LEARNSTACK Back to LearnStack

Privacy Policy

Clear notice for a focused learning tool.

This Privacy Policy states what LearnStack collects, why it collects it, where it is stored, and what information is shared with service providers or other users.

Effective date: June 8, 2026

1. Scope

This Privacy Policy applies to the LearnStack website and its Cloudflare Pages Functions. LearnStack lets users generate practice tests, submit answers, see correct answers or feedback, save missed questions, review session history, upload rubric images for analysis, use paid Pro or Teacher Mode features, and create temporary teacher share codes.

Guest practice and the current public LearnStack account are stored on the device and browser where they are used. Cross-device account sync is planned, but is not active in the current public build.

This policy does not apply to external websites or services that LearnStack links to or redirects to, including Stripe Checkout and OpenAI websites. Those services process information under their own privacy policies.

2. Summary

Practice data
Questions, answers, scores, missed questions, session history, review schedules, and settings.
Stored mainly in your browser. Sent to LearnStack server functions and OpenAI when AI generation, feedback, grading, references, or similar-problem features are used.
Account data
Email address, display name, guest status, local password hash if a password is used, 13+ confirmation, and legal-consent timestamps.
Stored in your browser in the current public build. Email is sent to Stripe Checkout when provided and may be returned to LearnStack in verified checkout or webhook records.
Payments
Plan choice, checkout session ID, payment status, subscription status, and Stripe customer identifier when returned by Stripe.
Processed by Stripe. Subscription lifecycle metadata may also be stored in Cloudflare KV. LearnStack does not receive full card numbers, card security codes, or bank account numbers.
Teacher sharing
Temporary share code, shared test subject, questions, correct answers, explanations, topics, and question types.
Stored temporarily in Cloudflare KV when configured, or in memory during local preview. Anyone with an active code can view the shared test.
Advertising
No advertising cookies, ad pixels, or third-party marketing analytics are included in the current site code.
LearnStack does not sell personal information and does not share personal information for targeted advertising.

3. Information collected

Account and profile information

  • Email address. Collected when you create or update a local account or log in locally. If you start Stripe Checkout, the app sends the email from the local profile to Stripe when available. Stripe may return that email to LearnStack with checkout or webhook status.
  • Display name. Collected when you create or update a local account profile.
  • Password hash. If you use a password, the current local account flow stores a hash of that password in browser localStorage. LearnStack does not send the password to its Cloudflare payment, entitlement, sharing, rubric, or AI endpoints.
  • Guest status. If you continue as a guest, the app stores a guest profile with the email value guest@learnstack.local in that browser.
  • Age confirmation. Account creation requires a checkbox confirming that you are at least 13. LearnStack does not ask for or store your full birth date.
  • Legal consent. LearnStack stores the date and version of your Terms acceptance, Privacy Policy agreement, and 13+ confirmation.

Practice and learning information

  • Subjects, learning goals, current ability level, target domain, difficulty settings, question counts, question style settings, calculator-question settings, rubric settings, and extra information that you enter.
  • Generated questions, answer choices, expected answers, explanations, references, thinking shortcuts, user answers, grading results, scores, correct-question IDs, missed-question IDs, and open questions.
  • Session history, saved missed questions, completed test records, and retention or review schedules.
  • Similar-problem regeneration state, including the original question, regenerated question, answer options, correct answer, explanation, calculator label, and whether the answer for that question was reset.

Rubric and upload information

  • Rubric image files uploaded for analysis. The app accepts PNG, JPG, and WebP images up to 5 MB.
  • File type, file size, file name, extracted rubric title, extracted rubric text, and extracted rubric criteria.
  • Image content verification data used to confirm that the file content matches the declared image type.

Teacher sharing information

  • Teacher share codes, creation time, expiration time, and revocation requests.
  • Shared test subject, record ID, questions, correct answers, explanations, topics, and question types.
  • Student answers, score, and shared-test completion record when a student submits a shared test. In the current site code, this completion record is saved in the student's browser session history.

Payment and entitlement information

  • Email address sent to Stripe Checkout when provided.
  • Stripe Checkout session ID, Stripe customer ID, subscription ID, invoice ID, subscription mode, checkout status, payment status, plan metadata, renewal period, cancellation status, and whether Pro or Teacher Mode is active.
  • LearnStack does not collect or store full payment card numbers, card security codes, or bank account numbers.

