Privacy Policy
This policy explains what Summa (“we”) collects, why, who can see it, and how to delete it. Questions: summacapybara@gmail.com.
The short version
- You sign in with your school (.edu) email address. There's no password: we email you a sign-in link. We don't ask for your real name.
- Your school is set from your email address. Each class room is visible only to signed-in students at that school.
- Students in a room see what you post there (questions, answers, notes, comments) with your display name and clout. Anonymous questions hide your name from other students, but Summa stores who posted them and moderators can see it when reviewing a report.
- Someone who opens a room link without signing in can play the latest class round as a guest (or the round a challenge link is about). For a course's room, the page shows only the course code. The preview card chat apps show for the link adds how many students have joined and the exam countdown (and, on a challenge or shared-rank link, the sharer's display name, rank on that round and score). Guest rounds are deleted after a day unless you sign in and save them.
- Notifications are off unless you turn them on, and then come at most twice a day, only for real events.
- To write quizzes and questions, the text of the notes shared in a room is sent to our AI provider, Anthropic. What you post (questions, answers, comments and note titles) is also sent to Anthropic for an automatic check for harassment, threats and other abuse; a post it flags is hidden until a moderator reviews it. Neither we nor Anthropic use any of it to train AI models.
- We don't sell your data or show ads. Besides the sign-in links you ask for, we send at most one reminder email a day (a new class round in your room, or your exam in 3 days). They're on by default if you're 18 or over and off if you're under 18, and every one has a one-click unsubscribe.
- Summa isn't run by or connected to your school, and we don't share your data with it.
- You can delete your account and everything in it at any time on the Your account page.
What we collect
| What | When | Why |
|---|---|---|
| Your school email address | You sign in | To send you sign-in links and reminder emails (if you get them), and keep your data in one account. Never shown to other students. |
| Your school | Your account is created | To show you your school's class rooms and keep other schools' students out of them. It's set from your email's domain (for example, jhu.edu); nothing else is read from your address. Classmates can tell you're at their school because you're in its rooms, but your school isn't shown on your posts. |
| When you signed in, and the session that keeps you signed in | You sign in | To keep you signed in and protect your account |
| Course code, name, section and exam date (the date is optional) | You open a course's room or set its exam date | To name the room, find it in search and show a countdown to the exam |
| Display name | You set up your account (you can change it later) | To show next to your posts, answers, notes and scores. A nickname is fine. |
| Your age group, the date you agreed to these terms, and (if you're 13 to 17) the date you confirmed a parent or guardian's consent | You set up your account | To keep under-13s out and to record that you agreed |
| Notes and review guides you share: text you type or paste, and files you upload (PDFs and images), with any text we extract from them. We remove location and other hidden details (metadata) from photos before anyone else can open them. | You share notes | To show them to your room and to write quizzes from them. Please don't include personal information. |
| Questions you ask (and whether you asked anonymously), answers and comments you post | You post | To show them in your room. For anonymous questions we store who asked, for moderation only. |
| Upvotes, likes, saves, and which answer you accepted | You use those buttons | To rank answers and notes, show your saved items, and award clout. Classmates see totals, not who liked or upvoted. |
| Your clout: a record of each point you earned, why, and in which room; your badges and tier | Classmates react to your contributions, or you finish rounds | To show your clout, badges and tier next to your name, and to detect gaming (such as students repeatedly liking each other) |
| Reports you make, and moderation decisions about your account or posts | You report something, or a moderator reviews your content | To hide and review content that may break the rules, and to keep a record of what we did and why |
| When you were last active in each room | You use a room | To show real counts like “12 classmates online” (a number only, never who) and to count return visits |
| Your answers, and when each question was shown and answered | You play a round | To score you on our servers (faster correct answers earn more points) |
| A guest round: a random ID kept in your browser, your answers and when you gave them | You play a room's class round before signing in | To score it and let you save it to your account. Guests aren't on any leaderboard. Deleted after a day if you don't save it. If you sign in on a different browser, we ask before saving it. |
| Where to send you after signing in, and which guest round to offer to save | You ask for a sign-in link | So the link works even if it opens in a different browser. Stored with a scrambled code of your email (not the address), deleted after an hour. |
| Challenges you send: the round, your score, and the classmate you picked (if any) | You challenge a classmate | To show your display name and score to whoever opens the challenge link, and to the classmate you picked |
| A notification subscription (a web address and keys from your browser) and when we last notified you | Only if you turn notifications on | To send at most two notifications a day about real events: your question was answered, your notes were liked or used in a quiz, a classmate passed you or challenged you, a new class round, or your exam is close. Turn them off in a room or on Your account. Notification history is deleted after 30 days. |
| Whether your initials may appear on room link previews | Only if you turn it on in Your account (off by default) | To show your initials, instead of “Classmate”, when you're in a room's top 3 |
| Questions you flag | You flag a question | To remove bad questions from everyone's scores |
| A scrambled, one-way code made from your IP address (not the address itself) | You ask for a sign-in email, open a room, post, like, share notes, start a round, play as a guest, or try to sign in to the admin page | To stop abuse and limit costs. Deleted after about 2 days. |
| Usage events: room opened or joined, question or answer posted, answer accepted, notes shared or liked, quiz made or played, round started or finished, first question shown, link opened, copied or shared, “play again”, challenges, clout earned, notification opened, sign-in, returning on a later day, guest score saved, question flagged | Only if you choose “Accept all” or allow analytics in cookie settings, and never if you told us you're 13 to 17 | To understand how Summa is used |
| Anonymous daily totals of those steps, for all of Summa and per room (for example “30 rounds finished today” or “12 visits to this room's link today”) | Always | To see where people get stuck. They hold no account, cookie, device or IP information and can't be linked to you. |
| Totals per room worked out from the records above: how many members were active this week, the share of questions that got answered and how long that took, how many notes were shared, how clout is spread, and how many newcomers joined and took part | Always | To see whether each room is working. Only the person who runs Summa sees them, and only as totals, never who did what. |
Please don't put personal information (yours or anyone else's) in your posts, notes, files or display name.
