Privacy Policy
Last updated: 2026-09-27
Footnote is a small, family-run project that turns a course's own class material into practice questions and tracks how a learner is doing. This page explains, in plain language, what we collect, why, and what control a parent or account owner has over it. We are not a big company with a legal team, so we have kept this short and tried to make every sentence actually true rather than impressive-sounding.
Who this is for
Every course has an owner (an adult — a parent, teacher, or the learner themselves if they are an adult) and a learner. A learner profile always belongs to an owner and cannot exist on its own. If the learner is a child, the owner is the parent or guardian acting on their behalf.
What we collect
We keep a table-by-table list of the fields we store in our engineering docs (the "data inventory") so nothing is left vague. In short:
- The course itself — the family's own class material (slides, worksheets, readings) that the app builds questions from, the facts and questions it builds, and the checklist of what the course covers. Rendered page images and saved video transcripts made while reading that material are kept on the same server.
- The learner's practice — the questions they were asked, the answers they typed, whether each answer was right, and when they are due to review it again. This is what lets the app space out practice sensibly instead of quizzing at random.
- Account basics — a handle (not necessarily a real name) for the owner and the learner, and the owner's email, which is how the app checks that the person signed in is the course's owner.
- The learner's PIN and devices — the learner opens a course on a device with a PIN the owner sets. We store only a scrambled (hashed) form of the PIN, never the PIN itself, plus a count of wrong tries so repeated guessing gets locked out. For each device the PIN has been entered on, we keep the browser's own description of itself (its "user agent", e.g. which kind of phone or tablet), when it was first and last used, and whether it has been signed out.
- A security log — a record of owner actions like setting or resetting the PIN, signing devices out, and deleting a course, with the owner's account handle (never their email) and when it happened.
- How much the course costs to run — behind the scenes, we track how much it costs us to generate and grade questions for a course, so we can keep that within a sensible budget. This is bookkeeping about the course, not about the learner personally.
All of this is stored in a Postgres database and a storage folder on a server we run. We do not collect location data, contacts, photos, biometric data, or anything from a device beyond what is needed to run a practice session in your browser. The browser itself keeps a sign-in cookie, and holds any answers typed while offline until they have been sent to our server.
What we don't do
- We do not sell data, ever.
- We do not share data with third-party advertisers or analytics companies.
- We run no ads and no third-party analytics or tracking SDKs in this app at all. Even the app's font is served from our own server rather than a third-party font service.
- We do not link out to other sites from the learner's screens without a parent or owner having set that up deliberately.
Services we use to run the app
Some of the work is done by outside services, and we would rather name them plainly:
- Anthropic's Claude AI. Course material is sent to Claude so it can pull out the facts in it and write practice questions from them, and some answers (longer, written ones) are sent to it to help grade them. That is a service we use to run the product, the same way a form-grading tool would be, not a third party we hand your data to for their own purposes.
- Our sign-in service. Owners sign in through a separate sign-in service run by the same team for our apps. It checks the owner's email and password and tells this app who is signed in. Learners do not use it; they use the PIN.
- YouTube. When course material links to a YouTube video, our server asks YouTube for that video's title and, where available, its captions, so the video can be studied like the rest of the material. That request carries only the video's address, nothing about you or the learner.
Who can see a learner's answers
Today, only the course's owner can sign in to see a course: the parent screens show readiness, progress, the questions waiting for review (which the owner can confirm or hold back from practice), and the class page each question came from. A course's settings have a place to list other people, such as another parent or a tutor, and what they would see — summary information like a readiness score, streak, or weak areas, and never the learner's actual answer text unless that is explicitly turned on (it defaults to off). There is no screen for those other people yet, so for now nobody but the owner sees any of it in the app.
How long we keep it
We keep course and practice data for as long as the course is active, so progress and review scheduling keep working correctly. We are working toward clearer, automatic limits on how long data is kept after a course goes inactive; today that cleanup is manual, on request.
Deleting your data
A parent who set up a class themselves can delete it, or their whole family account, from the class's Settings screen. Deleting a class permanently removes the files uploaded for it, the facts and questions made from them, the practice sessions and the learner's answers, quiz dates, the PIN and the device list, and our working copies of the pages; the learner's link stops working. Deleting the family account does that for every class, then removes the account itself and signs the parent out for good. Neither can be undone.
Two things are kept on purpose: a security-log entry recording that the deletion happened (with no names, class content or files in it), and what the AI work cost, as totals no longer linked to the family. The parent's email also stays with our sign-in service, which our other apps share, though it can no longer open Footnote; contact us using the address below and we will remove it there too.
For a class our team set up for you, the owner deletes the course data on its Security screen, or contacts us; we remove the class files and the sign-in account on request.
Kids and this app
Footnote is designed to be used by a child under a parent or guardian's account, not signed up on their own. We do not knowingly collect data directly from a child outside of that arrangement, we run no ads, and we do not use third-party analytics that could build a profile of a child across other apps or sites.
Contact
Questions about this policy, or a request to see or delete your data, can be sent to [CONTACT EMAIL].
Changes to this policy
If this policy changes in a way that matters, we will update the date at the top of this page. We will not quietly start doing something this page says we don't do.