Examo / Privacy

Privacy Policy

Last updated on 10 September 2026

Examo ("Examo", "we", "our", "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect your information when you visit dev.examo.ai, sign up for an account, or use our AI-powered study services.

It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR, the EU ePrivacy Directive, and Singapore's Personal Data Protection Act 2012 ("PDPA").

1. Data Controller

The data controller responsible for your personal data is EXAMO PTE. LTD. (UEN 202424124H). For all privacy-related questions, requests, or to exercise any of the rights described below, use our secure contact page. If you are based in the EU/EEA and believe we are not handling your data lawfully, you also have the right to lodge a complaint with your local supervisory authority.

2. Information We Collect

Account & Identity Data: name, email address, password (hashed), university, programme, and profile preferences you provide during onboarding or in settings.

Payment Data: if you upgrade to a paid plan, billing details (last 4 digits of card, billing country, VAT status, transaction IDs) are processed by our payment provider Stripe. We do not store full card numbers on our servers.

Referral Data: referral codes, referral clicks, signups attributed to a referral link or shared course, course-share attribution details, discount eligibility, commission amounts, manual payout verification status, and payout notes needed to operate the Examo referral programme. Referrers see a server-generated anonymous student identifier and signup/Pro status in their dashboard, not the referred person's email address.

Study Content You Submit: course materials, lecture notes, PDFs, slide decks, essay drafts, AI-tutor chat messages, flashcards, and other content you upload or generate while using the platform.

User-Submitted Content: you are responsible for all content you upload or submit to Examo and for ensuring that you have the rights and lawful authority to use it. Examo does not endorse or assume responsibility for user-submitted content, and you must not upload content that infringes another person's rights or violates applicable law.

Generated Study Files: audio summaries, two-speaker study podcasts, cheat-sheet images, generated study images, and presentation exports are saved so you can access them again. Access depends on your account permissions and the sharing choices for the related course or file.

Loki Browser Extension Data: when you send a tutor message, we process your selected text or useful page text, page title and address, chosen course, and relevant conversation history. Additional tabs are processed only when you explicitly attach them. If you explicitly attach an image of the visible page, we process that image to answer your visual question. When you request browser assistance, we also process information about relevant page controls, excluding password and payment fields.

We use device and login information to secure your extension connection. Files you attach are checked and read to answer your request; temporary copies are deleted after extraction.

If you press the extension microphone, Chrome or your operating system's speech service may process the audio; Examo receives only the resulting message text. The extension does not run an always-on page collector and does not transmit page content merely because it is installed or connected. Page content is stored as course material only when you separately confirm a save or artifact action.

Google Workspace Export Data: if you choose to connect Google Drive, Docs, or Sheets, we store the permissions you granted, connection details and export history to deliver the files you request. Connection credentials are encrypted.

You can disconnect the Google integration from the weekly-review controls inside Course AI; Examo then revokes the grant where the provider allows and deletes its stored connection. The Google connection is account-wide, so disconnecting it affects scheduled exports for every course.

AI Interaction Data: the prompts you send to the AI tutor, the model outputs returned to you, token counts, model selection, request timestamps, and usage metrics needed to enforce rate limits.

Usage & Device Data: IP address (last octet truncated for analytics), browser type, operating system, language, referrer URL, pages viewed, time spent, feature interactions, and approximate location (country level) derived from your IP.

Authenticated Account Activity: when you successfully sign in or return with a valid session, we keep the calendar date and the first and last authenticated time for that day, together with sign-in and session-refresh counts. This daily record does not contain the pages you viewed, study content, prompts, files, or feature clicks. We use it to understand whether accounts return to Examo, measure service retention, and protect account operations.

Learning records: Crash Course answers, grading results, and dated attempts are saved to provide your learning history. Starting again archives the previous attempt instead of deleting it. These records remain with your course/account and are removed when the course or account is deleted, subject to the deletion process below. Administrators can see aggregate feature-use counts without copying your answers into analytics.

