This Privacy Policy explains how AXS Group Inc, a California corporation that operates Preplet ("Preplet," "we," "us," or "our"), collects, uses, and discloses your information when you use the Services. Preplet is available as a web application at preplet.ai and as a mobile app for iOS and Android, and a single Preplet account works across all of them. Paid subscriptions may be purchased either inside the mobile app - through Apple's In-App Purchase on iOS or Google Play Billing on Android - or on the web at preplet.ai.
1. Information We Collect
We may collect information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you ("Personal Information") when you use our Services. The Personal Information we collect falls into three categories: (1) information you provide to us, (2) information we collect through automated methods, and (3) information we collect from other sources.
How Study Content Is Stored and Synced
The primary copy of your personal study content (submitted text, generated quizzes, flashcards, notes, transcripts, audio recordings, and related materials) is stored on the device you created it on. Preplet keeps an archived backup copy of that content on our servers solely so that you can recover it if your device is lost, damaged, replaced, or restored. This backup copy is tied to your authenticated account and is used only for recovery — it is not the primary store of your content, and in day-to-day use the app reads and writes content directly on your device.
CoWork content is the one exception. Because CoWork Sessions are inherently multi-user, any content you post or share into a CoWork group — group sessions, shared flashcards and notes, chat messages, Board edits, activity feed entries, scheduled events, and shared voice transcripts — is stored on our servers (via Google Firebase Cloud Firestore) so that every member of that group can see it. CoWork content and personal content are kept separate in our storage.
Please exercise caution and do not submit sensitive personal information such as health or medical data, Social Security numbers, financial account details, passwords, or private information about other people to the Services. When you use AI-powered features, the text, photographs, documents (including PDF and Word files), and audio recordings you submit — together with your app language setting — are transmitted to Preplet’s servers and passed to Google for processing, as described in Section 3.
Information You Provide to Us
We collect Personal Information that you provide directly to us in the following ways:
Account Registration: When you register for an account, we collect your display name, email address, and birth month and year. If you choose to sign in with your Google account or Apple account, the authentication is handled by Google or Apple respectively. We do not receive or store your Google or Apple account passwords. We receive only your name, email address, and confirmation that your identity was verified by the provider.
Onboarding Information: During account setup, we collect your birth month and year (required, used for age verification and age-based data-collection rules). You may also provide your grade level and expected graduation year.
Subscription Information: If you purchase a subscription, we collect information related to your subscription status, plan type, and billing period. There are two purchase paths, and they involve different companies. In-app purchases: if you subscribe inside the Preplet app on iOS or Android, the transaction is processed by Apple's In-App Purchase or by Google Play Billing. Apple or Google is the seller of record for that transaction; Preplet receives only the resulting entitlement information (the product purchased, the purchase, renewal and expiration dates, and a store purchase identifier). We never see or store your payment card details, and Apple and Google do not share your payment method with us. We use RevenueCat, Inc. as our subscription infrastructure provider to validate app store receipts and relay subscription events to our servers; RevenueCat receives your Preplet user identifier and your purchase and entitlement data, and no study content. Web purchases: if you subscribe on the web at preplet.ai, payment card information is processed by Stripe, a PCI-DSS Level 1 certified payment processor. For redundancy, if our primary processor is unavailable we may automatically route the transaction to a backup PCI-compliant payment processor. Preplet does not store your full card number — card details are handled directly by our payment processor(s). In every case we verify your subscription status server-side and store the verified state in your user record.
Study Content: When you create or upload study materials — whether typed text, imported documents, photographs of textbooks or whiteboards, audio recordings, or uploaded audio files — the working copy of that content lives on your device. Preplet writes an encrypted archived backup copy to our servers so that you can restore your content if your device is lost or replaced. Audio files are converted on your device before any upload to the AI provider; WAV files are not accepted because of file size. Preplet also runs optical character recognition on your device to read text out of photographs. This on-device step does not replace sending the file: when you ask Preplet to build study materials from a photograph, a document, or an audio recording, the file itself is uploaded to Preplet’s servers and passed to Google for AI processing, as described in Section 3.
CoWork Content: If you use CoWork Sessions (our collaborative study feature — see Section 8), additional Personal Information is collected and stored on our servers in Firestore for each group you host or join, because every member of the group needs to see it. This includes: the group name and avatar; your membership role (host, premium, or freemium) in each group; the sessions, flashcards, and notes shared to the group; chat messages you send through the group's Chat button; edits you make to the group Board; your scheduled events, RSVPs, and notification preferences; the activity feed entries recording your actions in the group; and, if you use Study Room Live Mode, the voice transcripts you choose to share with the group.
Voice and Audio Data: Preplet supports audio input in two ways. For lecture capture, you may record or upload audio in a personal session; that audio is transcribed via Preplet AI and the transcript becomes study content in your session. For Study Room Live Mode (a paid CoWork feature that is not yet available), you speak directly to Preplet AI, and Preplet AI generates a text transcript in real time. At the end of the Live Mode session, you decide whether to share the transcript with your group, keep it privately in your CoWork notes for that group, or discard it. Discarded transcripts are not written to our database.
Support and Contact: If you contact us for support, we collect your name, email address, and any additional information you provide in your message.
Feedback: When you provide comments, reviews, or feedback about the Services, we collect the content of that feedback along with any identifying information you include. Feedback is not treated as confidential and may be used to improve the Services without attribution or compensation.
User Reports: If you use the report button on any piece of content, any chat message, or any other user inside a CoWork group, we collect the content of your report, a pointer to the reported material, and the identifiers of the reporter and the reported party so that we can review and act on the report (see Section 8).
