Privacy Policy
Version 2026-06-12. This policy explains what The Norudit Academy (“Norudit”, “we”) collects, why, how long we keep it, and the controls you have. It is written to be readable by students, including younger ones, because you should actually understand it.
Who we are
The Norudit Academy is operated by Norudit Limited, a company registered in England and Wales (company number 17351666), with its registered office at Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom. We are the data controller for the personal data described here, registered with the UK Information Commissioner's Office (ICO) under registration number ZC204422. UK GDPR and the Data Protection Act 2018 are our home data-protection law; because we also offer the service to people in the EU/EEA, EU GDPR applies to their personal data too. Contact: [email protected]. As we are established in the UK but offer the service to people in the EU/EEA, we are appointing an EU (Article 27) representative to act as a local contact point for EU/EEA users. Their details will appear here once appointed.
What we collect, and why
| Data | What it is | Why (purpose & lawful basis) | Kept for |
|---|---|---|---|
| Account | Name, email, password (hashed) or Google/Microsoft sign-in, and interests you add | Operating your account; personalising examples to your interests (contract) | Until you delete your account |
| Your study materials | Documents you upload (textbooks, notes, timetables) and the content generated from them | The core service: building your classes, retrieval, generation (contract) | Until you delete the class or account |
| Learning records | Review history (FSRS), per-concept mastery estimates and observations (BKT), phase attempts and notes uploaded. | Scheduling reviews and tracking mastery, the product's purpose (contract) | Until you delete the class or account |
| Learner memory | Inferred learning state: weak/strong concepts, misconceptions, study patterns, a learner profile. Never textbook content or answers | Longitudinal personalisation (legitimate interest: you can see, edit, and delete every fact in Settings → Memory) | Until you edit/delete it or delete your account; superseded facts pruned after 90 days |
| Schedule | Commitments and exam dates you enter or import; whether you did/skipped planned blocks | Composing your study plan (contract). Raw done/skipped marks are a rolling ~14-day window, then deleted. Only consolidated patterns (visible and deletable in Memory) persist. Generated plans are never stored | Inputs: until you delete them. Raw adherence: ~14 days |
| Conversations | Chats with the tutor, phases, and Lura. Voice modes keep the text transcript only; live microphone audio is never recorded or stored (speech is transcribed in transit and discarded) | Continuity of your sessions (contract) | Until you delete the session/conversation or account |
| Avatar uploads | Optional, only if you create one: a custom avatar image for your companion. We do not store any recording of a voice; spoken replies use built-in preset voices only | Showing your chosen avatar (consent: given when you upload; nothing is captured unless you do) | Until you delete the avatar or your account |
| Usage & billing | Usage counters, subscription tier; payments are processed by Polar (we never see card numbers) | Fair-use limits and billing (contract) | Daily usage 90 days; billing per legal requirements |
| Learning telemetry | How you use the learning tools, tied to your account: time spent studying and how quickly you answer a card; and when you open a hint, ask Lura, or move between the study phases. The content of your work is not included, and nothing is shown to you as a timer, this runs quietly in the background | Tuning your own schedule and review difficulty to you, and improving the product in aggregate (legitimate interest). Never behavioural advertising or profiling | Until you delete your account |
| Errors & security | Error reports (Sentry) without request bodies or PII; rate-limit decisions (Arcjet) using IP | Keeping the service working and safe (legitimate interest). No session replay, no behavioural advertising, no ad trackers, ever | Per processor retention (≤90 days) |
How AI processing works
Your materials and messages are sent to AI providers to generate the service's output (explanations, questions, grading, presentations, schedules parsed from your timetable). Under terms that do not permit training on your data, we use: Mistral (language models); MiniMax (presentation generation: it receives only the document/topic content to build the slides, never your name, email, or other personal details); Nebius (embeddings) and Cohere (search ranking); and our own self-hosted retrieval, speech-to-text and text-to-speech infrastructure (Modal). Independent Research queries the open web through Linkup. We send only what each feature needs. Learning progress uses automated models (FSRS, BKT) and AI grading to personalise study; these do not make legally significant decisions about you, and staff may access limited content only for support, safety, or debugging, under confidentiality.
The other providers that process data for us are our hosting (Vercel, Render), database (Supabase), file storage (Cloudflare R2), payments (Polar, we never see card numbers), transactional email (Resend), and error/security tooling (Sentry, Arcjet). We will tell you about material changes to this list.
Your controls (and rights)
- See what the AI knows about you: Settings → Memory shows every inferred fact; you can correct or delete each one. This is the live, in-app version of your access and rectification rights.
- Delete: classes, conversations, schedule entries, and your whole account (Settings → Delete account); deletion cascades through your data and uploaded files.
- GDPR rights: access, rectification, erasure, restriction, portability, and objection. Email [email protected]. We respond within one month.
- Complaints:you may complain to your supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EU/EEA, your national data protection authority.
Children and young people
Norudit is designed for students, including those under 18, and we apply the standards of the ICO's Age Appropriate Design Code by design: high-privacy defaults, data minimisation (we keep outcomes, not archives, e.g. plans are recomputed, not stored; raw adherence logs self-delete), no behavioural advertising, no engagement-bait mechanics, no selling of personal data, and plain-language explanations like this one. You must be at least 13 (the age of digital consent in the UK; some EEA countries set it between 13 and 16). Where a user is below that age, we require verifiable consent from a parent or guardian before the account is used, and the parent/guardian accepts the Terms on the child's behalf. We do not knowingly create accounts for children under 13; if we learn we have collected an under-13's data without the required consent, we delete it and close the account promptly. We do not profile children for marketing or serve them behavioural advertising. Parents/guardians of younger users can exercise all the rights above on their child's behalf.
Where your data lives
Your account and study data are stored in Supabase (Postgres) and Cloudflare R2. Some providers that process data for us are outside the UK/EEA: providers in the US (Modal, Sentry, Arcjet, Vercel, Render) and Cohere (US/Canada) are covered by the UK International Data Transfer Agreement/Addendum and EU Standard Contractual Clauses, relying on the EU–US Data Privacy Framework where a provider is certified. MiniMax (presentation generation) runs in China, which has no UK/EU adequacy decision; we send it only the document/topic content for the slides, never your name, email, or other personal details, and you can avoid it entirely by not using presentation generation. Our EU-based providers (Mistral, Nebius, Linkup) and core stores (Supabase, Cloudflare R2) keep data in the UK/EEA.
Cookies
We use only strictly necessary cookies and local storage, for sign-in (better-auth) and security. We do not use advertising, cross-site tracking, or analytics-profiling cookies, and our error monitoring runs without session replay.
Security
Row-level security on every table, scoped service credentials, secrets kept server-side, TLS in transit, and rate-limiting on public and AI endpoints. No system is perfect; if a breach affects you, we will notify you and the regulator as the law requires.
Changes
If this policy changes materially we will ask you to review it again; your account records which version you accepted (2026-06-12 is current).