Legal

Privacy Policy

Last updated: May 26, 2026

This policy explains what Aluma collects, how we use it, who processes it on our behalf, and the choices you have. It applies to aluma.fun, app.aluma.fun, and the Aluma desktop and web apps.

What we collect

  • Account: your username or email and a securely hashed password (we never store it in plain text).
  • Your content: messages, projects, uploaded files, and preferences you create in the app.
  • Connected school and productivity accounts: when you link a platform like Google Classroom, Canvas, Schoology, Blackboard, Notion, or similar, Aluma reads the data you authorize (for example assignment titles, due dates, and course names). OAuth tokens are stored encrypted at rest. Aluma does not store your school password.
  • Billing: handled by Stripe. We store your plan status and a Stripe customer ID, never your card number.
  • Usage: basic counts (such as messages per day) to enforce plan limits.

How we use it

  • To run the Service, store your work, generate responses, and apply your plan.
  • To generate tutoring replies, we route your messages to third party model providers listed under Subprocessors below, subject to their terms.
  • To process payments through Stripe.
  • To keep connected school and productivity accounts in sync, we periodically fetch new data using the OAuth tokens you granted.

Subprocessors

Aluma uses a small number of vendors to operate the Service. Each processes data only to provide their service to us:

  • Anthropic (Claude API) — model inference for tutoring replies.
  • Stripe — payment processing and subscription billing.
  • Cloudflare — hosting, CDN, and DDoS protection.
  • School and productivity platforms you connect (Google, Canvas, Schoology, Blackboard, Notion, and others) — access is limited to the scopes you authorize, and you can disconnect at any time.

What we don't do

We don't sell your data. We don't use your private conversations to train models. Aluma does not write into your school documents or submit assignments on your behalf.

Your choices

  • Export: download your data anytime from Settings → Data & Privacy.
  • Delete: deleting your account permanently removes your data from our storage.
  • Disconnect: revoke any connected school or productivity account at any time from Settings → Connectors.

Data retention & security

Your data is stored for as long as your account exists and is deleted on account deletion. Passwords are hashed (PBKDF2); sessions use signed cookies; OAuth tokens for connected accounts are encrypted at rest. No system is perfectly secure, but we take reasonable measures and improve them over time.

Children

Aluma is intended for students 13+. If you're under 18, use it with a parent or guardian's involvement.

Contact

Privacy questions: privacy@aluma.fun.