Data Automatically Collected
We may use automated technologies to collect Personal Information when you use our Services:
Product Analytics (users 13 and older only): We record a small, fixed set of product events so we can see where the product works and where it breaks. The complete list is: account created, study build started, study build completed, upgrade screen viewed, upgrade completed, and CoWork group created. Each event carries only coarse, non-identifying properties such as which plan tier the account is on, how many output types were requested, and which screen the upgrade was started from.
These events are recorded against a one-way irreversible hash of your account identifier, not your account identifier itself. We also record a coarse age band (13-17 or 18+) and your platform. No study content, message text, quiz answers, study performance score, subject, display name, email address, precise or approximate location, or advertising identifier is ever included in an analytics event. Automatic screen and tap capture, session replay, and location lookup are all switched off.
This data is NOT collected from Kid Mode accounts (users under 13) under any circumstance, and is not collected at all until an account's age has been confirmed. If we do not know a user's age, nothing is collected.
Device Information: We collect information about the device you use to access the Services, including device type, operating system, operating system version, app version, and screen size.
Tracking Technologies: On our website, we may use cookies and similar tracking technologies to collect information including IP addresses, browser type, pages visited, referring websites, and approximate geographic location (country-level only). You may disable certain tracking technologies through your browser settings, though doing so may affect your use of the Services.
Data from Other Sources
We may receive information about you from third-party authentication providers (Google, Apple) when you use their services to sign in. This information is limited to what is described in the Account Registration section above.
We also receive subscription lifecycle events — renewals, refunds, billing grace periods, upgrades, expirations, and cancellations — so that your subscription state stays accurate. For web purchases these arrive as webhooks from our payment processor; for in-app purchases they originate with Apple's App Store or Google Play and reach us through RevenueCat.
2. Minimum Age and Age-Based Data Collection
Minimum age at launch: 13+ (with Kid Mode for under-13 users)
Preplet is available to users aged 13 and older through the standard signup flow. During signup, we ask for your birth month and year. Users under 13 may use Preplet through Kid Mode, a privacy-first, parent-in-the-loop experience in which we collect only the parent's email address and the child's birth month and year, and obtain verifiable parental consent before the account is activated. In free Kid Mode, the child uses the solo study tools; group study (CoWork) is turned off for children under 13 unless a parent purchases a subscription and provides consent. Study content submitted by a Kid Mode user is processed only to build the requested study materials and is then deleted. Kid Mode is described in detail in Section 6 (Children's Information) of this Policy.
Users Ages 13-17
For users aged 13-17 we collect the information necessary to operate the account and provide the Services: display name, email address, birth month and year, authentication method, subscription status, the study content the user creates or shares, and CoWork data if the user participates in a group. We also record the limited set of product events listed above under Product Analytics. We do not collect study performance scores, subject data, precise location, or advertising identifiers from users in this age band, and we do not build a behavioural profile of them. Data from users aged 13-17 is never included in aggregated datasets or shared with third parties for commercial purposes.
Users 18 and Older
Full data collection applies. Data from adult users may be included in aggregated, de-identified datasets as described in this Policy.
Automatic Age Updates
We use an automated system to periodically check user ages based on birth month and year and update data collection practices accordingly. When a user reaches a qualifying age, data collection for new activity begins automatically without requiring action from the user.
Relationship to CoWork Access
The data-collection age thresholds above (no analytics under 13, limited product analytics from 13, aggregated inclusion at 18) are separate from the minimum age required to use CoWork features. All 13+ users, regardless of their data-collection band, may use CoWork under the rules described in Section 8 below.
3. How We Use Your Information
We use Personal Information for the following purposes:
Providing the Services: We use your account information to authenticate you, manage your account, sync your study content across devices, and provide access to the features included in your subscription tier.
AI Processing: When you use AI-powered features — quiz generation, flashcard creation, note generation, reading text from photographs and documents, audio transcription, translation, Talk to Preplet, the Preplet button inside CoWork chat, and Study Room Live Mode — the content you submit is transmitted to Preplet’s servers and passed to Google for processing. That content consists of the text you type or paste, photographs you take or upload, documents you upload including PDF and Word files, and audio you record or upload, together with your app language setting so that results are returned in the language you are using. This is necessary to deliver the core functionality of the Services.
Google AI is the only third-party AI provider Preplet uses. Text, images, documents and audio transcription are processed by Google AI under Google’s enterprise terms. Under those terms Google AI uses your content solely to generate and return the output you requested, does not retain it after the output is delivered, and does not use it to train any AI model. This applies to every Preplet account, not only to accounts in Kid Mode. Real-time Preplet Voice uses a different Google AI service from the rest of the app, because the service used elsewhere does not currently offer a live-audio endpoint. Data retention is switched off for that service on Preplet's account: audio from a live voice session is used by Google AI only to produce the spoken response in the moment, is not retained afterwards, and is not used to train any AI model.
Your AI processing permission. Before any of your study content is sent for AI processing, Preplet shows you a dedicated in-app permission screen that names Google as the recipient, states the categories of content that will be sent, and requires you to tick a box and confirm. If you decline, nothing is sent and Preplet’s AI features stay switched off; the rest of the app continues to work, and you will be asked again the next time you use an AI feature. Preplet keeps a record of the permission decisions made on your account — the exact wording you were shown, your answer, and the date and time — so that we can demonstrate what was disclosed and what you agreed to. Your permission is stored against your account rather than your device: signing out of Preplet clears it, and you will be asked again the next time you sign in. To withdraw your permission at any time, sign out, delete your account, or contact us at info@preplet.ai.
