Trust & Security

    How OwlWho protects your data

    OwlWho is a study tool used by students. We take privacy, security, and responsible AI use seriously. This page describes the controls in place today.

    Encryption

    All traffic between your browser and OwlWho is encrypted in transit with HTTPS/TLS. Data at rest is encrypted by our managed cloud database provider using their platform encryption. We rely on that provider for at-rest encryption rather than operating our own key management, and we do not independently audit their implementation.

    Authentication & access control

    Accounts are protected by email + password or Google sign-in. Row-level security is enabled on the tables that store your content — essays, chats, flashcards, snaps, and similarity checks — so each account reads and writes only its own rows. Plan and subscription records are not writable from the browser; they are updated server-side from our payment provider's signed webhook.

    What we collect

    • Your email address and authentication identifiers.
    • Content you submit to the tools (essays, chat messages, uploaded photos, flashcard topics).
    • Usage events used to enforce per-plan limits (which tool, when).
    • Subscription and billing metadata returned by our payment provider — we never store full card numbers.

    AI processing

    Prompts you submit to OwlWho's AI tools are sent to third-party model providers through an AI gateway to generate a response; today that path uses Google Gemini models, and the model or provider may change. When you enable the web toggle or ask for citations, the search query is also sent to Perplexity's search model. OwlWho does not train any model on your prompts and does not sell your content, but we cannot control or guarantee how upstream providers handle data beyond their own published terms. Requests are sent over encrypted channels. The full subprocessor list and the data each one receives is in our Privacy Policy.

    Analytics and tracking

    We use PostHog for product analytics: a fixed list of events such as page visited, sign-in, tool opened, lecture transcribed, pricing viewed and subscription completed, with non-content values only (page path, tool name, plan, counters, lengths, error code). No advertising SDK is loaded and there are no advertising or behavioral-profiling cookies. Session recording, replay, surveys and automatic click capture are switched off. Your questions, essays, uploads, transcripts, notes and payment details are never sent to analytics, page paths are stripped of query strings, and signed-in events carry your account ID only — never your email or name. We also record usage counters needed to enforce plan limits and count unique daily views on published blog articles using a random browser identifier. Hosting and payment providers still generate ordinary request logs that include IP address and device details.

    Your controls

    • Delete any individual chat, essay, deck, or snap from inside the app.
    • Delete your entire account and all associated data from Settings.
    • Manage or cancel your subscription at any time from Settings.

    Reporting a vulnerability

    If you believe you've found a security issue, please email aj@owlwho.net with steps to reproduce. OwlWho is run by one person, so there is no staffed security team and no guaranteed response window — reports are read and acted on as quickly as possible.

    This page is maintained by OwlWho LLC and describes our own controls. It is not a certification, audit, or independent attestation, and no system is perfectly secure.