Privacy Policy

Effective: September 5, 2026

1. Who we are

Sylly is a Canadian service. Questions and privacy requests go to privacy@sylly.ai and are handled by our privacy officer. This policy explains what we collect, why, who we share it with, and the choices you have. It applies to the Sylly website, web app, and iOS app (the "Service").

2. What we collect

2.1 Before you sign up (demo, quiz, and waitlist)

You can try Sylly's interactive demo, take the setup quiz, or join a waitlist before creating an account. At those steps we collect: your first and last name, email address, phone number (where the form asks for it), school, your quiz answers (such as the study problems you selected), and referral or campaign attribution (whose link you used, and UTM parameters). We use this to personalize your setup, email you about your setup and our launch, understand where visitors come from, and, under Section 8, measure whether our ads work. Every such email includes an unsubscribe link that works without an account. These records are stored separately from accounts; to have yours deleted, email privacy@sylly.ai (see Section 9).

2.2 Your account

Name, email address, username, school, and a password (handled by our authentication provider; we never see or store your plaintext password). Email changes are made by contacting support.

How you found us: when you create an account we save the referring site, the page you landed on, and any campaign tags in the link, so we can understand which channels bring students to Sylly. If you answer the optional "how did you hear about us" question, we store that answer too.

2.3 Your content

  • Documents: uploaded files — PDF, DOCX, PPTX, and images (PNG/JPG) — including extracted text, and page or slide images processed by our AI provider's vision models.
  • Lecture recordings: audio you record, plus the transcripts we generate from it.
  • Study materials: notes, flashcards, practice tests and answers, schedules, classes, and evaluations.
  • AI tutor conversations: your messages and the responses.
  • Social messages: direct and group messages with friends on Sylly.

2.4 Collected automatically

  • Usage counters: feature usage against your plan's weekly allowances (for example AI messages per week, recording hours per week), kept in a caching layer where they expire on a weekly or monthly cycle.
  • AI usage log: every AI request is logged to your account with token counts and an estimated cost. We keep this to operate fairly-priced plans, detect abuse, and understand our costs. It is deleted with your account.
  • Study activity (Fall Lock-In): if you hold a founding seat, we record study-activity events (sessions completed, lectures recorded, documents uploaded, flashcards created/reviewed, tests created/taken, notes created/reviewed, tutor messages) to compute your challenge tracker and guarantee eligibility. Only qualifying activity counts toward the tracker (for the capture pillar, only lecture recordings of 30 minutes or more; document uploads feed your usage stats, not the challenge). See Section 7 on automated decisions.
  • Device and log data: IP address, browser type, and technical logs, used for security, rate limiting, and debugging.
  • Attribution: if you arrive via a campaign or referral link, we store the first-touch attribution (UTM values, landing page, timestamp) in your browser (Section 12) and attach it to signup analytics.

2.5 Payments and billing records

Card details are collected and stored by Stripe, not by us. We store: your Stripe customer and subscription IDs, plan and billing status, paid-through and pause dates, founding seat number, credit balance and a ledger of credit transactions, and referral relationships (who referred whom, to run the referral program).

2.6 iOS app

The iOS app additionally uses: microphone access (recording lectures), camera and photo library access (if you attach images), Face ID (to lock the app locally — biometric data never leaves your device), and crash/error reporting. Analytics in the app is off unless you consent.

3. How we use your information

  • Provide the Service: your semester, materials, transcription, and AI features.
  • Process payments, credits, referrals, and guarantee claims.
  • Compute your Fall Lock-In tracker and guarantee eligibility (founding seat holders).
  • Send transactional email (receipts, renewal reminders before every charge, security notices) and — unless you opt out — product emails such as the weekly digest.
  • Screen social messages automatically for abuse (Section 6) and act on reports.
  • Secure, rate-limit, debug, and improve the Service.
  • Measure whether our Facebook and Instagram ads lead to sign-ups and purchases (Section 8).

