Privacy Policy
This Privacy Policy explains how CLEVERLYAI INC. (“CleverlyAI,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use our website, mobile application, and related services (the “Service”).
By using the Service, you agree to the practices described in this Privacy Policy.
1. Information We Collect
A. Information You Provide
We may collect information you provide directly, including:
- Account information (such as name and email address)
- Date of birth, which we collect at signup to confirm you meet our minimum age and to apply the right protections to your account
- Login and authentication details
- Profile and study details you choose to give us, such as your education level, year or grade, school, and the subjects you study
- Support requests or communications you send us
- Content or inputs you submit when using the Service (such as prompts or messages)
- Files and images you upload, including documents and photographs of notes or coursework, from which we extract text
- Audio you record, such as lectures and voice input to our AI assistant, which we convert to text
B. Information Collected Automatically
When you use the Service, we may automatically collect:
- Device and application information (device type, operating system, app version)
- Usage data (features used, pages viewed, actions taken, timestamps)
- Log data (IP address, browser type, access times, referring URLs)
- Approximate location — city, region, and country — worked out from your IP address. We keep this with your account so we can see where the Service is being used. We do not collect your precise location, we do not use your device's GPS, and we never ask for location permission.
- Cookies or similar technologies on our website
C. Payment Information
If you purchase a subscription, payments are processed by third-party payment providers. We do not store full payment card details. We may receive limited information such as:
- Subscription status
- Plan type
- Transaction or invoice identifiers
- Billing timestamps
2. How We Use Your Information
We use information to:
- Provide, operate, and maintain the Service
- Create and manage user accounts
- Authenticate users and prevent unauthorized access
- Process subscriptions and manage billing status
- Respond to support requests and communicate with users
- Send you notifications about your account and your studying — including deadline reminders, study and streak reminders, and occasional messages about new features. You can turn these off; see Section 7B.
- Improve features, performance, and user experience
- Monitor for fraud, abuse, or violations of our Terms of Service
- Comply with legal obligations
We process personal information only where we have a lawful basis to do so, including to provide and operate the Service, to perform a contract with you, to comply with legal obligations, or where processing is based on our legitimate interests and does not override your rights. Where we send you reminders and product updates, our lawful basis is our legitimate interest in helping you get value from a service you signed up for, and you may object at any time by unsubscribing.
3. How We Share Information
A. Service Providers
We share information with third-party service providers that help us operate the Service. They act on our instructions, may access information only as necessary to perform services on our behalf, and are required to protect and process it in accordance with applicable laws.
The providers we rely on, and what each one receives:
- Vercel — hosts our website and runs the code behind it. Receives every request your browser makes to the site, including your IP address, your browser type, and the page you asked for. Its network works out the approximate city and country an IP address is in, which is how we know roughly where the Service is being used without ever asking your device for its location.
- ipapi.co — works out the approximate city and country for an IP address in the small number of cases where our host has not already done so. Receives the IP address and nothing else: no account details, no name, no email address, and none of your study material.
- Google Firebase (Google LLC) — account authentication and our primary database. Receives your account details and the content you save in the Service.
- Google Cloud Storage (Google LLC) — storage of files you upload.
- Google Cloud Vision (Google LLC) — reads text out of images and documents you upload, so they can be turned into notes and study material.
- OpenAI — powers our AI features. Receives the prompts you write, the content you ask us to work with, and material we index so the AI can answer questions about your own documents.
- Cloudflare — converts speech to text for lecture recordings and voice input. Receives the audio you record.
- Stripe — processes payments. Receives billing details directly; we do not store full payment card numbers.
- Resend — delivers the emails we send you. Receives your email address and the contents of those messages, along with whether each one was delivered, bounced, or reported as spam. It does not receive a copy of your account or your study material, and we do not upload our user list to it.
None of these providers are permitted to use your content to train AI models. This list may change as the Service develops, and we will update this policy when it does.
B. Legal and Safety
We may disclose information if required by law or if we believe disclosure is necessary to:
- Comply with legal process
- Enforce our Terms of Service
- Protect the rights, safety, or security of users, the public, or CleverlyAI
C. Business Transfers
If CleverlyAI is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. Information received from Google APIs will not be transferred as part of such a transaction unless we first obtain your explicit consent, as required by the Google API Services User Data Policy.
D. Sale of Personal Information
We do not sell your personal information.
If this changes in the future, we will update this Privacy Policy and provide notice as required by applicable law.
