policy explains what information Study collects, how that information is used and shared, how long it is kept, and the choices and rights available to you. We have written this policy to be specific and accurate rather than generic, because we believe you deserve to understand exactly what happens to your data. Please read this policy carefully before using Study. By installing or using the Study Chrome extension, signing in to My Materials, or otherwise using the services described below, you agree to the practices described in this policy. If you do not agree, please do not use Study.
1. Who We Are
Study is a Chrome browser extension that works alongside a student's existing courses as a personal AI tutor. Students choose and add the materials they want to learn from - by uploading files or, where supported, selecting Google Classroom coursework - and Study can then explain, summarize, quiz, review, and answer questions about those materials. We are an independent software developer. Study is not affiliated with, endorsed by, sponsored by, or an agent of Canvas, Instructure, Brightspace, D2L, Google Classroom, Google, Stripe, any school, university, instructor, or educational institution, unless we expressly state otherwise in writing. Study is a direct-to-consumer tool: an individual student chooses to install and use it. We do not currently offer Study through institutional contracts, and this policy describes Study as used directly by individual students unless stated otherwise. You can reach us at info@intoola.com or through our Chrome Web Store listing page. We do not currently have a dedicated privacy officer, legal department, or phone line, but we take privacy inquiries seriously and will do our best to respond in a timely manner.
2. Products and Services This Policy Covers
This policy applies to:
- The Intoola Study Chrome extension and all features and functionality it contains, including Study, Learn, Chat, Record, and the Calendar screen.
- My Materials, the companion web application at intoola.com/materials, where you can sign in with the same Google account used with the Extension to view and manage materials Study has generated for you.
- The Study-related pages of the intoola.com marketing website (such as the Study product page, this Privacy Policy, and the Referral Program page).
- All information processed in connection with the above, including files you upload, data you explicitly select through Google Classroom, prompts and chat messages, and data processed by AI services on your behalf.
Intoola Recruit is a separate Intoola product with its own extension and its own privacy policy, available on the Recruit product pages. This policy does not cover Recruit. This policy also does not apply to third-party services that Study connects to on your behalf, such as Google's Gemini API, Google Classroom, Google Drive, Google's speech-recognition service, or Stripe. Those services are governed by their own privacy policies, which we reference and link to in Section 10.
3. Information We Collect
For Canvas and Brightspace, Study provides a lightweight launcher and may read a plainly visible course label to personalize the Study heading. It does not use Canvas or Brightspace material APIs and does not automatically retrieve LMS files. Google Classroom continues to use Google OAuth through Chrome Identity.
3.1 Account, Sign-In, and Authentication Information
When you first open the Extension, Study may read the email address and Chrome account identifier associated with your current Chrome profile using Chrome's identity API, and store a one-time first-open record as described in Section 3.10. When you connect Google Classroom or sign in to My Materials, Study uses Google's OAuth sign-in flow; Study does not see or store your Google password. See Section 4 for how a Google identity token is verified.
3.2 Canvas and Brightspace Page Context
We may read a course name plainly visible on the page only to label the Study session. We do not enumerate Canvas or Brightspace courses or reconstruct an LMS account or course structure.
3.3 Canvas and Brightspace Page Content and Files
Study does not crawl Canvas or Brightspace page content, inspect attachment links, automate native downloads, intercept network traffic, use LMS cookies or session tokens to fetch files, or open temporary tabs to acquire material. You download the course files you want from your LMS and explicitly upload them to Study. Only the files you choose are sent through the Study processing pipeline.
3.4 Local File Uploads
Study and Chat accept supported documents, slides, spreadsheets, text files, and images that you explicitly select or drag into the Extension. Files are validated locally for supported type and size before processing. Study does not separately retain original uploaded files as a source-file library, though generated or saved outputs may contain information derived from them.
3.5 Canvas and Brightspace Calendar Feeds
Calendar connection is separate from adding course materials. If you choose to connect a Canvas or Brightspace calendar, you must copy the personal external iCalendar subscription URL shown by your LMS and paste it into intoola. intoola does not discover, scrape, or request this URL from the LMS, and it does not need your Canvas or Brightspace password, session cookie, or API token to retrieve the feed. The subscription URL may allow anyone who possesses it to read the calendar feed, so intoola treats it as a sensitive credential. The Extension uses it only to retrieve the iCalendar feed directly from the LMS, never includes it in analytics or support logs, and never sends it to Gemini or another AI provider. The URL is encrypted locally with AES-256-GCM; its non-extractable encryption key is kept separately in the browser's IndexedDB credential vault. Parsed calendar data is normalized and stored locally without retaining the raw ICS response. Connected feeds refresh no more frequently than approximately every six hours, when you manually request a refresh, or when you open a stale calendar. You can update the subscription URL or disconnect the feed. Disconnecting stops future retrieval and deletes the encrypted URL and its dedicated encryption key. You may choose whether to keep or remove normalized events already imported on that device.