First-party learning milestones: to understand whether students find material, return to study, review answers, and reach checkout, we record a limited action name, account identifier, course identifier where relevant, and calendar date. When you cancel a subscription, the reason you chose in the billing flow may also be counted. We do not copy summaries, questions, answers, files, or typed study content into these milestones. They support aggregate Growth & Learning reports for our administrators and are distinct from optional third-party browser analytics and session recordings. Raw milestones are removed after 180 days and with account deletion. Feedback you voluntarily submit may include your rating, reason and written comment; those answers are removed after 12 months.

Optional presentation analytics: with your consent, we record when you open, present, complete or export a presentation to understand how the feature is used. These records include account and presentation identifiers and dates, but no slide content or recordings. Declining analytics does not affect your access. Our retention period is 90 days, with older records removed during routine cleanup. Deleting the presentation or account also removes its analytics records.

Optional product-friction analytics: for consenting adults, we record a limited sequence of product areas opened and actions started, completed or failed, along with broad timing and device categories. We use a temporary pseudonymous session key and do not store your name, email, course name, study content, prompts, answers, typed text or full URL in these events. Raw events are deleted after 30 days. Aggregate counts may be kept longer to compare product performance over time. Declining analytics does not affect your access.

Cookies & Similar Technologies:we use essential cookies to keep you signed in, protect your account and remember your choices. Optional analytics require your consent and confirmation that you are 18 or older. Microsoft Clarity helps us improve usability through heatmaps and masked session recordings of page visits, clicks and scrolling, together with device and browser information. Page text and inputs are masked, and we do not send your name, email address or account identifier to Clarity. You can change your choice at any time in Cookie settings. Google Analytics measures visits to general page and feature categories using cookies and device/browser information. We exclude course names, study content, account identifiers and URL queries from these events and do not enable advertising personalization. Both services are disabled on admin pages. See Section 10 and our Cookie Policy for more information.

Error Diagnostics: we use Sentry to receive technical error reports and identify faults. Reports include error details and information about the affected page and software. Passwords, cookies, study prompts and responses, and contact details are not automatically attached. Diagnostic reports are separate from optional analytics and do not include session recordings.

Communications: messages you send to support, feedback submissions, and survey responses.

3. Lawful Basis for Processing (GDPR Art. 6)

  • Contract (Art. 6(1)(b)): to create and maintain your account, deliver the AI study tools you request, process payments, and provide customer support.
  • Legitimate interests (Art. 6(1)(f)): to detect and prevent abuse, enforce rate limits, secure our infrastructure, debug issues, and improve product reliability and usability. This basis is not used to train or fine-tune machine-learning models on your personal study content. We balance these interests against your rights and freedoms.
  • Consent (Art. 6(1)(a)): for non-essential cookies where required by law, marketing emails, and any optional personalisation. You can withdraw consent at any time without affecting prior processing.
  • Legal obligation (Art. 6(1)(c)): for tax, accounting, fraud-prevention and other statutory requirements.

4. How We Use Your Information

  • Service delivery: generate summaries, smart notes, cheat sheets, flashcards, AI tutor replies, practice questions, and essay assistance.
  • Account management: authentication, password resets, subscription billing, plan upgrades and downgrades.
  • Referral programme: applying referral discounts for the first Pro payment only, attributing signups, new-account course-share attribution and first Pro payments, calculating plan-specific fixed cash rewards, and verifying manual payout eligibility once the minimum withdrawal threshold is met.
  • Rate-limit enforcement: we count tokens, requests, generations and other usage metrics tied to your user ID to enforce the limits associated with your plan (see our Terms & Conditions for current quotas).
  • Safety & abuse prevention: detecting scraping, prompt-injection, payment fraud, account sharing, and academic-misconduct patterns. Account-abuse rules and refund eligibility are explained in our Terms and Conditions.
  • Product improvement: aggregated, often pseudonymised analytics to understand which features work and where users get stuck. Optional browser analytics require your choice; operational error diagnostics and the daily authenticated activity records described above are separate. Examo does not use these records to train AI models.
  • Communications: transactional emails (receipts, password resets, security alerts) and, only with consent, occasional product updates.

