Kematra

Privacy Policy

What Kematra holds about you, why, who else sees it, and how to get rid of it.

In effect from 2026-08-01.

This policy covers Kematra, operated by James Paas as a sole trader. It took effect on 2026-08-01.

Kematra is used by people who may be young, so it is built to hold as little as it can. There is no advertising and no tracking script anywhere in Kematra, no analytics service of any kind, and nothing follows you between sites. We do count how far people get — how many created a subject, opened a task, recorded a result, were still studying two weeks later — but those are counts on our own servers, worked out from what your account already records. They reach no third party, they are never about you individually, and they go when your account goes. One third-party script does run on every page, including before you answer the age question: an error reporter that tells us when something breaks. It is set up to collect no personal details, no performance tracing and no profile of you — it reports the fault, not the person. We do not sell your data and we do not advertise to you.

What we collect

To have an account: your email address, a password (stored only as a cryptographic hash — we cannot read it), your timezone, and your email preferences. If you sign in with Google we receive your verified email address and Google's own account identifier for you — a long number that lets us recognise you next time you sign in. We keep both. We do not receive your name, your profile picture or anything else from your Google account, because we do not ask for them.

We do not ask for your name, your date of birth, your school, your address, or your phone number. We ask whether you are 13 or older, and we record only the answer.

To plan your studying: your subjects, topics, goals, tests and exams, your available study time, and what you record about how each session went. This is the bulk of what Kematra holds, and the table below sets out each kind of it.

For security: a shortened form of your IP address, used to rate-limit sign-in attempts and to detect abuse, kept for 30 days. Shortened means the last part is removed, so it identifies a rough area rather than a connection.

If you subscribe: Stripe collects your billing details and card. We receive a record of what you subscribed to and when, and never your card number.

Before you have an account

You can try Kematra without signing up. We create an anonymous session — a random identifier in a cookie, valid for 7 days — and it holds only what you enter. There is no account and no email address. The session itself holds nothing that names you; separately, our servers record a shortened form of your IP address to stop one connection creating sessions in bulk, in the same way and for the same reason as described above.

The age question comes first, before anything is saved. If you answer that you are under 13, we delete the session record straight away rather than remembering that a refusal happened. We do not fingerprint devices, so nothing stops you from coming back.

Your text, category by category

Different kinds of text get treated differently, and rather than a single sweeping promise this table says exactly how. Two lines matter most. Your private notes are never sent to an AI model. And material you upload is read by a model — that is how the text comes off the page — with what it read shown to you to check before anything is derived from it.

How each kind of text you enter is used, retained and accessed
Kind of textWhat it isWhy we hold itSent to an AI model?Kept forWho can read it
Your private notesThe optional note you can leave on an assessment result, and any note you write to yourself about a topic.Yours to look back on. Kematra never calculates anything from these — they are not scored, ranked, or fed into your plan.NeverUntil you delete the note, or delete your account.You. Support staff cannot read it without asking you and receiving a time-limited grant, which is recorded.
Subject and topic names, and your goalWhat you called your subject, the topics you added or confirmed, and the goal you wrote in your own words.The plan is built from these. Your goal sets the scope of what Kematra tries to cover.Yes, for the feature that needs itWhile your account exists.You, and support staff under a recorded, time-limited grant.
Material you uploadA photo or PDF of a worksheet, past paper, or page of your notes.To read the text off it and offer you the topics it names. The model reads the file first — that is what reading it means — and what it read is then shown to you to check. Nothing reaches your plan until you confirm it.Yes, for the feature that needs itThe file itself is deleted as soon as the text has been read. The text stays until you delete it or your account.You, and support staff under a recorded, time-limited grant.
Your resultsWhat you scored, whether you passed a check, how confident the result was, and how long a session took.This is what makes the plan adapt. It drives what comes next and when a topic is due again.NeverWhile your account exists. Included in an export.You, and support staff under a recorded, time-limited grant.
Weak-area notesThe optional note explaining what specifically is hard about a topic.To make the task instructions for that topic more useful.Yes, for the feature that needs itUntil you clear the note, or delete your account.You, and support staff under a recorded, time-limited grant.
Your account detailsYour email address, your timezone, and your email preferences.To sign you in, and to send only what you have asked for.NeverWhile your account exists. Your email address is also held by Stripe if you have subscribed, and by Resend when a message is sent.You, and support staff for account issues.

