EduPill

Privacy Policy

Effective: August 5, 2026 · Version 1.0

EduPill reads code in order to generate questions about it. That makes "what leaves my machine?" the most important question this policy has to answer — and it answers it specifically, not generically.

The short version: your source code, directory tree and commit history never leave your machine in clear text, in any mode of operation. What leaves, to generate each card, are the excerpts retrieved for that specific question — at most 10 excerpts and 16 KB, after an automated credential scan. Generated cards are not stored on our servers.

1. Who the controller is

[LEGAL ENTITY NAME], Brazilian company number (CNPJ) [CNPJ], registered office at [FULL ADDRESS].

Data Protection Officer: [DPO NAME]privacidade@edupill.plaxo.app.

If you use EduPill through your employer, that company is the controller of professional usage data and we act as a processor in that relationship. Data subject requests in that context should be addressed to them first.

2. How we classify data

Every privacy decision in the product rests on this table. No category is reclassified for engineering convenience.

ClassWhat it isLeaves your machine?
A · Source Repository files, directory tree, commit history Never, in clear text, in any mode
B · Context 6 to 10 excerpts retrieved to generate a card, plus the file in focus Yes, under the rules in section 3
C · Card Generated question, options, explanation and citation Displayed and discarded; not persisted on the server
D · Performance Identifiers: user, topic, module, correct, time, difficulty Yes — this is what feeds your matrix and the team panel
E · Telemetry Sessions, latency, dismissal rate, extension errors Yes

Class D is the key to the architecture: it carries identifiers, not content. A typical signal is { module: "billing/charge", topic: "idempotency", correct: true }. The team graph, the Mastery Matrix and anonymous benchmarks are all built on that. None of them needs your code.

3. Egress rules — what crosses the network

For each generated card, the extension sends our server:

Every transmission is recorded in a local, auditable log on your machine: date, origin, size and scan result. You read it with the EduPill: ver o que saiu daqui command and export it as CSV. It is not a report we produce about you — it is a record that stays with you.

The credential scan is a safety net, not a guarantee. It reduces risk; it does not replace keeping secrets out of your code.

4. Personal data we process

4.1 Account

Name, email, profile picture (when you sign in with an external provider), password in irreversible form (bcrypt hash) and, for federated accounts, your identifier at the provider.

4.2 Usage and progress

Performance signals (class D), day streak, score, daily quota consumed, and extension telemetry (class E).

4.3 Content you write

Explanations you deliberately record for your team. The extension warns you before sending; this is authored content, not derived from code.

4.4 Billing

Plan, subscription status and Stripe customer identifier. We neither receive nor store card data.

4.5 Administration

Audit records of sensitive actions in team accounts: what action, by whom, on whom. Never the content of what was audited.

5. What we do not have

These items do not exist in our databases, by architectural decision:

This is verifiable by you: the data export (section 10) includes a notIncluded field stating exactly what is not there. The promise is structural, not a marketing line.

6. Purposes and legal bases

PurposeLegal basis (GDPR / LGPD)
Creating and maintaining your account; delivering the contracted servicePerformance of a contract — art. 6(1)(b) / art. 7, V
Generating cards from the excerpts sentPerformance of a contract — art. 6(1)(b) / art. 7, V
Billing and payment fraud preventionContract and legal obligation — art. 6(1)(b) and (c) / art. 7, V and II
Security, auditing and abuse investigationLegitimate interests — art. 6(1)(f) / art. 7, IX
Improving the product from aggregated telemetryLegitimate interests — art. 6(1)(f) / art. 7, IX
Marketing communications, where applicableConsent — art. 6(1)(a) / art. 7, I

Where the basis is legitimate interests, you may object (section 10).

7. Who we share with

We do not sell personal data. We share only with providers necessary to operate the service:

7.1 Language model providers

They receive class B excerpts to generate the card. Depending on your plan, these may be: NVIDIA NIM, Groq, Google (Gemini) and OpenAI.

We send them only what is needed to write the question: the excerpts retrieved for that query, with no repository name, no absolute path and no customer identifier. Your full codebase is never shared with any of them, on any plan.

What we do and what they do are different things. EduPill does not store the excerpts sent or the cards generated, and does not use them to train any model.

The providers, in turn, handle what they receive under their own terms, which vary by provider and by the plan contracted with each of them. Some retain content for a period for usage control, billing, security and abuse prevention; and certain free tiers allow the provider to use content to improve its own services. We cannot claim zero retention indiscriminately across all of them.

If your organization cannot accept that condition, Enterprise self-hosted keeps generation inside your own perimeter, with no external provider.

7.2 Other processors

We may also share data to comply with a court order or legal obligation, and we will inform you whenever the law allows.

8. International transfers

Our primary infrastructure is in the European Union (Germany). Some language model providers and the payment processor operate in the United States, which involves an international transfer of the data described in section 7.

These transfers rely on standard contractual clauses and the safeguards set out in chapter V of the GDPR and article 33 of the Brazilian LGPD.

9. How long we keep it

DataRetention
Code excerpts (class B)Not persisted — transmitted and discarded
Generated cards (class C)Not persisted
Account and progressFor as long as the account exists
Signals and telemetryFor as long as the account exists; aggregates may remain in anonymized form
Audit records[PERIOD] after the event
Billing and tax recordsFor the period required by tax law

Once your account is closed, we delete or anonymize your data within [PERIOD], except where the law requires us to keep it.

10. Your rights

The GDPR (arts. 15–22) and the Brazilian LGPD (art. 18) give you the right to:

Access and portability are available immediately: the dashboard offers a full JSON export of everything we hold about you — including the statement of what we do not hold.

For the other rights, write to privacidade@edupill.plaxo.app. We respond within 15 days.

You may also lodge a complaint with your national data protection authority in the European Economic Area, or with the ANPD in Brazil.

11. Security

Measures we take include:

No system is completely secure. In the event of an incident posing significant risk to data subjects, we will notify you and the competent authority within the statutory deadlines.

12. Cookies and local storage

We use no advertising cookies and no third-party trackers. The dashboard stores in your browser only what is needed to keep your session and remember preferences such as language and active team. The extension stores the repository index and the egress log on your machine.

13. Children

The service is not intended for people under 18 and we do not knowingly collect data from children or adolescents. If we identify such data, we will delete it.

14. Changes to this policy

We may update this policy. Material changes are communicated by email or in-product notice at least 30 days in advance, and the effective date at the top is always updated.

15. Contact

Data Protection Officer: privacidade@edupill.plaxo.app
General enquiries: contato@edupill.plaxo.app

This is a translation of the Portuguese original for convenience. In case of conflict, the Portuguese version prevails.

Draft — pending legal review This document was written from how the product actually works, but it is not a substitute for review by a lawyer. The bracketed fields must be filled in, each LLM provider’s current terms must be checked against section 7.1, and account deletion must exist in the product before section 10 holds in full. Remove this notice on publication.