4. Connected Apps & Google User Data
CleverlyAI lets you optionally connect a third-party account from Settings → Connections. Connecting is never required, and the Service works fully without it.
A. Google Calendar
If you choose to connect Google Calendar, the disclosure shown immediately before the Connect button explains the access and AI processing below. Selecting Connect authorizes CleverlyAI to request these Google API scopes:
- https://www.googleapis.com/auth/calendar.readonly — to read the calendars in your Google Calendar list, your Calendar time-zone setting, and existing events on calendars you can access. CleverlyAI uses this information to synchronize dates and times accurately, display Google events alongside your classes, assignments, and study sessions, and let scheduling assistance account for existing commitments.
- https://www.googleapis.com/auth/calendar.events — to view and synchronize event information and to create, update, or delete CleverlyAI events on Google calendars according to the synchronization choices you select. CleverlyAI’s automatic write path updates or deletes only Google events it previously created and linked.
- openid and https://www.googleapis.com/auth/userinfo.email — to identify the Google Account used for the connection and display its email address in Connections.
The Calendar API returns calendar, settings, and event records needed for synchronization. Google may include additional event metadata in an API response; CleverlyAI uses and persists only the fields needed for the connected features. For synchronized events, CleverlyAI stores the event title, description, location, start and end times, all-day status, meeting or conference link, and Google event identifier. We also store the connected Google Account email address, selected calendar identifiers, Calendar time zone, encrypted OAuth access and refresh tokens, synchronization cursors, connection preferences, and sync timestamps. Google Calendar event copies are stored in Google Cloud Firestore. The Google Calendar connection does not request or access Gmail message contents, Google Contacts, or Google Drive files. Gmail is a separate, separately authorized connection described in Section 4.B, and Google Drive is a separate, per-file authorization described in Section 4.C; connecting Google Calendar grants neither. CleverlyAI never requests Google Contacts.
While Google Calendar is connected and its events are synchronized into CleverlyAI, relevant upcoming event details, including titles, descriptions, dates, and times, are automatically included in Lev.E’s workspace context whenever you use Lev.E. Those details may be transferred to and processed by OpenAI solely to generate the response you requested, including when your request is not specifically about your schedule. OpenAI acts as a service provider for this user-facing feature. Disconnecting Google Calendar removes the synchronized Google event copies from CleverlyAI and stops this use. Google Workspace API data is not used to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
We retain the connection information and synchronized event copies while the connection remains active and as needed to provide synchronization. You can stop future access and remove the synchronized copies by disconnecting as described below. You may also request account or personal-data deletion under Section 7.
B. Gmail
Gmail is a separate optional connection with its own authorization. Connecting Google Calendar does not grant it, and connecting Gmail does not grant Calendar access. If you choose to connect Gmail, the disclosure shown immediately before the Connect button explains the access and AI processing below. Selecting Connect authorizes CleverlyAI to request these Google API scopes:
- https://www.googleapis.com/auth/gmail.readonly — to list new messages in the connected mailbox and read their sender, subject, and body text, in order to identify deadlines, assignments, exams, classes, meetings, and invitations that belong on your CleverlyAI calendar. This scope is read-only and cannot send or modify messages. CleverlyAI does not forward, delete, label, or otherwise modify messages in your mailbox.
- https://www.googleapis.com/auth/gmail.send — to send a reply from the connected Gmail account only after you open CleverlyAI’s reply composer, review or edit the message, and explicitly select Just send or Send & add to calendar. Nothing is sent automatically. Replies are sent as plain text in the original email thread and include the signature Sent with CleverlyAI · cleverlyai.com. CleverlyAI does not request permission to create or manage Gmail drafts or to delete, label, or otherwise modify mailbox data.
- openid and https://www.googleapis.com/auth/userinfo.email — to identify the Google Account used for the connection and display its email address in Connections.
Message contents are not stored. Message text is read in memory, used to work out whether the message contains something to do, and discarded. For each message CleverlyAI examines, it stores only: the Gmail message and thread identifiers, the sender name and address, the subject line, the date the message was received, and — where something was found — the proposed title, date, time, location, and one short quoted sentence from the message shown to you as the reason for the suggestion. CleverlyAI does not store message bodies, attachments, recipients, or other headers, and does not download attachments.
What is read. CleverlyAI reads messages that arrive after you connect, reaching back at most fourteen days on the first check. Messages Google classifies as Promotions, Social, or Forums, along with chats and drafts, are excluded. You may further restrict the connection to named senders or domains at any time in Connections, in which case nothing else is read. You can pause reading without disconnecting.
