Privacy Policy
EduPill reads code in order to generate questions about it. That makes "what leaves my machine?" the most important question this policy has to answer — and it answers it specifically, not generically.
The short version: your source code, directory tree and commit history never leave your machine in clear text, in any mode of operation. What leaves, to generate each card, are the excerpts retrieved for that specific question — at most 10 excerpts and 16 KB, after an automated credential scan. Generated cards are not stored on our servers.
1. Who the controller is
[LEGAL ENTITY NAME], Brazilian company number (CNPJ) [CNPJ], registered office at [FULL ADDRESS].
Data Protection Officer: [DPO NAME] — privacidade@edupill.plaxo.app.
If you use EduPill through your employer, that company is the controller of professional usage data and we act as a processor in that relationship. Data subject requests in that context should be addressed to them first.
2. How we classify data
Every privacy decision in the product rests on this table. No category is reclassified for engineering convenience.
| Class | What it is | Leaves your machine? |
|---|---|---|
| A · Source | Repository files, directory tree, commit history | Never, in clear text, in any mode |
| B · Context | 6 to 10 excerpts retrieved to generate a card, plus the file in focus | Yes, under the rules in section 3 |
| C · Card | Generated question, options, explanation and citation | Displayed and discarded; not persisted on the server |
| D · Performance | Identifiers: user, topic, module, correct, time, difficulty | Yes — this is what feeds your matrix and the team panel |
| E · Telemetry | Sessions, latency, dismissal rate, extension errors | Yes |
Class D is the key to the architecture: it carries identifiers, not content. A typical signal is { module: "billing/charge", topic: "idempotency", correct: true }. The team graph, the Mastery Matrix and anonymous benchmarks are all built on that. None of them needs your code.
3. Egress rules — what crosses the network
For each generated card, the extension sends our server:
- at most 10 excerpts, totalling at most 16 KB;
- subjected to an automated credential scan — API keys, tokens, private keys, connection strings. An excerpt suspected of containing a secret is discarded whole, not redacted;
- with no repository name, no absolute path and no customer identifier in the prompt.
Every transmission is recorded in a local, auditable log on your machine: date, origin, size and scan result. You read it with the EduPill: ver o que saiu daqui command and export it as CSV. It is not a report we produce about you — it is a record that stays with you.
The credential scan is a safety net, not a guarantee. It reduces risk; it does not replace keeping secrets out of your code.
4. Personal data we process
4.1 Account
Name, email, profile picture (when you sign in with an external provider), password in irreversible form (bcrypt hash) and, for federated accounts, your identifier at the provider.
4.2 Usage and progress
Performance signals (class D), day streak, score, daily quota consumed, and extension telemetry (class E).
4.3 Content you write
Explanations you deliberately record for your team. The extension warns you before sending; this is authored content, not derived from code.
4.4 Billing
Plan, subscription status and Stripe customer identifier. We neither receive nor store card data.
4.5 Administration
Audit records of sensitive actions in team accounts: what action, by whom, on whom. Never the content of what was audited.
5. What we do not have
These items do not exist in our databases, by architectural decision:
- your source code and directory tree;
- the cards generated from your repository;
- your repository index, which stays on your computer.
This is verifiable by you: the data export (section 10) includes a notIncluded field stating exactly what is not there. The promise is structural, not a marketing line.
6. Purposes and legal bases
| Purpose | Legal basis (GDPR / LGPD) |
|---|---|
| Creating and maintaining your account; delivering the contracted service | Performance of a contract — art. 6(1)(b) / art. 7, V |
| Generating cards from the excerpts sent | Performance of a contract — art. 6(1)(b) / art. 7, V |
| Billing and payment fraud prevention | Contract and legal obligation — art. 6(1)(b) and (c) / art. 7, V and II |
| Security, auditing and abuse investigation | Legitimate interests — art. 6(1)(f) / art. 7, IX |
| Improving the product from aggregated telemetry | Legitimate interests — art. 6(1)(f) / art. 7, IX |
| Marketing communications, where applicable | Consent — art. 6(1)(a) / art. 7, I |
Where the basis is legitimate interests, you may object (section 10).
