This Privacy Policy explains how General Grizzly ("General Grizzly," "we," "us," or "our") collects, uses, and protects information when you use the General Grizzly application (the "Service"). It is written to describe exactly what the Service does today, not a hypothetical future version of it.
1. Information we collect
Account information
You sign in with Google. We receive and store your Google account id, email address, display name, and profile picture URL from Google's sign-in flow. We never receive or store your Google password, and we cannot access your Google account beyond the basic profile information Google shares at sign-in.
Content you create
We store what you build in the Service so it is there the next time you sign in: chat threads and messages, generated lessons, bootcamp maps and progress, study decks (guides, flashcards, quizzes, worksheets, blurting sessions), notebooks, manga projects, study-timer history, and any files or documents you upload for a chat or a study kit.
Usage records
Each account has a daily usage allowance. We record how much of that allowance you have used each day, keyed to your account, so the limit can be enforced and so the usage indicator in the app can show you an accurate percentage. We do not show or share your raw usage count with anyone but you and, in aggregate anonymized form, ourselves for capacity planning.
Technical and log information
When a request fails or an error occurs, we log the error, the route it happened on, and the account id involved, so the problem can be diagnosed and fixed. We also keep basic connection-level information (such as IP address) briefly, only to enforce rate limits and to detect and block automated abuse (see "Automated abuse detection" below).
Feedback you send us
If you submit feedback through the in-app feedback form, we store what you wrote, along with your account id if you were signed in, so we can read and act on it.
Billing information
If you subscribe to a paid plan, our payment processor, Stripe, handles your payment details directly — we never see or store your card number. What we do store is the subscription record Stripe gives us back: which plan you're on, its status, its current billing period, and a record of each invoice actually paid (amount, currency, and date). This is what powers your plan and billing period shown in Settings.
2. Information we do not collect
We do not run advertising, we do not use third-party ad trackers or cross-site tracking pixels, and we do not sell your personal information to anyone, for any reason. We never receive or store your card number, bank details, or any other raw payment credential — Stripe is PCI-compliant and handles that itself.
3. How we use your information
We use the information above only to:
- Operate the features you use — generate lessons, decks, bootcamps, manga, and chat replies, and save your work so it persists across sessions and devices.
- Authenticate you and keep your account secure.
- Enforce the daily usage allowance fairly and show you how much of it you have left.
- Diagnose and fix bugs and outages.
- Detect and block automated abuse (bots, scripted traffic, credential stuffing against the sign-in flow).
- Respond to feedback and support requests you send us.
We do not use your prompts, uploads, or generated content to train any AI model, ours or a third party's.
4. Who else processes your data
Running the Service requires sending limited data to a small number of infrastructure and AI providers, each of whom processes it under their own privacy terms:
- AI model providers. To answer you, your prompt, conversation context, and any file you attach are sent to whichever provider powers the model you selected — Anthropic, OpenAI, or Google. Image generation requests are sent to OpenAI.
- Web search. If a feature performs a web search on your behalf, the search query (not your full conversation) is sent to the search provider that powers it.
- Google Sign-In. Authentication is handled by Google's own identity service.
- Stripe. If you subscribe to a paid plan, your payment details and billing information are processed and stored by Stripe, our payment processor, under Stripe's own privacy policy. We only receive back the subscription status and invoice records described above.
- Hosting and database. The application and its database are hosted on Railway's infrastructure. Railway can access data only in its capacity as our infrastructure host, not to use it for its own purposes.
We do not have any other data-sharing relationships. Documents you upload and content you generate are private to your account — every database query in the Service is scoped to your user id, so another signed-in learner cannot read your material, and there is no feature that makes your content visible to other users.
5. Automated abuse detection
The Service uses a hidden form field (a "honeypot") and request-rate monitoring to detect non-human traffic. If a client trips this detection, we temporarily block further requests from that client and may log the event. This mechanism does not identify or profile real users — it exists solely to keep the Service available and to keep the daily usage allowance meaningful.
6. Data retention
We keep your account and content for as long as your account exists, so your work is there whenever you come back. Error logs are retained only as long as needed to diagnose the issue they relate to. Usage records older than a rolling window may be aggregated or discarded once they are no longer needed to enforce the current allowance.
7. Your rights and choices
You can review and edit most of your content directly in the app (Library, Notebook, Bootcamp, Settings). You can request a copy of your data or ask us a question about it at any time by emailing us (below).
Deleting your account. Settings → Profile → Delete account permanently removes your account and everything linked to it — threads, messages, documents, decks, bootcamps, review history, and usage records. This cannot be undone, and we do not retain a recoverable backup of a deleted account past what is needed to confirm the deletion succeeded. The one exception is billing history: if you ever paid for a plan, the record of that payment (amount, date, plan) is kept as our own financial record after your account is deleted, the same way it would be for any business — it is disconnected from your account and can no longer be linked back to your other data.
8. Children's privacy
General Grizzly is a study tool and is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you are between 13 and 18, please use the Service with the awareness and, where your school or household requires it, the involvement of a parent or guardian. If you believe a child under 13 has created an account, contact us at the email below and we will delete it.
9. Data security
We scope every database read and write to the requesting account, use encrypted connections (HTTPS/TLS) for all traffic to and from the Service, and apply a strict content-security policy in the app to reduce the risk of malicious scripts. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security, but we do not treat that as an excuse to collect more than we need.
10. International use
The Service is operated from and hosted in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country of residence.
11. Changes to this policy
We may update this policy as the Service changes — most notably once billing for Pro and Max plans goes live. We will update the "Effective" date at the top of this page when we do. Material changes will be reflected here before they take effect; continuing to use the Service after an update means you accept the revised policy.
12. Contact
Questions, requests, or concerns about your data: rishigompa2@gmail.com.