Preplet AI applies content safety filters for harassment, hate speech, sexually explicit content, and dangerous content to text, image, study-material, and audio-transcription requests. Kid Mode accounts are filtered at the strictest available threshold on all four categories. All other accounts are filtered at the strictest threshold for harassment and at a moderate threshold for hate speech, sexually explicit content, and dangerous content. That distinction is deliberate: the strictest setting refuses legitimate coursework in history, literature, biology, health, chemistry, pharmacology, criminal justice, and psychology, which are ordinary subjects for the students who use Preplet. Certain categories, including child sexual abuse material, are blocked unconditionally by the AI provider at every setting and cannot be disabled by Preplet or by you. Real-time Preplet Voice conversations run on the underlying model's built-in default safety, because that live voice model does not accept a custom safety threshold; for these sessions Preplet applies an age-appropriate system prompt, with a stricter prompt for Kid Mode.
CoWork Collaboration: We use your CoWork data (group memberships, chat messages, Board edits, activity feed entries, events, RSVPs, shared sessions, and shared voice transcripts) to synchronize collaborative study across the members of the groups you belong to. Sync runs through Firestore's real-time database. A group member's chat messages, Board edits, and shared sessions are visible to every other member of that group by design.
Preplet Context in CoWork Chat: When a user on a paid plan taps the Preplet button in a CoWork chat, the client passes up to the last 20 chat messages from that group as context to the Preplet AI call so the assistant can respond meaningfully. The resulting response is group-visible.
Content Safety: We use your submitted content to enforce our content safety model. Every image upload, generated study material, and Preplet AI response is filtered by Preplet AI at the API level. Direct user-to-user text in CoWork Chat and Board edits is screened by a client-side profanity filter that runs on your device at send/save time. Text that the filter flags is written to the database with a flag marker so that recipients can choose to see a masked or unmasked rendering; the filter itself does not transmit a list of your words to any server outside Firestore.
Service Improvement: We use the product events described above (from users 13 and older) to understand how the Services are used, identify areas for improvement, fix technical issues, and develop new features.
Personalization: We use your birth month and year, grade level (if provided), and usage patterns to tailor the experience to your educational level and preferences.
Account Administration: We use your information to manage subscriptions, verify payments, process subscription lifecycle events, send service-related communications (such as account confirmations, subscription notices, and security alerts), and respond to support requests.
Business Analytics: We use aggregated and de-identified data from adult users (18 and older) to understand demographics, study trends, and market demand. This data helps us make informed decisions about the Services and may be shared with third parties as described in this Policy.
Trust, Safety, and Enforcement: We use the information associated with user reports, content flagged by the profanity filter, content blocked by Preplet AI's safety filters, and any record of blocks, strikes, appeals, or CoWork bans to review reports, take appropriate action under our Terms of Service, and maintain the integrity of the Services. See Section 8 for details.
Email Communications: We use your email address to send service-related and transactional messages, including account notifications, subscription updates, security notices, CoWork invite notifications, and parental consent flows for Kid Mode. We do not currently send promotional or marketing emails. If we decide to do so in the future, we will provide notice and you may opt out at any time using the unsubscribe link provided in such emails.
Legal Protection and Mandatory Reporting: We may use your information to protect our legal rights or interests, enforce these Terms, respond to legal requests, prevent fraud or abuse of the Services, or comply with mandatory reporting obligations. In particular, as described in Section 8, if Preplet becomes aware of apparent child sexual abuse material (CSAM) on the Services, we are required under 18 USC 2258A to report it to the National Center for Missing and Exploited Children (NCMEC), including associated account identifiers, timestamps, and content references.
Aggregated and De-Identified Data: We may process Personal Information from adult users (18 and older) to create de-identified and aggregated data that cannot reasonably be used to identify any individual. Such de-identified and aggregated data is not subject to this Privacy Policy, and Preplet is the sole and exclusive owner of such data. This data may include aggregated study trends, subject popularity, feature usage patterns, device and platform statistics, and educational demographic trends.
Tracking Technologies
On our website, we may use the following technologies:
Website analytics: Preplet does not run Google Analytics, advertising pixels, or cross-site tracking on this website.
Google Sign-In: If you use Google Sign-In, cookies and APIs provided by Google facilitate the authentication process. Information shared with Google through this process is subject to Google's privacy policy.
Apple Sign-In: If you use Apple Sign-In, authentication is handled by Apple. Information shared with Apple is subject to Apple's privacy policy.
Firebase: We use Google Firebase for authentication, Firestore cloud database, Cloud Functions, and Cloud Storage. We also use Sentry for crash and error reporting, PostHog for the product analytics described above (never from Kid Mode accounts), SendGrid to send transactional email such as verification, billing and safety notices, Twilio to send the SMS messages described in the Kid Mode section, Stripe to process payments made on the web, and RevenueCat to validate purchases made through the Apple App Store and Google Play. Each processes only the data needed for its function. Firebase's handling of data is governed by Google's privacy policies and Firebase's terms of service.
4. Retention of Personal Information
We retain Personal Information for as long as necessary to fulfill the purposes described in this Policy, or as required by law. We take reasonable steps to delete Personal Information when: (1) we have a legal obligation to do so, (2) we no longer have a purpose for retaining the information, or (3) you request deletion of your data.
