Privacy policy
Effective 21 August 2026
The short version: we store your email, your plan, and how many minutes you've used. We do not store your notes, your transcripts, your summaries or your class audio. Some of that material is transmitted while the service runs, and this explains exactly where it goes.
1.What we store
Three things, and only these:
Your email address, which Google gives us when you sign in. It identifies your account and it is how we reach you about it. We do not receive your Google password, your contacts, your files or anything else.
Your plan — free or paid, and if paid, the billing period and a Stripe customer reference.
Minutes used — the start time and duration of each listening session, so allowances can be enforced. We record how long a session ran, never what was said in it.
2.What we never store
Your notes, slides and documents. Your class transcripts. The summaries and answers generated for you. The class audio itself. None of it is written to our database, and there is no table it could live in.
Your material and transcript live in your browser for the length of a session. Close the tab and they are gone. If you want to keep a transcript or summary, save it before you leave.
3.What is transmitted while it runs
This is the part worth reading carefully. Your files are opened and read in your browser, so the file itself is never uploaded. But to do its job the service has to send some of what it reads onward.
Class audio streams to Deepgram, our transcription provider, and comes back as text within about a second. It is not written to disk at any point, so no recording of your lecture exists afterwards.
Parts of your notes are sent to Anthropic, which runs the language model that writes answers. When a question is detected, the relevant sections of your material go with it so the model has something to answer from. An index of your section headings is also sent periodically so the right page can be tracked as the class moves.
Stretches of the transcript are sent to Anthropic for the same purpose, and to produce the end-of-class summary.
These transmissions pass through our servers to reach those providers. Nothing is retained at either end, and none of it is used to train models.
4.Who else is involved
Google — sign-in. It is the only way into autofetch, so Google knows you have an account here. Supabase — accounts, sessions and the usage meter. Deepgram — live transcription. Anthropic — the language model behind topic tracking, answers and summaries. Vercel — hosting. Stripe — payments, if you subscribe. We never see your card details.
If you connect Notion, we hold an access token for your workspace in a cookie your browser sends back to us; it is never readable by JavaScript on the page. It is used only to read the pages you point us at, and disconnecting or signing out deletes it.
We do not sell your data, and there is no advertising or analytics tracking on the app.
5.Cookies
Four, all of them strictly necessary. A Supabase session cookie, which is what keeps you signed in. And if you connect Notion: an access token, a readable record of which workspace it belongs to, and a short-lived anti-forgery value used only during the connection handshake.
There are no advertising, analytics or tracking cookies of any kind, and no third party sets a cookie through us. Strictly necessary cookies do not require consent under EU or UK rules, which is why you have never seen a cookie banner here. If that ever changes, a banner appears before the cookie does.
6.If you are in the EU or UK
Our lawful basis for handling your email, plan and usage minutes is performance of the contract between us: without them there is no account and no way to enforce a limit.
You have the right to access, correct, export, restrict or delete your data, to object to processing, and to complain to your local supervisory authority. Email us and we will act within 30 days. Since we hold no notes, transcripts or recordings, most of what these rights cover does not exist in our systems in the first place.
Data is processed in the United States. Our processors operate under standard contractual clauses for transfers out of the EEA and UK.
7.If you are in California
You have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for asking. The complete list of what we hold is in section 1.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. There is nothing to opt out of because it does not happen.
8.If something goes wrong
If a breach affects your personal information we will tell you by email without undue delay, and notify regulators where the law requires it. We will say what happened and what to do about it rather than the minimum we can get away with.
9.Your rights
You can see everything we hold about you on your account page. It is a short list, by design.
To have the account and everything attached to it deleted, email info@ninek.co. We will confirm within seven days. Since we hold no notes or transcripts, deletion removes your email, your plan record and your usage history.
10.Security
Traffic is encrypted in transit. Account data sits behind row-level security, so one account cannot read another’s. Transcription credentials handed to your browser are short-lived tokens that expire in about a minute and can do nothing but open a transcription stream.
No system is perfect. If you find a security problem, email info@ninek.co and we will take it seriously.
11.Children
Autofetch is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.
12.Changes
If this policy changes materially you will be told by email or in the app before it takes effect, and the date at the top will change. NineK Apps LLC is the controller of the data described here.