Privacy
Your lectures are yours. Here is exactly what happens to them.
Last updated 11 October 2026
The short version
- Your lectures are never used to train anyone's model — not ours (we don't train models) and not Google's.
- We don't sell your data, show ads, or share it with your university.
- You can download everything we hold about you, or delete it, from Settings → Data & privacy at any time.
What we store
- Your account: your email address and name, handled by our sign-in provider (Clerk).
- The lectures you upload (PDF files, up to 300 pages each) and what PhysioTalk reads from them: page text, notes about the figures, sections and topics.
- Study material made from your lectures: summaries, flashcards and quiz questions.
- Your studying: the page you were on, your flashcard grades, your quiz answers, the days you studied (for streaks) and your settings.
- Your conversations with the tutor, and any error reports you send.
- Usage counts: how many AI tokens each request used, so we can keep costs and limits in check. These hold no content.
Who processes it
- Google Gemini (Google's AI service) reads your lecture pages to build the study material, and receives your questions, the parts of a page or figure you ask about, and voice recordings (below) to write the answers. PhysioTalk uses Gemini's paid service: under its terms Google does not use this content to improve its products or train its models. Google may keep it for a limited time only to detect abuse.
- Cloudflare R2 stores your PDF files. Supabase hosts our database. Vercel runs the website. Clerk handles sign-in. They store or process your data only to run PhysioTalk for you.
Speak-to-type (the microphone in the chat)
When you tap the microphone, your browser's own speech service (Google in Chrome, Apple in Safari) hears you live to show the words as you speak. When you stop, the recording is sent to Google Gemini via PhysioTalk to be written out more accurately. Nothing is stored: the recording is held only for that request and never saved or logged. The text appears in your message box, and is only kept if you send it as a message.
How long we keep it, and deleting it
- We keep your data while you have an account, so your lectures are there all semester.
- Delete one lecture from My lectures, or everything from Settings → Data & privacy: Delete all lectures (keeps your account) or Delete my account.
- Deletion is immediate: your files and every record linked to your account are removed from our database and storage, and your sign-in is closed. Usage counts are kept without your account attached. Copies in our providers' backups expire within 7 days.
- Deleting your account in the sign-in settings ("Manage account") deletes your PhysioTalk data in the same way.
Getting a copy
Settings → Data & privacy → Export everything gives you a zip with all of the above as JSON files and download links to your PDFs. The file and its links expire after 24 hours, and we delete the file from our storage after that.
Cookies and browser storage
We use the sign-in cookies Clerk needs to keep you signed in. Your browser also remembers a few preferences on your device (sidebar size, microphone language, which celebrations you have seen). No advertising or tracking cookies.
AI can be wrong
Summaries, flashcards, quizzes and tutor answers are written by AI from your slides. They can contain mistakes. Check them against your lecture and your teachers. PhysioTalk is a study tool, not medical advice — never use it to make decisions about a real patient.
Please don't upload patient information
Lecture slides only. Remove names, photos or records that could identify a real patient before uploading.
Changes and contact
If this policy changes in a way that matters, we'll say so in the app. Questions, or a request about your data? email us at ibrahim.malek.0.333@gmail.com.