Last updated: August 26, 2026

Privacy Policy

Classmax is a study tool. A Chrome extension reads your university's learning platform while you are signed in to it and copies your coursework into a web app, where an AI assistant can answer questions about it. This policy explains exactly what that involves: what we collect, why, how long we keep it, and every company it reaches.

Classmax is operated from the United Kingdom and is the data controller for the information described here. Questions, requests and complaints: privacy@classmax.ai.

What we collect, and why

Account and preferences

Your email address, display name, and optionally your institution. Your password is handled by our login provider and stored only as a salted hash; we never see it. Alongside this we store the settings you choose: language, grading scale and how you want grades worded, theme and colour palette, term dates, and any facts you add under "About you" so the assistant remembers them. Used to give you an account, keep you signed in, and make the product behave the way you set it.

Your coursework

Course names and codes, assignments and their descriptions, due dates, announcements, the grades your platform shows you, and your course materials, including the full text we extract from documents, slides and PDFs. Used to build your dashboard and calendar, and to give the AI the context that makes its answers specific to your courses. This is the core of the product; without it Classmax is a generic chatbot.

Things you create

Files you upload to your Library and the text extracted from them. Drafts you write or import into Draft Review, the feedback and estimated grade produced for them, any real mark you record, and any brief you paste in. Your chat history. Study sets, flashcards, practice exams and your attempts at them. Bug reports you send, including which page you were on. Used to provide those features and to let you return to your work later.

Billing

If you subscribe, we store your subscription status, plan, renewal date, and the customer and subscription identifiers Stripe gives us. Your card details are entered on Stripe's payment form and go to Stripe directly; they never touch our servers and we cannot see them. We also store any promo or referral code you use and how many referrals you have earned.

Product analytics

We record events describing how the product is used, for example that a draft review was requested or a study set was created, along with non-content details such as how many characters a draft had. These events are stored against your account and are not anonymous. We do not put the content of your work in them. Used to see which features are actually reached and which are broken.

Link clicks

When you follow one of our short links, we record which link, the time, and the host that referred you, for example "instagram.com". No account, no cookie, no IP address, no device fingerprint. This is counted before anyone signs up and cannot be tied to a person.

Stored in your browser

The extension keeps your Classmax session token, which university platform you connected, and sync progress in Chrome's extension storage. That stays on your computer. Removing the extension removes it.

How the extension reads your platform

The extension runs on your university's learning platform pages while you are already signed in there, and reads the same content the page shows you. It also downloads attached files, such as assignment briefs, to extract their text. It requests permission for Blackboard, Canvas and Moodle addresses, and for your Classmax tab so it can read your Classmax session. If your university uses an address we do not list, you can grant access to that specific site yourself. Nothing is read from a site you have not connected.

We never receive your university password. The extension uses the session already present in your own browser. It sends the coursework it reads to our servers over HTTPS. It does not read pages unrelated to your coursework, and it does not send anything to anyone other than Classmax.

Who we share it with

This is the complete list. These are service providers acting on our instructions, not independent users of your data. We share your data with no one else.

  • Supabase

    Receives: Everything you store in Classmax: account, coursework, files, drafts, chats, preferences, analytics events.

    Why: Our database, login and backend run on Supabase. It is where your data lives.

  • Anthropic (Claude)

    Receives: Your message or draft, plus the course context relevant to it, at the moment you use an AI feature.

    Why: Generates chat replies, draft feedback, flashcards, practice questions and brief summaries.

  • Voyage AI

    Receives: The text of your course materials and uploaded files.

    Why: Turns them into a search index so the assistant can find the right passage.

  • Stripe

    Receives: Your email and name, and your card details, which go from your browser to Stripe directly and never reach our servers.

    Why: Takes subscription payments and manages billing.

  • Cloudflare

    Receives: Standard request data: IP address, browser user agent, and the pages requested.

    Why: Serves classmax.ai and app.classmax.ai and protects them from abuse.

  • Discord

    Receives: Operational alerts only: the domain of a new signup (for example "regents.ac.uk", never the address), how you heard about us, and counts.

    Why: Tells us a signup or a sync happened so we can spot breakage early.

Anthropic and Voyage AI process what we send in order to produce a result and, under their API terms, do not train their models on it. We may also disclose data where we are legally required to, or if Classmax is ever acquired or merged, in which case we will say so on this page before your data moves.

Limited use

Data the Classmax extension collects is used only to provide and improve the features described in this policy. It is never sold, never transferred for advertising, never used to determine creditworthiness or for lending, and never used to train third-party AI models. Humans do not read your content except where you explicitly ask us to look at something, where it is necessary for security, or where the law requires it.

What we never do

  • We do not sell your data.
  • We do not use your data to train AI models, and our providers do not either.
  • We do not share your data with your university, your instructors, or anyone at your institution.
  • We do not share your data with other Classmax users. Every table is protected by row-level security tied to your account, so your account can only ever read its own rows.
  • We do not see or store your university password.
  • We do not run advertising, and we use no third-party advertising or tracking cookies.

How long we keep it

Your coursework, files, drafts and chats are kept while your account exists, so the product works when you come back. Re-syncing refreshes your coursework and replaces what was there before. Billing records are kept for as long as tax and accounting law requires, normally six years, even after you close your account. Link-click records contain no personal data and are kept as aggregate counts. Everything else is deleted within 30 days of you asking us to close your account.

Where it is stored

Your data is stored in encrypted Supabase Postgres databases and served through Cloudflare. Our providers operate in the United States and the European Union, so your data is transferred internationally and is protected by the standard contractual clauses those providers offer. Connections to and from our servers use HTTPS/TLS, and access is enforced by row-level security policies at the database level.

Your rights and your choices

You can ask us for a copy of your data, for corrections, for deletion, or for us to stop processing it. Email privacy@classmax.ai and we will act within 30 days. If you are in the UK or the EU you also have the right to object, to restrict processing, to data portability, and to complain to your data protection regulator, which in the UK is the Information Commissioner's Office.

You can disconnect at any time by removing the Classmax extension, which stops all reading of your university platform immediately. To close your account and have its data deleted, email us at the address above and we will do it within 30 days. There is no self-service delete button in the app; the request goes to a person.

Age requirement

Classmax is intended for university students aged 18 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has created an account, email privacy@classmax.ai and we will delete the account and its data.

Changes to this policy

If we change what we collect or who we share it with, we will update this page and the date at the top. If the change is significant we will tell you in the app before it takes effect.

Contact

privacy@classmax.ai