Privacy Policy

Last updated: August 3, 2026

This policy describes how Sitor handles personal data when you use sitor.ai and the services connected to it. The services you choose determine which categories of data and providers are involved.

01Information We Collect

We collect account identifiers and contact details, including your email address and the profile information returned when you choose Google or GitHub sign-in. We also process authentication logs, IP address, browser and device information, product interactions, error and performance diagnostics. When you use Sitor, we store the content needed to provide the service: prompts and conversations, learning plans and progress, mastery results, learner profile and memory data, uploaded documents, images, audio/video references, repository content or metadata you choose to import, and generated outputs. Voice or audio is processed only when you choose a voice, transcription, speaking, podcast, or other audio feature. Stripe receives payment details directly; Sitor stores billing identifiers, plan, status, transaction, and entitlement records rather than complete card numbers.

02How We Use Information

We use this information to create and secure accounts; provide AI tutoring, material and repository analysis, search, voice and generation features; personalize study plans; track progress and usage limits; process purchases and subscriptions; provide support; prevent abuse; diagnose failures; and understand product usage. We do not sell learning content or personal data, and we do not use it for third-party advertising.

03Hosting, Storage & International Processing

The sitor.ai web application is delivered through Vercel, the API runs on Fly.io with a primary deployment region in Singapore, and overseas authentication, PostgreSQL data, and learning-material storage use Supabase. User-uploaded learning documents and repository archives are stored in non-public object storage; Sitor issues short-lived signed links when authenticated display or processing requires access. Some profile or course-pack files may use Vercel Blob. Service logs, backups, caches, and provider systems may be stored separately. Requests may be processed in Singapore, the European Union, the United States, China, or other locations used by the selected provider. This can include cross-border transfers from your country. We use transport encryption and access controls, but no internet transmission or storage system can be guaranteed completely secure.

04Service Providers & AI Data Flow

Current infrastructure includes Supabase (authentication, database, and object storage), Fly.io (API hosting), Vercel (web delivery, blob storage where used, and AI gateway functions), Cloudflare (isolated code-sandbox execution for supported desktop-web features), Stripe (checkout, subscription, and billing), Google and GitHub (optional sign-in), PostHog Cloud EU (product analytics and feature flags), Langfuse Cloud US (AI-request tracing and diagnostics), and Resend or configured email delivery services. Instrumented tutoring requests can send Langfuse the Sitor user and session identifiers, the user's prompt, model and trace metadata, token usage, and step diagnostics. Depending on the feature and current configuration, relevant prompts, conversation context, search queries, uploaded text or files, images, repository content, code or task context submitted for sandbox execution, audio, or video may be sent to the selected AI model, OCR, search, transcription, speech, media-processing provider, code-sandbox provider, and any necessary API gateway. These may include DeepSeek; Google, OpenAI, Anthropic, Alibaba Cloud/Qwen, MiniMax, Groq, or VolcEngine services; Vercel AI Gateway, OpenRouter, unity2.ai, or nbility.dev gateways; Cloudflare for sandbox execution; Tavily or Jina for web search and reading; and MineRU or video-transcript services for material extraction. A provider is involved only when required by the feature or model route being used. Provider terms and privacy practices apply to their processing.

Selected official privacy notices for principal account, infrastructure, payment, analytics, and model providers:

05Retention

We retain account and learning data while your account is active and for as long as reasonably needed to provide the service, maintain security, resolve disputes, and satisfy payment, tax, accounting, or other legal obligations. Retention varies by data type and provider. When you delete your account, Sitor queues deletion of Langfuse traces linked to your Sitor user identifier and performs a delayed provider query to verify removal because trace deletion is asynchronous. After account deletion, some records may remain for a limited time in backups, fraud-prevention systems, transaction records, or provider deletion cycles where retention is required or technically necessary.

06Your Choices & Requests

Depending on where you live, you may have rights to request access to, correction of, a copy of, or deletion of personal data, and to object to or restrict certain processing. You can delete your Sitor account from Settings or contact us at sanyuan0704@gmail.com. We may need to verify your identity and may retain information where law or a legitimate security, billing, or dispute-resolution need requires it.

07Cookies & Product Analytics

Sitor uses browser storage and cookies for authentication, security, language, preferences, and service operation. The current web configuration also uses PostHog Cloud EU with cookies/local storage, page views, autocapture, product events, diagnostics, and feature flags; session recording is disabled. Blocking storage or cookies may prevent sign-in or other features from working correctly.

08Contact & Policy Changes

Questions or privacy requests can be sent to sanyuan0704@gmail.com. We may update this policy as the product, providers, or legal requirements change. The date above identifies the current version, and material changes will be communicated where required.