Back to Edgify

Privacy Policy

This policy describes what Edgify collects, why it collects it, and who else is involved in processing it. It describes how the service actually works today.

Last updated 11 August 2026

1. What Edgify is

Edgify is an academic study workspace. You provide study material — by pasting text or uploading a document — and Edgify uses automated systems to produce revision notes, explanations, quizzes and a concept dependency graph from it.

2. Information you give us

Account information

When you create an account, Edgify stores your email address, a display name and, if you sign in with Google, the profile picture URL that Google provides. If you sign in with Google, Google supplies these to Edgify; if you register with an email address and password, the display name is derived from the part of your email address before the@.

Passwords are never stored in a readable form. Password hashing is performed by our authentication library (Better Auth) using scrypt, and Edgify never receives, stores, logs or transmits your password in plain text.

Sign-in sessions

To keep you signed in, Edgify stores a session record containing a session token, an expiry time and — as recorded by the authentication library — the IP address and browser user-agent associated with the sign-in. Signing out invalidates the session.

Study material you submit

When you upload a document, Edgify extracts its text and stores only the extracted text — the original file is never saved. Extraction happens in memory during the request; the uploaded file is not written to disk or to any file storage service. Alongside the extracted text, Edgify stores a title, a character count, a page count, the source type (for example PDF or DOCX) and a content hash used for caching.

Text you paste directly is submitted for generation in the same way. Please do not upload material you are not permitted to share, and be aware that anything you submit is sent to a third-party AI provider for processing, as described in section 4.

Content generated for you

Revision notes, concept graphs, per-concept explanations and your recorded progress against each concept are stored in your account so you can return to them.

3. Information generated automatically

  • Usage and quota records. Edgify records the number of generations you run each day to enforce a per-user daily limit, and keeps an operational log of each model call containing the operation type, the model used, token counts, an estimated cost, how long it took and whether it succeeded. This log does not contain your study material.
  • Rate limiting. To protect the service from abuse, Edgify counts requests against short time windows. For requests made without a signed-in account, the counter is keyed by IP address.
  • Error reports. When something fails, a technical error report is sent to Sentry. Request bodies, cookies, authorization headers and IP addresses are stripped from these reports before they are sent, so the text of your documents is not attached to them.
  • Product analytics. Edgify uses PostHog to understand which features are used. See section 6.

4. AI processing

To generate notes, explanations, quizzes and graphs, the text you provide is transmitted to OpenRouter, which routes it to third-party AI model providers and returns the generated result. This means the study material you submit leaves Edgify's systems and is processed by companies other than Edgify.

Those providers handle your text under their own terms and privacy policies. Edgify cannot and does not make any commitment about whether those providers retain submitted text or use it to train their models. If that matters to you, do not submit confidential or sensitive material.

5. Caching, and what it means for shared documents

To keep the service affordable, Edgify caches generated results against a hash of the submitted content. This cache is not partitioned per user. If another person submits exactly the same source text and requests the same output, they may be served the cached result that was generated from that identical content, rather than a new generation.

The cache is keyed by content, not by account, and it does not reveal who submitted the content, their identity or any other information about them. It is described here because it is a real property of the system rather than one you could reasonably infer.

6. Analytics

Edgify uses PostHog to record how the product is used — for example that a generation was started, which revision format was chosen, and whether it succeeded or failed. This is deliberately constrained:

  • Automatic capture of clicked-element text is disabled.
  • Session recording and replay are disabled.
  • You are identified by your internal database identifier, never by your email address.
  • No document text, extracted text, generated notes, concept names, file names or prompt content is included in any analytics event.
  • Browsers sending a “Do Not Track” signal are respected.

Analytics events do record the page you are on, the referring site and any campaign parameters in the link you arrived through.

7. How your information is used

  • To create and maintain your account and keep you signed in.
  • To generate the notes, explanations, quizzes and graphs you ask for.
  • To store your material and results so you can return to them.
  • To enforce daily usage limits and to protect the service from abuse.
  • To diagnose and fix faults.
  • To understand which features are used, so the product can be improved.

Edgify does not sell your information, and does not serve advertising.

8. Who else processes your information

Edgify relies on the following third-party services:

  • Google (Sign in with Google) — Authenticates you when you choose to sign in with Google, and provides your name, email address and profile picture to create your account.
  • Google Cloud Run — Hosts and runs the Edgify application, and processes requests made to it.
  • Neon — Provides the PostgreSQL database in which your account and study material are stored.
  • OpenRouter — Routes text you submit for generation to third-party AI model providers, and returns the generated result.
  • Sentry — Receives technical error reports so faults can be diagnosed and fixed.
  • PostHog — Receives product analytics events describing how Edgify's features are used.

Each processes your information under its own terms and privacy policy.

9. Isolation between users

Every query for account-specific data — documents, notes, graphs, concepts and progress — is filtered by your user identifier, so one account cannot read another account's material. This is enforced in application code and covered by automated tests. The single deliberate exception is the content-addressed cache described in section 5.

10. Data retention

Your account and the material associated with it are kept for as long as your account exists. Edgify does not currently operate a defined retention schedule and does not automatically delete study material after a fixed period. This is stated plainly rather than dressed up: a retention period is a promise, and Edgify does not yet have the mechanism to keep one.

11. Deleting your data

There is currently no self-service control in the interface for deleting your account or your stored material. To request deletion, open a request via GitHub Issues at the Edgify repository. Deletion of an account removes the records associated with it, including documents, notes, graphs, concepts, progress and usage records. Cached generated results, which are keyed by content rather than by account and are not linked to your identity, may persist.

Because a public issue is visible to anyone, do not include private material or personal details in it.

12. Security

Edgify is served over HTTPS. Database connections require verified TLS. Credentials for third-party services are held server-side and are never exposed to the browser. Passwords are hashed by the authentication library. No system is perfectly secure, and Edgify does not claim to be.

13. Children

Edgify is intended for use by students in higher and further education. It is not directed at children, and accounts should not be created by anyone under the age at which they can agree to these terms in their country.

14. Changes to this policy

This policy may change as Edgify changes. The date at the top of this page records when it was last revised. Material changes will be reflected here.

Contact

Questions about this document, or about how Edgify handles your information, can be raised on GitHub Issues. Please do not include private study material or personal details in a public issue.

Privacy PolicyTerms of ServiceCookie PolicyAI Disclaimer