Privacy Policy
1. Who we are
Summit is operated by RED TENT, S.A., a company organized under the laws of the Republic of Panama (Folio 155661339, Registro Público de Panamá), with registered offices at Avenida 7ª, Urbanización Linares, Bella Vista, Ciudad de Panamá. You can contact us at hello@learnsummit.app. This policy explains what we collect, why, who we share it with, how long we keep it, and your choices.
2. A note on your academic data
Summit is built for students, so some of what you enter is academic — courses, assignments, grades, GPA, lecture recordings and transcripts, and notes. We treat this as sensitive. To provide features you ask for, some content (including grades and notes) is sent to third-party AI providers that process it on our behalf; under those providers' API terms, your content is not used to train their models. We do not sell it or use it for advertising. You can delete your content and account at any time (Section 9).
3. What we collect
- Account and identity: email, password (stored only as a secure hash), and name; optional phone number and recovery email; your two-factor secret (encrypted) and hashed backup codes if you enable two-factor authentication; sign-in identity from Google, Apple, or GitHub if you use them; and security records (sign-in events and the devices and sessions on your account, including IP address and browser type) to protect your account.
- Profile and academic: your school; the degree plan, courses, grades, GPA, and credits you enter; and how you heard about us (optional).
- Content you create or upload: classes (including instructor details you enter), assignments and drafts, grades and feedback, uploaded files, lecture recordings and their transcripts, notes, attendance, activities, personal events, and tables — any of which may contain personal information you choose to include.
- AI-generated content and study activity: flashcards, quizzes, study guides, mind maps, summaries, and podcasts, along with review and performance data used for spaced repetition.
- Connections you authorize: access tokens for your LMS, Google Classroom, or Google Calendar (encrypted) and the items synced. What we obtain from Google, and the limits on it, are set out in Section 5.
- Billing: your plan status and a billing record with identifiers from our payment processor. We never receive or store your full card number.
- Website and usage information: first-party usage events to operate and improve Summit, information collected through measurement and advertising tools on our public pages, and — if you open the live chat on a public page — what you type into it, which may include anything you choose to tell us about yourself (Section 8).
4. Who we share data with (subprocessors)
We share data only with providers that help us run Summit, and only as needed. Under our agreements with the AI providers below, your content is not used to train their models.
- Vercel — frontend hosting and delivery
- Railway — application hosting and database
- Anthropic (Claude) — AI features: extraction, flashcards, study materials, chatbot
- OpenAI, Groq, AssemblyAI — audio transcription
- ElevenLabs — AI audio ("podcast") generation
- PubChem (U.S. National Library of Medicine, National Institutes of Health) — chemical structure lookup: when the tutor names a molecule, we send that name and nothing else, and nothing that identifies you
- Resend — transactional email
- Twilio — SMS (verification, recovery, two-factor authentication)
- Google — sign-in, Google Calendar sync, and Google Classroom import (when connected); what we obtain and how it is limited is set out in Section 5
- Google (Tag Manager) — tag management and measurement on our public pages
- Meta — advertising measurement and audience delivery
- TikTok — advertising measurement and audience delivery
- respond.io — live chat on our public pages: it loads only when you open the chat, and only if you have not opted out and are in a region where we load these tools at all (Section 8). It then receives your IP address, your browser, the page you opened the chat from, and whatever you type into it; we send it nothing from your Summit account
- Apple, GitHub — optional sign-in
- Your school's LMS (Canvas, Blackboard, Brightspace, Moodle, Sakai) and Google Classroom — course, assignment, and grade sync (when connected)
- Chargebee, PayPal — billing and payments
We may add or change AI, transcription, measurement, advertising, and support providers over time; we will keep this list current and note material changes. We also use Have I Been Pwned to check passwords against known breaches, using a method that does not send your password or personal information.
We use advertising and measurement partners (see Section 8) that receive limited information about your visits to our website. Under some U.S. state privacy laws, this may be considered "sharing" personal information for cross-context behavioral advertising. We do not sell the content you create in Summit or anything we obtain from a service you connect — including your calendar and your Google Classroom data — and we never use any of it for advertising. See "Advertising choices" in Section 9.
5. Google data
This section covers what Summit obtains from Google when you choose to connect a Google service, what we do with it, and the limits we hold ourselves to. It applies in addition to the rest of this policy. Every Google connection is optional and off until you turn it on, and you can remove Summit's access at any time from your Google Account, under "Third-party apps with account access".