3.6 Google Classroom and User-Selected Drive Files
When you connect Google Classroom, Study reads your active Classroom courses, coursework, classwork materials, titles, descriptions, due dates, links, and attachment metadata on a read-only basis. If a Classroom item includes a Google Drive attachment, Study does not broadly browse your Drive. To read the contents of that file, Study opens Google Picker and you must select that specific file. Study then uses the drive.file scope to export or download only the file you selected for study material generation.
3.7 Optional Additional Notes, Prompts, and Chat Messages
You may optionally type additional context or instructions in the "Additional Notes" field on the Generate screen, type prompts in chat, or ask follow-up questions in supported features. This text is included in the prompt sent to the Gemini API. Study does not intentionally store the original prompt text as a separate source record after generation, but prompts and chat messages may be included in saved chat transcripts, generated materials, logs returned by third-party AI services, or generated outputs that you save or share.
3.8 Screen Content Used by the Learn Feature
Study's Learn tool can explain either a material you select (a file you uploaded or a connected Classroom item, processed the same way as Section 3.4 and 3.6) or, if you choose, the content currently on your screen. When you click a control such as "Explain what's on my screen," Study captures a single, one-time screenshot of the currently active, visible browser tab in your current window using Chrome's captureVisibleTab API. This capture happens only at the instant you click that control. Study does not take screenshots continuously or in the background, does not capture other open tabs or windows, does not capture tabs you have not brought to the front, and does not use this capability to monitor your browsing activity or history. The screenshot is sent through our Cloudflare Worker to Google's Gemini API for that single explanation request; Study does not separately retain the raw screenshot image as a standalone file after the explanation is generated, though - as with other submitted materials described in Section 3.13 - the generated explanation itself may be saved if you choose to save it.
3.9 Lecture Audio and the Record Feature
Study's Record feature turns a spoken lecture into structured notes. When you start a Record session, your browser separately prompts you for microphone permission (this is a standard browser permission prompt, not a Chrome extension permission). Study then uses your browser's built-in Web Speech API (SpeechRecognition) - running either in the active tab or in a hidden offscreen page within the Extension - to convert audio picked up by your microphone into text in real time. Study does not capture, transmit, or store the raw audio itself. In most Chrome installations, audio processed through the Web Speech API is converted to text using the browser's built-in cloud speech-recognition service, which is generally operated by Google and governed by Google's own terms rather than this policy. Study receives only the resulting text, delivered in short transcript chunks as your browser's speech-recognition engine produces them. That transcript text - not audio - is what Study uses, together with the Gemini API, to generate structured lecture notes. You can stop a Record session at any time from the Extension.
3.10 Chrome Profile Email and First-Open Record
We store a one-time first-open record containing your email address if available, Chrome account identifier if available, a locally generated install identifier, the Extension version, and the first-open timestamp. We use this record to understand first-time usage, support account-related troubleshooting, and prevent duplicate first-open records for the same browser profile. Study also uses your Chrome profile email address when you request AI generation through our Cloudflare Worker. This helps us reduce API abuse, enforce generation access controls, and associate AI generation requests with a signed-in Chrome profile. If Chrome does not provide a valid profile email address, the Extension may block AI generation until you sign in to Chrome with an email account. Study also stores lightweight product analytics connected to the same Chrome account or install identifier. These analytics may include onboarding progress and screens viewed, whether onboarding was completed, feature screens viewed, and feature click counts. We use this information to understand where users drop off and which features are most useful.
3.11 Website Analytics on intoola.com
Certain informational pages of the intoola.com website - including this Privacy Policy page, the About page, the Features page, and the Referral Program page - load Firebase Analytics, a Google Analytics-based service, where supported by your browser. Firebase Analytics may collect standard web-analytics information such as the pages you view, how you arrived at the page, general browser and device information, and an approximate location derived from your IP address, and it may use cookies or similar local-storage technologies to do so. This website analytics is generally tied to your browser or device rather than to your Study account, and is separate from the product analytics collected inside the Extension described in Section 3.10. Google's own terms govern how Google processes data collected through Firebase/Google Analytics; see Section 10.
3.12 Billing, Subscription, and Referral Information
When you subscribe to Study, Stripe collects and processes your payment details on Stripe-hosted pages; Study does not see or store your full card number. Our Cloudflare Worker stores subscription entitlement metadata needed to verify Pro access, such as Stripe customer ID, subscription ID, subscription status, and billing period metadata. Stripe Checkout may let you enter an optional discount or referral code on your initial purchase. We store the redeemed code, verified billing email and customer/subscription identifiers, product, reward status, and any Stripe Global Payout identifier needed to enforce one redemption and one reward per email across Intoola Study and Recruit.
3.13 Saved, Shared, and Generated Materials
Study may store generated materials that you create, save, sync, import, or share. These records may include the generated output text, material type, title, course name, creation and update timestamps, share code, access records, and the Chrome profile email associated with the saved or shared material. Chat sessions and Record transcripts may be saved as generated materials and may include both your messages and Study's responses. Generated materials may contain information from the course materials, files, screenshots, transcript text, prompts, or other content you selected or typed if that information appears in the AI-generated output. Study does not separately store the original submitted files, screenshots, or audio as source files, but generated or saved materials can contain excerpts, summaries, names, or other details derived from what you submitted.