Account Deletion. Preplet provides an in-app Delete Account flow that permanently removes your account and the Personal Information associated with it. When you delete your account, the app clears its on-device data store, deletes the archived recovery backup held on our servers, and removes or anonymizes your CoWork memberships, authored chat messages, Board edits, and voice transcripts in accordance with the relevant group's retention needs. Certain information may be retained in our backup systems for a limited period or as required by law, including: (a) records required to comply with mandatory reporting obligations (Section 3), (b) records associated with confirmed Terms of Service violations, including strike ladder state, retained for enforcement purposes, and (c) subscription and billing records required by tax and accounting law.
CoWork Version History. Each collaborative session document and Board retains up to the last 20 versions of content. Activity feeds retain up to the last 200 events per group. Older entries are automatically pruned.
Chat Retention. CoWork chat messages are persistent for the life of the group in v3.0. We may adopt automatic chat pruning in a future version if storage costs require it; any such change will be reflected in this Policy.
Voice Transcript Retention. Transcripts you choose to share with a group live for the life of the group. Transcripts you keep private live in your personal CoWork notes for that group, accessible only to you. Transcripts you discard are never written to our database.
Downgrade Archive. When you cancel a paid subscription, the sessions above the free-plan allowance are flagged as archived rather than deleted. Archived sessions remain listed under Archived on the Sessions screen and can be restored at any time, subject to the active-session cap for your current plan. Archived data is not automatically deleted. Deleting your account deletes archived data along with active data.
5. Disclosure of Personal Information
We may disclose Personal Information to the following categories of recipients:
Third-Party Service Providers: We disclose Personal Information to service providers that support our Services, including Google Firebase (authentication, Firestore database, Cloud Functions, Cloud Storage, App Check), Sentry (crash and error reporting), PostHog (product analytics), Stripe (payment processing for web purchases), Apple and Google (in-app purchase processing for subscriptions bought in the mobile app), RevenueCat (app store receipt validation and entitlement management), SendGrid (transactional email), Twilio (SMS notices described in Section 6), and Google AI (processing of the study content you submit, including real-time Preplet Voice). We take commercially reasonable steps to ensure our service providers maintain appropriate protections for Personal Information.
Other CoWork Group Members: If you join or host a CoWork group, your display name, avatar, membership role, chat messages, Board edits, shared sessions, activity feed entries, RSVPs, and shared voice transcripts are visible to every other member of that group. Email addresses are visible only to the group host. If you block another user, you and the blocked user are removed from each other's visibility in shared group content.
AI Processing Provider: When you use AI-powered features, the text, photographs, documents, audio and app language setting you submit are transmitted to Preplet’s servers and passed to Google AI for processing. Google AI is the only third-party AI provider we use for these features. Study guide generation, chat, image reading and audio transcription run under Google’s enterprise terms: Google AI uses the content solely to return the output you requested, does not retain it after the output is delivered, and does not use it to train any AI model. Real-time Preplet Voice uses a different Google AI service from the rest of the app, because the service used elsewhere does not currently offer a live-audio endpoint. Data retention is switched off for that service on Preplet's account: audio from a live voice session is used by Google AI only to produce the spoken response in the moment, is not retained afterwards, and is not used to train any AI model. This transmission is necessary to provide the Services.
Payment Processors and App Stores: Subscriptions purchased on the web at preplet.ai are handled by Stripe (or, for redundancy, a backup PCI-compliant payment processor). Subscriptions purchased inside the iOS or Android app are handled by Apple's App Store or Google Play, with receipt validation and entitlement management by RevenueCat. Preplet does not receive or store your full payment details from any of them.
NCMEC and Law Enforcement (Mandatory Reporting): If Preplet becomes aware of apparent CSAM on the Services, federal law (18 USC 2258A) requires us to report it to NCMEC via the CyberTipline, preserving the associated content, account identifiers, and metadata for the period required by law. Reports may also be shared with law enforcement. This obligation applies regardless of the user's age or subscription status.
Educational Institutions: We may disclose account information to educational institutions with which you are affiliated if required to enforce our Terms of Service or Honor Code, or in response to a valid institutional inquiry regarding academic integrity.
Government and Law Enforcement: We will cooperate with law enforcement and governmental agencies, and may disclose Personal Information: (i) if we believe in good faith we are legally required to do so, (ii) when advised by legal counsel, (iii) to protect the rights, safety, or property of Preplet or others, or (iv) as otherwise required by law.
Professional Advisors: We may disclose Personal Information to our attorneys, accountants, and other professional advisors in their capacity as advisors.
Successor Entities: In the event of a merger, acquisition, bankruptcy, reorganization, or sale of assets, your Personal Information may be transferred to the acquiring or successor entity.
Aggregated Data Recipients: We may share aggregated, de-identified data derived from adult users (18 and older) with third parties for research, analytics, or commercial purposes. This data cannot reasonably be used to identify any individual.
With Your Consent: We may disclose Personal Information to third parties when you explicitly request or consent to such disclosure.
6. Children's Information
Preplet v3.0 supports users under 13 through a dedicated Kid Mode flow that complies with the Children's Online Privacy Protection Act ("COPPA"). Children 13 and older use the standard signup flow. This Section describes how Personal Information is handled for users in each age band.
Users Ages 13-17: We collect the Personal Information necessary to operate the account and provide the Services (display name, email, birth month and year, authentication method, subscription status, study content, and CoWork content if the user uses CoWork), plus the limited set of product events described in Section 3 under Product Analytics. We do not collect behavioural analytics, study performance scores, subject data, precise location, or advertising identifiers from users in this age band, we do not build a behavioural profile of them, and we do not include their data in aggregated datasets or share it for commercial purposes.
