Privacy Policy
Version 1.0 · Effective 1 September 2026
Nooc is a study companion for university students. It is operated by Gur Geron, an Israeli sole trader operating Nooc ("we", "us"), and we are responsible for the personal data described here.
This policy covers the Nooc web app, the Nooc iPad app, and Nooc's public pages.
Questions or privacy requests: gur.geron@gmail.com.
1. In short
- Your uploads, handwriting, conversations, answers, and learning progress are the core of Nooc. We use them to provide your study experience.
- We do not sell personal data, serve advertising, or track you across other apps or websites.
- We do not use your content to train Nooc or our own AI models. Anthropic and OpenAI state that API inputs and outputs are not used for model training by default. Other processors handle content under their own commercial terms and the controls described below.
- We use only the authentication storage needed to keep you signed in; Nooc does not use advertising cookies.
- You can delete your account from Settings.
2. What we collect
2.1 Information you give us
Account information. Your email address, display name, and any university or institution information you provide. If you sign in with Google or Apple, we receive the identity information that provider shares with us. Supabase handles authentication credentials; Nooc does not see your Google or Apple password.
Learning content. This includes:
- course materials you upload, such as slides, exams, notes, textbook extracts, filenames, and your notes about those files;
- text, summaries, questions, exams, topics, and search indexes derived from those materials;
- tutor conversations, attachments, answers, drafts, code, canvas work, and revision history;
- handwriting sent from the iPad app, including page images, pen-stroke data, notebook and page information, and tutor comments;
- generated images and the requests used to produce them; and
- dictation audio sent for transcription. Nooc does not intentionally store the audio after transcription, but the resulting text may become part of your conversation.
Learning assessments. Nooc estimates your understanding of course topics, including a level, confidence, and supporting evidence. These estimates personalize the tutor and dashboard. They are not university grades, are not shared with your institution, and do not produce legal or similarly significant effects.
Support, feedback, referrals, and access requests. We collect what you submit, including an invitee's email address when you use a referral feature.
2.2 Information collected when you use Nooc
Product events. We record allow-listed events such as opening a feature, sending a message, or switching courses. Product-event properties are designed not to include the content of messages, answers, notes, or handwriting.
Diagnostics. The iPad app may report crashes, out-of-memory terminations, app and operating-system versions, device model, memory figures, and limited information about the notebook that was open.
Usage records. For AI requests we record the provider or model, token or usage totals, estimated cost, and the usage deducted from or granted to your account.
Technical logs. Hosting and security logs may include IP address, request time, route, browser or device information, and error details. We may derive a country from an IP address to show a localized Paddle price, but Nooc does not request precise device location.
Billing information. If you start checkout, Paddle collects the billing and payment details needed to complete the purchase. Nooc may receive your Paddle customer, transaction, and subscription identifiers; email; country; currency; totals; purchase status; and entitlement details. Nooc does not receive or store your complete card number or card security code.
3. Why we use it
| Purpose | Data | GDPR basis where applicable |
|---|---|---|
| Create and secure your account | Account and technical information | Contract; legitimate interests |
| Tutor you, process materials, search, transcribe, and generate content | Learning content | Contract |
| Personalize progress and recommendations | Learning content and assessments | Contract |
| Operate paid plans and additional usage | Account, billing, and usage records | Contract; legal obligation |
| Diagnose failures and protect Nooc from abuse | Diagnostics, logs, and usage records | Legitimate interests |
| Understand which product features are useful | Product events | Legitimate interests |
| Respond to support, feedback, and rights requests | Information in the request | Contract; legitimate interests; legal obligation |
| Meet tax, accounting, fraud-prevention, and legal duties | Billing and account records | Legal obligation; legitimate interests |
Where Israeli privacy law applies, we process data to provide the Service you request, based on your agreement and other lawful grounds available to us.
We do not use learning content for advertising or sell it to data brokers.