3.14 What We Do NOT Access
For the avoidance of doubt, Study does not access:
- Your Canvas, Brightspace, or Google Classroom passwords. Study does not extract Canvas or Brightspace authentication tokens; Google Classroom and My Materials authorization is handled through Google OAuth and Chrome Identity.
- Canvas or Brightspace course lists, assignments, modules, page bodies, attachment links, or files. The only exceptions are a plainly visible course label used for session context and normalized scheduling information from a calendar feed you explicitly connect. Google Classroom access remains limited to its existing OAuth workflow.
- Gmail, Google Drive files you have not selected through Google Picker, browser history, bookmarks, or other extensions.
- Browser tabs or windows other than the one you have made active at the moment you invoke a feature that reads page content.
- Any information from other Chrome extensions you may have installed.
4. How We Use Your Information
The information we access is used primarily to generate study materials on your behalf, to operate and secure the Service, and to understand how Study is used so we can improve it. The specific data flow for AI features is as follows:
- When you upload files, select a screen to explain, or select authorized Google Classroom materials within the Extension, their text, image, or file content is transmitted through our Cloudflare Worker to Google's Gemini API for AI processing.
- When you select a Google Classroom Drive attachment through Google Picker, the selected file content may be exported or downloaded from Google Drive and transmitted through our Cloudflare Worker to Google's Gemini API for AI processing.
- When you use Record, your browser's built-in speech-recognition engine converts your microphone audio to text; Study receives and processes only that text, as described in Section 3.9.
- When you request AI generation, your Chrome profile email address is sent to our Cloudflare Worker for API abuse prevention and generation access control.
- For AI generation, subscription management, and saved or shared material ownership checks, the Extension or My Materials sends a short-lived Google OAuth access token to our Cloudflare Worker over HTTPS. The Worker sends that token to Google's OAuth validation and user-information endpoints to confirm that it was issued to Study, has not expired, and belongs to a verified Google account. The Worker derives the verified email address and Google account identifier from Google's response instead of trusting identity values supplied by the browser.
- The Gemini API uses this content to generate flashcards, study notes, practice questions, explanations, chat responses, lecture notes, or other study materials, which are then returned to the Extension and displayed to you.
- The original source files, screenshots, and selected source materials are not intentionally stored by Study as source files after generation. However, generated outputs, saved materials, shared materials, and saved chat or lecture transcripts may persist and may contain excerpts, summaries, course names, prompts, or other information derived from the submitted content.
We also use information described in Section 3 to authenticate you, process payments and enforce subscription entitlements, apply free-tier and daily usage limits, detect and prevent fraud or abuse, provide customer support, operate the Referral Program, understand feature usage and onboarding drop-off so we can improve Study, and comply with legal obligations. We do not use your information for any of the following purposes:
- Targeted or behavioral advertising.
- Building advertising profiles or selling behavioral profiles.
- Training or fine-tuning our own AI models - Study does not currently develop or train any AI model of its own. See Section 5 for how this differs from Google's handling of content sent to the Gemini API.
- Selling or licensing your personal information to third parties.
- Any purpose not described in this policy.
5. AI Processing and Model Training
Study relies on Google's Gemini API to generate explanations, study materials, and chat responses, and relies on your browser's built-in speech-recognition service for Record transcription. Study itself does not use the content you submit - files, screenshots, prompts, chat messages, or lecture transcripts - to train, fine-tune, or improve any AI model that Study owns or operates, because Study does not currently develop or train its own AI models. Once your content is sent to Google's Gemini API, Google's own terms govern how Google may handle it, including whether and how Google may use API content to improve its services. We encourage you to review Google's current terms directly at the links in Section 10, since they may change independently of this policy and we cannot make representations on Google's behalf about its own data-handling practices. AI-generated outputs can be inaccurate, incomplete, or unsuitable for your specific course; you are responsible for reviewing them against your own course materials and instructor guidance, as described further in our Terms of Service.
6. Data Storage and Retention
Study is designed with a minimal data footprint. Here is the complete picture of what data is stored and where:
6.1 On Your Device (Local Storage)
The Extension stores several pieces of data on your device using your browser's local storage:
- A free generation counter - a single integer recording the total number of free AI generations you have used. This counter is used to enforce the free-tier limit (2 generations) for users who have not subscribed to Pro.
- A daily token-usage counter - a date string (today's date) and a number of AI tokens consumed today, which may include prompt, context, cached-context, and output tokens as reported by the AI provider or measured by intoola's systems. This counter is used to enforce daily usage limits that apply to all users. It resets automatically based on intoola's server-side usage records.
- A first-open tracking flag and install identifier - values used to avoid creating duplicate first-open records for the same browser profile.
- Feature and platform-selection usage counters - local counts used to calculate feature click and learning-platform selection percentages.
