This Privacy Policy explains how General Grizzly ("General Grizzly," "we," "us," or "our") collects, uses, and protects information when you use the General Grizzly application (the "Service"). It is written to describe exactly what the Service does today, not a hypothetical future version of it.
1. Information we collect
Account information
You sign in with Google. We receive and store your Google account id, email address, display name, and profile picture URL from Google's sign-in flow. We never receive or store your Google password, and we cannot access your Google account beyond the basic profile information Google shares at sign-in.
Content you create
We store what you build in the Service so it is there the next time you sign in: chat threads and messages, generated lessons, course maps and progress, study decks and per-unit study material generated inside a course (guides, flashcards, quizzes, worksheets, blurting sessions), notebooks, manga projects, study-timer history, and any files or documents you upload for a chat or a study kit.
Usage records
Each account has a daily usage allowance. We record how much of that allowance you have used each day, keyed to your account, so the limit can be enforced and so the usage indicator in the app can show you an accurate percentage. This is visible to you, and to us for support and capacity planning — it is never shown to any other learner, sold, or shared with advertisers.
Product analytics
We record which pages you visit and when, and basic counts of how the Service is used — chat conversations started and prompts sent — tied to your account id if you are signed in. This is internal product analytics only: it tells us which parts of the Service are actually used, not what you wrote or what General Grizzly taught you. It is never sold, never shared with advertisers, and is only ever viewed by us in aggregate to decide what to build or fix next.
Technical and log information
When a request fails or an error occurs, we log the error, the route it happened on, and the account id involved, so the problem can be diagnosed and fixed. We also keep basic connection-level information (such as IP address) briefly, only to enforce rate limits and to detect and block automated abuse (see "Automated abuse detection" below).
Feedback you send us
If you submit feedback through the in-app feedback form, we store what you wrote, along with your account id if you were signed in, so we can read and act on it.
2. Information we do not collect
We do not run advertising, we do not use third-party ad trackers or cross-site tracking pixels, and we do not sell your personal information to anyone, for any reason. General Grizzly is free to use — we do not process payments and never collect card numbers, bank details, or any other payment information.
3. How we use your information
We use the information above only to:
- Operate the features you use — generate lessons, decks, courses, manga, and chat replies, and save your work so it persists across sessions and devices.
- Authenticate you and keep your account secure.
- Enforce the daily usage allowance fairly and show you how much of it you have left.
- Diagnose and fix bugs and outages.
- Detect and block automated abuse (bots, scripted traffic, credential stuffing against the sign-in flow).
- Respond to feedback and support requests you send us.
We do not use your prompts, uploads, or generated content to train any AI model, ours or a third party's.
4. Who else processes your data
Running the Service requires sending limited data to a small number of infrastructure and AI providers, each of whom processes it under their own privacy terms:
- AI model providers. To answer you, your prompt, conversation context, and any file you attach are sent to whichever provider powers the model you selected — Anthropic, OpenAI, or Google. Image generation requests are sent to OpenAI.
- Web search. If a feature performs a web search on your behalf, the search query (not your full conversation) is sent to the search provider that powers it.
- Google Sign-In. Authentication is handled by Google's own identity service.
- Application hosting. The application itself runs on Railway's infrastructure.
- Database hosting. The database is a PostgreSQL instance hosted by Supabase. We use Supabase purely as a database host — none of its other products (authentication, storage, row-level security) are used by the Service.
- File and backup storage. Cloudflare R2 serves two purposes. First, encrypted backups of the database, retained on a rolling 90-day schedule, so your work survives a failure at the database host. Second, PDFs and images you import into a Notebook are stored there so they sync across your devices — each file is stored under your account only and is not reachable by any other learner. Neither use is readable by anyone but us.
- Email delivery. If the Service sends you an email (for example an account notice), your email address and the message content are handled by Resend, our email delivery provider.
Railway, Supabase, Cloudflare and Resend can access data only in their capacity as our infrastructure providers, under their own terms — not to use it for their own purposes.
Pages we fetch on your behalf
If you import a course from a public course page, the Service opens that page from our servers and reads its unit and lesson titles. The request comes from us, not from your browser: the site you are importing from receives our server's request, not your IP address, your account, or anything else that identifies you. We store only the outline (the titles you selected) — no page content, cookies, or credentials.
We do not have any other data-sharing relationships. Documents you upload and content you generate are private to your account — every database query in the Service is scoped to your user id, so another signed-in learner cannot read your material, and there is no feature that makes your content visible to other users.
5. Automated abuse detection
The Service uses a hidden form field (a "honeypot") and request-rate monitoring to detect non-human traffic. If a client trips this detection, we temporarily block further requests from that client and may log the event. This mechanism does not identify or profile real users — it exists solely to keep the Service available and to keep the daily usage allowance meaningful.
6. Data retention
We keep your account and content for as long as your account exists, so your work is there whenever you come back. Error logs are retained only as long as needed to diagnose the issue they relate to. Usage records older than a rolling window may be aggregated or discarded once they are no longer needed to enforce the current allowance.
Backups. We take regular encrypted backups of the database so that a failure at our database host cannot destroy your work. Those backups are kept for up to 90 days and then deleted automatically. Because a backup is a snapshot of the database as it was at the time it was taken, data you delete can persist inside older backups until they age out — see the account-deletion note in section 7.
7. Your rights and choices
You can review and edit most of your content directly in the app (Library, Notebook, Course Builder, Settings). You can request a copy of your data or ask us a question about it at any time by emailing us (below).
Deleting your account. Settings → Profile → Delete account permanently removes your account and everything linked to it — threads, messages, documents, decks, courses, review history, and usage records. This cannot be undone, and we do not retain a recoverable backup of a deleted account past what is needed to confirm the deletion succeeded.
Deletion removes your data from the live database immediately. Backups taken before you deleted your account still contain it until they expire on the 90-day schedule described in section 6. We do not restore a backup to recover a deleted account, and those copies are not used for any purpose other than disaster recovery.
8. Children's privacy
General Grizzly is a study tool and is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you are between 13 and 18, please use the Service with the awareness and, where your school or household requires it, the involvement of a parent or guardian.
9. Data security
We scope every database read and write to the requesting account, use encrypted connections (HTTPS/TLS) for all traffic to and from the Service, and apply a strict content-security policy in the app to reduce the risk of malicious scripts. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security, but we do not treat that as an excuse to collect more than we need.
10. International use
The Service is operated from and hosted in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country of residence.
11. Changes to this policy
We may update this policy as the Service changes. We will update the "Effective" date at the top of this page when we do. Material changes will be reflected here before they take effect; continuing to use the Service after an update means you accept the revised policy.
12. Contact
Questions, requests, or concerns about your data: hello.generalgrizzly@gmail.com.