OwlWho is a study tool used by students. We take privacy, security, and responsible AI use seriously. This page describes the controls in place today.
All traffic between your browser and OwlWho is encrypted in transit with HTTPS/TLS. Data at rest is encrypted by our managed cloud database provider using their platform encryption. We rely on that provider for at-rest encryption rather than operating our own key management, and we do not independently audit their implementation.
Accounts are protected by email + password or Google sign-in. Row-level security is enabled on the tables that store your content — essays, chats, flashcards, snaps, and similarity checks — so each account reads and writes only its own rows. Plan and subscription records are not writable from the browser; they are updated server-side from our payment provider's signed webhook.
Prompts you submit to OwlWho's AI tools are sent to third-party model providers through an AI gateway to generate a response; today that path uses Google Gemini models, and the model or provider may change. When you enable the web toggle or ask for citations, the search query is also sent to Perplexity's search model. OwlWho does not train any model on your prompts and does not sell your content, but we cannot control or guarantee how upstream providers handle data beyond their own published terms. Requests are sent over encrypted channels. The full subprocessor list and the data each one receives is in our Privacy Policy.
We use PostHog for product analytics: a fixed list of events such as page visited, sign-in, tool opened, lecture transcribed, pricing viewed and subscription completed, with non-content values only (page path, tool name, plan, counters, lengths, error code). No advertising SDK is loaded and there are no advertising or behavioral-profiling cookies. Session recording, replay, surveys and automatic click capture are switched off. Your questions, essays, uploads, transcripts, notes and payment details are never sent to analytics, page paths are stripped of query strings, and signed-in events carry your account ID only — never your email or name. We also record usage counters needed to enforce plan limits and count unique daily views on published blog articles using a random browser identifier. Hosting and payment providers still generate ordinary request logs that include IP address and device details.
If you believe you've found a security issue, please email aj@owlwho.net with steps to reproduce. OwlWho is run by one person, so there is no staffed security team and no guaranteed response window — reports are read and acted on as quickly as possible.
This page is maintained by OwlWho LLC and describes our own controls. It is not a certification, audit, or independent attestation, and no system is perfectly secure.