- Saved materials and chat sessions - generated materials, saved study outputs, shared/imported materials, and chat transcripts may be stored locally so you can view them again later.
- Connected LMS calendar state - normalized Canvas/Brightspace calendar events, refresh timestamps, and the encrypted calendar-feed credential. The feed URL is encrypted with AES-256-GCM and the dedicated non-extractable key is stored separately in IndexedDB. Raw ICS responses are not retained.
These local values do not include original Canvas, Brightspace, or Google Classroom source files stored as separate source files, but saved generated materials and chat transcripts may contain text derived from selected course materials, prompts, screenshots, transcripts, or files.
6.2 On Our Servers: Identity, Usage, Billing, and Analytics
Study stores one-time first-open records, lightweight product analytics, optional subscription referral records, subscription entitlement records, and AI generation requester records through a Cloudflare Worker, which writes those records to Firebase Realtime Database, Cloudflare KV, D1, Stripe, or another Study-controlled datastore where appropriate. These records may include your Chrome profile email address if available, Chrome account identifier if available, a locally generated install identifier, the Extension version, the first-open timestamp, onboarding progress, onboarding pages viewed, onboarding completion status, summarized onboarding answers (student status, level of study, school attended, learning goals, referral source, and connected learning platform or self-guided study selection, as described in Section 3.10), feature screens viewed, feature click counts, feature click percentage distribution, learning-platform selection counts and percentage distribution, selected course names used for analytics context, daily generation count by Chrome email, daily AI token usage by Chrome email, Stripe customer ID, subscription ID, subscription status, billing period metadata, and any referral code you choose to submit. The raw Google OAuth access token is not intentionally stored by Study. To reduce repeated validation requests, the Worker may keep verification metadata keyed by a one-way hash of the token in Cloudflare KV for up to approximately five minutes. That short-lived metadata may include the verified email address, Google account identifier, OAuth client audience, and token expiration time, but not the raw access token. Study uses two separate Firebase Realtime Database projects for these purposes: one primarily for saved and shared study materials (see Section 6.3), and a second, separate database used to store account-level usage records, including the one-time onboarding sample-quiz record described in Section 3.10. Both databases are Study-controlled and are listed in Section 9.
6.3 On Our Servers: Saved and Shared Materials
If you save, sync, share, import, or revisit generated materials, Study may store those generated materials in Firebase Realtime Database or another Study-controlled datastore. Saved or shared material records may include the generated output text, material type, title, course name, user email, share code, access records, roles such as creator or importer, created/updated timestamps, and saved chat or lecture transcript content. Study does not intentionally store your original submitted files, selected LMS source materials, screenshots, or raw prompt packages as separate source records after generation. But saved/generated materials may contain information from those inputs because AI outputs and chat transcripts can include excerpts, summaries, names, course details, or other derived content.
6.4 In Transit
Data transmitted between your browser and third-party APIs (the Gemini API, Google OAuth validation endpoints, and Stripe) is transmitted using encrypted HTTPS connections. AI generation requests, short-lived Google OAuth access tokens, Chrome profile email addresses used for generation access control, first-open records, product analytics, subscription entitlement checks, and optional referral records are transmitted to our Cloudflare Worker using encrypted HTTPS connections. The Worker validates access tokens with Google's OAuth token-information and user-information endpoints, forwards selected study content to Google's Gemini API for generation, and writes analytics, billing entitlement, or abuse-prevention records to Firebase Realtime Database, Cloudflare KV, or another Study-controlled datastore where appropriate.
6.5 Retention
We keep personal information only for as long as it is reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law, such as tax, accounting, billing, security, or fraud-prevention obligations. No purpose described in this policy requires us to keep your personal information for longer than the period during which you have an account, install, or active subscription associated with Study.
Applied to the categories described above: first-open records, product analytics, optional referral records, subscription entitlement records, and generation requester records are retained for as long as you have an account or install associated with Study, and are deleted or anonymized once we no longer have an ongoing need to process them or in response to a valid deletion request, whichever comes first. Daily generation-count and token-usage records expire automatically based on Cloudflare KV retention settings. Local storage counters, the install identifier, saved materials, saved chat sessions, and the referral prompt flag on your device persist until you uninstall the Extension, delete the materials where the product allows it, or clear your browser's extension data. Saved or shared generated materials remain in Study-controlled storage until deleted through the product, replaced by sync, or deleted in response to a valid request.
When we no longer have an ongoing need to process personal information under this policy, we delete or anonymize it. Where that is not immediately possible - for example, because the information is contained in backup archives - we securely store the information and isolate it from further processing until deletion becomes possible.
