Privacy Policy
Effective August 27, 2026
This policy explains how What Beats Learning (“we,” “us,” or the “Service”) handles information when you use its website and remote Model Context Protocol (MCP) tutoring service.
Information we collect
- Google account information. When you sign in with Google, we receive your Google account identifier, name, and email address. We do not receive or store your Google password.
- Learning content. We store the decks, cards, tags, prompts, review history, scheduling data, and generated audio and images that you or your connected AI agent create through the Service. Text submitted for speech is sent to our speech provider and stored with the resulting clip in a shared content-addressed cache, so identical requests can reuse one clip. Image subjects and drawing prompts are sent to Cloudflare Workers AI; the resulting image is stored in a shared cache keyed by subject, so later requests for the same subject reuse the first image.
- Authorization data. We process OAuth tokens, client approvals, and strictly necessary cookies so that you can sign in and connect an MCP client.
- Operational data. Our infrastructure provider may process request metadata such as IP address, user agent, timestamps, and error or security logs to deliver and protect the Service.
We do not collect payment information, address-book contacts, precise location, or advertising profiles. We do not use advertising or analytics trackers.
How we use information
We use this information only to authenticate you, keep each user’s learning library isolated, provide spaced-repetition and tutoring features, maintain security, diagnose failures, and comply with law.
Your AI agent and MCP client
The Service is designed to be used through an MCP client and AI agent that you authorize. Tool responses are returned to that client and agent. In particular, the whoami tool currently returns your name, email address, Google account identifier, and library counts. Other tools return or modify your learning content as needed to tutor you. Your MCP client, AI provider, or agent may process and retain this information under its own terms and privacy policy. Only connect clients and agents you trust.
How we disclose information
We do not sell personal information, share it for cross-context behavioral advertising, or rent it to others. We disclose information only:
- to Google for sign-in;
- to Cloudflare, which hosts the Service and its storage;
- to MiniMax or Fish Audio when you ask the Service to generate speech;
- to Cloudflare Workers AI when you ask the Service to generate an image;
- to the MCP client and AI agent you authorize, as described above;
- when required by law or reasonably necessary to protect users, the Service, or others; or
- in connection with a merger, acquisition, financing, or transfer of the Service, subject to this policy or notice of a replacement policy.
Cookies
We use only cookies needed for OAuth security, session binding, and remembering an approved MCP client. We do not use cookies for advertising or behavioral tracking.
Retention and deletion
We retain account and learning data while your library remains in the Service, and retain limited operational records as reasonably needed for security, debugging, legal compliance, and backups. You may request access, correction, or deletion through the project contact below. Deleting data from the Service does not delete copies already sent to an MCP client or AI provider; contact those providers separately.
Security
Each Google account is assigned an isolated storage object, and access requires OAuth authorization. No system is completely secure, so we cannot guarantee that information will never be lost or accessed improperly.
Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has provided information, contact us so we can delete it.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, or to appeal a denied request. We do not discriminate against anyone for exercising a privacy right. Submit a request through the contact below; we may need to verify that the request relates to your account.
Changes to this policy
We may update this policy as the Service changes. We will post the revised policy here and update its effective date. Material changes apply prospectively.
Contact
For questions or privacy requests, contact the operator through the What Beats Learning project repository. Do not include passwords, access tokens, or sensitive learning content in a public issue.