Technical and security information

  • IP address or proxy IP address from Cloudflare request headers, used for rate limiting, abuse prevention, security logging, and delivery of the site.
  • Request method, request path, query parameters, request headers needed for CORS, content type, authorization checks, entitlement checks, and rate limiting, response status, and timestamps that may appear in Cloudflare logs.
  • Hashed rate-limit identifiers derived from IP address and, when present, an authenticated user identifier or authorization header.
  • Browser storage values used by the app, including learnstack_user_account, learnstack_account_consent, learnstack_tutorial_done, learnstack_completed_tests, learnstack_retention_schedule, learnstack_teacher_entitlement, learnstack_pro_entitlement, learnstack_exam_upgrades, learnstack_rubric_analysis, learnstack_question_regenerations, learnstack_question_reset_answers, learnstack_question_reset_pending, learnstack_local_share_codes, learnstack_issued_share_codes, learnstack_force_practice_start, and learnstack_account_reminder_dismissed.
  • Optional host-platform token. The bundled application can accept a creao_auth_token when LearnStack is launched through a compatible CREAO host environment. That token is separate from the public LearnStack local account and is used to authenticate host-platform data requests.

Information not collected by the current site code

  • No advertising cookies or advertising pixels.
  • No third-party marketing analytics scripts.
  • No precise geolocation, contacts, camera recordings, microphone recordings, or device files other than rubric images you choose to upload.
  • No full birth date, school name, student roster, advertising ID, or exact location through the current public account flow.
  • No medical, disability, financial, family, or confidential school records are requested. Do not submit this information in prompts or uploads.
  • No full card numbers, card security codes, or bank account numbers.

4. How information is used

  • To generate practice tests and simulated exams from the subjects, settings, questions, answers, rubrics, and extra information you provide.
  • To show correct answers, feedback, explanations, references, thinking shortcuts, scores, missed-question review items, and saved session history.
  • To save practice progress, completed tests, missed questions, review schedules, account state, and premium state in browser storage.
  • To operate Pro features, including calculator-question generation, rubric-guided simulated exams, and similar-problem regeneration.
  • To operate Teacher Mode features, including shared test links, temporary share codes, and teacher editing controls.
  • To create, verify, and manage Stripe Checkout sessions for Pro and Teacher Mode subscriptions.
  • To record a 13+ attestation and legal consent before creating a local account.
  • To validate requests, sanitize inputs, reject unsafe uploads, apply rate limits, prevent abuse, troubleshoot errors, enforce CORS, and apply security headers.
  • To comply with applicable legal obligations and protect LearnStack, users, payment security, and the rights and safety of others.

5. Information shared

LearnStack does not sell personal information and does not share personal information for targeted advertising.

OpenAI

LearnStack sends prompts, questions, answer choices, expected answers, user answers, learning settings, rubric text, and related learning content to OpenAI through LearnStack server functions when AI generation, grading, feedback, references, thinking shortcuts, similar-problem regeneration, or rubric analysis is requested. If you upload a rubric image, the image is converted to an image payload and sent to OpenAI for extraction. OpenAI returns generated content to LearnStack, and LearnStack returns that content to your browser.

LearnStack displays a short AI notice beside generation and rubric-analysis controls. AI output may be inaccurate or fabricated, so users should review questions, answers, references, and extracted rubric criteria before relying on them.

Stripe

LearnStack sends checkout information to Stripe when you start Pro or Teacher Mode checkout. This may include email address, plan price ID, success URL, cancel URL, feature metadata, and plan metadata. Stripe processes payment details. LearnStack receives checkout session, customer, subscription, invoice, payment, cancellation, and renewal status needed to unlock paid features and process billing webhooks.

Cloudflare

LearnStack is hosted on Cloudflare Pages and uses Cloudflare Pages Functions. Cloudflare processes site requests, API requests, IP addresses, headers, timestamps, response status, and logs needed to deliver and secure the site. When Cloudflare KV is configured, Cloudflare KV stores temporary teacher share codes and rate-limit counters.

Optional CREAO host integration

The application bundle includes an optional CREAO host integration. When LearnStack is launched with a valid CREAO authentication token, the app may send that token, learning profiles, learning sessions, session metrics, retention tests, performance analytics, and shared-test records to same-origin CREAO data-store routes. The ordinary public LearnStack email-and-password account does not create this host token and does not currently activate cross-device synchronization.