7. Cookies, Local Storage, and Similar Technologies
The Extension uses your browser's local storage and IndexedDB to store the items described in Section 6.1; it does not use HTTP cookies, because browser extensions do not set cookies against websites you visit. My Materials and the intoola.com marketing pages described in Section 3.11 are ordinary web pages and may use cookies, local storage, or similar technologies - our own, or those of the analytics provider described in Section 3.11 - to keep you signed in and to collect the analytics information described there. Most browsers let you block or delete cookies and clear site data through your browser settings; doing so may affect whether My Materials keeps you signed in or whether analytics data is collected, but will not affect the Extension's own local storage, which is cleared separately as described in Section 14.3. Our systems do not currently detect or respond to browser "Do Not Track" signals or the Global Privacy Control. Because Study does not sell personal information or use it for cross-context behavioral advertising, these signals would not currently change how we process your information even if we did detect them; see Section 15 for more on California's requirements in this area.
8. How We Share Your Information
We do not sell, rent, or trade your personal information. We do not disclose your personal information to third parties for their own independent marketing or advertising purposes. The information we share is limited to what is necessary to operate Study, is described throughout this policy, and is summarized here:
- The text, file, and image content of materials, screenshots, or Google Classroom items you select is sent through our Cloudflare Worker to Google's Gemini API (generativelanguage.googleapis.com) for AI-powered study content generation.
- A short-lived Google OAuth access token is sent through our Cloudflare Worker to Google's OAuth token-information and user-information endpoints to verify your identity and confirm that the token was issued to Study. Study does not intentionally store the raw access token.
- Saved or shared generated materials may be stored in Firebase Realtime Database or another Study-controlled datastore so you can access, sync, import, or share them.
- Your payment details are collected and processed by Stripe. Study's Cloudflare Worker stores subscription entitlement metadata such as Stripe customer ID, subscription ID, subscription status, current billing period, and the Chrome profile or install identifier needed to verify Pro access. We do not store payment card numbers or bank-account details ourselves.
- Chrome profile email addresses used for generation access control, first-open records, product analytics, subscription entitlement, saved/shared material ownership, and optional referral records are sent to our Cloudflare Worker and stored in Firebase Realtime Database, Cloudflare KV, D1, Stripe, or another datastore for the account tracking, subscription verification, product improvement, saved-material sync, referral attribution, and API abuse-prevention purposes described in this policy.
- Your one-time onboarding sample-quiz record (see Sections 3.10 and 6.2) is stored in a second, separate Firebase Realtime Database used for account-level usage tracking, keyed to your Chrome account or install identifier.
- Website analytics information described in Section 3.11 is collected by Firebase/Google Analytics on certain intoola.com pages.
Each of these service providers operates under its own privacy policy, which governs their handling of data they receive. See Section 10 for links to those policies. Legal process and safety. We may access, preserve, or disclose information if we reasonably believe it is necessary to comply with a law, regulation, court order, subpoena, or other valid legal process; to enforce our Terms of Service; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Study, our users, or the public. Business transfers. If Study or substantially all of its assets are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of our assets, information we hold may be transferred as part of that transaction. We will provide notice, where required by law, before your information becomes subject to a different privacy policy as a result of such a transaction. De-identified and aggregated data. We may create de-identified or aggregated information (for example, aggregate feature-usage statistics) that does not identify you, and we may use or share that information for any lawful purpose, including to describe or improve Study.
9. Chrome Extension Permissions
Study requests the following Chrome permissions. Below is a complete list of each permission and why it is required:
- activeTab - Grants temporary access to the page active when you invoke Study, so the Extension can detect page content, capture a screenshot for the Learn feature (Section 3.8), and detect visible supported file links after your action.
- scripting - Allows the Extension to run the page-scoped detector, retrieve a selected same-origin file in that active tab, and inject the Record transcription script described in Section 3.9. No persistent Canvas/Brightspace content script is installed by this permission (the Canvas/Brightspace launcher instead uses the declared content script described below).
- storage - Allows the Extension to store the free-tier generation counter, local usage records, settings, saved materials, saved chat sessions, and related local state in your browser.
- offscreen - Allows the Extension to run a hidden offscreen page that hosts the Web Speech API for Record transcription when needed, as described in Section 3.9.
- alarms - Schedules conservative background refreshes for connected Canvas and Brightspace calendar feeds approximately every six hours.
- https://cloudflare-dns.com/* - Resolves only the hostname portion of a submitted LMS calendar feed before and after retrieval so local, private, link-local, and other unsafe network destinations can be rejected. The secret path and subscription token are never included in this DNS request.
- Optional HTTPS site access - Requested only after you click Connect Calendar and limited to the origin of the Canvas or Brightspace feed you supplied. It is used only to retrieve that feed without LMS cookies or other credentials.
- identity and identity.email - Allow the Extension to read the Chrome profile email address and Chrome account identifier used for first-open records, analytics identity, and AI generation access control.
- tabs - Allows the Extension to identify the active browser tab after you click an add-material control and supports existing non-LMS features such as lecture capture.
- sidePanel - Allows the Extension to open as a Chrome side panel alongside your browser content rather than as a popup window.
- A declared content script on Canvas, Brightspace, and D2L domains (https://.instructure.com/, https://.brightspace.com/, https://.desire2learn.com/) - Runs the lightweight Study launcher described in Section 3.2, which reads only a plainly visible course label. It does not read assignments, files, or page content.