Who can see your information
Students in your rooms
Only signed-in students at your school can join your school's class rooms. Everyone in a room can see the members' display names, clout, badges, scores and rounds played; everything posted there (questions, answers, comments, notes and review guides, which they can view and download) with the poster's display name; and totals of likes, saves and upvotes. Anonymous questions don't show who asked. Quiz questions show which notes they came from and who shared them. After a round, its questions are shown with short quotes from the notes. Room pages are hidden from search engines.
Moderators
Summa's moderators (for now, the person who runs Summa) can see reported content and posts the automatic check flags, and the author of an anonymous question when they review a report, enforce the Terms, or respond to a legal request. Each time they look, it's logged.
Anyone who sees a room link
When a course room's link is shared in a chat, the chat app's preview shows the course code, how many students have joined and the exam countdown. When you share a challenge or your rank, that link's preview shows the course code and your display name, current rank on that round and score. Someone who opens a room link without signing in sees only the course code (and, on a challenge link, those challenge details) and can play the latest class round as a guest; they don't see names, posts or notes.
Older rooms that were shared by link, rather than made for a course, keep their fuller preview: the room name, the exam countdown, how many people are in the room, how many questions are unanswered, how many played this week, and the top 3. The top 3 are shown as “Classmate” unless a student turned on initials in their account.
Our service providers
- Anthropic (AI provider): receives the text of a room's shared notes and review guides, its topic labels and the text of earlier questions (so they aren't repeated), to write quizzes, questions and topic labels. It also receives the text of each question, answer and comment, and the title and typed text of notes, to check them automatically for harassment, threats, hate, sexual content, personal information, self-harm and spam. Email addresses, display names, account IDs and IP addresses are not sent. Under its commercial terms, Anthropic doesn't use what we send to train its models, and deletes it within 30 days (or keeps it up to 2 years if it's flagged as breaking Anthropic's usage policy).
- Supabase (database, file storage and sign-in): stores the information and files listed above, and runs sign-in.
- Google (Gmail) (email delivery, for now): receives your email address and the sign-in email to deliver it. We plan to move email delivery to Resend, which would receive the same. Reminder emails are sent through Resend: it receives your email address and the reminder (your course code, the round or exam date, and your weakest topic).
- Cloudflare Turnstile (security check): runs on the sign-in page to tell people from bots. It receives technical information about your browser and connection, including your IP address. It doesn't set advertising cookies.
- Vercel (hosting): runs Summa and keeps standard request logs, which include IP addresses and browser details.
- Your browser's push service (for example Apple, Google or Mozilla), only if you turn notifications on: delivers each notification's short text to your device.
Each provider handles data under its own terms and privacy policy. They may store and process data in the United States or other countries. Summa's fonts are served from our own site, so loading a page doesn't contact Google. The sign-in page is the only page that loads anything from another company (the Turnstile check).
Us
Our private dashboard shows, for each room, its course, when it was made, member counts, weekly active students, how many questions are answered and how fast, notes shared, rounds played, share counts and how clout is spread. We use it to understand how Summa is being used, not to market to you.
Nobody else
We don't sell or rent your information, share it for targeted advertising, or use it to train AI models. We may disclose it if the law requires us to, or if we need to protect someone's safety or Summa from fraud or abuse.
If Summa changes hands
If Summa is sold, merged or taken over by someone else, your information would pass to them along with the service. They would have to keep to this policy, and we'd tell you before your information came under a different one, so you could delete your account first.
Your school
Summa is an independent service. It isn't run by, endorsed by or connected to Johns Hopkins, UIUC or any other school, and your school doesn't give us your data. We use your school email only to confirm which school you attend. What you do on Summa isn't part of your school record, and we don't share it with your school, unless the law requires it.