4. Who we share it with

We do not sell your personal information for money. We share it only with the providers below — to operate the Service and, under Section 8, to measure our advertising — under agreements that restrict their use of it:

ProviderRoleWhat they receive
SupabaseDatabase, authentication, file storageAll account data and content you store in Sylly
VercelWeb hosting and serverless infrastructureRequest data passing through our web application
StripePayment processingName, email, payment details (card data is held by Stripe, never by us). Where the consent rules in Section 8 allow advertising measurement, the checkout record also carries your IP address, browser user agent and Meta ad identifiers.
AnthropicAI (chat, notes, flashcards, tests, document and syllabus parsing, message moderation)The content being processed: your messages to the tutor, class materials and context, documents and slide/page images, transcripts, and social messages screened for abuse
GroqSpeech-to-text transcription (primary)Lecture audio recordings, for transcription
OpenAISpeech-to-text transcription (fallback)Lecture audio recordings, for transcription when the primary provider is unavailable
Trigger.devBackground job processingThe content being processed asynchronously: audio for transcription, documents for parsing, AI generation inputs and outputs, export bundles
ResendEmail deliveryEmail address, name, and the content of emails we send you (which can include class names, upcoming assignments, usage stats, and quiz responses)
UpstashRate limiting and usage countersUser ID or IP address, and feature usage counts (no content)
PostHogProduct analyticsPseudonymous IDs, plan tier, and product/billing lifecycle events with their properties (see Section 8)
Meta Platforms, Inc.Advertising measurement (Meta Pixel and Conversions API), USAOnly under the consent rules in Section 8: hashed contact details and a hashed account identifier where you have given them to us, Meta ad identifiers, IP address and browser type, and the pages and actions involved, including the amount and currency of a purchase
SentryError monitoring (runs on every visit; not part of the choice in Section 8)Technical error reports, which can include your user ID and request metadata
CloudflareBot protection (Turnstile)A browser challenge token on signup, login, password reset, checkout, and quiz forms

Two further third parties receive limited technical data in the course of ordinary use. Google serves the web font used across the site, so it receives your IP address and browser type whenever a page loads. Have I Been Pwned checks a password you are setting against known breaches: your browser sends only the first five characters of a hash of it, never the password itself.

AI and transcription providers process your content to return results and handle retention per their own published policies; we have instructed our AI provider not to train models on our API data. We may also disclose information if required by law, or as part of a corporate transaction with notice to you.

5. Recordings and other people's voices

Lecture recordings can capture the voices of instructors and classmates. You are responsible for having the permission required to record (Terms, Section 8). We process third-party voice data in recordings solely to provide your transcription and study features, we do not build voice profiles, and it is deleted when the recording is deleted. If you believe you were recorded in someone's Sylly account and want the audio removed, contact privacy@sylly.ai.

6. Messages and automated moderation

Messages you send to friends and groups are visible to their recipients, and every message is also screened automatically by an AI moderation system for abuse; messages that violate our rules can be hidden automatically. Users can report messages, and reports are reviewed. Moderation exists to keep the community safe — we do not use your private messages for advertising or model training.

7. Automated decisions

The Fall Lock-In tracker computes Deep Weeks and checklist completion automatically from your logged study activity, and that computation feeds guarantee eligibility (Terms, Section 6). Guarantee claims themselves are always adjudicated with human review, and you can contest any outcome at support@sylly.ai. Message moderation (Section 6) can hide content automatically; hidden content can be reviewed on request. No other automated decisions with significant effects are made about you.

8. Analytics, advertising measurement, and consent

In your browser, analytics and advertising measurement run under region-based rules. If you're in the EEA, UK, Switzerland, or Quebec — or if we cannot tell where you are — nothing runs until you accept the consent banner. Elsewhere, they run by default and you can opt out at any time: from the notice, from the “Cookies & ads” link in the footer of our public pages — which works whether or not you have an account — or, if you are signed in, in Settings → Privacy. Your choice is stored in your browser's local storage (Section 12). When you have declined or opted out, no analytics or Meta script is loaded. This choice covers analytics and advertising measurement only: the error monitoring in Section 4 runs on every visit either way. In the iOS app, analytics is off unless you turn it on.

Advertising measurement (Meta). We use the Meta Pixel and Meta's Conversions API — one from your browser, one from our servers, paired so nothing is counted twice — to learn whether our Facebook and Instagram ads lead to sign-ups and purchases. Under the consent above, Meta receives the pages you view and the actions you take, its ad identifiers (the _fbp/_fbc cookies), your IP address and browser type, and — where you have given them to us — your email address, phone number, and name, hashed. Meta Platforms, Inc. is a US company and is its own controller of what it receives.

On our servers, we additionally record product and billing lifecycle events (for example: signed up, purchased, paused, refunded, hit a usage limit, lead captured) with a pseudonymous ID, plan details, and event properties, regardless of the banner — these keep billing and product decisions accurate and are not used to profile your browsing. You can object to server-side analytics at privacy@sylly.ai.