- https://classroom.googleapis.com/* - Allows the Extension to list the Google Classroom courses, coursework, and classwork materials you choose to study.
- https://www.googleapis.com/drive/v3/* - Allows the Extension to export or download only Drive files you explicitly select through Google Picker using the
drive.filescope. - https://generativelanguage.googleapis.com/* - Allows the Extension to send selected course content to Google's Gemini API for AI generation.
- https://socrianstudyassistantshare-default-rtdb.firebaseio.com/* - Allows the Extension to store, sync, and import saved or shared study-material records in Firebase Realtime Database.
- https://socrianstudyassistantuserdata-default-rtdb.firebaseio.com/* - Allows the Extension to store the one-time onboarding sample-quiz record and other account-level usage records in a separate Firebase Realtime Database (see Sections 3.10 and 6.2).
- https://socrian.socrianstudyassistant.workers.dev/* - Allows the Extension to send AI generation requests, first-open records, product analytics, billing requests, saved-material sync requests, share-access records, usage records, and optional referral records to Study's Cloudflare Worker.
Microphone access for the Record feature is requested separately, through a standard browser permission prompt rather than a Chrome extension permission, as described in Section 3.9. All permissions are scoped to the minimum necessary to provide the Extension's functionality.
10. Third-Party Services and Their Privacy Policies
Study integrates with the following third-party services. Each service has its own privacy policy that governs how they handle data. We encourage you to review these policies:
10.1 Google LLC (Gemini API, OAuth, Classroom, Drive, and browser speech recognition)
The text, file, and image content of materials you upload, screenshots captured for the Learn feature, or Google Classroom materials you explicitly select, is sent to Google's Gemini generative AI API. Google OAuth is used to authenticate Google Classroom connections and My Materials sign-in. Google Classroom and Google Drive APIs are used as described in Sections 3.6 and 3.4. Where your browser routes Web Speech API audio to a cloud speech-recognition service for the Record feature (Section 3.9), that processing is also generally performed by Google. Your use of these services through Study is subject to Google's Privacy Policy and Google's Generative AI Additional Terms of Service. Importantly, Google's policies govern how Google handles the content you send for AI processing, speech recognition, or authentication, including any restrictions on Google's use of that content for model training purposes. We recommend reviewing Google's current terms directly for the most up-to-date information.
10.2 Stripe
Subscription payments are processed by Stripe. We use Stripe Checkout and the Stripe Customer Portal so payment-card details are entered on Stripe-hosted pages rather than inside the Extension or My Materials. Stripe's privacy practices are governed by its own privacy policy, available at stripe.com/privacy.
10.3 Cloudflare
Our backend runs on Cloudflare Workers, with Cloudflare KV and D1 used for usage, billing, and abuse-prevention records, and Cloudflare's DNS-over-HTTPS resolver used to validate calendar-feed hostnames as described in Section 9. Cloudflare's privacy practices are governed by its own privacy policy, available at cloudflare.com/privacypolicy.
10.4 Firebase (Google)
We use Google Firebase for Realtime Database hosting (Section 6) and, on certain website pages, Firebase Analytics (Section 3.11). Firebase is a Google product and is governed by Google's Privacy Policy linked above.
10.5 Learning Management System and Classroom Providers
Your use of Canvas, Brightspace, and Google Classroom remains subject to the privacy policies and terms of the applicable provider and your school or institution. Study accesses only the course information and materials described in this policy when you use a supported connection.
11. Security
We take reasonable steps to protect the information processed by Study, including:
- All communications between the Extension or My Materials, Study's Cloudflare Worker, Google's OAuth validation endpoints, the Gemini API, and Stripe are conducted over encrypted HTTPS connections.
- The Extension does not read Canvas/Brightspace page material or retrieve LMS files. You explicitly upload the materials you want to use, while Google Classroom access is authorized through Google OAuth. Canvas/Brightspace cookies, tokens, and passwords are never extracted or transmitted by us.
- Canvas/Brightspace calendar feeds are retrieved only from the student-supplied external subscription URL, without cookies or API fallback. Feed URLs are encrypted locally, excluded from analytics and AI prompts, and deleted with their dedicated encryption key when disconnected.
- Learn screenshots and Record audio are processed only for the single request that triggered them, as described in Sections 3.8 and 3.9; Study does not intentionally retain raw audio or the underlying screenshot image as separate source records.
- First-open records, usage records, and billing records are transmitted over encrypted HTTPS connections and stored separately from original LMS source files. Saved and shared generated materials are stored separately from analytics records, but may contain text derived from selected course content or prompts.
However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. While we use the measures described above and design our systems with data minimization in mind, no security program can eliminate all risk. The security of your Canvas, Brightspace, or Google Classroom account is governed by the applicable provider's and your institution's security practices and your own account security settings, including the strength of your own passwords and device security.
