This policy covers Cerebryx (University & Beyond). For our children's privacy policy, see Privacy (Jr). You can also review our Terms of Service.
Cerebryx
Build your brain, brick by brick
Effective Date: April 20, 2026
Privacy Policy
Welcome to Cerebryx. We're committed to protecting your privacy and ensuring transparency about how we collect, use, and store your data. This Privacy Policy explains our data practices for the Cerebryx app and related services.
Age Notice: Cerebryx is designed for users 18 years and older. If you are under 18, please do not use this app. We have a separate, compliant privacy policy for Cerebryx Jr, our kids' app.
When you ask the AI tutor for help, your question is encrypted and sent to Anthropic's Claude API through a Supabase Edge Function (server-to-server, never directly from your device). The Claude model processes your request and returns an explanation, which we store in your session for context.
What Anthropic Receives
Your question / prompt
The concept you're studying (for context)
Your current mastery level (to adjust explanation depth)
Anonymous session ID (no personal identifiers sent to Anthropic)
What Anthropic Does NOT Do
Does not train future models on your data. Anthropic's default policy excludes all customer inputs from model training
Does not share your prompts with third parties
Does not use your learning data for any purpose other than processing your request
Data Retention by Anthropic
Anthropic may retain prompts for up to 30 days for abuse detection, then deletes them. See their privacy policy for details.
Your AI Usage Quota
Free tier: 3 AI messages per day
Pro tier: Unlimited AI messages
We track token usage server-side to enforce these limits
Your privacy is protected: We never sell, train on, or share your tutor conversations. They're stored securely in Supabase and used only to provide context for your next session.
Data Retention
Data Category
Retention Period
Account data (email, password)
Until account deletion requested
Learning data (mastery, attempts, sessions)
Until account deletion requested (kept for continuity of your learning journey)
Gamification data (XP, streaks, badges)
Until account deletion requested
AI tutor conversations
Until account deletion requested (or 1 year of inactivity)
Diagnostic assessment data
Until account deletion requested
Firebase Analytics (anonymized)
14 months (Google's default retention)
Mixpanel event data
Per Mixpanel's retention policy (typically 5 years)
Push notification tokens
Until you disable notifications or delete account
Server access logs
30 days (security & debugging)
Account Deletion
When you delete your Cerebryx account, we will:
Remove your email, password, and personal identifiers from our database
Anonymize your learning data (so we can't connect it back to you) or delete it entirely per your request
Stop sending push notifications
Revoke your subscription (if applicable)
To request account deletion, email help@cerebryx.ai with your account email address.
Your Rights
You have the right to:
Access Your Data
Request a copy of all personal data we hold about you. Email help@cerebryx.ai with "Data Access Request" in the subject line.
Correct or Update Your Data
Update your email, password, or profile settings directly in the app. If you need changes we can't support, contact us.
Delete Your Data
Request full account deletion at any time. We'll remove your personal information and anonymize your learning data (unless you ask for complete deletion).
Opt Out of Analytics
You can opt out of Firebase Analytics and Mixpanel in the app settings under Privacy & Tracking. This limits our product insights but won't affect your learning experience.
Opt Out of Push Notifications
Disable notifications in your device settings or in the Cerebryx app under Notifications.
Withdraw Consent
If you've given consent for data processing, you can withdraw it by deleting your account or changing app settings.
Response Time: We aim to respond to all privacy requests within 30 days. If we need more time, we'll notify you.
Security
What We Do
Encrypt all data in transit (HTTPS/TLS 1.2+) and at rest (AES-256)
Use bcrypt hashing for passwords (salted, bcrypt cost factor 12)
Implement row-level security (RLS) so users only see their own data
Rate-limit API endpoints to prevent abuse
Audit access logs for suspicious activity
Keep server software and dependencies patched and updated
Do NOT store payment information (delegated to RevenueCat & app stores)
What We Can't Guarantee
No system is 100% secure. While we take extensive precautions, we cannot guarantee absolute safety against determined attackers. If you suspect a security breach, please email help@cerebryx.ai immediately.
Your Responsibility
Keep your password strong and unique
Don't share your login credentials
Sign out on shared devices
Report suspicious account activity immediately
Changes to This Policy
We may update this Privacy Policy as Cerebryx evolves and as laws change. We will:
Post the updated policy at cerebryx.ai/privacy with a new effective date
Notify you in-app if there are material changes (changes that significantly expand data collection or use)
Request your consent if required by law
Your continued use of Cerebryx after policy updates constitutes acceptance of the new terms. If you disagree with changes, please delete your account.
Governing Law
This Privacy Policy is governed by the laws of India. Any dispute arising out of or relating to this policy shall be resolved in accordance with the Arbitration and Conciliation Act, 1996, with the seat and venue of arbitration in Hyderabad, Telangana, India. Users outside India retain all rights and protections afforded to them under their local privacy laws (including GDPR for EU/UK residents and CCPA/CPRA for California residents).
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out: