Privacy Policy
Effective date: 3 August 2026
Top of Class (“the app”, “we”, “our”) is an iOS spaced-repetition study app. You build a library of flashcards — by hand, by importing an Anki deck, or by having our AI assistant (“Atlas”) turn material you provide into atomic cards — and review them over time. The app is local-first: study happens from a library stored on your device, and you can enable sync to keep an account-linked copy available across your devices.
This policy describes what information we collect, how we use it, and what choices you have. We try to keep it short and plain. If anything here is unclear, email hello@topofclass.app and we’ll explain.
TL;DR
- Your library is stored on your device. If you enable sync, an account-linked copy of your decks, cards, review history, scheduling state, and media is also stored by our backend so it can follow you across devices and personalize scheduling.
- When you use the AI to generate or rewrite cards, the material you submit is sent to our backend and on to our AI provider to produce the cards, then returned to you. It is not retained as a separate AI request by us afterwards. Generated cards become part of your library and may be stored by sync.
- You sign in through Clerk. Depending on the method you choose, Clerk may provide us with an account identifier, name, and email address.
- Subscriptions are handled by Apple and RevenueCat.
- We do not run ads, add product-analytics SDKs, or do any cross-app tracking. Service providers may collect limited operational and security telemetry when they deliver their service.
- We do not sell your data.
- You can delete your account and its server-side data from inside the app, or contact us for help.
1. Who is responsible
The “data controller” (in GDPR terms) is the developer of Top of Class:
- Ossian Hempel
- Contact: hello@topofclass.app
2. What we collect
Top of Class collects the following information, and only this:
| Data | Why | Where it lives |
|---|---|---|
| An anonymous device identifier (a random ID we generate on first launch, kept in your iCloud Keychain) | Metering free AI usage and matching your device to your subscription | Your iCloud Keychain, and our backend (Convex) |
| Account identifiers from Clerk and, when you use Sign in with Apple, Apple’s stable user identifier | Recognising you on subsequent sign-ins and across devices | Convex (our backend) |
| Name and email address, when provided through your chosen sign-in method | Showing your account and supporting account requests | Clerk; the display name may also be stored in Convex |
| The material you submit to the AI (a topic, pasted notes, or the text of a card you ask Atlas to rewrite) | Generating or rewriting flashcards on your request | Processed in transit by our backend and our AI provider (OpenRouter); the resulting cards are returned to your device. Not retained as a separate AI request by us. Generated or rewritten cards may later be stored as part of your synced library. |
| A monthly count of how many AI generations you’ve run | Enforcing free-tier limits and unlocking unlimited generation for Scholar members | Convex |
| Subscription / purchase status (if you become a Scholar) | Unlocking Scholar features and restoring purchases on a new device | RevenueCat; receipts validated by Apple StoreKit |
| Technical request data, such as IP address, device or browser details, timestamps, and security or error metadata | Delivering network requests, preventing abuse, authenticating sessions, and keeping the service reliable | Processed by the relevant service provider, including Clerk, Convex, OpenRouter, and RevenueCat |
| Your library (decks, cards, review history, media, and any Anki deck you import) | Studying locally and, when sync is enabled, carrying your library across devices, protecting it from device loss, and personalizing your review schedule | On your device; also in Convex and Convex file storage while sync is enabled. Imported review history may be staged briefly while we prepare a personalized scheduling model. |
We do not request access to your contacts or location, access your photo library beyond files you explicitly choose, use the advertising identifier, or track your activity across other companies’ apps and websites.
3. How the AI feature handles your material
When you ask Atlas to generate cards from some material, or to rewrite an existing card, that text is sent over an encrypted connection to our backend and then to OpenRouter, which routes it to a large-language-model provider (by default OpenAI’s gpt-4o-mini) to produce the cards. The finished cards are returned to your device and saved into your local library.
We do not retain the material you submit as a separate AI request after the response is returned. Generated cards are saved to your local library and, if sync is enabled, its server-side copy. Please don’t paste highly sensitive personal, health, or financial information into the AI generator — treat it like any other AI tool. The AI material is also processed under OpenRouter’s and the selected model provider’s terms. Their retention and model-training practices vary by endpoint; do not submit material you are not comfortable sending to those providers.
