Privacy Notice
Last updated August 9, 2026
Who may use Refresh
You must be at least 13 years old to create a Refresh account.
Information Refresh handles
- Your account email and account creation information.
- Notes, PDFs, Word-document text, or images you submit for generation.
- Generated and edited decks, folders, flashcards, practice questions, and answers.
- Flashcard progress, review dates, study days, streak information, and usage counts for generation, tutoring, and AI grading.
- Device-local preferences such as theme and sound settings.
How information is used
Refresh uses this information to authenticate your account, generate study materials, save your library, provide study and progress features, enforce product usage limits, and support account export and deletion.
Uploaded notes and AI processing
The current Refresh code reads uploaded files in your browser and sends the relevant text or file data through a Supabase Edge Function to OpenRouter for AI processing. The current repository does not upload or retain the original source file in a Supabase Storage bucket. Generated decks, cards, and questions are saved only after you choose to save them.
OpenRouter receives the study material and instructions needed for generation, grading, or tutoring. Avoid submitting sensitive personal information or material you are not allowed to use.
Service providers
- Supabase provides authentication, database storage, and Edge Functions.
- OpenRouter processes AI generation, grading, and tutor requests.
- Stripe may process checkout when Refresh’s optional Stripe-hosted payment links are configured. Payment-card details are entered on Stripe’s service, not stored in Refresh’s frontend database.
- Google AdSense code is loaded on Refresh’s landing and app pages. Google may process browser, device, network, cookie, or advertising information according to its own services and settings.
Sharing
Your decks are private by default. If you create a share link, signed-in people with that link can copy the shared deck content. Revoking the link stops later access through that link, but it does not remove copies someone already added to their own account.
Export and deletion
Settings provides a JSON export of your Refresh account content, study progress, and usage. It omits passwords, authentication tokens, billing information, service secrets, and unrelated users’ data.
You can request permanent account deletion from Settings. Paid-plan accounts must resolve subscription cancellation before deletion so external billing cannot continue. Account deletion removes the Supabase Auth account and data connected to it through Refresh’s database relationships.
Your choices
You can edit or delete individual decks, revoke share links, export your data, or request account deletion. For privacy or account questions, use the Support page.