Google Sign-In. If you sign in with Google, we receive the identifier Google uses for your account, the email address on it, and the display name on it. We use them to create and identify your Summit account, and for nothing else. We request nothing further about your Google account.
Google Calendar. Summit requests one permission, https://www.googleapis.com/auth/calendar.events, and uses it in one direction: to put your Summit work onto your calendar. We write events to your primary calendar for your assignment due dates and planned work, and — if you turn schedule sync on — for your class meetings, activities, personal events, scheduled work blocks, and study sessions. We update or remove those same events when the item behind them changes in Summit. Every event Summit creates carries a private tag marking it as ours, and the only reading Summit does is a lookup of that tag, which returns the identifiers of Summit's own events and nothing more. Summit does not read, receive, or store the contents of your calendar, your other events, your invitees, or anyone else's calendar. What we store is the identifier Google returns for each event we created, so the next sync can update that event instead of adding a second copy of it.
Google Classroom. If you connect Google Classroom, Summit requests read-only permission for your courses, for your own coursework, and for your own submissions. We use it to bring your classes, your assignments and their due dates, and your own grades into Summit, so you do not have to enter them by hand. Summit does not request or receive other students' work, other students' grades, or teacher-only material. Coursework you import becomes an assignment in your Summit account, and Summit does not send it to an AI provider. The title and description that came from Google Classroom are not sent for an AI time estimate, are not part of what the tutor is told about your class, and are not given to a model for any other purpose. An imported assignment keeps Summit's own default time estimate instead of an AI one, and the assignment tells you that is why. This holds even if you rewrite the imported text yourself: Summit continues to treat the whole assignment as having come from Google, which is the more protective answer.
Who we share it with. No one. We do not sell Google data, we do not use it for advertising, and we do not hand it to anyone for their own purposes. It sits inside Summit, on the hosting providers named in Section 4 that run Summit itself.
How long we keep it. We keep your Google connection — the access we stored, encrypted, and the identifiers of the events Summit created — for as long as the connection is on. Disconnecting Google Calendar deletes the stored access and those identifiers, and then asks Google to revoke the calendar permission itself, so Summit's access ends at Google and not only inside Summit. Deleting your Summit account does the same for your calendar connection once the deletion completes on the schedule in Section 9 — through the 30-day grace period the connection is still in place, so restoring your account brings it back — and removes anything imported from Google Classroom along with the rest of your data. Revoking is a request we send to Google, so it can fail: if we cannot reach Google at that moment you are still disconnected here, and the permission stays at Google until you remove it. You can remove Summit yourself at any time in your Google Account under "Third-party apps with account access", and that is also where you end a Google Classroom connection — Classroom is a separate permission, and neither disconnecting nor deleting revokes it for you. We delete our stored Classroom access when your account deletion completes; only the permission record at Google remains until you remove it. Events Summit added to your Google Calendar are yours and stay in your calendar: we do not remove them when you disconnect or when you delete your account — once the calendar permission is revoked we can no longer reach them — and you can delete them yourself in Google Calendar at any time.
Google data is never used to train AI. Summit does not use data obtained from Google APIs — your calendar, your Google Classroom courses and coursework, or your Google Sign-In profile — to develop, improve, or train artificial-intelligence or machine-learning models, whether our own or anyone else's, and we do not permit anyone to use it that way on our behalf. Summit builds no models of its own. Nothing Summit reads from your Google Calendar is sent to an AI provider for any purpose, and neither is the coursework Summit imports from Google Classroom. Summit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. How your content is used with AI
Some features send the content you give them to the AI providers above, which process it and return a result — for example, extraction sends your syllabus; the chatbot sends your notes and question; transcription sends your audio; and podcasts send study material to Anthropic and then script text to ElevenLabs. Your content — including academic information such as grades, and details such as instructor emails within what you upload — is sent as needed to provide the feature. It is not used to train the providers' models, not sold, and not used for advertising. We log only operational metadata (such as timing and cost), never the content of your prompts or the responses.
7. Payments
Card entry happens on our payment processor's hosted page. Summit never sees or stores your card number or CVV. We store your plan status and a billing record with processor identifiers and the amount. See our Terms of Service, Section 5.
8. Cookies, analytics, and advertising
Our own analytics. We record first-party usage events to operate and improve Summit (such as which features are used, and interactions with pricing or upgrade prompts), using small predefined fields kept in our own database. To keep you signed in, we store authentication tokens in your browser's local storage, along with a referral tag and some interface-state values; these stay on your device. A link that brings you to Summit may carry a click identifier added by an advertising platform — for example when you arrive from one of our ads. We read it in your browser only to record which platform the click came from, and we discard the identifier itself: we do not store it, and it is never attached to your account. What we keep is the platform name, which does not identify you. We record anonymous visits to our public pages in a form that cannot identify you, using a one-way, daily-rotating value rather than storing your IP address, and we retain this in anonymized form.