4. How we use it
We use the data only to:
- Sign you in and keep you signed in through the authentication method you choose
- Generate and rewrite flashcards when you ask
- Meter free AI usage and honour your Scholar subscription across devices
- Sync the library when you enable sync and use review evidence to fit and distribute your personalized spaced-repetition model
- Reply to you if you contact us for support
We do not use your data for advertising, profiling, training generative AI models, or any purpose unrelated to running the app. Personalizing your spaced-repetition schedule is part of the app’s core functionality, not advertising profiling.
We process account, sync, and subscription data because it is necessary to provide the service you request. We process AI material when you ask us to generate or rewrite cards. Security, abuse prevention, and basic operational records are processed for our legitimate interest in running a reliable service and protecting it from misuse.
5. Sub-processors
We rely on a small set of services to run the app. They process your data on our behalf:
| Service | What they do | Where they store data |
|---|---|---|
| Clerk | Provides account authentication and the sign-in methods shown in the app | United States and other locations described in Clerk’s legal terms |
| Apple (Sign in with Apple, StoreKit) | Authenticates you with your Apple ID and processes your subscription purchase | Apple’s global infrastructure |
| Convex | Our backend: stores account and device records, usage and subscription state, the synced library and media, and the data and model state needed for personalized scheduling | The region configured for our Convex deployment |
| OpenRouter (and the model provider it routes to, e.g. OpenAI) | Runs the AI that turns the material you submit into flashcards. Receives that material without your Top of Class account record; provider-side technical metadata and data practices still apply | United States or another provider processing location |
| RevenueCat | Manages subscription state and validates App Store receipts | Locations described in RevenueCat’s legal terms |
We do not share your data with any other third parties.
6. Where your data is stored, and international transfers
Account and service records, and your library while sync is enabled, are stored in the region configured for our Convex deployment and are processed by the providers listed above. AI material is processed by OpenRouter and the selected model provider. If you are in the EU/EEA/UK, your data may be transferred outside your country, including to the United States. Where required, these transfers rely on provider safeguards such as an adequacy framework or standard contractual clauses.
7. How long we keep it
- The device link, usage counter, synced library, scheduling model, and operational sync records are kept while your account and the related service are active.
- The user record is kept for as long as your account exists.
- We do not persist a separate copy of AI request material in Convex after the response. OpenRouter and model-provider retention varies by endpoint and is governed by their policies.
- If you delete your account (see below), we immediately disable it and start a background deletion of its active server-side records and synced media.
- Residual copies in provider backups expire according to each sub-processor’s backup and retention schedule.
- Apple and RevenueCat retain receipts and minimal billing records for up to 7 years where required for tax/legal reasons.
8. Your rights
Wherever you live, you can ask us to:
- Access the data we hold about you
- Correct anything that’s wrong
- Delete your account and all associated data
- Object to or restrict how we use your data
If you are in the EU/EEA/UK (GDPR), Switzerland (FADP), California (CCPA/CPRA), or India (DPDP), you have these rights by law. You can also lodge a complaint with your local data protection authority — but we’d much prefer you write to us first so we can fix things.
To exercise any right, email hello@topofclass.app from the address tied to your account. We respond within 30 days.
We do not sell or share personal information for cross-context behavioural advertising. There is nothing for you to “opt out” of in that sense.
9. Account deletion
You can delete your account in the app:
- Open You → Account, choose Delete account, and confirm. You can also email hello@topofclass.app for help.
Deletion revokes active sessions and removes the account, synced library, media, review evidence, scheduling models, agent access, device links, usage records, and entitlement mirrors from our active systems. The local library on a device is not erased by server-side account deletion; uninstalling the app removes that device’s local copy. Apple and billing providers may retain transaction records where legally required.
10. Security
- All traffic between the app and our servers is over HTTPS/TLS.
- Authentication is provided through Clerk. Our backend verifies the Clerk session and mints its own revocable session token. We never see the password or Apple ID credentials used with your sign-in provider.
- Our AI provider’s API key lives only on our backend, never in the app.
- Our sub-processors maintain their own security programs and controls.
No system is perfect. If we ever discover a breach affecting your data, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR.
11. Children
Top of Class is not directed at children under 13 (or under 16 in some EU countries). We do not knowingly collect personal information from children. If you believe a child has signed up, email us and we will delete the account.
12. Changes to this policy
We may update this policy as the app evolves. The “Effective date” at the top will change. For material changes (new data types, new sub-processors), we’ll notify you in the app before the change takes effect.
13. Contact
Questions, requests, complaints, or just hello:
We reply to everything from a real person.