AI, and where your text goes

Some features use an AI model run by Anthropic. Only what a feature needs is sent, and the table above says which categories that includes.

Anthropic's API terms provide that what we send is not used to train their models. Nothing you write is used to train any model by us either.

A model can be wrong, so nothing it produces is applied silently: an upload's text is shown to you to check before anything is derived from it, topics arrive as a list you tick, and confidence is labelled honestly rather than rounded up. To be exact about the order, because it is easy to imply otherwise: the model reads your file first, and your confirmation decides what happens to what it read — not whether it was read.

Who else sees your data

Kematra runs on other companies' infrastructure, and some of your data necessarily reaches them. This table names every one of them, what actually reaches them, and how long it stays.

We disclose the retention we control as a figure, and say when the retention is the processor's to decide rather than inventing a number for someone else's system.

Other companies that process your data, and what reaches them
CompanyWhat they do for usWhat reaches themWhereHow long they keep it
NeonThe database. Everything Kematra remembers about your studying.Your account details, subjects, topics, plan, results, and history — all of it.United States (AWS us-east-2).Held while your account exists. Deleted when you delete your account, on the schedule in the erasure section below. Point-in-time recovery keeps 6 hours.
VercelRuns the website and the servers behind it.The ordinary record of a web request: which page, when, and your IP address. Vercel is the front door, so your full address reaches them before any of our code runs — the shortening we do protects our own database, and cannot reach their logs. No study content is written to these logs.United States, with a global edge network serving the pages.Short-lived operational logs, kept by Vercel under their terms.
StripeTakes payments and holds your card details.Your email address, billing address, and what you subscribed to. Your card number goes straight from your browser to Stripe and never reaches Kematra — we could not show it to you if we wanted to.United States, with global processing.Stripe keeps payment records for as long as financial law requires them to, independently of your Kematra account. We keep our own record of your subscription for the same reason — see the erasure section.
GoogleSigning in, if you chose "Continue with Google" rather than a password.The sign-in request itself. Google tells us your verified email address and its own account identifier for you, and nothing else — not your name, not your profile picture, not your contacts, because we do not ask for them. If you signed up with a password instead, Google is not involved at all.United States, with global processing.Google keeps its own record of the sign-in under their terms. We keep your email address and Google's account identifier for you, so that signing in again finds the same account.
ResendSends the emails Kematra sends you.Your email address and the message itself. Kematra does not put your study material into emails — with one exception you control: if you set up a reminder, the words you typed into it are sent to you by email, so they reach Resend too. Nothing else about your studying does.United States.Delivery records kept by Resend under their terms.
Cloudflare R2Holds a photo or PDF you upload, briefly, while it is read.The file itself, exactly as you uploaded it.Cloudflare's global network.Deleted immediately after the text is read — on success and on failure alike — with a 24-hour rule on the storage bucket as a backstop in case that delete does not happen. The file is never copied anywhere else.
AnthropicThe AI model that reads uploaded documents and writes tailored task instructions.Only what the feature needs: the pages of a document you uploaded, or the name of a topic and the method being used. Which of your text is ever sent to a model, and which never is, is set out in the table above — your private notes are not.United States.Inputs and outputs are deleted within 30 days under Anthropic's standard terms, subject to the exceptions those terms state. Anthropic's API terms provide that inputs are not used to train their models.
Brave SearchFinds candidate study resources for a topic.A search query built from the topic name and your subject — for example "Indices and Surds Year 10 Mathematics". Nothing that identifies you is sent.United States.Query logs kept by Brave under their terms.
SentryTells us when something breaks, so it can be fixed.The technical details of an error, from our servers and from your browser — the reporter runs on the page, so it is active from the first page you open. Request bodies, cookies, headers and any user identity are removed before anything is sent, and performance tracing is switched off entirely. Study content is not sent.United States.In line with our error-monitoring provider's standard retention.
InngestQueues the background work that reads an upload or prepares a task ahead of time.Identifiers only — which account and which task a job is for. No study content travels in a job.United States.Job history kept by Inngest under their terms.

