Sumi

Sumi

Privacy Policy

Effective and last updated: July 19, 2026 · Version 2026-07-19

Your notes are yours. Sumi stores and processes information to provide the study service, does not sell personal information, and does not run ads. This policy explains the details and the choices available to you.

1. Information Sumi collects

Account information: name, email, profile image, provider account identifiers, sign-in sessions, plan, legal-document acceptance, and account status. Sumi does not receive your provider password.

Your work: uploads, extracted text, notes, notebooks, study kits, mind maps, questions, flashcards, planner and class data, review history, progress, collaboration records, shared content, forum posts, feedback, and reports you submit.

Service information: feature usage, AI model and token counts, estimated cost, operational events, error and security logs, timezone, notification preferences, and first-touch campaign information when present. Sumi does not use third-party advertising trackers.

2. Why information is used

  • provide, sync, personalize, export, and secure your account and work;
  • generate the AI-assisted material you request;
  • operate collaboration, school, community, and sharing features;
  • enforce plan limits, prevent abuse, and maintain service reliability;
  • respond to feedback, support requests, reports, and appeals;
  • process billing when paid plans are enabled; and
  • comply with law and protect users, Sumi, and third-party rights.

3. AI processing

When you request an AI feature, the content needed for that request is sent to an API service operated by Google, OpenAI, or Anthropic, depending on the model or feature. Audio, images, and documents may also be extracted or transcribed through those provider services.

Sumi does not use your content to train its own general-purpose model, and Sumi uses these providers only under paid API terms that do not permit training on your content. Avoid submitting information that is unnecessary for your study task.

4. Service providers and disclosure

Sumi uses vendors to provide authentication, hosting, databases, file storage, AI processing, email delivery, and payment processing. Current subprocessors: Vercel (hosting, edge network, file storage), Neon (database), Google Gemini API (paid tier — AI processing), OpenAI API (paid tier — AI processing, when enabled), Anthropic API (paid tier — AI processing, when enabled), your OAuth identity provider (Google, GitHub, or Apple), Resend (email), and, when billing is enabled, Stripe (payments). Each receives only information reasonably needed for its role.

Information may also be disclosed when you direct Sumi to share it, when required by law, or when reasonably necessary to investigate fraud, abuse, security threats, or violations of rights. Sumi does not sell or rent personal information and does not disclose it for targeted advertising.

5. Private, collaborative, and public content

Notes and study content are private by default and selected with owner-scoped database queries. Administrators do not have an ordinary interface for browsing private notes, impersonating users, or reading arbitrary accounts.

When you create a public link, publish to a gallery or school library, invite a collaborator, or post in a forum, the selected information is shown to that audience. Public or shared content may be reported and reviewed by moderators. Revoking access does not erase copies another person already exported, screenshotted, or lawfully forked.

6. Moderation and support access

Moderators can review reports about public or shared kits, forum content, and reviews; remove or delist that content; and suspend or reinstate accounts. Moderation actions are recorded. Report records may include the reporter, reason, affected content identifier, resolution, moderator, and timestamps.

Private content is not a routine customer-support surface. Exceptional direct access should occur only when narrowly necessary for a user-requested support case, security investigation, or legal obligation, with authorization and an audit record.

7. Storage, retention, and deletion

Active account information and work are retained while your account exists. Shorter-lived operational logs, temporary provider files, and cached device copies follow their operational retention periods. Safety, moderation, transaction, and legal records may be retained as reasonably needed to prevent abuse, resolve disputes, and meet legal obligations.

Account deletion removes your active database account and its associated content and initiates deletion of separately stored uploaded and generated files. A provider outage may delay the external-file sweep; limited backups, security logs, moderation records, and legally required records may persist until their retention period expires. Contact support if a public file remains reachable after deletion.

Notebook pages you open may be cached in your browser for offline editing. Browser data remains on that device until the browser, app, or device removes it; signing out does not necessarily erase every local browser cache.

8. Your controls

  • edit account and public-profile fields;
  • choose what to share and revoke active links or collaborators;
  • export your work without upgrading;
  • manage notifications and accessibility preferences;
  • cancel a paid subscription through the billing portal when enabled;
  • appeal moderation at support@sumichi.app; and
  • delete your account.

These account rights remain available when product participation is suspended.

9. Children and students

Sumi is not offered to children under 13, and we do not knowingly create accounts for them. If you believe a child under that age has provided personal information, contact support so the account can be reviewed and removed. School use may require additional agreements and consent before Sumi can support younger students.

10. Security

Sumi uses HTTPS in transit, provider authentication, tenant-scoped data access, and restricted administrative routes. No online service can guarantee absolute security. Report suspected unauthorized access to support@sumichi.app.

11. Changes and contact

Material changes will update the date and version above and may require a new acknowledgment. Questions, privacy requests, copyright/PII reports, or account concerns can be sent to support@sumichi.app.