Privacy Policy
Last updated 22 July 2026
AthenisOS is a study tool. You upload your own school work; it reads it and turns it into a concept map, quizzes, and a plan for what to revise. This page says exactly what that involves, in the order it happens.
It describes the software as it is actually built, not as a category of product. Where something is a limitation rather than a promise, it says so.
Who runs this
AthenisOS is operated by Max Singer. For anything on this page — including a request to see or delete your data — contact [email protected].
What we collect
- Your email address and Google account identifier, so you can sign in. Signing in with Google is the only way in; we never see or store a password.
- Documents you upload — notes, timetables, marked work, results — and everything extracted from them: concepts, links between concepts, exam dates, grades, and the feedback points a teacher wrote.
- What you do with the study material: quiz answers, scores, which flashcards you found hard, whether you ticked off a plan item.
- Your timezone, if you set one, so a deadline turns overdue at your midnight rather than the server's.
- A count of AI tokens used per request, so a daily limit can be enforced and shown to you.
There is no analytics, no advertising, no tracking pixels, and no third-party cookies. The only cookie is the one that keeps you signed in.
Uploaded files are not kept
A PDF you upload is held in memory for as long as it takes to read it — typically twenty to forty seconds — and is then discarded. It is never written to disk or to file storage. What persists is what was extracted from it: the concepts, dates, grades or feedback points, which you can see and delete individually on the Your data page.
Google account data
Two separate things use Google, and they are worth keeping apart.
Signing in. We receive your email address, name and Google account identifier. That is all sign-in uses.
Connecting your files. Separately, and only if you choose to connect it, AthenisOS can read parts of your Google account. Every scope requested is read-only — nothing is ever created, edited or deleted in your Google account:
- drive.metadata.readonly — file names and revision history, to see which documents a group project is actually being written in and who edited them.
- documents.readonly — the text of Google Docs you have linked, to measure how much of a document changed between revisions.
- spreadsheets.readonly — the contents of Google Sheets you have linked, so data in a sheet can be read the same way as a document.
- calendar.readonly — events from your primary calendar, so they appear alongside your deadlines in the sidebar calendar.
- classroom.courses.readonly — the list of Classroom courses you are in, so coursework can be attached to the right one.
- classroom.coursework.me.readonly — your own Classroom coursework only. Google never provides other students' work, and none of it can appear here.
Access tokens for these are stored so the connection survives you closing the tab, and are protected by row-level security so no other account can read them. You can disconnect at any time from the Connections page, or revoke access directly at myaccount.google.com/permissions. Disconnecting deletes the stored tokens immediately.
Limited Use of Google user data
AthenisOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide the features described above, which you can see working in the product.
- It is not transferred to anyone else, except as required to provide those features (see Who else sees your data), to comply with the law, or as part of a merger or acquisition with your prior notice.
- It is not used for advertising, and is never sold.
- No human reads your Google user data, except where you have explicitly asked us to for support, where it is necessary for security purposes such as investigating abuse, or where the law requires it.
- Google user data is not used to train generalised artificial intelligence or machine learning models. It is sent to Anthropic's Claude API only to produce your own results, and Anthropic does not train on API inputs or outputs.
Who else sees your data
AthenisOS is a small product built on other people's infrastructure. Three companies process data on our behalf:
- Supabase — the database and sign-in. Everything listed above is stored there. Every table is protected by row-level security, so a query made as you can only return your own rows.
- Anthropic — the AI. The contents of a document you upload, and the questions you ask about your own material, are sent to Anthropic's Claude API to produce your results. Anthropic does not train its models on API inputs or outputs.
- Vercel — hosting. Serves the site and keeps ordinary server logs, which include IP addresses.
Nobody else. Your data is not sold, rented, or shared with advertisers, schools, or parents.
How long it is kept
- Your data stays until you delete it. There is no automatic expiry.
- Deleting a single document, quiz or result removes it immediately, along with anything derived from it.
- Clear everything moves all your content into a backup you can restore for 30 days, after which it is permanently deleted.
- Deleting your account removes the account and everything attached to it at once, by database cascade. There is no copy to restore and no way for us to undo it.
Your rights
You can see everything held about you on the Your data page, export nothing you cannot already read there, correct anything by editing or re-uploading, and delete any part of it or all of it without asking us. If you are in the UK or the EU you also have the right to object to processing, to request a copy in a portable format, and to complain to your data protection authority. Email the address above and you will get a reply.
Age
AthenisOS is built for school students, and many will be under 18. If you are under 13 — or under the minimum age where you live, which is 16 in some countries — you need a parent or guardian's permission before using it, and they should read this page with you. We do not knowingly collect data from anyone below that age without it. If you believe a child has an account without permission, email the address above and it will be deleted.
Security, honestly
Every table is protected by row-level security, sign-in is handled by Google rather than by us, and no passwords are stored. Uploaded files are never written to disk. Those are real protections and they are the ones that matter most.
But no system is perfectly secure, and this one is early and small. If you find a problem, email the address above rather than posting it — you will get a fast and grateful reply.
Changes
If this policy changes in a way that affects what happens to data already collected, you will be told before it takes effect. The date at the top always reflects the current version.