Privacy Policy
Last updated: 30 April 2026
This Privacy Notice for Mackenzie Graungaard-Robinson (doing business as Didact Arc; “we,” “us,” or “our”) describes how and why we might access, collect, store, use, and/or share (“process”) your personal information when you use our services (“Services”), including when you visit our website at https://www.didactarc.dev or any website of ours that links to this Privacy Notice.
Didact Arc is a web-based self-study tracking application that helps users manage long-term learning across multiple subjects. The service uses spaced-repetition principles and proficiency decay modelling to surface topics for review at appropriate intervals, and includes AI-assisted features for generating study topics and answering subject-scoped questions. Didact Arc is offered through a free tier with limited monthly usage and a paid subscription tier with expanded access.
Questions or concerns? If you do not agree with our policies and practices, please do not use our Services. For questions, contact us at privacy@didactarc.dev.
Summary of key points
- What information do we process? We process the account information you give us (name, email, password) and the study data you create in the app. We do not process sensitive personal information.
- Do we collect information from third parties? Only what you choose to share when signing in with Google (name, email, profile picture).
- How do we process your information? To run the Services, communicate with you, prevent fraud, and comply with law.
- Who do we share information with? A small set of vendors that help us operate the Services (hosting, database, payments, transactional email, AI inference). We do not sell personal information.
- What are your rights? Depending on where you live, you may have rights to access, correct, or delete your information. Email privacy@didactarc.dev to exercise them.
1. What information do we collect?
Personal information you disclose to us
We collect information you voluntarily provide when you register, use the Services, or contact us. Depending on how you interact with us, this may include:
- Name
- Email address
- Password (stored hashed; never in plain text)
- Profile information you receive from Google when you choose to sign in with Google (name, email, profile picture)
- Study content you create in the app (subjects, topics, notes, to-dos, proficiency ratings, study path selections, AI chat messages)
- Messages you send via the contact form
Sensitive information
We do not process sensitive personal information.
Payment data
Didact Arc does not collect or store payment card information directly. All payment processing is handled by Stripe, our third-party payment processor. When you subscribe to a paid plan, you are redirected to Stripe's hosted checkout where your payment information is collected and processed under Stripe's privacy policy and security standards. Stripe is PCI-DSS compliant. We receive only non-sensitive transaction metadata (subscription status, plan, renewal dates) needed to provide the Service.
Information automatically collected
We automatically collect limited technical information when you use the Services, such as IP address, browser type, operating system, language preferences, referring URLs, and request timestamps. This information is recorded in standard server logs by our hosting provider (Vercel) and is used to maintain the security and operation of the Services. We do not use third-party analytics, advertising, or tracking technologies.
See our Cookie Policy for details on the cookies we set.
Google API
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2. How do we process your information?
We process your personal information for the following purposes:
- To create and manage your account and authenticate sign-in
- To provide the core study tracking features (subjects, topics, decay scoring)
- To deliver AI-assisted features (topic generation, scoped tutor chat) when you use them
- To process payments and manage subscriptions
- To respond to your contact-form submissions and support requests
- To prevent fraud, abuse, and security incidents
- To comply with legal obligations
We process your information only when we have a valid legal reason and only as described in this Notice.
3. What legal bases do we rely on?
For users in the EEA, UK, and Switzerland, we rely on the following lawful bases under the GDPR:
- Performance of a contract — to provide the Services you requested
- Legitimate interests — to keep the Services secure, prevent fraud, and improve them
- Legal obligation — to comply with applicable law
- Consent — where you have explicitly consented (you can withdraw consent at any time)
For Canadian users, we may process your information where you have given express or implied consent, or where collection and use without consent is permitted by law.
4. When and with whom do we share information?
We share information only with the third-party vendors needed to operate the Services, and only the minimum information needed for them to perform their function. We do not sell personal information.
