Privacy Policy
Last updated: July 29, 2026
This Privacy Policy explains how LEW (“LEW,” “we,” “us”) collects, uses, and safeguards your information when you use our learning workspace application (the “Service”). LEW is currently offered as a beta. By using the Service you agree to the practices described here.
1. Who we are
LEW is a student-focused learning workspace that combines notes, study rooms, file storage, and AI-assisted study tools. A core design principle of LEW is that your files live in your own Google Drive — LEW stores references to those files, not the files themselves, except where processing is required to provide a feature you request.
2. Information we collect
We collect only what we need to run the Service:
- Google account information. When you sign in with Google, we receive your name, email address, and profile picture to create and identify your account.
- Google Drive content you choose to use. Using the
drive.filescope, LEW can only access files it creates on your behalf or files you explicitly open with LEW — it cannot see the rest of your Google Drive. This is used to store files you upload and study materials in a dedicatedLEW/folder in your Drive. Notes you write in LEW are stored in LEW’s own database, not your Google Drive. - Google Calendar events. Using the
calendar.eventsscope, LEW creates calendar events with Google Meet links when you schedule a class or study-room meeting. LEW creates these events; it does not read your broader calendar. - Content you create in LEW. Notes, study-room messages, comments, and AI chat conversations you create are stored so the Service can function.
- A LEW password, only if you choose to set one. Signing in with Google is all LEW needs; you can additionally set a LEW password so you can sign in on a shared or lab computer. If you do, we store it only as a cryptographic hash — never as readable text, and we cannot recover or tell you your password. We also keep basic sign-in security state, such as the number of recent failed attempts and whether sign-in is temporarily paused, to protect your account from someone guessing at it. You can remove your password at any time in Settings → Account.
- Usage metadata. We record limited, non-content metadata — such as feature usage counts, AI token counts, estimated costs, timestamps, and sign-in events — to operate the Service, enforce usage limits, and understand aggregate reliability and demand. This metadata does not include the contents of your files, notes, scans, or chats.
3. How we use AI and OCR (important disclosure)
Some optional features send content to Google Cloud services to generate a result you requested:
- AI Study Tools & AI Assistant. When you run Summarize, Flashcards, or Quiz on a file, or attach a file to the AI Assistant, LEW sends the contents of that file to Google Vertex AI (Gemini) to generate the study material or answer. For some requests the file is first handled by LEW’s own background worker (hosted on Render — see Section 5), which receives it only to pass it to Gemini and return the result.
- Scan to Note (OCR). When you scan an image, LEW may send that image to Google Cloud Vision to extract text.
This processing happens only when you actively invoke the feature. Google Cloud processes this data to return your result and, under the terms governing these services, does not use it to train generalized AI/ML models. Generated study results (summaries, flashcards, quizzes) are cached and tied to your account so you can view them again without re-processing; this cache is only ever shown back to you and is deleted when you disconnect Google or delete your account.
Checking a new password against known breaches. If you set a LEW password, we check it against Have I Been Pwned so we can refuse a password that has already leaked in someone else’s data breach. Your password is never sent. LEW hashes it, sends only the first five characters of that hash — a fragment shared by many hundreds of different passwords — and compares the results on our own server. That service cannot learn your password, your identity, or which account the check was for.
4. Google API Services — Limited Use disclosure
LEW’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for advertising, we do not sell it, we do not transfer it to third parties except to provide or improve the user-facing feature you requested (or as required by law), and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.
5. How your data is stored and shared
We do not sell your personal data. We share data only with the infrastructure providers (sub-processors) needed to run LEW:
- Google Cloud — Drive/Calendar APIs, Vertex AI, and Cloud Vision (as described above).
- Supabase — our PostgreSQL database, which stores your account and the LEW-created content and metadata above. Supabase also delivers real-time study-room chat.
- Vercel — application hosting.
- Render — hosts LEW’s real-time collaboration server (which delivers live note edits and comments to other collaborators) and the background worker that generates AI study results. When you use AI Study Tools on a larger file, that file is sent to this worker only to be processed into your result.
- Sentry — error and performance monitoring, so we can detect and fix crashes. It receives diagnostic data about errors (which may include limited account identifiers and technical request details); it does not receive the contents of your files, notes, or chats.
- Razorpay — payment processing, used only if and when you choose to buy Premium. Razorpay handles your card, UPI, or bank details directly to process the payment; LEW never receives or stores those details.
Your Google OAuth tokens are stored so LEW can act on your behalf and are transmitted only over encrypted connections.
Some of these providers store and process data on servers outside your country (for example, in the United States). By using LEW you consent to your information being transferred to and processed in those locations, protected by the safeguards described in this policy.
6. Data retention and deletion
You are in control of your data:
- Disconnect Google. From Settings → Account you can disconnect your Google account at any time. This revokes LEW’s access tokens and deletes cached AI results derived from your files.
- Delete your account. From Settings → Account you can permanently delete your LEW account and the data we store about you, including your password hash if you set one. Files that live in your own Google Drive remain in your Drive and are yours to keep or delete.
- Remove your password. From Settings → Account you can turn password sign-in back off at any time, which deletes the stored hash and leaves Google as the only way in.
- You may also revoke LEW’s access directly from your Google Account permissions page.
7. Security
We use encrypted connections (HTTPS) and rely on the security controls of our infrastructure providers. If you set a LEW password, it is stored using Argon2id password hashing combined with a secret key held outside the database, so the stored value cannot be turned back into your password. Repeated wrong guesses temporarily pause sign-in on that account, and you can sign out of every other device from Settings → Account if you ever think someone else has your password. No method of transmission or storage is 100% secure, but we work to protect your information and limit access to it. Because LEW is a beta, we recommend not storing highly sensitive information in it.
8. Children and students
LEW is intended for students and educators. If you are under the age required to consent to online services in your country, please use LEW only with the involvement of a parent, guardian, or educational institution. We do not knowingly collect more data than described in this policy.
9. Changes to this policy
We may update this Privacy Policy as the Service evolves out of beta. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app.
10. Contact us
Questions or requests about your data? Contact us at deeppebbletech@gmail.com.
See also our Terms of Service.