Privacy Policy
This policy explains how ScholarMind handles study data, AI requests, analytics, and security. It is written for the current preview product and should be reviewed before a larger public launch.
Mind Security Engine
Security and Abuse Protection
ScholarMind uses the Mind Security Engine to add security headers, local suspicious-request detection, upload validation, human verification for suspicious traffic, API throttling, and optional Arcjet protection. Supabase row-level security keeps signed-in users scoped to their own studios, files, chat history, and settings.
What ScholarMind Stores
ScholarMind stores the information needed to run your study workspace: account details from Supabase Auth, studios, uploaded source metadata, extracted study text, saved AI outputs, chat history, revision plans, preferences, and usage-limit records.
Uploaded files are used to create source-grounded study help. Extracted text is stored so chat, AI Notes, quizzes, flashcards, and exams can use the same material without asking you to upload it repeatedly.
AI Processing
When you ask the tutor or generate a tool, ScholarMind sends the relevant prompt, enabled source text, and study context to configured AI providers such as OpenRouter. Do not upload highly sensitive personal documents unless you are comfortable using them for AI processing.
The AI is instructed to use enabled sources as the evidence base. You can disable a source from being used by chat, tools, revision schedules, and generated outputs.
Analytics
ScholarMind records basic product analytics such as page views, feature use, source search, and source import events. These events help improve reliability, spot popular features, and detect abuse.
The host panel can view aggregate usage and onboarding trends. It is not designed to expose private study answers publicly.
Your Controls
You can remove sources, disable sources from AI use, create or delete studios, redo the personalisation quiz, and change preferences in settings.
If you want account data removed, contact the site owner. Supabase account deletion removes dependent database rows where cascading deletes are configured.