12. Children's Privacy and Age Eligibility
Study is not directed at children under the age of 13, and our Terms of Service require that you be legally able to agree to those Terms to use Study. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use Study. If you are a parent or guardian and believe that your child under the age of 13 has used Study and provided personal information through it, please contact us at info@intoola.com. We will take prompt steps to investigate and, where appropriate, delete any such information. Users between the ages of 13 and 18 should use Study only with the awareness and consent of a parent or guardian, and should be mindful of their school's own rules about AI tools. Study does not currently operate an automated age-verification mechanism beyond what is described here and in our Terms of Service.
13. Educational Records and FERPA
Study is offered directly to individual students who choose to install and use it; we do not currently operate Study through a contract with a school, district, or university, and Study is not a school, educational agency, or an agent of any educational institution. As a direct-to-consumer tool, the materials and information you provide to Study are generally provided by you, in your individual capacity, rather than disclosed to us by a school as an "education record" under the Family Educational Rights and Privacy Act (FERPA). We do not represent that Study is, or that our use of your information is governed by, FERPA, and we do not describe Study as "FERPA compliant." If a school or institution enters into a written agreement with us under which Study would act as a "school official" with a legitimate educational interest in education records under FERPA, that arrangement would be governed by the terms of that specific agreement rather than by this general policy, and we would provide updated disclosures describing that relationship. Absent such an agreement, students should assume that Study is not authorized to receive education records on a school's behalf, and should follow their institution's policies about which tools may be used with school-provided materials.
14. Your Rights and Choices
You may contact us at info@intoola.com to request access to or deletion of first-open records, product analytics, optional referral records, subscription entitlement records, generation requester records, and saved or shared generated materials associated with your Chrome profile email address or install identifier. For data held by Canvas, Brightspace, Google Classroom, Stripe, Google Gemini, or another third-party service, you should contact those services directly. We may need to verify your identity - typically by confirming you control the Chrome profile email address or Google account associated with your data - before completing a request.
14.1 Disconnecting a Learning Platform
You can disconnect a Canvas or Brightspace calendar from the Calendar screen. This immediately stops future synchronization and deletes the locally encrypted feed credential and its dedicated encryption key; you can choose whether to keep or remove normalized imported events. The separate Canvas/Brightspace add-material workflow remains page-scoped. You can manage Google Classroom and My Materials authorization through your Google Account permissions.
14.2 Uninstalling the Extension
You can uninstall the Study Chrome extension at any time through your browser's extension management settings (chrome://extensions/). Uninstalling the Extension will remove locally stored extension data from that browser profile, including local usage counters and locally stored saved materials. Uninstalling does not automatically delete server-side records such as subscription entitlement records, analytics records, or saved/shared materials already synced to Study-controlled storage, and does not cancel an active subscription (which you can manage through the Stripe Customer Portal or by contacting us).
14.3 Clearing Local Storage
You can clear the Extension's local storage, including local usage counters and locally stored saved materials, by uninstalling the Extension or by clearing your browser's extension data. Clearing local storage does not automatically delete server-side records already synced to Study-controlled storage.
14.4 Marketing Communications
Study does not currently send promotional marketing emails or text messages. If that changes, any marketing message we send will include a way to opt out, and opting out will not affect administrative or transactional messages (such as billing receipts or security notices) that are necessary to operate your account.
15. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you certain rights over the personal information we collect about you. Study does not sell or share personal information (as those terms are defined by the CCPA/CPRA, including for cross-context behavioral advertising), and we do not use or disclose sensitive personal information for purposes requiring an opt-out right under the CPRA beyond what is necessary to provide Study. Subject to certain exceptions, you may have the right to: know what personal information we have collected about you and how it has been used and disclosed; access a copy of that information; correct inaccurate personal information; delete personal information we have collected from you; and not receive discriminatory treatment for exercising these rights. To submit a request, email us at info@intoola.com. We will take reasonable steps to verify your identity before responding, typically by confirming you control the Chrome profile email address or Google account associated with your data. You may use an authorized agent to submit a request on your behalf where permitted by law; we may still require you to verify your own identity directly or require the agent to provide proof of authorization.
16. Other U.S. State Privacy Rights
A number of other states have enacted comprehensive privacy laws that give their residents rights similar to those described in Section 15. Study does not sell personal data or use it for targeted advertising, as those terms are defined under these laws. These rights are not absolute and remain subject to the exceptions set out in the applicable law. If you are a resident of one of the states below, you may submit a request to exercise these rights by emailing info@intoola.com.
16.1 Colorado
Under the Colorado Privacy Act (CPA), you have the right to: be informed whether we are processing your personal data; access your personal data; correct inaccuracies in your personal data; request deletion of your personal data; obtain a portable copy of the personal data you previously shared with us; and opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
16.2 Connecticut
Under the Connecticut Data Privacy Act (CTDPA), you have the same rights described for Colorado residents above. If we decline to take action on your request and you wish to appeal, email us at info@intoola.com; within sixty (60) days of receiving an appeal, we will inform you in writing of any action taken or not taken in response, including a written explanation of our reasons.
