Privacy Policy
Last updated: August 25, 2026
TheoremPath is a reference and learning site for ML theory and mathematics. This page describes what data is collected, why, and how it is handled.
What we collect
- Anonymous usage analytics. Page views, referrers, device type, and country via Vercel Analytics. No cookies, no advertising profiles. We do not use these measurements to follow your activity on other sites.
- Product analytics. On the website, PostHog receives bounded events such as landing views, search result-count buckets, account starts, and diagnostic completions. Its web client uses an opaque identifier in first-party local browser storage. In the signed-in iOS app, PostHog receives app lifecycle and explicit product-interaction events associated with the Clerk user ID and a device analytics identifier. The app does not send your email to PostHog. Automatic element and screen capture, session replay, and error capture are disabled.
- Performance metrics. Core Web Vitals via Vercel Speed Insights. Aggregated, not tied to identity.
- Error reports. Client and server errors via Sentry. May include request path and a sanitized stack trace.
- Account data (optional). If you sign in, we store your email and authentication provider ID via Clerk for authentication and progress tracking. If you start web checkout, we also send your account email, optional name, and internal TheoremPath account identifier to Stripe to create and reconcile the billing customer and subscription.
- Diagnostic and progress data (if signed in). Your diagnostic answers, review schedule, and topic completion are stored so you can resume later.
- Billing and entitlement records. When you start or manage a subscription, we store the payment provider, provider customer, subscription, product, and transaction identifiers; subscription status and period dates; an App Store account token; and hashed signed-payload and webhook audit metadata. Stripe or Apple processes the payment. TheoremPath does not store full card numbers or card security codes.
What we do not collect
- No advertising identifiers.
- No social graph or contact list uploads.
- No selling or sharing of personal data with advertisers.
Information you submit
Notes, diagnostics, search queries, contact messages, and model-assisted prompts can contain text you choose to enter. Do not include sensitive personal information, confidential information, or proprietary material in these fields.
Cookies
We use first-party cookies for authentication through Clerk. Theme preference and PostHog product analytics use first-party local browser storage. The PostHog cookie is disabled, but its opaque local-storage identifier persists in your browser for product analytics. We do not use third-party advertising cookies.
Data retention
Usage analytics are retained for 12 months. Error reports are retained for 90 days. Signed-in users can delete their account from the profile page. Self-service account deletion removes the local account row and cascades saved topics, notes, progress, quiz attempts, review cards, and mastery assessments; it also deletes the associated Clerk sign-in account. Billing and reconciliation records may be retained after account deletion when needed for payment reconciliation, fraud prevention, disputes, accounting, or other legal and operational obligations. The local user link is removed from those retained records. Account deletion does not cancel renewal with Stripe or Apple; cancel through the provider first. For a broader verified deletion request covering logs, backups, processor records, or data not reachable from the account UI, contact us via the contact page. Broader verified deletion requests will be completed within 30 days.
Processors we use
- Vercel (hosting and analytics)
- PostHog (bounded product analytics)
- Cloudflare (DNS, edge)
- Clerk (authentication)
- Neon (Postgres database hosting)
- Upstash (request rate limiting)
- Sentry (error reporting)
- Stripe (web checkout, subscription management, and payment processing)
- Apple (App Store subscription, payment, refund, and signed transaction services)
- OpenAI (embeddings): public keyword search may be available without sign-in. Semantic search, when active, may require sign-in and may send the submitted query to OpenAI's embedding API (
text-embedding-3-large) to produce a vector. Results may be served from a cached embedding when the same query has been seen recently. - OpenAI and Groq (generation): experimental model-assisted features may use third-party model providers when those features are active. The integration does not add your Clerk account ID or email to model-provider requests. User-submitted prompts or queries may still contain personal information if you include it.
Your rights
You can delete your account from the profile page. You can also request access to, correction of, or broader deletion of your data by contacting us via the contact page. Where applicable, users may have rights to access, correct, delete, or restrict certain personal data. TheoremPath accepts verified access, correction, and deletion requests regardless of jurisdiction, subject to legal obligations and technical limits.
Changes
Material changes to this policy will be announced on the homepage and dated above. Continued use after notice constitutes acceptance.