AI processing. The sender, subject, and body text of a message being examined are transferred to and processed by OpenAI solely to determine whether the message contains something to add to your calendar and to extract its title, date, and time. OpenAI acts as a service provider for this user-facing feature. Google user data obtained through this connection is not used to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
What CleverlyAI does with what it finds. Where the extracted item is unambiguous and you have left automatic adding switched on, CleverlyAI creates the corresponding event or task in your CleverlyAI workspace and shows you where it came from. Everything else waits on your home screen for you to accept or reject. Rejecting an item that was added automatically deletes it again.
Outbound replies. When an extracted item can be answered, CleverlyAI may offer editable suggested replies in its reply composer. These suggestions are templates based on the extracted item and are never sent without your action. At the moment you choose to send, CleverlyAI reads the original message’s sender, subject, message identifier, thread identifier, and reply-thread headers solely to address the reply and keep it in the correct conversation. CleverlyAI sends the exact reply text shown in the composer, with the CleverlyAI signature appended by the server. CleverlyAI does not add the reply body or those threading headers to the stored suggestion record. The sent reply remains in the connected Gmail account’s Sent mail and can be managed there like any other message.
We retain the records described above while the connection remains active, and they expire automatically after sixty days. Disconnecting Gmail deletes all records CleverlyAI derived from the mailbox immediately and stops future reading and sending. Messages already sent through Gmail remain in the user’s Gmail account, and events or tasks already added to CleverlyAI remain as the user’s own calendar entries.
C. Google Drive
CleverlyAI does not hold a Google Drive connection. There is nothing to connect and nothing stored: each time you choose From Google Drive in your library, or Save to Drive on a note, mini lesson, flashcard deck or practice test, Google asks you for permission at that moment and issues a short-lived authorization to your browser.
- https://www.googleapis.com/auth/drive.file — to read the specific file you select in the Google Picker, and to create new Google Docs that CleverlyAI itself writes. This scope grants access only to files you select and files the application creates. It does not permit CleverlyAI to list, browse, search, or open any other file in your Google Drive.
The authorization is issued to the web page in your browser and is never transmitted to CleverlyAI’s servers. A file you import is downloaded by your browser and then uploaded to CleverlyAI as an ordinary file, exactly as if you had selected it from your device; CleverlyAI stores that copy as study material and you can delete it from your library at any time. A document you save to Drive is written to your Drive and no copy of the resulting Google Doc is retained by CleverlyAI. CleverlyAI does not store Drive authorizations, Drive file identifiers, or a listing of your Drive contents, and the authorization expires on its own. You can review or withdraw the permission at myaccount.google.com/permissions.
D. Limited Use
CleverlyAI’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the user-facing calendar, mail and file features described above; we do not sell it; we do not use or transfer it for advertising; we do not use it to develop, improve, or train generalized or non-personalized AI/ML models; and humans do not read it except with your explicit consent, for security purposes such as investigating abuse, to comply with applicable law, or on data that has been aggregated and de-identified.
E. Disconnecting
You can disconnect at any time from Settings → Connections, or revoke CleverlyAI’s access directly at myaccount.google.com/permissions. Each connection is disconnected separately. Disconnecting revokes that connection’s access with Google and deletes its stored tokens.
Disconnecting Google Calendar also removes the copies of your Google Calendar events from CleverlyAI. Events you originally created in CleverlyAI remain in CleverlyAI, and any copies already written to your Google Calendar remain yours to keep or delete in Google Calendar.
Disconnecting Gmail deletes every record CleverlyAI derived from your mail, including the stored senders, subject lines, and suggestions. Events and tasks that were already added to your CleverlyAI calendar remain there, as your own entries, and can be deleted individually like any other.
Google Drive has nothing to disconnect, because CleverlyAI holds no standing access to it. Files you imported are ordinary study material in your library and can be deleted there; documents you saved to Drive are yours to keep or delete in Google Drive.
5. AI & User Content
If the Service includes AI-powered features, you may submit content such as prompts or inputs (“User Content”). We process User Content to provide the Service and its functionality.
We may use aggregated or de-identified data to improve performance, reliability, and safety. User Content remains subject to applicable laws and this Privacy Policy.
Our AI features are provided using third-party AI providers, listed in Section 3.A. To answer your questions we send them the relevant User Content — your prompts, and the notes, documents, images, or recordings the request concerns. Some of that content is indexed and stored with our AI provider so the assistant can answer questions about your own material later.