7. Who we share with
We do not sell personal data. We share only with providers necessary to operate the service:
7.1 Language model providers
They receive class B excerpts to generate the card. Depending on your plan, these may be: NVIDIA NIM, Groq, Google (Gemini) and OpenAI.
We send them only what is needed to write the question: the excerpts retrieved for that query, with no repository name, no absolute path and no customer identifier. Your full codebase is never shared with any of them, on any plan.
What we do and what they do are different things. EduPill does not store the excerpts sent or the cards generated, and does not use them to train any model.
The providers, in turn, handle what they receive under their own terms, which vary by provider and by the plan contracted with each of them. Some retain content for a period for usage control, billing, security and abuse prevention; and certain free tiers allow the provider to use content to improve its own services. We cannot claim zero retention indiscriminately across all of them.
If your organization cannot accept that condition, Enterprise self-hosted keeps generation inside your own perimeter, with no external provider.
7.2 Other processors
- Stripe — payment processing;
- Resend — transactional email (sign-up confirmation, account notices);
- Google and GitHub — only if you choose to sign in with those accounts;
- your company's identity provider, on SSO accounts;
- [INFRASTRUCTURE PROVIDER] — hosting and database.
We may also share data to comply with a court order or legal obligation, and we will inform you whenever the law allows.
8. International transfers
Our primary infrastructure is in the European Union (Germany). Some language model providers and the payment processor operate in the United States, which involves an international transfer of the data described in section 7.
These transfers rely on standard contractual clauses and the safeguards set out in chapter V of the GDPR and article 33 of the Brazilian LGPD.
9. How long we keep it
| Data | Retention |
|---|---|
| Code excerpts (class B) | Not persisted — transmitted and discarded |
| Generated cards (class C) | Not persisted |
| Account and progress | For as long as the account exists |
| Signals and telemetry | For as long as the account exists; aggregates may remain in anonymized form |
| Audit records | [PERIOD] after the event |
| Billing and tax records | For the period required by tax law |
Once your account is closed, we delete or anonymize your data within [PERIOD], except where the law requires us to keep it.
10. Your rights
The GDPR (arts. 15–22) and the Brazilian LGPD (art. 18) give you the right to:
- Confirmation and access — know whether we process your data and obtain a copy;
- Rectification of incomplete or outdated data;
- Portability in a structured format;
- Erasure of data processed on the basis of consent;
- Objection to processing based on legitimate interests;
- Information about who we share data with;
- Withdrawal of consent, where that is the basis.
Access and portability are available immediately: the dashboard offers a full JSON export of everything we hold about you — including the statement of what we do not hold.
For the other rights, write to privacidade@edupill.plaxo.app. We respond within 15 days.
You may also lodge a complaint with your national data protection authority in the European Economic Area, or with the ANPD in Brazil.
11. Security
Measures we take include:
- traffic encrypted in transit (TLS);
- passwords stored as bcrypt hashes; never in clear text;
- long-lived session credentials stored as hashes, rotated on every renewal;
- in the extension, credentials kept in the operating system keychain, not in a config file;
- isolation between organizations, with membership verified on every access to team data;
- the ability to end all of a user's sessions immediately;
- audit logging of sensitive operations.
No system is completely secure. In the event of an incident posing significant risk to data subjects, we will notify you and the competent authority within the statutory deadlines.
12. Cookies and local storage
We use no advertising cookies and no third-party trackers. The dashboard stores in your browser only what is needed to keep your session and remember preferences such as language and active team. The extension stores the repository index and the egress log on your machine.
13. Children
The service is not intended for people under 18 and we do not knowingly collect data from children or adolescents. If we identify such data, we will delete it.
14. Changes to this policy
We may update this policy. Material changes are communicated by email or in-product notice at least 30 days in advance, and the effective date at the top is always updated.
15. Contact
Data Protection Officer: privacidade@edupill.plaxo.app
General enquiries: contato@edupill.plaxo.app
This is a translation of the Portuguese original for convenience. In case of conflict, the Portuguese version prevails.