We do not use your study content, chat messages, uploaded materials, or generated artifacts to train or fine-tune Examo or third-party machine-learning models. Aggregate operational statistics may be used to improve the product, but they are not training examples and are not intended to identify an individual student.

5. AI Processing & Sub-processors

Examo uses third-party AI providers to power the AI tutor, summaries, smart notes, flashcards, cheat sheets, and essay tools. When you use these features, the relevant prompt and related course context are transmitted to the provider strictly to generate a response. Providers act as sub-processors under written data-processing agreements. Current sub-processors include:

  • Third-party AI providers: process the prompts and relevant study material needed to deliver the feature you request, subject to our restrictions on AI training.
  • Stripe Payments Europe: subscription billing and payment processing.
  • Amazon Web Services / Hetzner: hosting, databases, file storage in the EU.
  • Resend / Postmark: transactional email delivery.
  • Firebase: identity and supporting account infrastructure where configured.
  • Google Workspace APIs: optional Drive, Docs, and Sheets delivery that runs only after you connect Google and grant permission. Access is limited to files Examo creates or that you explicitly open through the integration.
  • Google Analytics: optional website usage analytics for consenting adults. Google processes measurement data as described in How Google uses information from sites that use its services.
  • Microsoft Clarity: optional behaviour analytics for consenting adults, as described in Section 2. Microsoft processes this data under its own privacy statement and Clarity terms, including permitted research and development using non-personal data. We do not use Clarity for advertising tracking. See the Microsoft Privacy Statement and Clarity terms.
  • Sentry (Functional Software, Inc.): technical error monitoring using the diagnostic information described in Section 2. Learn more in the Sentry privacy notice.

We do not train AI models on your content. Examo does not use your uploads, prompts, essays, generated study materials, or other personal data to train, fine-tune, or otherwise improve any machine-learning model. Examo uses business services with data-use restrictions intended to prevent providers from training on submitted content.

For the current list of service providers, processing locations and international transfer safeguards, use our secure contact page.

6. Sharing Your Information

We never sell, rent or trade your personal data. We share data only with:

Sub-processors (see Section 5) under binding data-processing agreements that include EU Standard Contractual Clauses where required.

Universities and programme leaders if you have explicitly enrolled in a course managed by them, and only the data they need to administer that course.

Authorities or legal advisors when required by law, court order, or to protect the rights, safety, and property of Examo or its users.

Successors in the event of a merger, acquisition, or asset sale, in which case we will notify you and give you the option to delete your data.

6.1 Public and Private Course Links

Eligible courses can use a Private link or a Public link. Anyone with a Private link can view and add the course. A Public link also lets anyone find the course online. You can change this setting from your dashboard.

Private links are not listed in search results or Examo's public course directory, but they are not confidential. Anyone who receives the link can forward it, and Examo cannot control onward sharing by recipients. Only share course content you are comfortable making available to anyone who receives the link.

If you enable a Public link, the following information is published on a public web page: the course name and description, its section structure and content counts, the university and programme you associated with the course, and your display name as course creator.

A public page may also include a limited excerpt of course content (a short summary extract and a small number of sample questions). The full course content is not published; it remains available only to signed-in users under the course's normal access rules.

You can make a course private at any time by switching it to a Private link. Its public page will then stop being available.

You can also request removal through our secure contact page. Public links are not available for accounts that told us they are 17 or younger. Anyone can report a public course page (spam, offensive content, copyright, or personal data) using the report option on the page; reported pages are hidden pending review.

7. International Data Transfers

Examo is operated by EXAMO PTE. LTD., a company incorporated in Singapore. We and our sub-processors may process personal data in Singapore, the European Economic Area, the United States, or other countries where the providers supporting the requested service operate.

For transfers subject to the GDPR, we use an applicable safeguard under GDPR Chapter V, such as an adequacy decision or the European Commission's Standard Contractual Clauses (SCCs), together with appropriate supplementary technical and organisational measures. For transfers subject to Singapore's PDPA, we require a standard of protection comparable to the protection provided by the PDPA.