Kid Mode (users under 13)
Kid Mode is the experience Preplet provides to users whose signup information indicates they are under 13 years old. Kid Mode is available in v3.0 at launch. This section describes every aspect of how a Kid Mode account is created, what data is collected, how parental consent is obtained and renewed, and what safeguards are in place.
What we collect at Kid Mode signup. A Kid Mode account is created with only two pieces of information: the child's birth month and year (used solely to confirm the child is under 13 and to transition the account when the child turns 13), and the email address of the child's parent or legal guardian (used to obtain and record parental consent and to contact the parent). We do not collect the child's name, phone number, school, location, photograph, or any other directly identifying Personal Information at signup. We do collect a phone number for the parent or guardian. It is used only to reach the parent about their own child's account — specifically, to text a parental-approval request when the parent has not responded to the approval email, and to send urgent safety notices. It is never used for marketing, never shared with other users, and never associated with the child in any content. These messages are sent through Twilio, which receives the parent's phone number and the message text solely in order to deliver it. If you would prefer we did not hold a phone number for you, email info@preplet.ai and we will remove it; parental approvals will then arrive by email only. If the child signs in with Apple or Google, any real-name fields returned by the provider are discarded server-side; only the authentication identifier and the provider email (used for authentication only) are retained.
How we obtain parental consent. Under 16 CFR §312.5(c)(2), an operator may collect a parent's online contact information in order to obtain verifiable parental consent. Before a Kid Mode account is activated, we email the parent a consent request that explains what Kid Mode collects and how the child's study content is used and deleted, and the parent must confirm consent. Because free Kid Mode does not disclose a child's personal information to other users or to third parties for their own use, and study content is processed only to build the child's own study materials and then deleted (described below), this email-based consent is used consistent with COPPA's requirements for services that do not disclose children's information to third parties.
Preplet Voice and Kid Mode. If a parent purchases a paid plan for a Kid Mode account, that account can use Preplet Voice, the real-time spoken conversation feature. Parents should understand two specific things before enabling it. First, spoken audio from a live voice session is sent to Google AI to produce the spoken response; retention is switched off for that service on Preplet's account, so the audio is not retained afterwards and is not used to train any AI model. Second, and unlike every other AI feature in Preplet, the live voice service does not accept a custom safety threshold — it runs on the AI provider's own built-in default safety settings rather than the stricter Kid Mode thresholds Preplet applies to text, images, study material and transcription. Preplet applies a stricter Kid Mode system prompt to voice sessions, but a prompt is not the same control as a safety filter. A parent who does not want their child using spoken conversation should not purchase a paid plan for the Kid Mode account, or should contact info@preplet.ai to have voice disabled on that account.
What a child can do in Kid Mode. A Kid Mode account can use the solo study tools — building study guides, flashcards, quizzes, summaries, and outlines from the child's own notes, photos, documents, and audio. Group study (CoWork Sessions) is turned off for children under 13. CoWork can be enabled for a Kid Mode account only if a parent purchases a subscription and provides verifiable parental consent, because CoWork discloses the child's display name and content to other users.
How study content is processed and backed up. To build a study guide, the content a Kid Mode user submits (text, photos, documents, or audio) is sent to our AI providers solely to generate the requested output. That input is sent to Google AI, is not retained by Google after the output is delivered, and is not used to train any AI model. Preplet stores the child's study content on our servers in Google Firebase, tied to the account and authorized by the parent's consent, so the child can reach their materials from any device they sign in on and recover them if a device is lost or replaced. It is encrypted in transit and at rest by that service, and is deleted when the account is deleted. On-device optical character recognition runs first to read text out of photographs, but this does not replace sending the file: the photograph, document or recording itself is uploaded and passed to Google for processing as described above.
Parental control and revocation. A parent may, at any time, review the Personal Information collected from their child, refuse further collection or use, withdraw consent (including any consent given to enable CoWork), and request deletion of the account and associated data. To do so, the parent emails Preplet from the registered parent email address — subject "revoke" to withdraw group-feature consent, or "delete account" to delete the account and its data. We act on these requests within the time required by COPPA.
Automatic age-up on the child's 13th birthday. Preplet uses the birth month and year collected at signup to automatically transition the account out of Kid Mode on the child's 13th birthday. At that time, the account is prompted on next login to review the standard (13+) Privacy Policy and Terms. Until the child completes this transition, the account remains in Kid Mode with all Kid Mode protections in place.
Data handling for under-13 users. Personal Information collected from a child while they are under 13 is used only to operate the Kid Mode experience and fulfill the Services. It is not sold, not shared with third parties for commercial purposes, not used for behavioral advertising, and not included in any aggregated dataset — now or after the child turns 13. All under-13 data is anonymized where possible and compartmentalized from adult account data. Preplet's privacy posture for under-13 users is deliberately more protective than the posture of major consumer social platforms.
Closed system. Preplet does not expose a public directory, search, or discovery function for any user. Kid Mode accounts in particular cannot be found by searching, cannot be invited by strangers without the parent's explicit per-contact approval, and cannot appear in any public listing. CoWork Sessions are visible only to users whose participation the parent has separately approved.
Parental rights under COPPA. A parent may review the Personal Information collected from their child, refuse to permit its further collection or use, and request its deletion at any time. To exercise these rights, the parent contacts Preplet at info@preplet.ai from the registered parent email address, and we will act on the request within the time required by COPPA.