9. Retention, deletion, and export

  • Your account and content: kept while your account exists. Deleting your account (Settings → Privacy → Danger Zone on web; Settings → Account on iOS) is immediate and irreversible: it cancels billing, deletes your content and files, and removes your account records, including the AI usage log.
  • Pre-signup lead and waitlist records (Section 2.1): deleting your account also deletes any lead or waitlist records matching your account email. If you never created an account (or used a different email before signing up), email privacy@sylly.ai and we will delete those records for you.
  • Payment records are retained by Stripe and in our accounting records as required by tax law.
  • Provider logs (AI, transcription, email, analytics, errors) expire per each provider's published retention policy.
  • Export: you can export your data anytime from Settings → Privacy; we email you a download link.

10. Security

Data is encrypted in transit and at rest by our infrastructure providers. Access to production data is restricted. Sensitive API endpoints are rate-limited, uploads are validated and scanned by content-type checks, and payments never touch our servers. No system is perfectly secure; if a breach affects you, we will notify you as required by law.

11. Commercial electronic messages (CASL)

We send commercial electronic messages in accordance with Canada's Anti-Spam Legislation, on the basis of your express or implied consent (for example, when you join the waitlist, take the quiz, or purchase). Every marketing email identifies us and contains a working unsubscribe that takes effect promptly — including for pre-signup emails, which carry their own one-click unsubscribe link. Transactional messages (receipts, renewal reminders, security notices) are sent as needed to operate your account.

12. Cookies and local storage

  • Essential: authentication/session cookies, and the Cloudflare Turnstile token required to submit signup, login, password-reset, checkout, and quiz forms.
  • Preference: sylly_analytics_consent (your analytics and advertising-measurement choice), sylly_consent_notice_seen (that you have dismissed the notice, where it is not blocking, so it isn't shown again), sylly_consent_regime (which consent rules apply to you; see below), and first-touch campaign attribution — UTM values, referring site, landing page, timestamp — stored for every visitor, not only those arriving from a tagged link, in local storage (sylly_attribution) and in a first-party cookie (sylly_attr, 180 days). Two more keys belong to the same record: sylly_attribution_last (local storage — the most recent visit that carried a campaign source or a referring site) and sylly_attr_echoed (session-only, so the same record is not sent to our server twice).
  • Optional analytics: run under the region-based consent rules described below (and Section 8).
  • Optional advertising measurement (Meta): _fbp (a browser id Meta uses to tell visits apart; 90 days) and _fbc (the click id from a Facebook or Instagram ad link; 90 days), set under the same region-based consent rules as analytics (Section 8) and turned off by the same opt-out. Two local-storage keys — sylly_meta_quiz_completed and sylly_meta_purchase_ followed by the checkout session id — each hold a timestamp so the same event is not reported to Meta twice.
  • Referral: sylly_ref remembers a referral code for 30 days so your friend's discount applies at checkout.

We ask for your permission before running analytics or advertising measurement if you're in the EEA, UK, Switzerland, or Quebec, or if we cannot tell where you are; elsewhere they run by default and you can opt out at any time (Section 8). A small cookie (sylly_consent_regime) remembers which of these applies to you. It contains only the word “strict” or “implied” and nothing about you.

13. Your rights

Subject to Canadian privacy law (PIPEDA and, where applicable, provincial law including Quebec's Law 25), you can access, correct, export, or delete your personal information, withdraw consent, and complain to the Office of the Privacy Commissioner of Canada. Self-serve tools cover most of this: Settings once you are signed in, and — for the analytics and advertising choice specifically — the “Cookies & ads” link in the footer of our public pages, which works without an account. For anything else, email privacy@sylly.ai and we will respond within 30 days.

California. Our use of the Meta Pixel is “sharing” for cross-context behavioral advertising under the CPRA. Turning off advertising measurement — the “Cookies & ads” link in the footer, or Settings → Privacy when you are signed in — is our “Do Not Sell or Share My Personal Information” opt-out.

14. Children

The Service is for users 16 and older and is not directed at children under 13. See Terms Section 1 for purchases by minors.

15. Changes to this policy

We will post changes here and update the effective date; for material changes we will notify you by email or in the Service.

16. Contact

Sylly
Privacy: privacy@sylly.ai · Support: support@sylly.ai · Terms of Service