8. Data Retention

  • Account data: retained for as long as your account is active. After account deletion, limited account records may be retained for up to 6 months to handle disputes and refund requests. We do not automatically delete accounts simply because they are inactive. We review continued retention against service, legal and legitimate business needs; account information is not kept indefinitely solely for possible future use. Account owners may instead request deletion through the available privacy controls.
  • Study content (summaries, notes, flashcards): retained while your account is active. You may delete individual items at any time. On account deletion, associated personal study content and user-created course materials are removed or de-identified within 30 days from primary systems and within 90 days from encrypted backups.
  • Content retention review: our current review does not automatically delete courses. An administrator may review and delete selected private courses belonging to free users who have not logged in for six months, while protecting paid, shared, purchased, public, approved and legacy courses. Generated course images are not subject to the saved-source upload expiry period.
  • Product statistics: lifetime course counts, active-day counts and first-payment dates may be retained with your account and included in an account export. These account-linked counters are removed when the account is deleted. Monthly cohort totals without names, email addresses or account identifiers may remain to measure product usage and conversion. Historical totals can be incomplete where records were deleted before these counters were introduced.
  • Growth & Learning records: account-linked, content-free milestone events are kept for up to 180 days. Voluntary quick-feedback ratings, reasons and comments are removed after 12 months; a minimal campaign-response marker may remain with the account so the same prompt is not repeated. Account deletion removes these records.
  • Generated study files: kept with the related account, course or item. Deleting or replacing that item starts the removal of its associated files through our deletion process.
  • Saved course uploads: files saved through Course Builder or Add content are private to the uploader and course. Up to 100 unique files per course can be kept for 60 days from their original upload, with 500 MB of combined storage on Free or 2 GB on Pro. Identical uploads in the same account and course reuse one copy; reuse does not extend expiry. Files and preparation previews are processed to provide the study features you request, not to train AI models. You can delete individual files or all saved files from Saved uploads. Deleted or expired files become unavailable immediately and are queued for physical deletion. Generated study materials remain until you delete them, their course, or your account.
  • Study podcasts: when you request a podcast, the selected summary is processed to create a two-speaker transcript and audio file. The transcript and audio are kept privately with that summary so you can replay or download them. Deleting the summary, course, or account queues the related private audio for deletion.
  • Lecture recordings and transcripts: raw lecture audio is private and is automatically queued for deletion after 24 hours unless a shorter operational period is required. The transcript remains until you delete its lecture source, course, or account. The generated summary is an ordinary course summary and remains until you delete that summary, course, or account. Deletion queues related private audio objects for removal and revokes their access links.
  • Browser-extension clips and artifacts:retained as account-scoped study content until you delete them or your account. Extension access sessions expire and rotate independently from the website session; disconnect, password reset, account-wide logout, or account deletion revokes the applicable extension session.
  • AI tutor conversations: recent context may be retained in your browser to continue the visible conversation. Routine server AI logs are metadata-only and do not intentionally retain full tutor prompts or replies; time-limited incident capture, if enabled, follows the security-log retention and deletion process.
  • Payment records: retained for 7 years to comply with EU/UK tax and accounting law, even if an inactive account is deleted.
  • Server & security logs: retained for 90 days, then deleted or anonymised.
  • Sentry diagnostic events: retained according to the configured project retention limit, then removed by the provider. You can request the current retention period and raise a data-rights request through our secure contact page. Deleting browser cookies does not delete previously submitted diagnostic events.
  • Authenticated account activity: daily first/last authenticated times and sign-in/session counts are retained for up to 24 months and deleted with your account.
  • Marketing preferences: retained until you withdraw consent or unsubscribe.

