Accessible Notes

Privacy Policy

Effective July 1, 2026

Who we are

Comply.AI (“Accessible Notes”) converts handwritten lecture notes into accessible, screen-reader-friendly PDFs. This policy explains what data we collect when you use the service, why we collect it, how long we keep it, and the choices you have.

What we collect

  • Account information. When you sign in with Google, we receive your email address and basic profile information through our authentication provider. We never see or store your Google password.
  • Documents you upload. We store the original PDF in private storage, along with the page images, transcription, and accessible PDF produced from it, so the document can be reviewed, edited, downloaded, and quality-checked during its retention period.
  • Audit records.For security and accountability we log key actions (sign-in, sign-out, upload, view, download, generate, delete) with a timestamp, your user ID, the document’s job ID, and the request’s source IP address. Audit records never contain document content.
  • Feedback. If you submit feedback, we store the message, any contact details you choose to provide, and any files you attach.

How we use your data

Your data is used solely to provide, maintain, secure, and support the service. We do not sell your data, share it with advertisers, or use it for any purpose unrelated to the service.

How long we keep it

  • Signed-in jobs (original PDFs, page images, transcriptions, preview PDFs, and final PDFs): deleted automatically 30 days after upload, or immediately when you delete the job yourself.
  • Guest jobs (used without signing in): deleted automatically after 7 days.
  • Internal transcription caches: purged on the same 30-day schedule.
  • Audit logs and feedback: retained as security and business records for as long as they remain relevant.

Where your data lives

We use vetted subprocessors to operate, maintain, and secure the service. These subprocessors may process information only as necessary to perform services on our behalf. We maintain a current list of our subprocessors, including their purposes and processing locations. This list is available upon request at complyaibusiness@gmail.com. Service data is hosted and processed in the United States.

How we protect it

  • All traffic is encrypted with HTTPS/TLS; stored data is encrypted at rest.
  • Every document is owned by the account that uploaded it — access is verified on every request, and no other user can see your documents.
  • Uploads are validated and size-limited; endpoints are rate-limited.
  • Privileged (administrative) access is token-controlled and audit-logged.

Students and FERPA

Lecture notes may constitute student education records. We act as a service provider to you (or your institution): we process notes only to provide the conversion you request, we do not disclose them to third parties beyond the subprocessors described above, and we delete them on the schedule described in this policy.

Your choices

  • Delete any job at any time from the My Docs page — this removes all stored files.
  • Use guest mode to avoid creating an account (jobs are then short-lived).
  • Email us at complyaibusiness@gmail.com to request deletion of your account and all associated data.

Changes and contact

If this policy changes materially, we will update the effective date above and note the change on this page. Questions or concerns: complyaibusiness@gmail.com.

See also our Terms of Service.