Privacy Policy
Effective Date: May 2, 2026 · Last Updated: September 11, 2026
GPAce (“we,” “us,” “our”) operates the GPAce platform accessible at gpace.ai (the “Service”). This Privacy Policy describes how we collect, use, share, and protect your personal information when you use the Service.
By creating an account or using the Service, you acknowledge that your information will be handled as described in this Privacy Policy.
1. Information We Collect
1.1 Information You Provide
- Account and identity information — your verified university email address, username, password if you use password authentication, and any name or provider email supplied through a supported OAuth sign-in option
- University affiliation — your institution, region, and academic calendar, which we derive from your university email domain
- Profile and preferences — a profile picture if you upload one, along with language, timezone, theme, notification, and study-scheduling preferences
- Course and study content — course details, lecture slides, past examination papers, notes, flashcards, quiz responses and progress, calendar events and tasks, and other information you enter, edit, upload, or choose to share through the Service
- Referral and rewards information — referral codes, referral relationships, qualifying activity, and earned or applied rewards
- Billing information — plan, billing cycle, subscription status, and customer, invoice, transaction, and payment-method references needed to manage your subscription. Stripe collects payment credentials and billing details directly; GPAce does not store your complete card number or security code.
1.2 Information We Collect Automatically
- Device and connection information — IP address, network and regional signals, and an app-generated device identifier used for account security and abuse prevention
- Authentication and activity information — login dates, session and security events, and account activity such as course creation and feature use
- Operational information — upload and processing status, usage counts, processing duration, errors, and similar information needed to deliver and monitor the Service
1.3 Information from Third Parties
- OAuth providers — basic identity information supplied when you choose a supported sign-in provider. Our Google-specific practices are set out below.
- Payment processor — Stripe provides subscription and transaction status, payment-method summaries, and related billing information. Stripe handles the underlying payment credentials under its own privacy terms.
1.4 Google Sign-In
If you choose Google to sign up, sign in, or link an account, we request the basic sign-in permissions openid, email, and profile.
- Information received: your Google account identifier, email address, email-verification status, and given and family names when available. Google's sign-in response may also contain a profile picture URL; we do not import or save that picture to your GPAce profile.
- How we use it: verify your identity, create or link your GPAce account, recognize you on later sign-ins, and populate basic account details. If your verified Google email is a supported university address, we also use it to confirm university eligibility; otherwise, you must verify a separate university email.
- Access limits: Google sign-in does not give GPAce your Google password or access to your Gmail messages, Google Drive files, Google Calendar events, or contacts. We use Google's identity token to verify the sign-in and do not request Google access or refresh tokens for ongoing access to those services.
- Sharing and processing: Google sign-in information is processed by our hosting, database, and authentication infrastructure to operate and protect your account. If your Google email is also your GPAce account email, it may be shared with our service providers for transactional communications and billing as described in Sections 2 and 3. We may also disclose Google account information when necessary for security or to comply with law. We do not sell Google user data, use it for advertising, or use it to train AI models.
GPAce handles information received from Google APIs in accordance with the Google API Services User Data Policy, including its Limited Use requirements. See Sections 5 and 8 for retention, disconnection, and deletion.
2. How We Use Your Information
We use the information we collect to:
- Provide and personalize the Service — authenticate you, maintain your profile and preferences, display your courses, and synchronize study and calendar data
- Process course materials — use document-processing, OCR, and AI services to extract and organize content and generate notes, flashcards, quizzes, course analysis, and study schedules
- Administer access — apply academic-period course limits, plan features, referral rewards, subscriptions, payments, and account changes
- Communicate with you — send verification and password-reset codes, processing notifications, receipts, and support or other service-related messages. We do not currently send marketing emails.
- Protect the Service — detect abuse, fraud, unauthorized access, and violations of our Terms
- Operate and improve the Service — troubleshoot issues and review performance, capacity, and aggregated or de-identified usage patterns
3. How We Share Your Information
We do not sell, rent, or trade your personal information. We disclose information only as needed to provide, secure, and support the Service, including to:
- AI and OCR providers — relevant portions or representations of uploaded materials, such as document pages, extracted text or equations, images, and limited course context, are submitted for document analysis and study-material generation. We do not intentionally attach your account contact details to these processing requests unless needed for the requested function or support.
- Stripe — payment and billing information needed to create and manage customers, subscriptions, transactions, invoices, and payment authentication. Stripe's handling of that information is governed by the Stripe Privacy Policy.
- Infrastructure providers — cloud hosting, database, file storage, background processing, and related operational services
- Communications and security providers — services used for transactional email, CAPTCHA, payment-fraud controls, and protection against automated or malicious activity
- Other users at your direction — when you use a sharing feature, the selected users receive the event or other information you chose to share
We may also disclose information when reasonably necessary to comply with law or legal process, enforce our Terms, investigate misuse, or protect the rights, safety, and property of GPAce, our users, or others.