If a parent or legal guardian believes their child's Personal Information has been collected or used in a manner inconsistent with this Policy, please contact us at info@preplet.ai and we will make commercially reasonable efforts to address the concern, including deleting the account if requested.
7. Data Security
We use commercially reasonable technical and organizational measures to protect Personal Information against loss, misuse, unauthorized access, and alteration. These measures include: encryption of data in transit (TLS) and at rest (Google's managed encryption for Firestore and Cloud Storage), secure authentication through Firebase Auth, server-side subscription validation through our payment processor's webhooks, Firestore security rules that enforce membership and permission boundaries at the database layer, and Firebase App Check to deter automated bot signups and API abuse.
YOU UNDERSTAND THAT NO DATA TRANSMISSION OVER THE INTERNET OR METHOD OF ELECTRONIC STORAGE CAN BE GUARANTEED TO BE 100% SECURE. WHILE WE STRIVE TO PROTECT PERSONAL INFORMATION, WE CANNOT GUARANTEE ITS ABSOLUTE SECURITY AND YOU PROVIDE PERSONAL INFORMATION AT YOUR OWN RISK.
8. CoWork Sessions — Group Data, Safety, and Enforcement
CoWork Sessions is Preplet's collaborative study feature. When you use CoWork, Preplet handles several additional data categories and safety processes described in this section.
8.1 What CoWork Data Is Collected
For each CoWork group you host or join, Preplet stores in Firestore: the group name, avatar, and invite code; the list of members and each member's role (host, premium, or freemium); the sessions, flashcards, notes, and AI-generated materials shared to the group; version history of shared materials (up to 20 most recent versions); chat messages sent via the group's Chat button, including a flag indicating whether the client's profanity filter matched; Board edits and any flagged regions; the activity feed (up to 200 most recent events); scheduled events, RSVPs, and notification preferences; and, for Study Room Live Mode sessions you choose to share, the resulting voice transcripts.
A denormalized pointer to each group you belong to is also stored under your user record so that the app can quickly list your groups.
8.2 Who Can See What in a Group
Sessions, flashcards, notes, chat messages, Board edits, activity feed entries, scheduled events, and shared voice transcripts within a group are visible to every member of that group. This is the core design of a collaborative study space.
Email addresses of group members are visible only to the group host. Non-host members see display names and avatars only. If two members share a display name, a short stable identifier may be shown alongside to disambiguate them.
Free-plan members in a group can read all group content but cannot write — they cannot post chat messages, edit the Board, or contribute session content. Study materials received through CoWork (such as study guides shared by other members) can be used by free-plan users, but each one occupies a slot in the free plan's 5-session active cap. If all slots are occupied, the user must archive or delete an existing session before they can use a new study guide received through CoWork. See Section 5 of the Terms of Service for the full soft-archive model. Writing to a group and hosting a group each require a paid subscription. Membership and permission rules are enforced at the Firestore security rule level.
Group material never crosses into personal sessions, and personal sessions never cross into groups, unless you explicitly copy content between them.
8.3 Invite Model and Contact Controls
CoWork groups are invite-only. There is no public directory, group search, join-by-code lookup, user search, friend suggestions, or direct messaging feature. Invites can be sent only by a group host and only to an email address the host already knows. A block button on every member card lets you remove yourself from mutual visibility with another user; a report button on every member card and every piece of content lets you escalate to Preplet for review.
8.4 Content Safety Model
Preplet uses a two-part content safety model for CoWork:
Preplet AI as the single firewall for images and generated content. Every image you upload and every piece of AI-generated study material passes through Preplet AI's safety filters covering harassment, hate speech, sexually explicit content, and dangerous content, at the thresholds described in Section 4 — strictest throughout for Kid Mode accounts. If a submission is blocked, the content is not saved and the user is told the material was filtered. This covers all image uploads, all generated study material, Preplet responses inside CoWork chat, and Talk to Preplet responses.
Client-side profanity filter on direct Chat and Board text. CoWork chat messages sent with the Chat button and Board edits do not pass through Preplet AI. A client-side profanity filter screens these texts on the sending device and flags matches so that receiving devices can render the flagged text masked until tapped. The filter has a user setting (strict, relaxed, or off) and a host-level minimum strictness control. Under-18 accounts default to strict and see a warning before weakening the setting.
8.5 CSAM Handling and NCMEC Reporting
Apps that accept user-uploaded images are legally required to report apparent child sexual abuse material (CSAM) to the National Center for Missing and Exploited Children (NCMEC) under 18 USC 2258A. Preplet's controls are:
- Provider-level blocking. Every image upload and every piece of generated content passes through the AI provider before it is saved or shared. The provider blocks child sexual abuse material unconditionally, at every safety setting, and that block cannot be disabled by Preplet or by any user.
- Reporting. Any CoWork report flagged as a severe violation immediately suspends the reported account, revokes its active sessions, and preserves the associated content, account identifiers and metadata. The matter is then reviewed by a person at Preplet and, where the material appears to be CSAM, reported to NCMEC via the CyberTipline as federal law requires. Preservation follows the federal retention requirements.
- Anyone can report. Reporting controls appear on CoWork chat messages and on every item shared to a group Board. You can also email info@preplet.ai directly.
We describe this honestly rather than overstating it: at present the escalation to NCMEC involves a human review step rather than an automatic filing. Automated hash matching (PhotoDNA) and automated CyberTipline submission are planned and are not in place today. This obligation applies regardless of the user's age or subscription status.