Our AI providers are not permitted to use your content to train AI models, and we do not use your content to train models of our own. Deleting the underlying material in CleverlyAI also removes it from that index.
This section does not expand how we use Google user data. Google user data is handled only as described in Section 4, Connected Apps & Google User Data.
6. Data Retention
We retain information for as long as reasonably necessary to:
- Provide the Service
- Maintain user accounts
- Meet legal, accounting, or security requirements
- Resolve disputes and enforce agreements
You may request deletion of your account as described below.
7. Your Choices & Rights
A. Account Information
You may update certain account information through available account settings.
B. Communications
We email you about things that happen in your account — an assignment due, a deck finished generating, someone sharing work with you — and we send study reminders, streak reminders and occasional notes about new features. We do not sell your email address, rent it, or send you anyone else's advertising.
You can stop any of it in three ways, and you never need to be signed in to do so:
- The unsubscribe link at the bottom of every email. It works in one click and stops that kind of email.
- “Unsubscribe from all”, on the page that link takes you to. This stops every non-essential email at once.
- Your notification settings, where you can choose exactly which messages reach you and by which channel, set quiet hours, and switch email off entirely.
Two kinds of message are sent regardless, because they concern your money or the security of your account: billing notices (renewals, failed payments, plan changes) and security alerts (new sign-ins, password changes). These are not marketing and cannot be switched off while your account is open.
If an email to you permanently bounces, or you report one as spam, we stop sending you email automatically — you do not have to tell us twice.
C. Cookies
You may disable cookies through your browser settings, though some features may not function properly.
D. Access & Deletion
You may request access to or deletion of your personal information by contacting support@cleverlyai.com.
Where required by law, you may have the right to opt out of the sale or sharing of personal information.
8. Security
We use commercially reasonable administrative, technical, and organizational measures to protect personal information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children’s & Students’ Privacy
A. Under 13
CleverlyAI is not intended for children under 13, and we do not knowingly collect personal information from them. This applies whether a child signs up themselves or is added by a school. We ask for a date of birth at signup for this reason. If we learn that we have collected information from a child under 13, we will delete it and close the account.
Where the age of digital consent where you live is higher than 13, we treat that higher age as the minimum instead.
If you believe a child under 13 has given us personal information, contact us at privacy@cleverlyai.com and we will remove it.
B. Students aged 13 to 17
Accounts held by someone under 18 carry extra protections that are on by default and cannot be turned off:
- Other users cannot browse or search for them in an open directory — someone must already know their handle
- They are excluded from cash referral rewards
- They cannot purchase a subscription; a parent, guardian, or school does that instead
- Their email address is never sold, rented, or shared for anyone else's advertising, and the only email they receive from us is about their own account and their own studying
We do not serve advertising, we do not use personal information to build advertising profiles, and we do not sell personal information. We do not use behavioural profiling to keep anyone using the Service longer.
C. What a parent or guardian can see
A parent or guardian who is linked to a student's account can see that student's academic progress — coursework, deadlines, grades, and attendance — to the extent allowed by the scope set when the link was created.
A guardian cannot see the student's notes, uploaded files, or conversations with our AI assistant. Paying for the student's subscription does not change this. Both the student and the guardian can end the link at any time.
D. Schools and districts
Where a school, district, or other institution provides CleverlyAI to its students, the institution directs our handling of student information under a separate written agreement. In that arrangement we act as a school official with a legitimate educational interest under FERPA: we use student information only to provide the Service for the institution's educational purposes, we do not use it for advertising, we do not sell it, and we return or delete it at the institution's request.
Questions about a student record held on a school's behalf should go to the school, which controls that record.
E. Parental rights
A parent or legal guardian may ask us to review, correct, or delete their child's personal information, or ask us to stop collecting it further. Contact privacy@cleverlyai.com. We may need to verify the relationship before acting. Where a school provides the account, we will refer the request to the school.
10. International Users
Our Service may be operated and hosted using cloud infrastructure in multiple jurisdictions. If you access the Service from outside Canada, your information may be processed in countries where our service providers operate. By using the Service, you consent to such processing where permitted by law.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The “Last Updated” date reflects the most recent version. Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
If we propose to access a new type of Google user data or use Google user data for a new purpose, we will provide notice and obtain your consent before that new access or use begins.
12. Contact Us
CLEVERLYAI INC.
7 St Thomas St #402, Toronto, ON M5S 2B7, Canada
Email: support@cleverlyai.com