Privacy Policy
Clear notice for a focused learning tool.
This Privacy Policy states what LearnStack collects, why it collects it, where it is stored, and what information is shared with service providers or other users.
1. Scope
This Privacy Policy applies to the LearnStack website and its Cloudflare Pages Functions. LearnStack lets users generate practice tests, submit answers, see correct answers or feedback, save missed questions, review session history, upload rubric images for analysis, use paid Pro or Teacher Mode features, and create temporary teacher share codes.
Guest practice and the current public LearnStack account are stored on the device and browser where they are used. Cross-device account sync is planned, but is not active in the current public build.
This policy does not apply to external websites or services that LearnStack links to or redirects to, including Stripe Checkout and OpenAI websites. Those services process information under their own privacy policies.
2. Summary
3. Information collected
Account and profile information
- Email address. Collected when you create or update a local account or log in locally. If you start Stripe Checkout, the app sends the email from the local profile to Stripe when available. Stripe may return that email to LearnStack with checkout or webhook status.
- Display name. Collected when you create or update a local account profile.
- Password hash. If you use a password, the current local account flow stores a hash of that password in browser localStorage. LearnStack does not send the password to its Cloudflare payment, entitlement, sharing, rubric, or AI endpoints.
- Guest status. If you continue as a guest, the app stores a guest profile with the email value
guest@learnstack.localin that browser. - Age confirmation. Account creation requires a checkbox confirming that you are at least 13. LearnStack does not ask for or store your full birth date.
- Legal consent. LearnStack stores the date and version of your Terms acceptance, Privacy Policy agreement, and 13+ confirmation.
Practice and learning information
- Subjects, learning goals, current ability level, target domain, difficulty settings, question counts, question style settings, calculator-question settings, rubric settings, and extra information that you enter.
- Generated questions, answer choices, expected answers, explanations, references, thinking shortcuts, user answers, grading results, scores, correct-question IDs, missed-question IDs, and open questions.
- Session history, saved missed questions, completed test records, and retention or review schedules.
- Similar-problem regeneration state, including the original question, regenerated question, answer options, correct answer, explanation, calculator label, and whether the answer for that question was reset.
Rubric and upload information
- Rubric image files uploaded for analysis. The app accepts PNG, JPG, and WebP images up to 5 MB.
- File type, file size, file name, extracted rubric title, extracted rubric text, and extracted rubric criteria.
- Image content verification data used to confirm that the file content matches the declared image type.
Teacher sharing information
- Teacher share codes, creation time, expiration time, and revocation requests.
- Shared test subject, record ID, questions, correct answers, explanations, topics, and question types.
- Student answers, score, and shared-test completion record when a student submits a shared test. In the current site code, this completion record is saved in the student's browser session history.
Payment and entitlement information
- Email address sent to Stripe Checkout when provided.
- Stripe Checkout session ID, Stripe customer ID, subscription ID, invoice ID, subscription mode, checkout status, payment status, plan metadata, renewal period, cancellation status, and whether Pro or Teacher Mode is active.
- LearnStack does not collect or store full payment card numbers, card security codes, or bank account numbers.
Technical and security information
- IP address or proxy IP address from Cloudflare request headers, used for rate limiting, abuse prevention, security logging, and delivery of the site.
- Request method, request path, query parameters, request headers needed for CORS, content type, authorization checks, entitlement checks, and rate limiting, response status, and timestamps that may appear in Cloudflare logs.
- Hashed rate-limit identifiers derived from IP address and, when present, an authenticated user identifier or authorization header.
- Browser storage values used by the app, including
learnstack_user_account,learnstack_account_consent,learnstack_tutorial_done,learnstack_completed_tests,learnstack_retention_schedule,learnstack_teacher_entitlement,learnstack_pro_entitlement,learnstack_exam_upgrades,learnstack_rubric_analysis,learnstack_question_regenerations,learnstack_question_reset_answers,learnstack_question_reset_pending,learnstack_local_share_codes,learnstack_issued_share_codes,learnstack_force_practice_start, andlearnstack_account_reminder_dismissed. - Optional host-platform token. The bundled application can accept a
creao_auth_tokenwhen LearnStack is launched through a compatible CREAO host environment. That token is separate from the public LearnStack local account and is used to authenticate host-platform data requests.