8.6 User Reports and the CoWork-Only Strike Ladder
You can report any message, Board edit, shared session, or other user from within a CoWork group. Reports write to a secure queue in Firestore and trigger a notification to the Preplet review team.
Enforcement is handled by a four-step CoWork-only strike ladder. The ladder restricts CoWork access only; solo study features, Talk to Preplet in personal sessions, and all non-CoWork app functionality remain available at every step, including after permanent CoWork loss.
- Strike 1 is a warning that shows the reported content along with an Appeal button. No CoWork restriction is applied yet.
- Strike 2 is a 7-day CoWork ban, triggered only if Strike 1 was reviewed and confirmed. The user retains CoWork read access and all solo features. Appealable.
- Strike 3 is a 30-day CoWork ban with the same scope, triggered only if Strikes 1 and 2 were confirmed. Appealable.
- Strike 4 is permanent loss of CoWork write privileges, with no appeal, triggered only if Strikes 1, 2, and 3 were confirmed. The rest of the app continues to work.
Strikes 1-3 decay after 12 months of clean record. Strike 4 does not decay. Severe violations (CSAM, illegal content, targeted harassment, credible threats) skip the ladder and go directly to full account suspension plus appropriate legal reporting. Ban state is enforced at the Firestore security rule level so that it cannot be bypassed by a modified client. Preplet retains strike history, appeal records, and related evidence for enforcement purposes.
8.7 Voice Transcripts in Study Room Live Mode (v3.1)
Study Room Live Mode is not available in the current release. When it ships it will let a user on a paid plan speak directly with Preplet AI. Preplet AI produces a text transcript of the conversation in real time. At the end of each session, you choose one of three dispositions:
- Share with group — the transcript is written to the group chat as a special message visible to every member.
- Keep private — the transcript is stored in your personal CoWork notes for that group, accessible only to you.
- Discard — the transcript is not written to our database. The default for an unanswered prompt is Discard.
Other users in the group do not hear the live audio in v3.1; multi-user voice is not implemented. Voice transcripts are produced by Preplet AI. Real-time Preplet Voice runs on the underlying model's built-in default safety rather than the custom strict threshold used for text and image content (see Section 3).
8.8 DMCA and Copyright Complaints
Because CoWork lets users post study content, chat, and Board edits visible to other group members, the Services function as a user-generated content host for the purposes of the Digital Millennium Copyright Act. Preplet maintains a designated agent for receiving notices of claimed copyright infringement under 17 USC 512(c). To submit a DMCA notice, contact:
DMCA Designated Agent
AXS Group Inc — DMCA Agent (Preplet)
Email: admin@AXSGP.com
AXS Group Inc has registered its designated agent for copyright complaints with the U.S. Copyright Office. Valid DMCA notices must include the elements required by 17 USC 512(c)(3), including a description of the copyrighted work, a description of the allegedly infringing material, contact information for the complainant, a good-faith statement, and a statement under penalty of perjury that the complainant is authorized to act. Upon receiving a valid notice, Preplet will act expeditiously to remove or disable access to the allegedly infringing material and notify the affected user, who may submit a counter-notice under 17 USC 512(g).
9. Data Storage, Sync, and Backups
Preplet uses a device-first data storage model. The primary copy of your personal content lives on your device, and we keep an archived backup copy on our servers so that you can recover your content if your device is lost. Multi-user CoWork content is the only category that is server-primary.
On Your Device (Primary): Personal sessions, flashcards, quizzes, notes, personal Preplet conversations, on-device audio files, and imported documents are stored on the device you use them on, using the platform's secure local storage (iOS/macOS protected data, Android internal storage, or equivalent). Day-to-day reading and writing happens against this on-device store.
Server storage and recovery: Your study content — sessions, study guides, flashcards, quiz questions, notes, uploads and recordings — is stored on our servers in Google Firebase, tied to your authenticated account, and encrypted in transit and at rest by that service. This is what lets you sign in on another device and find your materials there, and recover them if a device is lost, damaged or replaced. Deleting content in the app deletes it from our servers. Preplet does not currently offer backups to your own iCloud Drive or Google Drive, and does not keep prior versions of your content; if you delete something, it is gone.
CoWork Content (Server-Primary): CoWork group sessions, chat messages, Board edits, activity feed entries, scheduled events, RSVPs, and shared voice transcripts are stored on our servers in Google Firebase Cloud Firestore ("Firestore"), on servers located in the United States. This is the only content category for which the server holds the primary copy, and it is necessary because every member of a CoWork group needs to see the same data.
Real-Time CoWork Sync. For CoWork content only, the app uses Firestore's real-time listeners to keep data current across the members of each group. A sync-on-save model writes discrete updates rather than per-keystroke streams; each save also appends to a version history and an activity feed. Personal content is not synced in real time to the server — only the archived recovery backup is updated.
Disaster Recovery. Preplet maintains a daily scheduled export of the Firestore database (CoWork content plus archived personal backups) to Cloud Storage for disaster-recovery and billing-dispute purposes, with a bounded retention window.
Account Deletion. When you delete your account through the in-app Delete Account flow, Preplet deletes (a) the content stored on your device by signing you out and clearing the app's local store, (b) the archived backup copy held on our servers, and (c) your CoWork content subject to the retention exceptions described in Section 4.
10. Access from Outside the United States
If you access the Services from outside the United States, please be aware that your Personal Information may be transferred to, stored in, and processed in the United States, which may have different data protection laws than your country of residence. Preplet's processing of Personal Information under the Google Firebase and Google Cloud Data Processing Addenda is intended to support transfers consistent with applicable cross-border data transfer requirements. International availability of the Services and additional regional protections will be reviewed before any international launch.