4. Who receives it
We disclose data only where needed to provide Nooc, complete a purchase, protect the Service, or comply with law.
| Provider | Role | Typical data received |
|---|---|---|
| Vercel | Web hosting and delivery | Web requests and server logs |
| Supabase | Database, authentication, and file storage | Account information, learning content, and uploaded files |
| Anthropic | Tutor and course-processing AI | Relevant conversations, instructions, and course material |
| OpenAI | Transcription and image generation | Dictation audio or image-generation requests |
| Voyage AI | Search embeddings | Extracts of course material sent to create search vectors |
| Google sign-in and email delivery | Sign-in identity or message recipient information | |
| Apple | Apple sign-in, iPad distribution, and platform diagnostics | Apple identity token and information Apple collects through its platform |
| Mermaid Chart | Diagram rendering when requested | Diagram source text |
| Paddle | Merchant of record, checkout, tax, fraud prevention, and billing support | Account, checkout, transaction, subscription, and payment information |
Anthropic and OpenAI state that their API services do not use customer inputs or outputs for model training by default. Voyage AI offers a dashboard opt-out from storing and using API content for future model training; Nooc must keep that opt-out enabled before sending learner content. Provider security or abuse-monitoring logs may be retained under provider terms even after Nooc deletes its active copy.
We may also disclose information to comply with a binding legal request, protect rights or safety, or establish or defend a legal claim. If Nooc is transferred as part of a merger, financing, or sale, data may transfer with the Service; we will give notice where required.
Course library. Nooc does not publish a student-created course or its uploaded materials to other students without first obtaining permission. Conversations, answers, handwriting, notes, and progress are not shared through the course library.
5. International processing
Nooc is operated from Israel. Nooc's primary Supabase project data is stored in eu-central-1 (Frankfurt, Germany). Other providers may process data in the United States, Europe, Israel, and other locations where they or their subprocessors operate.
Where transfer law requires it, we rely on an applicable adequacy decision, contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism. You may ask for more information at gur.geron@gmail.com.
6. Retention and deletion
We keep account and learning content while your account is open so Nooc can preserve course continuity and progress.
- Course deletion removes the course and its active materials and learning records from Nooc. Limited copies may remain temporarily in backups, security logs, or processor systems until their normal deletion cycle ends.
- Account deletion is available in Settings and removes the account and associated active learning content. We may retain limited billing, fraud-prevention, dispute, tax, security, or legal records where required or reasonably necessary.
- Product events and diagnostics are kept only while reasonably needed to understand feature use, investigate reliability, protect the Service, and meet legal obligations. We periodically review whether identifiable records are still needed.
- Paddle and financial records are retained according to Paddle's obligations and any tax, accounting, dispute, or fraud-prevention period that applies.
- Provider copies follow each provider's retention and security rules. Standard Anthropic and OpenAI API safety logs may be retained for up to 30 days, subject to exceptions in their terms. Voyage AI content sent after its training/storage opt-out is enabled is described by Voyage AI as having zero-day retention.
- On-device notebooks that you have not sent to Nooc remain on your iPad and are removed when you delete them or remove the app, subject to your own device backups.
We may retain statistics that have been irreversibly aggregated or de-identified so they no longer identify a student.
7. Your rights and choices
Depending on where you live, you may ask us to:
- access and receive a copy of your personal data;
- correct inaccurate information;
- delete data or your account;
- provide portable data where applicable;
- restrict or object to particular processing; or
- withdraw consent where processing relies on consent.
Email gur.geron@gmail.com from the address associated with your account. We may need to verify your identity. We aim to respond within 30 days, or within another period the applicable law allows.
You may complain to the Israeli Privacy Protection Authority or, where applicable, your local data-protection authority.
8. Security
Nooc uses encrypted connections, provider encryption at rest, access controls, and separation between product-event data and learning content. The iPad stores its sign-in session in the iOS Keychain. Access to production data is limited to people who need it to operate or secure Nooc.
No system can be guaranteed perfectly secure. We will notify affected people and authorities of a personal-data breach where the law requires it.
9. Cookies and similar storage
Nooc uses authentication cookies or local storage needed to sign you in, keep the Service secure, and remember essential preferences. We do not use advertising cookies or cross-site tracking technology.
10. Age
Nooc is for university students. You must be at least 18 to use Nooc. We do not knowingly create accounts for children. Contact gur.geron@gmail.com if you believe a minor is using Nooc.
11. Changes
We may update this policy. The version and effective date at the top identify the current text. We will give notice before a material change takes effect where required, and request consent where the law requires consent. Previous versions are available on request.
12. Contact
Controller: Gur Geron, an Israeli sole trader operating Nooc, Israel
Privacy and support: gur.geron@gmail.com