← Back to UniVerse
Privacy Policy
Last updated: July 14, 2026
UniVerse (the "Service") is operated by UniVerse ("we", "us", "our"). This policy explains what we collect, how we use it, and the choices you have. We aim for plain language; if anything is unclear, email jack@getuniverse.app.
What we collect
Account data
- Email address — for sign-in and password reset.
- Display name (optional) — if you set one in Settings.
Content you create or import
- Notes, highlights, and chats with Cosmo.
- Documents you import from Canvas (slides, readings, syllabi, wiki pages) — text content extracted for search and AI context.
- Class metadata: course names, lecture titles, schedules.
- "User memory" — small, specific facts Cosmo learns from your conversations (your major, what you struggle with, etc.) so it gives better answers. You can review and clear this anytime in Settings → Memory.
Canvas data (if you connect)
- A Canvas access token, used only to read your courses, syllabi, lectures, assignments, and files. We never write to your Canvas account, modify grades, or post on your behalf.
- The token is stored in your account on Supabase (encrypted at rest, scoped to your user via row-level security) so you don't have to re-paste it on every device. We use it only to make read-only API calls on your behalf. When you click Disconnect Canvas in Settings, the token is removed from your account immediately.
Usage data
- Standard server logs (IP address, browser, request paths) for security and debugging, retained per our infrastructure provider's defaults (typically days, not months).
- Pro-quota counters (number of AI calls per day) so we can offer fair limits.
What we don't do
- We don't sell or share your data with advertisers.
- We don't train AI models on your notes. Your content is used to answer your prompts, not to improve any third-party model.
- We don't read your data ourselves outside of debugging an issue you've reported, or as required by law.
Where your data lives
- Account, notes, classes, memory: Supabase (Postgres + auth), hosted in the United States. Encrypted at rest and in transit.
- Local cache: in the app's local storage on your device. Cleared when you sign out.
- Our backend proxy (
noted-proxy.onrender.com): a thin relay we operate to extract text from PDFs and DOCX files and forward AI requests to providers. Uploaded file bytes are not retained server-side; only the resulting text is returned and stored under your account.
- AI model providers (where your prompts and selected context are sent to generate answers): Anthropic (Claude) and Groq (Llama). Per their published API policies, these providers do not use API inputs to train their models; they may retain inputs briefly for abuse review.
- Payments (only if you upgrade to Pro): Stripe processes the transaction. We never see or store your card number. Stripe shares back a customer ID and subscription status only.
Your choices
- See what Cosmo knows about you: Settings → Memory. View, delete, or wipe everything.
- Disconnect Canvas: Settings → Canvas → Disconnect. Revokes the token.
- Export everything: Settings → Account → Export data. Download all your notes, classes, and conversations as JSON.
- Delete your account: Settings → Account → Delete. Wipes all account data immediately and irreversibly.
Who this is for
UniVerse is intended for college-age students.
Changes to this policy
If we make material changes, we'll update the date at the top of this page and email signed-in users.
Contact
Questions, requests, or "please delete my data" emails: jack@getuniverse.app.
UniVerse · getuniverse.app