9. Your Rights Under GDPR

If you are located in the EU, EEA, UK or Switzerland you have the following rights, free of charge, in respect of your personal data:

  • Right of access (Art. 15): a copy of the personal data we hold about you.
  • Right to rectification (Art. 16):correction of inaccurate or incomplete data.
  • Right to erasure / “right to be forgotten” (Art. 17): deletion of your personal data, subject to legal retention obligations.
  • Right to restrict processing (Art. 18):pause processing in defined circumstances.
  • Right to data portability (Art. 20):receive your data in a structured, machine-readable format and have it transmitted to another controller where technically feasible.
  • Right to object (Art. 21): object to processing based on legitimate interests, including profiling.
  • Right not to be subject to automated decision-making (Art. 22): we do not use your data for solely automated decisions producing legal or similarly significant effects on you.
  • Right to withdraw consent: for any processing based on consent, at any time.
  • Right to lodge a complaint: with your local data-protection supervisory authority.

To exercise any of these rights, use our secure contact page. We will respond within one month, as required by Art. 12 GDPR. We may need to verify your identity before acting on a request.

10. Cookies & Tracking Technologies

We use the following categories of cookies:

  • Strictly necessary: session cookies, CSRF tokens, and authentication cookies. These cannot be disabled because the platform will not function without them.
  • Functional: remember your sidebar state, dark mode, language and other preferences.
  • Optional analytics: off unless you choose them in Cookie settings. Google Analytics measures page and feature visits; Microsoft Clarity provides masked session recordings and heatmaps for signed-in users who have confirmed they are 18 or older. We do not enable optional analytics for anyone aged 17 or younger, or whose age has not been confirmed, even with cookie or guardian consent. Withdrawing consent stops further uploads; it does not remove data already received by Google or Microsoft. Contact us for help with a data-rights request.
  • Marketing: no advertising pixel is enabled by the analytics preference. Marketing-email choices are managed separately.

You can adjust your preferences at any time through the public cookie banner, Dashboard Settings when signed in, or your browser settings. More detail is available in our Cookie Policy.

11. Security

We use encryption, protected password storage, access controls and security monitoring to help protect your information from unauthorised access, loss or misuse.

No system is 100% secure; if we become aware of a personal data breach we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by Art. 33 and 34 GDPR.

12. Children

Examo is intended for university students and adults aged 16 and over. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us through our secure contact page and we will delete it.

13. Third-Party Websites

Examo may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to read their privacy policies before providing any personal data.

14. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email and/or by posting a notice in the product at least 14 days before they take effect. The “Last Updated” date at the top of this page indicates when the policy was last revised.

15. Your Rights Under Singapore's PDPA

If Singapore's PDPA applies to the processing of your personal data, you may ask for access to personal data we hold about you and information about how we used or disclosed it during the preceding year.

You may also ask us to correct an error or omission in your personal data and may withdraw consent to our collection, use, or disclosure of your data by giving reasonable notice, subject to legal or contractual restrictions and reasonable consequences that we will explain to you.

To make a PDPA request or complaint, use our secure contact page. We may need to verify your identity before acting on a request. If your concern remains unresolved, you may contact Singapore's Personal Data Protection Commission.

16. Your U.S. State Privacy Rights (California & Others)

If you are a resident of California or another U.S. state with a comprehensive consumer-privacy law (including Virginia, Colorado, Connecticut, and Utah), you have additional rights regarding your personal information. These rights are in addition to, and consistent with, the rights described above.

We do not sell or share your personal information. Examo does not sell your personal information for money, and we do not “share” it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act (CCPA, as amended by the CPRA). We have not done so in the preceding 12 months.

Subject to identity verification and legal exemptions, you may request to:

  • Know and access the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of recipients.
  • Delete personal information we hold about you.
  • Correct inaccurate personal information.
  • Opt out of any sale or sharing of personal information or targeted advertising (we do none of these).
  • Limit the use of sensitive personal information.

To exercise any of these rights, use our secure contact page. You may use an authorised agent to submit a request on your behalf, and we will not discriminate against you for exercising any of your privacy rights.

17. Contact

For all enquiries - including privacy, data subject requests, and security matters - use our secure contact page.

You can manage optional analytics in Cookie settings and contact us at any time about your personal information.