Measurement and advertising tools. We use third-party tools for measurement and advertising, including Google Tag Manager and advertising pixels from Meta and TikTok. These tools may set cookies or similar identifiers and may share information about your visit — such as pages viewed and actions taken — with those platforms, including for advertising measurement and to show you Summit ads. We use these tools on our public and marketing pages.
What advertising tools never see. We do not use these advertising tools to share anything from your Summit account. Your notes, grades, coursework, uploaded documents, lecture recordings, and everything we obtain from a service you connect — including your Google Calendar and Google Classroom data — are never sent to advertising platforms.
Live chat. If you open the live chat on one of our public pages, it is run by respond.io, and opening it is what loads it — nothing from respond.io is requested before that. It does not load at all for a visitor who has opted out of advertising sharing (Section 9), or who is in a region where we do not load these tools: the chat sits behind the same gate as the tools above. Once it is open, respond.io receives your IP address, your browser, the address of the page you have open — sent again when you come back to the tab — and whatever you type into the chat. Nothing from your Summit account goes to it: not your notes, grades, coursework or recordings, and nothing from a service you connect. If you would rather not use the chat, email us at hello@learnsummit.app.
Your controls. See "Advertising choices" in Section 9. You can also use your browser's controls and the ad settings offered by these platforms to limit tracking.
9. Your choices and deletion
You can view and edit most of your information in the app. You can delete your account in-product; for your protection, deletion requires re-entering your password (and your two-factor code if enabled) and confirming. Your account is deactivated for a 30-day grace period — you can restore it by logging in — after which your data is permanently and irreversibly deleted from our active systems, including your content, academic records, study materials, and connections. What survives deletion: a single deletion record containing your email (to evidence that deletion occurred), any legally required billing records, any usernames you released (described below), and references on shared or institutional objects that are disassociated from you rather than deleted. Operational error logs are deleted on a rolling 90-day basis. Accounts managed by an institution may need to be deleted through that institution.
Released usernames. If you used a username, a record of a name you no longer hold can outlive your account. A released name is held for a period before anyone else can take it, and how long depends on how it was released: 90 days after you change your username, during which you are the only person who can take it back; 365 days after your account is deleted, during which nobody can take it, so that for that year no one can wear your name and be mistaken for you; and indefinitely if we had to rename an account ourselves because its username broke our rules. A hold covers the name however it is punctuated or capitalised — dots, underscores, hyphens and capital letters do not make it a different name — but it does not cover a different spelling of it. Each record holds the name, how it was released, and the dates its hold runs. When your account is deleted, every record of a name of yours is unlinked from it, so nothing is left but those three things: no link back to you, no email, no real name, and nothing you wrote. Shortly after a hold ends, the record is deleted and the name is free for someone else; a hold with no end date does not expire, and that record is kept.
Advertising choices. You can opt out of our sharing of personal information for cross-context behavioral advertising by emailing hello@learnsummit.app. You can also limit tracking through your browser settings and through the ad preferences offered by Google, Meta, and TikTok.
10. Security
We use industry-standard measures, including: strong one-way password hashing; encryption in transit and encryption at rest for the most sensitive stored items (your two-factor secret and the access tokens for connected services); optional two-factor authentication with single-use backup codes; short-lived session tokens with rotation, reuse detection, session limits, and revocation on logout or password change; rate limiting on sensitive actions; checking new passwords against known-breach databases when that service is reachable; and strict security headers and a cross-origin policy. No system is perfectly secure, and we cannot guarantee absolute security; some information, such as your email and name, is stored unencrypted within our secured database.
11. Children
Summit is not directed to children under 13, and you must be at least 13 to use it. Users aged 13 to 17 must have parental or guardian permission. If we learn that we have collected personal information from a child under 13, we will delete it.
12. Where we operate
Summit is operated from Panama and is intended for students in the United States. Our providers operate in the United States and elsewhere, so your information may be processed outside your country, including in the United States.
13. Changes
We may update this Privacy Policy. For material changes, we will update the version and effective date and re-prompt you before you continue using Summit.
14. Contact
Data questions or requests: hello@learnsummit.app · RED TENT, S.A. · Avenida 7ª, Urbanización Linares, Bella Vista, Ciudad de Panamá.