How long we keep it
- An account is deleted automatically, with everything in it, 12 months after its last activity. Activity means signing in, or anything you do in a room: opening it, joining, asking, answering, commenting, liking, upvoting, adding notes or playing.
- A room and everything in it (members, notes, rounds, questions, answers, flags and usage events) is deleted automatically 12 months after its last activity. Activity means someone opening or joining it, asking, answering, commenting, liking, upvoting, adding notes, starting a round or playing.
- Usage events not tied to a room are deleted after 12 months.
- Scrambled IP codes are deleted after about 2 days.
- Guest rounds you don't save are deleted after a day (by the next daily clean-up).
- Sign-in destinations are deleted after an hour, and notification history after 30 days.
- Anything you delete yourself is removed straight away.
- Content a moderator removes is kept hidden for up to 90 days, in case of an appeal or a legal request, then deleted. Reports and the moderation log are kept for 12 months.
Deleted data may remain in our providers' backups and logs until those expire.
Deleting your data
On the Your account page, “Delete my account” permanently removes:
- your account, email address and profile
- the notes, review guides and files you shared, and the questions, answers and comments you posted, including anonymous ones
- your likes, saves, upvotes and clout
- your answers and scores, which takes you off every leaderboard
- your flags and solo practice rounds, including the practice questions written for you
- the challenges you sent, and your notification subscriptions
- your usage events and your place in each room
Class rounds, quizzes and questions already written from a room's notes stay for the other members, because they belong to the whole class (without your name). Reports you made stay in the moderation log without your name. That includes practice questions a classmate has already been given. A room nobody else has joined is deleted completely.
If you can't sign in any more, email summacapybara@gmail.com from your school address and we'll delete your account. We may ask for more details to make sure we're deleting the right person's data.
Your rights
Wherever you live, you can ask us to:
- tell you what information we hold about you and send you a copy in a common file format
- correct information that's wrong (you can change your display name yourself)
- delete your information (you can also do this yourself, as described above)
- stop using your information for analytics (you can also do this yourself in cookie settings)
Email summacapybara@gmail.com from your school address. We'll reply within 30 days, and we may ask for details to confirm it's you. Someone you authorize can ask for you, if they can show you gave them permission. If we turn down a request, we'll say why, and you can reply to ask us to look at it again. We won't treat you differently for asking.
Some US states, including California, give residents the right to opt out of the sale or sharing of their personal information and of targeted advertising. We don't do either, so there's nothing to opt out of. We don't use your information to make automated decisions that have legal or similarly serious effects on you.
Do Not Track and Global Privacy Control
Summa doesn't track you across other websites or let advertisers do so, and usage analytics stay off unless you turn them on. So “Do Not Track” and Global Privacy Control signals from your browser don't change anything on Summa.
If you're outside the United States
Summa is run from the United States, and our providers store data there and in other countries. If you use Summa from the European Economic Area or the United Kingdom, your information is transferred to the United States, which may not protect it in the same way as your country's laws. Our providers protect these transfers with safeguards such as standard contractual clauses.
Under the GDPR and UK GDPR, our legal reasons for using your information are:
- to provide Summa to you (performance of a contract): your account, rooms, posts, notes, rounds, scores, clout and notifications
- our legitimate interests: keeping Summa secure, stopping abuse and limiting costs, moderating content, and anonymous totals of how Summa is used
- your consent: usage events, notifications and initials on link previews. You can withdraw it at any time in cookie settings or on Your account.
- legal obligations: responding to lawful requests and keeping records the law requires
You also have the right to object to or restrict how we use your information, and to complain to your local data protection authority.
Children and teens
Summa is not for children under 13, and we don't knowingly collect their information. If you choose “Under 13” when setting up an account, the account and its email address are deleted straight away. If we learn that a child under 13 has used Summa, we'll delete their data. If you think this has happened, contact summacapybara@gmail.com.
Students aged 13 to 17 need a parent or guardian's consent. They can't post anonymously. For them, we collect only what Summa needs to work and never record usage events.
Security
Only Summa's servers can read the database and stored files; files are shown through links that expire within minutes. Answers are checked and scored and clout is awarded on the server, sign-in links and codes work once and expire after an hour, and the sign-in cookies can't be read by scripts in the page. No system is perfectly secure, so please don't paste anything sensitive.
If a security breach affects your information, we'll email you at your school address and tell the authorities when the law requires it.
Links to other websites
Notes and posts may link to other websites. This policy doesn't cover them, so check their own privacy policies.
Changes
If we change this policy, we'll update the effective date above. If the change matters, we'll ask you to agree again the next time you use Summa.
Contact
Summa is run by one person in the United States, who is responsible for your information under this policy. Email: summacapybara@gmail.com.