Privacy Policy
Last updated: August 8, 2026
Introduction
Semora ("we", "our", "us") is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information when you use our applications and websites.
Information We Collect
We collect the following information:
- Account information: Email address and password (encrypted) when you create an account.
- Academic data: Semesters, courses, tasks, grades, and syllabus content that you enter or scan.
- Learning-platform data (optional): If you choose to connect Canvas, Blackboard, Moodle, or Google Classroom, we retrieve the courses and assignments you select to import or sync. The imported information is stored as academic data in your Semora account.
- Device information: Timezone, device type, and operating system version for app functionality.
- Syllabus files: Documents you upload for AI-powered scanning. These are processed to extract deadlines and are not shared with third parties beyond the AI processing services named below.
- Study notes: Lecture notes or slides you optionally upload to the AI Tutor. These are stored privately in your account and used only to answer your questions about that course.
- Lecture recordings (optional):If you choose to record a class, Semora captures the audio around you — which includes your instructor's voice and anyone speaking nearby. The audio is stored privately in your account only until it has been transcribed, and is then deleted automatically. Recording never starts until you tap Record and confirm you have permission to record.
- Lecture transcripts and generated study material: The text transcript of a recording, plus the notes, quizzes, and flashcards generated from it. These stay in your account until you delete the recording or your account.
- Usage analytics: Anonymous events (e.g. a page viewed, a scan completed, a paywall viewed) tied to a random identifier, never to your name or email, to help us understand which features are used and improve the app. On this website that identifier is stored in a first-party cookie named
semora_device_id, set onsemoraai.comso the website and the app recognise the same browser and we can tell whether a page actually helped someone get started. It is a random number, it is never sold, and clearing your browser data removes it. The website also uses Google Analytics, which sets its own first-party cookies (their names begin_ga) to count visits and tell one visit apart from the next; thesemora_device_idabove is deliberately not sent to Google, so the two measurements cannot be joined into a profile of you. No advertising cookie is set on any Semora site, and nothing measured here is used for ad targeting. - Push notification token: If you grant notification permission, a device push token so we can send occasional reminders about upcoming deadlines and new semesters.
- Referral data: If you use an invite link, the referral code and the fact that two accounts are linked, so we can grant the free-month reward.
How We Use Your Information
- To provide and maintain the app's core functionality (task management, grade tracking, calendar sync).
- To process syllabus documents using AI to extract course information and deadlines.
- To send you local notification reminders about upcoming deadlines, and, if you grant permission, occasional push reminders about deadlines and new semesters.
- To sync tasks with your device calendar, and, if you connect it, with Google Calendar.
- To import and sync the courses and assignments you choose from a connected learning platform.
- To power study tools you choose to use (flashcards, focus timer, and an AI tutor grounded on your syllabus and any notes you upload).
- To transcribe class lectures you choose to record, and to generate notes, quizzes, and flashcards from those transcripts.
- To apply referral rewards when you invite friends.
Data Storage and Security
Your data is stored securely on Supabase (hosted on AWS). Authentication tokens are stored in your device's secure keychain (iOS Keychain / Android Keystore). We use row-level security to ensure you can only access your own data.
Third-Party Services
- Supabase: Database and authentication provider.
- OpenAI GPT-5.6 Luna:Semora's text AI provider. It reads your syllabus documents, generates flashcards, practice questions and quizzes, writes your lecture notes, and answers your questions in the AI Tutor. Your syllabus content, any study notes you choose to upload, and lecture transcripts are sent to the OpenAI API for processing. OpenAI states that API data is not used to train its models unless a customer explicitly opts in. Semora disables response storage for these requests; OpenAI may still retain abuse-monitoring logs for up to 30 days unless a stricter retention control applies to the account.
- Groq (speech-to-text):Used only if you record a lecture. The audio of that recording is sent to Groq's transcription API to be converted into text, along with the title you gave the recording and the last few sentences already transcribed — those help the transcription keep names and terminology consistent across a long lecture. Transcription is the only purpose your audio is used for, and Groq is the only service it is sent to. Nothing else from your account — no syllabus, no notes, no tutor messages — is sent to Groq.
- Google Analytics (website only): Used on
semoraai.comto measure which pages and which channels actually bring people to Semora. Google receives the address of the page viewed, the events described above, and the technical data any web request carries — including the request's IP address, which Google Analytics 4 uses to derive an approximate location and does not store. It does not run inside the app, and it never receives your account data. - Apple StoreKit: For processing in-app subscription purchases.
- Expo push service: Delivers push notifications to your device if you enable them.
- Google Calendar (optional): If you connect Google Calendar, we access your calendar solely to add and update your Semora deadlines; we do not read your other events.
- Learning platforms (optional): Canvas, Blackboard, Moodle, and Google Classroom provide the course and assignment data you choose to sync. Automatic sync is on from the moment you connect one, so the credential you provide is stored encrypted in Supabase Vault at that point rather than only if you later switch something on. That is what lets Semora notice a deadline your instructor moved while the app is closed; a connection whose credential never reached the Vault would import once and then go quiet. It is never exposed in your Semora account, never written to a log, and never sent to analytics, and we delete it when you turn off Automatic sync or disconnect the platform.
- What that credential is, for Canvas and Moodle:a private calendar link rather than a password — you never type your Canvas or Moodle password into Semora. Two things are worth knowing about it. Anyone holding the link can read your course calendar, which is why we store it the way we do. And on Moodle the link is derived from your account, so disconnecting in Semora deletes our copy but does not invalidate the link itself; changing your Moodle password is what retires it. Canvas lets you reset your calendar feed from Canvas's own settings at any time.
Data Retention
Your data is retained as long as your account is active. You can delete your account and all associated data at any time through the app's settings (Me tab > Delete Account).
Lecture audio is the exception, and is deleted sooner. The recording itself is removed from our storage as soon as its transcript has been created — usually within a few minutes of you stopping the recording. Only the transcript and the study material generated from it remain, and those are deleted when you delete the recording or your account.
Your Rights
You have the right to:
- Access your personal data through the app.
- Delete your account and all data permanently.
- Export your data by contacting us.
Children's Privacy
Semora is intended for college and university students. We do not knowingly collect information from children under 13.
Changes to This Policy
We may update this policy from time to time. We will notify you of any changes by posting the new policy in the app.
Contact Us
If you have questions about this privacy policy, please contact us at semora365@gmail.com.