- Vercel — hosting and request logs
- Neon — managed Postgres database for account and study data
- Stripe — payment processing and subscription management
- Google— when you choose “Sign in with Google” (OAuth)
- Anthropic— AI inference for topic generation and scoped tutor chat. Prompts and the surrounding context are sent to Anthropic's API only when you actively trigger an AI feature.
- Resend — transactional email delivery (e.g., contact-form submissions)
We may also disclose information if required by law, to protect our rights, or as part of a business transfer (merger, acquisition, or sale of assets), in which case you will be notified.
5. Do we use cookies and other tracking technologies?
Yes — we use only strictly necessary cookies to keep you signed in and protect authentication forms. We do not use analytics, advertising, or cross-site tracking cookies. See our Cookie Policy for full details.
6. Do we offer AI-based features?
Yes. Didact Arc offers AI-assisted topic generation and a scoped tutor chat, available on both free and paid tiers (with monthly usage limits on the free tier). These features use Anthropic's Claude models via the Anthropic API.
- Your prompts and the relevant subject/topic context are sent to Anthropic for inference only when you trigger an AI feature.
- Anthropic's API does not train models on data submitted by API customers. See Anthropic's privacy policy.
- AI-generated content (topics, chat responses) is stored in your account so you can review and reuse it. You can delete it at any time.
7. How do we handle your social logins?
If you choose to sign in with Google, we receive your name, email address, and profile picture from Google to create or link your account. We use this information only for authentication and account display. We do not share your social login information with third parties beyond what is described in this Notice.
8. How long do we keep your information?
We keep your personal information only as long as necessary to provide the Services, comply with our legal obligations (such as tax and accounting), resolve disputes, and enforce our agreements. When your account is deleted, we delete or anonymize your personal information within a reasonable period, except where retention is required by law (for example, billing records).
9. How do we keep your information safe?
We use reasonable organisational and technical measures to protect your personal information, including encryption in transit (HTTPS), encrypted database storage, hashed password storage, and least-privilege access to vendor dashboards. However, no transmission or storage system is 100% secure. We cannot guarantee that unauthorised third parties will never defeat our security; you use the Services at your own risk.
10. Do we collect information from minors?
The Services are not directed at children under 13 (or the equivalent minimum age in the relevant jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@didactarc.dev and we will delete it.
11. What are your privacy rights?
Depending on your location, you may have the right to access, correct, update, or delete your personal information; to object to or restrict processing; to data portability; and to withdraw consent. To exercise any of these rights, email privacy@didactarc.dev. You also have the right to lodge a complaint with your local data protection authority.
12. Controls for Do-Not-Track features
Most browsers and some mobile operating systems include a Do-Not-Track (“ DNT”) feature. Because no uniform technology standard for recognising and implementing DNT signals has been finalised, we do not currently respond to DNT browser signals. If a standard is adopted in the future, we will update this Notice.
13. Do United States residents have specific privacy rights?
If you reside in California, Colorado, Connecticut, Florida, Nebraska, Texas, Virginia, or another US state with a comprehensive privacy law, you may have additional rights, including:
- The right to know what personal information we have collected about you
- The right to request deletion of your personal information
- The right to correct inaccurate personal information
- The right to opt out of the sale or sharing of personal information
- The right to non-discrimination for exercising these rights
We do not sell personal information and we do not share it for cross-context behavioural advertising. To exercise any of the above rights, email privacy@didactarc.dev. We will respond within the timeframe required by the applicable law.
14. Do we make updates to this Notice?
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated “Last updated” date at the top of this page. Material changes may be communicated by email or by a notice in the app. Please review this Notice periodically.
15. How can you contact us about this Notice?
For questions or comments about this Notice, email privacy@didactarc.dev or use our contact form. You may also reach us by post:
Didact Arc31 Penetang St, APT 109
Barrie, Ontario L4M 6E8
Canada
Phone: (+1) 705-984-8333
16. How can you review, update, or delete the data we collect from you?
You can review and update most of your account information directly in the app (Settings). To request a copy of all data we hold about you, or to delete your account and associated data, email privacy@didactarc.dev. We will respond within 30 days.