Information not collected by the current site code
- No advertising cookies or advertising pixels.
- No third-party marketing analytics scripts.
- No precise geolocation, contacts, camera recordings, microphone recordings, or device files other than rubric images you choose to upload.
- No full birth date, school name, student roster, advertising ID, or exact location through the current public account flow.
- No medical, disability, financial, family, or confidential school records are requested. Do not submit this information in prompts or uploads.
- No full card numbers, card security codes, or bank account numbers.
4. How information is used
- To generate practice tests and simulated exams from the subjects, settings, questions, answers, rubrics, and extra information you provide.
- To show correct answers, feedback, explanations, references, thinking shortcuts, scores, missed-question review items, and saved session history.
- To save practice progress, completed tests, missed questions, review schedules, account state, and premium state in browser storage.
- To operate Pro features, including calculator-question generation, rubric-guided simulated exams, and similar-problem regeneration.
- To operate Teacher Mode features, including shared test links, temporary share codes, and teacher editing controls.
- To create, verify, and manage Stripe Checkout sessions for Pro and Teacher Mode subscriptions.
- To record a 13+ attestation and legal consent before creating a local account.
- To validate requests, sanitize inputs, reject unsafe uploads, apply rate limits, prevent abuse, troubleshoot errors, enforce CORS, and apply security headers.
- To comply with applicable legal obligations and protect LearnStack, users, payment security, and the rights and safety of others.
5. Information shared
LearnStack does not sell personal information and does not share personal information for targeted advertising.
OpenAI
LearnStack sends prompts, questions, answer choices, expected answers, user answers, learning settings, rubric text, and related learning content to OpenAI through LearnStack server functions when AI generation, grading, feedback, references, thinking shortcuts, similar-problem regeneration, or rubric analysis is requested. If you upload a rubric image, the image is converted to an image payload and sent to OpenAI for extraction. OpenAI returns generated content to LearnStack, and LearnStack returns that content to your browser.
LearnStack displays a short AI notice beside generation and rubric-analysis controls. AI output may be inaccurate or fabricated, so users should review questions, answers, references, and extracted rubric criteria before relying on them.
Stripe
LearnStack sends checkout information to Stripe when you start Pro or Teacher Mode checkout. This may include email address, plan price ID, success URL, cancel URL, feature metadata, and plan metadata. Stripe processes payment details. LearnStack receives checkout session, customer, subscription, invoice, payment, cancellation, and renewal status needed to unlock paid features and process billing webhooks.
Cloudflare
LearnStack is hosted on Cloudflare Pages and uses Cloudflare Pages Functions. Cloudflare processes site requests, API requests, IP addresses, headers, timestamps, response status, and logs needed to deliver and secure the site. When Cloudflare KV is configured, Cloudflare KV stores temporary teacher share codes and rate-limit counters.
Optional CREAO host integration
The application bundle includes an optional CREAO host integration. When LearnStack is launched with a valid CREAO authentication token, the app may send that token, learning profiles, learning sessions, session metrics, retention tests, performance analytics, and shared-test records to same-origin CREAO data-store routes. The ordinary public LearnStack email-and-password account does not create this host token and does not currently activate cross-device synchronization.
Teachers and students using share codes
When a teacher creates a share code, anyone with the active code can load the shared test subject, questions, correct answers, explanations, topics, and question types while the code remains valid. A student who submits answers through a shared test creates a completion record in that student's browser.
Legal and safety disclosures
LearnStack may disclose information if required by law, subpoena, court order, or valid government request, or if disclosure is reasonably necessary to protect the site, users, payment security, or the rights, property, or safety of others.
