SoASmartest of All

Privacy

How we handle your data.

Plain-English summary on top. The lawyer language follows below.

In short

  • Your notebooks, cards, audio, notes, and conversations belong to you. You can export everything at any time.
  • We do not sell your data. We do not show ads.
  • We use your data to personalize the tutor and recommend next-best content — never to train external models outside the providers needed to run the product.
  • You can delete your account and all associated data with a single action.

Last updated: August 20, 2026

1. Introduction

This Privacy Policy explains how Smartest of All collects, uses, stores, shares, and deletes personal data when you use our mobile app, website, and related services.

Smartest of All is a study product that lets you create notebooks, decks, cards, notes, uploads, audio study materials, and AI-assisted conversations. This policy applies to the Smartest of All website at smartestofall.com.br, the mobile application, and the backend services that support them.

2. What data we collect

We collect the following categories of data:

  • Account data: email address, password hash, display name, account settings, preferred content language, email-verification status, login/lockout state, and account timestamps.
  • Profile data: bio, avatar URL, public/private profile flag, learning interests, and learning-profile settings.
  • Study content you create or upload: notebooks, decks, cards, card media, notes, text entries, links, document uploads, audio uploads, generated audio artifacts, and related metadata such as filenames, page counts, durations, and storage paths.
  • Study activity and progress: review history, ratings, response times, study states, concept mastery, daily session progress, and other learning-progress data.
  • AI interaction data: chat sessions, chat messages, AI generation requests, generated outputs, model identifiers, token usage, cost logs, and limited audit records for AI calls.
  • Personalization data: recommendation signals and related preference or engagement data used to personalize tutoring, ranking, and recommendations.
  • Mobile telemetry: app interaction events, event timestamps, and structured payloads. The backend contract limits telemetry payloads to semantic tags and numeric IDs rather than free text.
  • Notifications data: push tokens, platform, locale, and timezone for push delivery.
  • Subscription and billing metadata: subscription tier, subscription status, founder lock status, Stripe customer ID, Stripe subscription ID, and related billing state.
  • Support and security data: password-reset requests, verification codes, refresh tokens, and crash-reporting diagnostics when crash reporting is enabled in the mobile app.

3. How we use your data

We use your data to:

  • create and maintain your account;
  • authenticate you and protect account security;
  • send transactional emails such as verification and password-reset emails;
  • store, sync, and display the study content you create or upload;
  • run study features such as reviews, planning, tutor chat, audio, and generation flows;
  • personalize recommendations, tutoring behavior, and next-best study suggestions using recommendation signals and study history;
  • measure usage, reliability, and product behavior through telemetry and operational logs;
  • provide push notifications you have enabled;
  • manage subscriptions and billing state;
  • export your data when you request it; and
  • delete your account and associated data when you request deletion.

4. What we do not do

  • We do not sell your personal data.
  • We do not run third-party advertising in the product.
  • We do not process payment card details on our own servers. Checkout is handled on Stripe-hosted pages.
  • We do not rely on mobile telemetry payloads for free-text content or direct personal identifiers.

5. Third parties we share data with

We share data with third-party service providers only when needed to operate the product features present in the codebase. Those providers include:

  • Stripe, to create and manage checkout sessions, customer records, billing portal sessions, and subscription state.
  • Anthropic, for product features that call Anthropic models through the backend's canonical messages client.
  • OpenAI, for embeddings, audio transcription, and text-to-speech features enabled through backend clients.
  • fal.ai, for AI image and diagram generation when image-generation features are configured.
  • Microsoft Azure, as an alternative text-to-speech backend when that backend is configured.
  • Expo / platform push providers, to deliver mobile push notifications using push tokens and related device metadata.
  • Sentry, for mobile crash reporting when a Sentry DSN is configured and crash reporting is enabled outside development builds.

We may also store files and generated bytes through pluggable storage backends used by the application infrastructure.

6. AI processing

Smartest of All includes AI-powered features such as tutoring, generation, and other model-assisted workflows. To provide those features, the backend may send relevant prompts or content to the AI providers configured for the product.

The backend also records operational details about AI calls, including model name, use case, token counts, cached token counts, costs, and timestamps. The system additionally supports an audit layer that stores prompt and response hashes by default and can store truncated raw prompt/response text only when the audit-content setting is explicitly enabled.

We use AI-related data to run the requested feature, monitor cost and reliability, and support product auditing. The code verified for this policy does not establish a separate pipeline that uses your personal data to train external models outside the providers needed to run the product.

7. Data retention

Retention varies by data type and by what is codified in the backend:

  • Account, profile, study-content, and study-progress data are kept until you delete them, delete your account, or the relevant feature removes them.
  • LLM call logs are retained for operational analytics, and the export path documents a 90-day hot-retention window. After account deletion, some of those rows can remain with the user reference cleared.
  • LLM audit rows are purged using a configurable retention period, with a default of 30 days. By default, the audit layer stores hashes instead of raw prompt or response content unless operators explicitly enable content persistence.
  • Mobile telemetry events are subject to a 90-day retention window.
  • Password-reset and email-verification codes are short-lived and expire automatically.

8. Your rights

Depending on your jurisdiction, you may have rights to:

  • access the personal data we hold about you;
  • export your data;
  • correct or update information in your account and content;
  • delete your account and associated data; and
  • contact us with privacy-related questions or requests.

The codebase includes a full-data export path and an authenticated account-deletion path that deletes the user account and associated data, including subscription cleanup and best-effort bytes cleanup.

9. Security

We use technical measures in the product to protect your data, including password hashing with BCrypt, account lockout controls, token-based authentication, verification and reset flows, and server-side controls around billing and AI integrations.

No method of storage or transmission is completely secure, but we work to reduce risk and limit unnecessary exposure of personal data in logs and operational flows.

10. Children's privacy

This policy does not represent the product as directed specifically to children. If you believe a child has provided personal data in a way that requires review or deletion, contact us and we will review the request.

11. International transfers

Because Smartest of All uses third-party providers for billing, AI, notifications, crash reporting, and infrastructure, your data may be processed in countries other than your own, including where those providers operate their systems.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the date at the top of this page and publish the revised version here.

13. Contact

For privacy questions, contact privacy@smartestofall.com.br.

For product support, contact support@smartestofall.com.br.