Legal

Privacy Policy

Last updated: July 29, 2026. See also Security & Data Practices and Terms of Service.

In plain language
What we collect
Your account info, the content you create, and — for platforms you connect — the assignment, grade, and schedule data your school account exposes.
What we never do
We never sell your data, never train models on private conversations, and never submit schoolwork on your behalf.
Who can see conversations
You, and a small number of support staff investigating a bug or a report — never routine browsing.
How to delete
Delete your account from Settings → Data & Privacy or email privacy@aluma.fun. See Data retention below for what happens to backups.
What the browser extension sees
Only what you turn on for that message — a selection, the page title and address, or a screenshot. With those off, nothing about the page is sent. It can never type into or submit a page.

This policy explains what Aluma collects, how we use it, who processes it on our behalf, and the choices you have. It applies to aluma.fun, app.aluma.fun, the Aluma web app, and the Lumi Anywhere Chrome extension.

What we collect

  • Account: your username or email and a securely hashed password (we never store it in plain text).
  • Your content: messages, projects, uploaded files, and preferences you create in the app.
  • Connected school and productivity accounts: when you link a platform like Google Classroom, Canvas, Schoology, Blackboard, PowerSchool, Blackbaud, Notion, or similar, Aluma reads the data you authorize (for example assignment titles, due dates, grades, and course names). Depending on the platform, access is granted through OAuth, your school's own SSO sign-in page, or a personal access token you provide; see Security for exactly how each connector type works. We do not store your school password in plain text.
  • Billing: handled by Stripe. We store your plan status and a Stripe customer ID, never your card number.
  • Usage: basic counts (such as messages per day) to enforce plan limits and understand product usage.

How we use it

  • To run the Service, store your work, generate responses, and apply your plan.
  • To generate tutoring replies, we route your messages to third party model providers listed under Subprocessors below, subject to their terms.
  • To process payments through Stripe.
  • To keep connected school and productivity accounts in sync, we periodically fetch new data using the access you granted.
  • For internal analytics — basic feature and usage counts used to run the product and understand what's working. This is not sold or used for advertising.

Subprocessors

Aluma uses a small number of vendors to operate the Service. Each processes data only to provide their service to us:

  • Anthropic (Claude API) — model inference for tutoring replies.
  • Stripe — payment processing and subscription billing.
  • Cloudflare — hosting, CDN, and DDoS protection.
  • School and productivity platforms you connect (Google, Canvas, Schoology, Blackboard, PowerSchool, Blackbaud, Notion, and others) — access is limited to the scopes you authorize, and you can disconnect at any time.

What we don't do

We don't sell your data. We don't use your private conversations to train models. Aluma does not complete or submit assignments on your behalf. The one exception is Autopilot, which can type a drafted answer into a Google Doc it has confirmed is your own editable copy — but only when you turn it on for that task, never automatically. The Lumi Anywhere Chrome extension is not a second exception: it is read-only and cannot write to any page.

Lumi Anywhere (Chrome extension)

  • Your Aluma sign-in. When you authorize the extension, your browser stores a token identifying your Aluma account. It stays on your machine and is sent only to Aluma to authenticate requests. The extension never sees or stores your password.
  • Page content you choose to share. Nothing from a page you visit is sent anywhere until you turn on Selection, This page, or Screenshot for that message. With none of them on, the page's address, title, and contents are not transmitted. What you do share is sent to Aluma to answer that message and is saved with that chat in your history, like any other conversation.

The extension reads pages only to build that optional snapshot. It never types into a page, fills a form, clicks a control, or submits anything. It stops entirely on a detected live quiz or exam. It makes network requests to Aluma only, contacting no analytics or advertising service, and it loads no code from outside the installed package.

Signing out clears the token and the saved transcript from that browser, but the token stays valid for your account until you change your Aluma password.

Academic integrity

Aluma is designed to coach students through their work, not to do it for them. Tutoring flows check understanding with follow-up questions rather than accepting an explanation at face value, and hints unlock one step at a time instead of handing over an answer. Using Aluma to violate your school's academic integrity policy is against our Terms of Service.

Your choices

  • Export: download your data anytime from Settings → Data & Privacy.
  • Delete: deleting your account permanently removes your data from our primary storage immediately.
  • Disconnect: revoke any connected school or productivity account at any time from Settings → Connectors.

Data retention & security

Your data is stored for as long as your account exists and is removed from our live, primary database on account deletion. Not currently offered: a published fixed timeline for purging deleted data from encrypted backups — contact us for current status. Passwords are hashed (PBKDF2); sessions use signed cookies; and connector access is encrypted, whether stored on your device through Lumi Anywhere or server-side in the web app (see Security for the breakdown by connector type). No system is perfectly secure, but we take reasonable measures and improve them over time.

School data processing agreements

Aluma does not currently have standard data processing agreements (DPAs) or state student-data-privacy addenda published for schools and districts. Contact us for current status if your school or district requires one.

Children

Aluma is intended for students 13+. If you're under 18, use it with a parent or guardian's involvement.

Contact

Privacy questions: privacy@aluma.fun. Security questions: security@aluma.fun.