4. Browser Storage and Tracking Technologies
4.1 Functional Browser Storage
The GPAce client relies primarily on localStorage and sessionStorage to operate:
- localStorage — session credentials, an app-generated device identifier, display preferences, and limited cached course or interface data that may persist across browser sessions
- sessionStorage — temporary OAuth and sign-in state, navigation state, and other short-lived interface data that normally clears when the tab closes
4.2 Third-Party Technologies
Providers you interact with through the Service, including OAuth, payment, and security providers, may use their own cookies or similar technologies for sign-in, payment authentication, fraud prevention, and security. Their practices are governed by their own privacy policies.
4.3 Advertising and Cross-Site Tracking
We do not use advertising or retargeting technologies, sell behavioral profiles, or currently use third-party behavioral analytics trackers. We may use first-party operational and usage records as described in this Policy.
5. Data Retention
- Account and preference data — generally retained while your account remains open and as reasonably needed to operate, secure, and support the Service
- Google account information: we store your Google account identifier, email, and verification status with your account link, and may save your name in your GPAce account. These records are retained while needed to provide your account and Google sign-in. Temporary sign-in and incomplete signup data expire automatically. Requests to remove stored Google data follow the deletion process and limited retention exceptions below.
- Course content and generated materials — an ended academic period may cause a course to become inactive and unavailable in normal course views without immediately deleting its source files, records, or generated materials. Eligible unprocessed files or courses can be removed through the Service; certain processed course materials may require an account-deletion or support request rather than individual removal.
- User-created study and calendar items — retained until you delete or replace them, the related account is deleted, or they are no longer reasonably needed, subject to the exceptions below
- Temporary authentication data — verification codes, temporary sign-in state, and similar data expire automatically based on their security purpose
- Billing, referral, security, and support records — retained for reasonable accounting, fraud prevention, dispute resolution, legal, and operational periods
When an account-deletion request is completed, we delete or de-identify account data as reasonably required, subject to limited retention in backups and records needed for security, billing, legal compliance, dispute resolution, or enforcement. Deletion from backups and downstream systems may not be immediate.
6. Data Security
We use technical and organizational safeguards designed to protect personal information, including encryption in transit, access controls, limited-duration credentials and file links, secure credential storage, and abuse-prevention measures. Passwords are stored using one-way hashing and not as readable plaintext.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for protecting access to your account and device.
7. AI Processing and Model Training
7.1 GPAce Model Training
GPAce does not use your uploaded content or generated study materials to train or fine-tune its own general-purpose machine-learning models.
7.2 Third-Party Processing
We submit limited content to commercial AI and OCR API services to perform the processing you request, not as a contribution to a general training dataset. Those providers handle submissions under the terms applicable to their API services, and we select and configure providers with the goal of limiting use to service delivery.
7.3 Human Access
Uploaded content and generated materials are processed primarily by automated systems and are not routinely reviewed by GPAce personnel. Authorized access may occur when reasonably necessary to:
- Investigate or resolve a support or processing issue
- Secure, maintain, or operate the Service
- Investigate suspected misuse or enforce our Terms
- Comply with law or legal process
7.4 Service Metrics
We may use operational metadata and aggregated or de-identified statistics to monitor reliability, capacity, cost, and feature performance. This may include counts, processing status, duration, and errors, but does not grant us a right to train models on the contents of your documents.
8. Your Rights and Choices
- Access and correction — you can view or update available profile information, preferences, and your password through the Service
- Content controls — you can edit or delete supported user-created items and remove eligible unprocessed files or courses in the Service. For content that cannot be removed individually after processing, contact support.
- Notifications — you can change available service-notification preferences in your account settings
- Google connection and data: you can remove GPAce from your Google Account connections. This stops future sharing through Google Sign-In until you reconnect, but does not automatically delete your GPAce account or previously received data, or end an existing GPAce session. To request removal of stored Google account data or deletion of your GPAce account, email support@gpace.ai. We handle these requests subject to identity verification and the limited retention exceptions in Section 5.
- Account deletion — request deletion at support@gpace.ai. We will handle the request as described in Section 5, subject to identity verification and applicable retention requirements.
- Data access or portability — contact support@gpace.ai to request a copy of your personal data, subject to applicable law and reasonable verification.
9. Children’s Privacy
The Service is intended for university students and is not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will take steps to delete it.
10. International Data Transfers
GPAce and its service providers may process information outside your country of residence, including in the United States and other locations where they operate. Where applicable, we use provider commitments and other safeguards designed to protect information in accordance with applicable law.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service with a revised “Last Updated” date. Your continued use of the Service after such changes constitutes your acceptance of the updated policy.
Before accessing additional Google user data or using Google data for a new purpose, we will explain the change and obtain your consent.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: support@gpace.ai