16.3 Nevada
We do not sell personal information, as that term is defined under Nevada law. Nevada residents may email questions about our practices relating to personal information to info@intoola.com.
16.4 Utah
Under the Utah Consumer Privacy Act (UCPA), you have the right to: be informed whether we are processing your personal data; access your personal data; request deletion of your personal data; obtain a portable copy of the personal data you previously shared with us; and opt out of the processing of your personal data for targeted advertising or the sale of personal data.
16.5 Virginia
Under the Virginia Consumer Data Protection Act (VCDPA), you have the same rights described for Colorado residents above. If we decline to take action on your request, we will inform you of our decision and the reasoning behind it; if you wish to appeal, email us at info@intoola.com, and within sixty (60) days of receiving an appeal we will inform you in writing of any action taken or not taken, including a written explanation of our reasons. If your appeal is denied, you may contact the Virginia Attorney General.
16.6 Verification and response times
To protect your information, we may request additional information reasonably necessary to verify your identity before responding to a request under this Section, and if you submit a request through an authorized agent we may need to verify the agent's authorization as well as your own identity. We will respond to a verified request without undue delay and, in all cases, within forty-five (45) days of receipt. Where permitted, we may extend that period once by an additional forty-five (45) days when reasonably necessary, and we will notify you of any such extension, and the reason for it, within the initial 45-day period.
17. European Economic Area, United Kingdom, and Switzerland
If you are located in the EEA, UK, or Switzerland, you may have the following rights under applicable data protection law (including the GDPR and UK GDPR):
- The right to be informed - to know what we do with your personal data, why, and how you can withdraw consent.
- The right of access - to know what data we hold about you, confirm it is accurate and lawfully used, and receive a copy of it.
- The right to rectification - to have inaccurate information we hold about you corrected.
- The right to erasure - to have information we hold about you deleted, also known as the right to be forgotten (this may require us to stop providing you with the Service).
- The right to restrict processing - to ask us to restrict processing of your personal data if you believe it is inaccurate, you object to the processing, or you wish us to retain it past the point we would otherwise remove it because you need it to establish or defend a legal claim.
- The right to data portability - to receive a copy of the data we hold about you in a machine-readable format for reuse elsewhere.
- The right to object - to object to our handling of your data for direct marketing, order processing, or other purposes; while we consider a written objection we agree with, we will not use the data in the way objected to.
- Rights related to automated decision-making and profiling - Study does not make automated decisions based on GDPR special categories of personal information (such as ethnicity, race, sex, gender, or disability), and does not otherwise make automated decisions about you beyond limited automated processing related to marketing materials, if any; you may object to any such automated processing.
Because Study is offered directly to individual students who choose to use it, we generally rely on your consent or on our need to provide the Service you requested as the basis for processing your information, and on our legitimate interests in securing and improving Study where those interests are not outweighed by your rights.
You may exercise these rights, or ask questions about our processing, by contacting us at info@intoola.com. We will respond to verified requests as required by applicable law. We have not designated a formal EU or UK Article 27 representative at this time; requests should be directed to the contact above. If you believe we have not adequately addressed your request, you may have the right to lodge a complaint with your local data protection supervisory authority.
18. International Data Transfers
Study's infrastructure and service providers (including Cloudflare, Google Firebase, Google's APIs, and Stripe) may process and store information in the United States and other countries where those providers operate. If you access Study from outside the United States, your information may be transferred to, stored, and processed in a country with data protection laws that differ from those of your home country. By using Study, you understand that your information may be processed in this manner.
19. Third-Party Links and Services
Study, My Materials, and the intoola.com website may contain links to third-party websites or services, such as the Chrome Web Store, Canvas, Brightspace, Google Classroom, or Stripe's hosted checkout pages. This policy does not apply to those third-party sites, and we are not responsible for their content, security, or privacy practices. We encourage you to review the privacy policy of any third-party site or service before providing it with information.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time as Study evolves or as legal requirements change. When we make material changes, we will update the "Last Updated" date and version number at the top of this policy and, where feasible, provide notice through the Chrome Web Store listing, within the Extension, or on this page. We encourage you to review this policy periodically. Your continued use of Study after changes are posted constitutes your acceptance of the revised policy. If you do not agree to the changes, you should stop using Study and uninstall the Extension. A history of prior versions of this policy is not currently published on this page, but we are committed to providing clear, up-to-date disclosures about our data practices.
21. Contact Us
If you have any questions, concerns, or requests related to this Privacy Policy or Study's data practices, please contact us at info@intoola.com or through our Chrome Web Store listing page. We will do our best to respond to your inquiry in a timely manner. We do not have a dedicated privacy officer or legal department at this time, but we take privacy-related inquiries seriously and respond to them directly.
This policy describes intoola's data practices as of the Last Updated date above and does not constitute legal advice. If you have specific legal questions about compliance with GDPR, CCPA/CPRA, COPPA, FERPA, or other applicable laws, please consult a qualified attorney.