Back to home

CourseMate — Privacy Policy

Last updated: March 2026 | Effective immediately | coursemate.cards/privacy

At CourseMate, your privacy matters. This Privacy Policy explains what data we collect, why we collect it, how we use it, and what rights you have over your data. CourseMate is committed to complying with the Singapore Personal Data Protection Act 2012 (PDPA) and other applicable data protection laws.

By using CourseMate, you agree to the collection and use of your information as described in this policy. If you do not agree, please discontinue use of the service.

1. Who We Are

CourseMate is an AI-powered study tool operated independently and accessible at coursemate.cards. For any privacy-related questions or requests, you can contact us through the contact details provided on our website. As the operator of CourseMate, we act as the data controller for personal data collected through the platform.

2. What Data We Collect

2.1 Data You Provide Directly

When you create an account or use CourseMate, we collect:

  • Email address — used for account creation, login, and service communications
  • Password — stored securely in encrypted form via Supabase Auth (we never see your raw password)
  • Name or display name — if provided during signup
  • Payment information — processed securely by Stripe; CourseMate never stores your card details directly
  • Document content — text extracted from PDFs you upload for the purpose of generating flashcards and quizzes
  • Subject names and labels — organisational data you create within the app

2.2 Data Collected Automatically

When you use CourseMate, we may automatically collect:

  • Usage data — pages visited, features used, quiz attempts, study streaks
  • Device information — browser type, operating system, screen resolution
  • IP address — for security purposes and approximate location
  • Cookies and session tokens — to keep you logged in and maintain your session

2.3 Data We Do NOT Collect

  • We do not store your raw uploaded PDF files. Text is extracted and the file is immediately discarded.
  • We do not collect government identification numbers, passport details, or financial account numbers.
  • We do not collect biometric data.
  • We do not knowingly collect data from children under 13.

3. How We Use Your Data

We use your personal data only for the following purposes:

  • Providing the service — generating flashcards, quizzes, and study analytics
  • Account management — creating and maintaining your account, authentication
  • Processing payments — managing Pro subscriptions via Stripe
  • Improving the service — understanding how features are used to make CourseMate better
  • Communication — sending important service updates, security notices, or responses to your enquiries
  • Security — detecting and preventing fraud, abuse, or unauthorised access
  • Legal compliance — meeting obligations under applicable laws

We do not sell, rent, or trade your personal data to third parties for marketing purposes. We do not use your data to serve advertising.

4. How We Share Your Data

CourseMate does not sell your data. We share your data only in the following limited circumstances:

4.1 Service Providers

We use trusted third-party services to operate CourseMate:

  • Supabase — database hosting and authentication (data stored on secure servers)
  • Stripe — payment processing for Pro subscriptions
  • Vercel — website hosting and deployment
  • AI providers (Google Gemini / Anthropic Claude) — processing document text to generate flashcards and quizzes. Only the extracted text content of your document is sent, not your personal details.

Each of these providers has their own privacy policies and data protection measures. We only share the minimum data necessary for each service to function.

4.2 Shared Flashcard Sets

If you choose to share a flashcard set using the share feature, the content of that set becomes accessible to any CourseMate user who has the share link. Your first name may be displayed as the creator. You can disable sharing at any time from your dashboard.

4.3 Legal Requirements

We may disclose your data if required to do so by law, court order, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of CourseMate, its users, or the public.

4.4 Business Transfer

In the event CourseMate is acquired, merged, or its assets transferred, your data may be transferred as part of that transaction. You will be notified via email or an in-app notice before your data becomes subject to a different privacy policy.

5. Document Content and AI Processing

This section is particularly important given the nature of CourseMate's core functionality.

When you upload a PDF, CourseMate extracts the text content and sends it to an AI provider (Google Gemini or Anthropic Claude) to generate flashcards and quiz questions. The following applies to this process:

  • The raw PDF file is not permanently stored on our servers
  • The extracted text is stored in our database linked to your account to enable flashcard retrieval
  • Text sent to AI providers is subject to their respective privacy and data retention policies
  • You are responsible for ensuring you have the right to upload and process any document you submit
  • Do not upload documents containing sensitive personal data about third parties, confidential information, or content you do not have the right to share

CourseMate is not responsible for how AI providers handle data sent to their APIs. We recommend reviewing Google's and Anthropic's privacy policies for details on their data handling practices.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide the service.

  • Account data (email, name): retained until you delete your account
  • Flashcard and quiz data: retained until you delete the document or your account
  • Quiz attempt history: retained for 24 months then automatically deleted
  • Payment records: retained for 7 years as required by financial regulations
  • Usage logs: retained for 90 days for security and debugging purposes

When you delete your account, all personal data is permanently deleted within 30 days, except where retention is required by law.

7. Your Rights Under the PDPA and Applicable Law

As a user of CourseMate, you have the following rights regarding your personal data:

  • Right of Access — you can request a copy of the personal data we hold about you
  • Right to Correction — you can request that inaccurate or incomplete data be corrected
  • Right to Withdrawal of Consent — you can withdraw consent for data processing at any time (this may affect your ability to use the service)
  • Right to Deletion — you can request deletion of your account and associated data
  • Right to Data Portability — you can request an export of your data in a common format
  • Right to Object — you can object to certain types of data processing

To exercise any of these rights, contact us through the details on coursemate.cards. We will respond to all legitimate requests within 30 days. We may need to verify your identity before processing your request.

8. Cookies and Tracking

CourseMate uses the following types of cookies:

  • Essential cookies — required for login sessions and authentication. Cannot be disabled.
  • Functional cookies — remember your preferences such as difficulty level and last subject viewed
  • Analytics cookies — help us understand how the app is used so we can improve it (anonymised data only)

We do not use advertising or tracking cookies. You can control cookie preferences through your browser settings, though disabling essential cookies will prevent you from logging in.

9. Data Security

CourseMate takes reasonable technical and organisational measures to protect your personal data from unauthorised access, loss, or misuse. These measures include:

  • HTTPS encryption for all data in transit
  • Encrypted password storage via Supabase Auth
  • Row-level security policies in our database
  • API keys stored as environment variables, never exposed to the frontend
  • Regular security updates to all dependencies

However, no method of data transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that affects your personal data, we will notify you as required by applicable law.

10. International Data Transfers

CourseMate is based in Singapore. However, our service providers (Supabase, Vercel, Stripe, and AI providers) may process your data in other countries, including the United States and the European Union. By using CourseMate, you consent to your data being transferred to and processed in these countries, which may have different data protection laws than Singapore.

We ensure that all international transfers are conducted in compliance with applicable law and that our service providers maintain adequate data protection standards.

11. Children's Privacy

CourseMate is intended for users aged 13 and above. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately and we will delete it promptly.

12. Third-Party Links

CourseMate may contain links to third-party websites or services. We are not responsible for the privacy practices of those sites. We encourage you to review the privacy policies of any third-party services you visit.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will notify you by email or through a prominent notice on coursemate.cards before the changes take effect. The date at the top of this policy reflects when it was last updated. Continued use of CourseMate after changes are posted constitutes your acceptance of the revised policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how CourseMate handles your personal data, please contact us through the contact page on coursemate.cards. We take all privacy enquiries seriously and will respond within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore at www.pdpc.gov.sg.

This Privacy Policy was last updated in March 2026. CourseMate is an independent product operated in Singapore and governed by the Personal Data Protection Act 2012 (PDPA). This document does not constitute legal advice. For formal legal guidance, consult a qualified lawyer.