VignetteStudy
How it worksQuestion typesPricing
Sign inUpload a lecture
On this page
  • 01Information we collect
  • 02How we use it
  • 03Subprocessors
  • 04Data retention & deletion
  • 05Your rights
  • 06Cookies and analytics
  • 07Children's privacy
  • 08Changes to this policy
  • 09Contact
Vignette Study/Privacy

Privacy Policy

Updated May 2026
The 30-second version
  • What you give us: your email, the lecture content you upload, and how you study (which cards you grade, how fast).
  • What we do with it: generate flashcards and assessments for you, schedule reviews, and improve the product in aggregate. We never sell your data and we never use your content to train AI models.
  • Your rights: export everything, delete everything, ask us anything — support@vignettestudy.com.

01Information we collect

We collect the minimum we need to run the service. Three buckets, nothing else:

Account information

Your email address (used to sign in and to send transactional emails like password resets) and a display name if you set one. We do not require a phone number, a real name, or a profile photo.

Content you upload

The lecture files (PDFs, audio, slides, notes), the transcripts we generate from audio, the learning objectives and flashcards the AI extracts, and any edits or personal notes you attach.

Usage telemetry

How you use the app: session counts, review ratings (Again / Hard / Good / Easy), response times per card, device platform, app version, and basic crash diagnostics. We do not attach this telemetry to advertising identifiers or third-party trackers.

02How we use it

We use what you give us to do the thing you signed up for:

  • Generate flashcards, learning objectives, and assessments by sending your uploaded text to Anthropic's API. Your content is processed server-side and is not retained by Anthropic beyond the request.
  • Transcribe audio recordings by sending the audio to OpenAI's Whisper API. We retain the transcript; the audio source is encrypted at rest and deletable at any time.
  • Schedule reviews with the FSRS algorithm based on the grades you give each card.
  • Improve the product using aggregate, de-identified usage data. We look at things like "how often does the 'Generating' step fail?" — never "what is Amelia studying?"

We do not use your content, your transcripts, your cards, or your review history to train any AI model, ours or anyone else's. This is a contractual term with both Anthropic and OpenAI.

03Subprocessors

The vendors below process Vignette Study data on our behalf. Each is bound by a data processing agreement and may only use the data to provide their service to us.

SubprocessorWhat they doWhere
SupabaseAccount auth and primary database. Encrypted at rest.US-east
AnthropicGenerates learning objectives, flashcards, and assessment items via the Claude API.US
OpenAITranscribes audio recordings via the Whisper API.US
VercelHosts the web app and serverless API routes. No content is persisted on Vercel infrastructure.US · EU edge
Apple · GoogleDeliver push notifications to iOS and Android devices. Notification payloads contain no card content.Global

04Data retention & deletion

You can delete your account at any time from /settings/delete-account inside the app. When you do:

  • All account data, content, transcripts, generated cards, and review history are queued for hard deletion immediately.
  • Encrypted backups containing your data are rotated out within a 30-day window, after which no copy of your content remains.
  • Aggregate, de-identified product analytics may persist (e.g. "10,000 lectures were uploaded in March"), since they cannot be reattributed to you.

If you only want to remove a specific lecture or card, you can do that anywhere it appears in the app — deletion is immediate and propagates across your devices.

05Your rights

You have the right to:

  • Access the data we hold about you.
  • Export your cards, decks, and review history in JSON and (where possible) Anki .apkg format.
  • Correct inaccurate account information.
  • Delete your account and all associated content, as described above.
  • Object to processing for any purpose we haven't named in this policy. (There aren't any.)

Most of these are available as self-serve actions inside the app. For anything else — including GDPR and CCPA requests — write to support@vignettestudy.com and we will respond within 30 days.

06Cookies and analytics

The web app uses one first-party cookie to keep you signed in. We do not use third-party advertising cookies, fingerprinting libraries, or session replay tools. Aggregate product analytics are collected via a self-hosted event pipeline that ignores IP and User-Agent.

07Children's privacy

Vignette Study is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has created an account, please contact us and we will delete it.

08Changes to this policy

If we make material changes to this policy, we will notify users by email and surface a banner inside the app at least 14 days before the changes take effect. We keep an archive of previous versions on request.

09Contact

Questions, requests, or concerns about privacy go to support@vignettestudy.com. A human will read your email.

This policy is written in plain English. Where regulators expect specific phrasing — GDPR, CCPA, PIPEDA — please assume those phrasings are incorporated by reference. If something is unclear, that's a bug; tell us and we'll fix it.
PricingTermsPrivacySupport
AI-generated content may contain errors and is not medical advice.