Learnara takes your privacy seriously. This policy explains what data we collect on our website and mobile apps, why we collect it, and how it is used and protected. Learnara is operated in the United States; you can reach us anytime at support@learnara.ai.
Account information: When you sign up we collect your email address, display name, and sign in method via Firebase Authentication (Google). Firebase also processes your IP address and device information for security purposes.
Learning content: We store the topics you enter, the lessons generated for you, lessons you save, quiz answers, progress, streaks, points, and feedback ratings. This data is stored in Firebase Firestore and tied to your account. Study files you upload are stored so we can generate study tools from them.
Payment information on the web: Web subscriptions are processed by Stripe. Your card details are collected and processed by Stripe and never touch our servers; we receive and store your subscription status, plan, and a Stripe customer reference. Stripe may also process your data as an independent business for fraud prevention and legal compliance under its own privacy policy.
Payment information on iOS: Subscriptions in the iOS app are billed by Apple. We never see your card details. We use RevenueCat to manage subscription status and entitlements; RevenueCat receives your App Store receipt, a user identifier, and purchase metadata.
Payment information on Android: Subscriptions in the Android app are billed by Google Play. We never see your card details. RevenueCat receives your Play Store purchase token, a user identifier, and purchase metadata to manage subscription status and entitlements.
Analytics: Our production website, iOS app, and Android app use Google Analytics for Firebase by default to understand how the product is used, for example which features are reached and where users drop off. On the website, Google Analytics may set analytics cookies; in the mobile apps, it uses app-instance data and an identifier supplied to RevenueCat's Firebase integration. Google processes device and usage information under its policies; you can read how Google uses this data. Our production website also uses Microsoft Clarity across the customer journey to create heatmaps and session replays. Clarity processes page and session information, rendered page content, navigation, clicks, scrolling, device and browser details, and approximate location derived from network information. This means a replay may include topics, topic descriptions, generated lesson or study content, quiz options, and the interactions made with that content. Profile and checkout pages are explicitly masked, and Clarity automatically masks sensitive form-field content such as input values, numbers, and email addresses. After authentication, we may associate the session with a stable pseudonymous analytics key so we can connect pre-signup and post-signup funnel steps; the key is derived from, but is not, your raw account ID, and we do not send Microsoft your email or name through this integration. We do not deliberately send credentials, payment details, payment client secrets, or the text of support messages through analytics custom events. Separately, we record limited first-party authenticated product receipts, such as server-observed active days, app/platform schema versions, and a claim that a completed lesson appears in your account ledger. These records help us operate the product and measure aggregate retention.
Emails and engagement: We send transactional emails (welcome, billing confirmations, receipts) and, unless you unsubscribe, a daily learning email. Our marketing emails contain tracking links, provided by Resend, that record when you click a link in them. This engagement information is tied to your account and used to measure whether our emails are useful and to stop emailing addresses that never engage. Transactional billing emails are not used for marketing. You can stop marketing emails anytime with the unsubscribe link in any of them.
Server logs and approximate location: Like most services, our servers log IP addresses and request information for security and abuse prevention. We may derive your approximate location (country or region) from your IP address for fraud prevention, regional pricing and offers, tax and legal compliance, and analytics. We do not collect precise GPS location.
Lessons are generated using Anthropic, a third party AI provider. The topics you enter, related learning inputs, and lesson context are sent to Anthropic's API to generate lesson content. Under our agreement with Anthropic, Anthropic does not use this data to train its models and deletes API inputs and outputs within about 30 days, except where retention is required for safety or legal reasons.
Please do not include personal, sensitive, or confidential information in topics or study uploads. Generated lessons may be stored in our lesson library and served to other users who request the same topic, as described in our Terms of Service.
For users in the EU, EEA, and UK, our legal bases are: performance of our contract with you (accounts, lesson generation, billing, transactional email), your consent (marketing email and its engagement tracking, and analytics storage where required), and our legitimate interests (security, fraud prevention, and privacy-minimized product analytics where permitted).
Learnara shares data with the following providers, who are bound to protect it:
We do not sell your personal data, and we do not share it with third parties for their own advertising.
The website uses cookies and similar technologies for authentication, Google Analytics, and Microsoft Clarity as described above. Google Analytics may set analytics cookies on production visits. Clarity may use first-party cookies such as _clck and _clsk to connect page views and sessions when analytics storage is available; without that storage, some recordings and funnel features may be limited. Your browser's Do Not Track signal is not currently given a distinct response, and we do not sell personal data regardless of browser signals.
Learnara is operated from the United States and your data is processed there. Where data of users in the EU, EEA, UK, or Switzerland is transferred to the US, our providers rely on recognized safeguards such as standard contractual clauses and, where applicable, their own certifications.
Your account data and learning content are retained while your account is active. Google Analytics event-level data is configured for 14-month retention, and the linked BigQuery raw analytics export is configured for a maximum of 425 days. Under Microsoft's current standard Clarity schedule, session-playback data is retained for 30 days, while click and heatmap data and labeled or favorited sessions may be retained for up to 9 months. Server logs containing IP addresses are kept for no more than about 30 days.
If you delete your account, your personal data and lesson history are deleted within 30 days. We queue deletion of your Google Analytics user ID and BigQuery-linked rows because those external systems cannot be erased in the same transaction as your Learnara account. Microsoft currently does not provide deletion of one specific Clarity user's project data, so any pseudonymous Clarity records age out under the retention periods above unless the entire Clarity project is deleted sooner. We may retain provider transaction identifiers, amounts, currency, and lifecycle status where needed for billing, tax, accounting, fraud, dispute, or legal obligations; the Learnara user-ID linkage is removed from those retained financial ledger rows. Lessons stored in the shared lesson library may be retained after deletion in a form no longer tied to your identity. Anonymized, aggregated statistics may be kept indefinitely.
You have the right to:
You can delete your account from within the Service, and exercise any of these rights by contacting support@learnara.ai. If you are in the EU, EEA, or UK you also have the right to complain to your data protection authority.
Learnara is not directed at children under 13, and accounts for children under 13 are not permitted. We do not knowingly collect personal data from children under 13. If we learn that a child under 13 has created an account, we will delete the account and its data promptly. If you believe a child has provided us with personal data, contact us at support@learnara.ai.
We use reasonable technical and organizational measures to protect your data, including encryption in transit, access controls, and reliance on established infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If you are a California resident, you have the following additional rights:
To exercise your California privacy rights, contact us at support@learnara.ai.
The following summarises how Learnara's data use maps to Apple's App Store privacy nutrition labels and the corresponding Android data disclosures. Most data categories below are linked to your identity. No data is used for cross-app tracking.
| Data Type | Purpose | Linked to User | Used for Tracking |
|---|---|---|---|
| Email address | Account authentication, email delivery | Yes | No |
| Name | Display name in app | Yes | No |
| User ID | Account identification (Firebase, RevenueCat) | Yes | No |
| Purchase history | Subscription and entitlement management (RevenueCat) | Yes | No |
| Product interaction | Lesson history, progress, feedback, streaks | Yes | No |
| Search history | Topics entered to generate lessons (processed by Anthropic) | Yes | No |
| Device identifier | RevenueCat subscription verification | Yes | No |
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a notice in the product before they take effect. The date at the top shows the current version.
Questions about this Privacy Policy? Contact us at support@learnara.ai.
Learnara: Learn Visually