11. Third-Party Websites and Services
The Services may contain links to websites or services not operated by Preplet. We are not responsible for the privacy practices of third-party websites or services. This Policy does not apply to any third-party websites or services, and we encourage you to review the privacy policies of any third-party services you access.
12. Do Not Track Signals
At this time, our Services do not respond to "Do Not Track" browser signals, as there is no industry-wide standard for how to interpret these signals.
State Privacy Exhibit
A. Notice to California Consumers
In this Section, capitalized terms not defined in this Policy have the meanings set forth in the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and including its implementing regulations (the "CCPA").
Categories of Personal Information Collected:
In the last twelve (12) months, we have collected the following categories of Personal Information:
- Identifiers: real name or display name, email address, unique user ID, online identifiers, IP address, account name, and, within a CoWork group, identifiers tied to other users with whom you collaborate.
- Personal Information described in subdivision (e) of Section 1798.80: name, address (country-level).
- Commercial Information: subscription plans purchased, transaction history, subscription lifecycle events.
- Internet Activity: browsing history on our Site, interaction with the Services, feature usage data, CoWork engagement data.
- Education Information: grade level, graduation year, subjects studied, quiz performance scores, study content, CoWork group content (users 16+ only for analytics; study and CoWork content for all users regardless of age, because it is the content of the Services).
- Audio Information: voice recordings and transcripts submitted by the user for transcription or Study Room Live Mode.
- Geolocation Data: approximate country-level location only.
- Inferences: preferences, study patterns, improvement trends (users 16+ only, derived from usage data).
Categories of Sources: As described in Section 1 of this Policy.
Business Purposes for Collection: As described in Section 3 of this Policy, including providing the Services, AI processing, CoWork collaboration, content safety, service improvement, personalization, administration, analytics, trust and safety enforcement, mandatory reporting, and legal protection.
Disclosure for Business Purposes: In the last 12 months, we have disclosed Personal Information to the categories of service providers described in Section 5 of this Policy, including Google (Firebase, Firestore, Cloud Functions, Cloud Storage), Google AI (processing of the study content you submit, including real-time Preplet Voice), SendGrid (transactional email), Twilio (SMS notices), Stripe (payment processing for web purchases), Apple and Google (in-app purchase processing), RevenueCat (app store receipt validation), other CoWork group members as an inherent function of the collaborative product, NCMEC (where mandatory reporting obligations applied), and professional advisors.
Sale or Sharing of Personal Information: We may use aggregated, de-identified data derived from adult users (18+) for commercial purposes as described in this Policy. We do not sell or share Personal Information of users under 18. We do not have actual knowledge of selling or sharing Personal Information of individuals under 16.
California Privacy Rights:
California consumers have the following rights:
- Right to Know and Access: You may request that we disclose the categories and specific pieces of Personal Information we have collected about you, the sources of that information, the business purposes for collection, and the categories of third parties with whom we have shared it.
- Right to Delete: You may request that we delete your Personal Information, subject to certain exceptions, including retention required for mandatory reporting obligations, enforcement of our Terms of Service, and legal, tax, or accounting requirements.
- Right to Opt-Out of Sale and Sharing: You may opt out of the sale or sharing of your Personal Information with third parties. To exercise this right, contact us at info@preplet.ai.
- Right to Correct: You may request that we correct inaccurate Personal Information.
- Right to Limit Use of Sensitive Personal Information: In certain circumstances, you may limit the use and disclosure of Sensitive Personal Information.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
How to Exercise Your Rights: To exercise your California privacy rights, contact us at info@preplet.ai. We will verify your identity before processing your request and may require additional information to do so.
Authorized Agents: You may designate an authorized agent to submit requests on your behalf. We will require proof of written authorization and verification of your identity.
B. Notice to Maryland and Montana Consumers
In this Section, capitalized terms not defined in this Policy have the meanings set forth in the Maryland Online Data Privacy Act ("MODPA") and Montana Consumer Data Privacy Act ("MTCDPA").
Maryland Consumer Rights:
- Right to Access: You may request confirmation of whether we are processing your Personal Data and access such data.
- Right to Know: You may request a list of specific third parties or categories of third parties to whom we have disclosed your Personal Data.
- Right to Data Portability: You may request a copy of your Personal Data in a portable, readily usable format.
- Right to Delete: You may request deletion of your Personal Data.
- Right to Correct: You may request correction of inaccurate Personal Data.
- Right to Opt Out: You may opt out of processing of your Personal Data for targeted advertising, sale, or profiling.
Montana Consumer Rights:
- Right to Access: You may request confirmation of whether we are processing your Personal Data and access such data.
- Right to Data Portability: You may request a copy of your Personal Data in a portable format.
- Right to Delete: You may request deletion of your Personal Data.
- Right to Correct: You may request correction of inaccurate Personal Data.
- Right to Opt Out: You may opt out of processing for targeted advertising, sale, or profiling.
How to Exercise Your Rights: To exercise your state privacy rights, contact us at info@preplet.ai. We will verify your identity and respond within the timeframes required by applicable law. If we deny your request, you may appeal by contacting us at the same email address.
We will not discriminate against you for exercising any of your state privacy rights.
13. Contact Us
If you have questions or concerns regarding this Privacy Policy, contact us at:
Email: info@preplet.ai
Website: https://preplet.ai/support.html
For DMCA notices, use the designated agent contact in Section 8.8.
Last updated: August 7, 2026