Emails we send

Some emails are part of having an account and cannot be turned off: verifying your address, resetting your password, payment receipts and payment problems, and anything about your account being deleted.

Everything else is optional and controlled from Settings: reminders you set up yourself, and occasional messages about your studying. You can turn those off without affecting your account.

We do not put your study material into emails. There is one exception, and it is yours: a reminder you set up is sent to you with the words you typed into it, so those words reach our email provider. If you would rather they did not, delete the reminder — nothing else about what you are studying is ever emailed.

A reminder's subject line never says what the reminder is about, so a notification on a locked screen shows only that one arrived.

Getting your data out

You can export everything from Settings, at any time, as a file. It includes your raw results — the individual records, not a summary — because a summary is our interpretation and the records are your data.

Deleting your account

You can delete your account from Settings. It is staged deliberately: for 30 days it is recoverable, because people change their minds and because an account deleted by accident is a lot to lose. During that window your account keeps working normally — you can sign in, your plan still updates, and if you had paid for time you have not used you keep it. Deleting is a decision with a waiting period, not a lock on the door. After the 30 days, erasure runs and cannot be undone.

If you would rather not wait, there is an immediate-erasure option with its own confirmation. It does the same thing, now.

Our erasure guarantee: your data is purged from the live DB at erasure; aged out of all backups within 30 days.

A small amount has to be kept, and it is worth being specific about what:

Everything else — your subjects, topics, plan, results, history, notes, reminders and uploads — is erased. If you had paid for time you had not used, that entitlement is honoured through the deletion process rather than being cancelled along with it.

If you stop using Kematra entirely, we email you and then take the same path after 24 months of inactivity, rather than holding your data indefinitely.

How it is protected

Traffic is encrypted in transit and the database is encrypted at rest. Separation between accounts is enforced by the database itself and not only by our code, so on the paths that serve your requests a bug in the application cannot hand your data to someone else — the database refuses it. A small number of internal paths run with wider access because they have to: signing you up, receiving a payment notice, running a background job, an administrator acting on a support request, and erasure. Those are held to review and audit rather than to the database's own refusal, and we would rather say so than imply a guarantee that covers everything.

Records of your results are append-only, enforced by the database rather than by our good intentions: an attempt to change one is rejected outright, and a correction is added alongside rather than written over the top. We hold the database credentials that could remove that protection, so it is not a promise that no one could ever alter a record — it is a guarantee that nothing in the running service can, and that doing so would require a deliberate act against our own database. Support staff cannot read your study content by default. Doing so requires you to grant access, the grant is time-limited, and the fact that it happened is recorded permanently.

Error reports have request bodies stripped and personal details filtered before they are sent, and no study content is written to any log.

Where your data is

Kematra's servers and database are in the United States, as are most of the services listed above. Using Kematra means your data is transferred to and stored in the United States and handled under the terms of those providers.

Your rights, and complaints

You can see what we hold (export), correct it (edit it in the app), and delete it (Settings). If you want something we do not offer a button for, email us and ask.

Privacy questions and requests: legal@kematra.com. If you are in Australia and are not satisfied with how we have handled a privacy matter, you can complain to the Office of the Australian Information Commissioner.

Changes to this policy

We will post changes here with a new effective date, and email you before any change that materially affects how your data is handled.