6. Storage and retention
- Browser localStorage. Local account data, legal-consent records, completed tests, missed questions, review schedules, premium state, rubric summaries, and similar-problem state remain in the browser until you delete the relevant item, use the in-app deletion control, or clear browser storage.
- Browser sessionStorage. Local preview share codes, force-practice-start flags, and account-reminder dismissal state remain for the browser session or until the browser clears session storage.
- Optional host token. A CREAO host authentication token may remain in localStorage until it expires, is found invalid, or browser data is deleted.
- Teacher share codes. Server share codes are designed to expire after 15 minutes and are also revoked when the teacher closes the share panel. Local preview share codes exist only in sessionStorage.
- Rate-limit records. Rate-limit counters use a 60-second window. When Cloudflare KV is configured, each counter is written with an expiration of about 120 seconds.
- Rubric uploads. The server validates and forwards rubric images for analysis. LearnStack does not intentionally store the original rubric image after processing. Extracted rubric title, text, and criteria may be saved in browser localStorage.
- Payment records. Stripe retains checkout, subscription, and payment records under Stripe's own retention practices. LearnStack checks the session and status information needed to confirm access.
- LearnStack billing KV. When configured, Cloudflare KV stores checkout-session and subscription lifecycle metadata received from Stripe, including customer email when Stripe returns it. Webhook event idempotency records expire after about seven days. Current subscription lifecycle records do not have an automatic deletion period in the present code and may require a manual deletion request.
- Cloudflare logs. Cloudflare may retain request logs and security logs according to the Cloudflare account settings and Cloudflare's own retention practices.
7. Your choices
- You may use LearnStack as a guest. Guest progress stays on the device and browser where it was created.
- You may create or update a local account profile with an email address and display name. In the current public build, this saves account and learning data in that browser. It does not yet provide cross-device sync.
- You may delete individual session history cards using the remove control in the session history interface.
- You may use Delete saved progress in Account Settings to remove practice history, missed questions, review schedules, rubric summaries, and learning settings while keeping the local account and verified premium-access reference.
- You may use Delete local account/data in Account Settings to revoke tracked temporary share codes and remove the local account, practice history, missed questions, settings, entitlements, browser databases, caches, and LearnStack browser storage from that device.
- Deleting local LearnStack data does not cancel an active Stripe subscription or require Stripe to erase payment records that it retains under its own legal and operational obligations. Contact LearnStack before deletion if you need billing help.
- For deletion of server-side records that LearnStack can identify and control, email djoseb2007@gmail.com.
- You may choose not to upload rubric images if you do not want rubric images sent for AI analysis.
- You may choose not to create teacher share codes if you do not want shared test content stored temporarily and made available to code holders.
- You may contact LearnStack to request access, correction, or deletion of records that LearnStack can identify and control.
8. Security
LearnStack uses HTTPS through Cloudflare, content security policy headers, security response headers, CORS controls, request validation, input sanitization, upload type and size checks, image magic-byte checks, payment verification through Stripe, server-side API keys, and rate limiting. Standard API endpoints are limited to 60 requests per minute. API paths beginning with /api/auth, if added, are limited to 5 requests per minute. Rate limits are applied by IP address and by user identifier when a user identifier is present.
No website can guarantee perfect security. Do not upload sensitive personal, medical, financial, confidential school, or confidential employer records unless you are authorized to do so.
9. Students and children
LearnStack is designed for high school, early college, and similar learners. It is not directed to children under 13. Account creation requires the user to confirm that they are at least 13. LearnStack does not collect a full birth date for this purpose. Teachers, schools, parents, or guardians remain responsible for any additional notice, consent, or authorization required before asking students to use the site or shared test codes.
10. Changes
LearnStack may update this Privacy Policy as the product changes. The effective date above shows when the current version took effect. Material changes should be posted on this page before or when they take effect.
11. Contact
For privacy questions or requests, contact LearnStack at djoseb2007@gmail.com.