Teachers and students using share codes

When a teacher creates a share code, anyone with the active code can load the shared test subject, questions, correct answers, explanations, topics, and question types while the code remains valid. A student who submits answers through a shared test creates a completion record in that student's browser.

Legal and safety disclosures

LearnStack may disclose information if required by law, subpoena, court order, or valid government request, or if disclosure is reasonably necessary to protect the site, users, payment security, or the rights, property, or safety of others.

6. Storage and retention

  • Browser localStorage. Local account data, legal-consent records, completed tests, missed questions, review schedules, premium state, rubric summaries, and similar-problem state remain in the browser until you delete the relevant item, use the in-app deletion control, or clear browser storage.
  • Browser sessionStorage. Local preview share codes, force-practice-start flags, and account-reminder dismissal state remain for the browser session or until the browser clears session storage.
  • Optional host token. A CREAO host authentication token may remain in localStorage until it expires, is found invalid, or browser data is deleted.
  • Teacher share codes. Server share codes are designed to expire after 15 minutes and are also revoked when the teacher closes the share panel. Local preview share codes exist only in sessionStorage.
  • Rate-limit records. Rate-limit counters use a 60-second window. When Cloudflare KV is configured, each counter is written with an expiration of about 120 seconds.
  • Rubric uploads. The server validates and forwards rubric images for analysis. LearnStack does not intentionally store the original rubric image after processing. Extracted rubric title, text, and criteria may be saved in browser localStorage.
  • Payment records. Stripe retains checkout, subscription, and payment records under Stripe's own retention practices. LearnStack checks the session and status information needed to confirm access.
  • LearnStack billing KV. When configured, Cloudflare KV stores checkout-session and subscription lifecycle metadata received from Stripe, including customer email when Stripe returns it. Webhook event idempotency records expire after about seven days. Current subscription lifecycle records do not have an automatic deletion period in the present code and may require a manual deletion request.
  • Cloudflare logs. Cloudflare may retain request logs and security logs according to the Cloudflare account settings and Cloudflare's own retention practices.

7. Your choices

  • You may use LearnStack as a guest. Guest progress stays on the device and browser where it was created.
  • You may create or update a local account profile with an email address and display name. In the current public build, this saves account and learning data in that browser. It does not yet provide cross-device sync.
  • You may delete individual session history cards using the remove control in the session history interface.
  • You may use Delete saved progress in Account Settings to remove practice history, missed questions, review schedules, rubric summaries, and learning settings while keeping the local account and verified premium-access reference.
  • You may use Delete local account/data in Account Settings to revoke tracked temporary share codes and remove the local account, practice history, missed questions, settings, entitlements, browser databases, caches, and LearnStack browser storage from that device.
  • Deleting local LearnStack data does not cancel an active Stripe subscription or require Stripe to erase payment records that it retains under its own legal and operational obligations. Contact LearnStack before deletion if you need billing help.
  • For deletion of server-side records that LearnStack can identify and control, email djoseb2007@gmail.com.
  • You may choose not to upload rubric images if you do not want rubric images sent for AI analysis.
  • You may choose not to create teacher share codes if you do not want shared test content stored temporarily and made available to code holders.
  • You may contact LearnStack to request access, correction, or deletion of records that LearnStack can identify and control.

8. Security

LearnStack uses HTTPS through Cloudflare, content security policy headers, security response headers, CORS controls, request validation, input sanitization, upload type and size checks, image magic-byte checks, payment verification through Stripe, server-side API keys, and rate limiting. Standard API endpoints are limited to 60 requests per minute. API paths beginning with /api/auth, if added, are limited to 5 requests per minute. Rate limits are applied by IP address and by user identifier when a user identifier is present.

No website can guarantee perfect security. Do not upload sensitive personal, medical, financial, confidential school, or confidential employer records unless you are authorized to do so.

9. Students and children

LearnStack is designed for high school, early college, and similar learners. It is not directed to children under 13. Account creation requires the user to confirm that they are at least 13. LearnStack does not collect a full birth date for this purpose. Teachers, schools, parents, or guardians remain responsible for any additional notice, consent, or authorization required before asking students to use the site or shared test codes.

10. Changes

LearnStack may update this Privacy Policy as the product changes. The effective date above shows when the current version took effect. Material changes should be posted on this page before or when they take effect.

11. Contact

For privacy questions or requests, contact LearnStack at djoseb2007@gmail.com.