This Privacy Policy explains what information OwlWho LLC ("we", "us", "our") collects when you use our website and AI study assistant, why we collect it, how we store and share it, and the choices you have. We aim to collect only what the product needs to work, and we do not sell your personal information.
AI Disclosure
OwlWho is an AI-powered study assistant. The content of your prompts, uploaded photos, and chat messages is sent to third-party model providers (listed under Subprocessors below) to generate responses. When you turn on the optional web-search toggle, the question you typed is also sent to a third-party search provider. AI output may be inaccurate, incomplete, or out of date — including citations and similarity guidance — and should always be independently verified. Do not submit information you would not want processed by an AI system.
Privacy Summary — Data We Collect
The categories below describe the personal data OwlWho collects:
Account information: name (if provided), email address, password hash, authentication provider (e.g. Google), unique user ID.
Prompts & uploads: questions, essay drafts, photos you upload to Snap & Solve, flashcard inputs, and similarity-check text. Uploaded photos are stored inline in your own database rows; OwlWho does not use a separate file-storage bucket.
Chat & activity history: AI responses, conversation history, tool usage, timestamps, and feature interactions.
Subscription & billing: plan tier, subscription status, and billing identifiers. Payment card details are collected and stored by our payment processor (Stripe), not by OwlWho.
Device & technical data: IP address, browser and device details, and request logs processed by our hosting and infrastructure providers. Approximate location can be inferred from IP by those providers; OwlWho does not store a location field.
Usage counters: one row per AI request (which tool, timestamp, your user ID) used to enforce plan limits. Published blog articles also count unique daily views using a random identifier stored in your browser — it is not linked to your account.
Product events: a fixed list of in-app events (page visited, sign-up, sign-in, sign-out, tool opened, tool used, lecture recorded/transcribed/notes created, pricing viewed, upgrade started, subscription completed, feature error) with non-content values only — page path, tool name, plan, counters, recording length, word or card counts, and a short error code. See Analytics below.
Communications: emails or support messages you send to us.
How We Use Your Data
Provide, operate, and improve the OwlWho service and AI features.
Authenticate your account, maintain sessions, and prevent abuse or fraud.
Generate aggregated analytics to understand product usage and reliability.
Comply with legal obligations and respond to lawful requests.
We do not sell your personal information, and OwlWho does not train any model on your prompts, uploads, or chat history. We cannot control how upstream model or search providers handle data beyond their own published terms; their current terms and training practices are set by them and may change.
Analytics, Cookies & Browser Storage
We use PostHog as our product-analytics provider to count the events listed above. No advertising SDK is loaded and there are no advertising or behavioral-profiling cookies.
Session recording, session replay, surveys, heatmaps and automatic click capture are switched off. Page visits are recorded as the page path only — query strings and page fragments are removed before anything is sent, and identifiers in the path are replaced with a placeholder.
None of your content is ever sent to PostHog: no questions, chat messages, essays, uploads, photos, flashcards, similarity-check text, lecture audio, transcripts, notes, file names, passwords or payment details. Only the fixed event names and the short list of non-content values above can leave the browser.
When you are signed in, events are linked to your account ID only. Your email address, name and any schoolwork are never attached. Signing out ends that link.
If analytics is blocked or unavailable, OwlWho keeps working normally.
Browser storage we use: your sign-in session (managed by our auth provider), the page you were heading to before sign-in, unsent tool drafts (kept in session storage on your device only, never sent to analytics or placed in a URL), and a random blog-visitor identifier.
Server-side request logs (including IP address and user agent) are generated by our hosting and database providers as part of operating the service.
Subprocessors & Sharing
We share limited data only with the following categories of service providers, under contractual confidentiality and security obligations:
Lovable Cloud (Supabase) — hosting, database, authentication. Receives: email address, authentication identifiers, password hash, all content you save (chats, essays, snaps, flashcards, similarity checks), usage counters, and request metadata such as IP address.
Lovable AI Gateway → Google Gemini models. Receives: the prompt, notes, essay text, or photo you submit for that request, plus prior messages in that conversation. Does not receive your email address or payment data.
Perplexity (web search, "sonar" model) — only when you enable the web toggle or request citations. Receives: the search query derived from your question. Does not receive your account identity.
Stripe — payments and subscription billing. Receives: your email address, payment card details you enter directly on Stripe's checkout, and subscription/customer identifiers. OwlWho never sees or stores full card numbers.
Auth email delivery (built-in service of our auth provider). Receives: your email address for sign-up confirmation and password-reset messages. OwlWho does not operate a marketing email list.
PostHog — product analytics. Receives: the fixed event names listed above, page paths without query strings, plan and counter values, and (when signed in) your account ID. Does not receive your email address, name, prompts, uploads, transcripts, notes, or payment data.
This list reflects the providers wired into the deployed application at the date below. Models and providers may change; we will update this list when they do.
We may also disclose information when required by law, to protect our rights, or in connection with a corporate transaction (with notice to you where required).
Storage & Security
Data is stored on managed cloud infrastructure in the United States. We use row-level security on the tables that store your content, encrypted transport (HTTPS/TLS), and the at-rest encryption provided by our cloud platform. No system is perfectly secure; we cannot guarantee absolute security but work to maintain reasonable safeguards appropriate to the sensitivity of the data.
Age Restriction & COPPA
OwlWho is intended for users age 13 and older. We do not knowingly collect personal information from children under 13. We do not offer school, district, or parental-consent accounts, and we have not undergone any children's-privacy certification or third-party review. If we learn that a child under 13 has provided personal data, we delete the account and its data.
Retention, Deletion & Your Rights
Account data, prompts, and chat history are retained for as long as your account is active. You can delete individual chats from within the product, and you can delete your account and associated personal data at any time from Settings → Delete Account. That action runs server-side: it cancels any active subscription with Stripe and deletes your rows from the live database (chats, messages, essays, similarity checks, snaps, flashcard decks and cards, usage counters, profile). Residual copies may remain for a period in our cloud provider's automated backups; we do not control that rotation schedule and cannot guarantee a specific purge date. Stripe retains its own billing records under its terms, and we retain minimal billing records as required by tax and accounting law.
Depending on where you live, you may have the right to access, correct, port, or delete your personal data, and to object to or restrict certain processing. To exercise these rights — or to ask us any privacy question — contact aj@owlwho.net.
This page is maintained by OwlWho LLC to describe our privacy practices. It is not legal advice and has not been reviewed by an attorney. Last updated: August 4, 2026.