Privacy Policy
Last updated: December 18, 2025
1. Introduction
QtpiAI ("we," "us," or "our") operates an online math contest preparation platform designed to help students prepare for Waterloo CEMC math competitions including Gauss, Pascal, Cayley, and Fermat contests.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website, mobile applications, and related services (collectively, the "Service").
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Password (stored in hashed format; we never store plain-text passwords)
- Display name
- Grade level
- Target contest(s) you are preparing for
2.2 Usage and Performance Data
As you use our Service, we collect:
- Practice question attempts and answers selected
- Time spent on questions and study sessions
- Accuracy rates and performance metrics
- Topic-level accuracy and progress over time
- Contest practice history and scores
2.3 AI Conversation Data
When you interact with our AI tutor, we collect and store:
- Chat messages you send to the AI tutor
- AI tutor responses
- The specific question context associated with each conversation
2.4 Payment Information
Payment processing is handled by Stripe, a PCI-compliant payment processor. We do not store your credit card numbers, bank account details, or other sensitive payment information on our servers. We receive from Stripe:
- Subscription status and plan type
- Billing cycle dates
- Transaction history (amounts and dates)
- Last four digits of payment card (for display purposes only)
2.5 Automatically Collected Information
When you access our Service, we automatically collect:
- Device information (browser type, operating system, device type)
- IP address and approximate geographic location
- Pages visited and features used
- Referring website or source
- Date and time of access
- Cookies and similar tracking technologies
3. How We Use Your Information
We use the information we collect to:
3.1 Provide and Improve Our Service
- Create and manage your account
- Deliver practice questions and contest preparation materials
- Power our AI tutor to provide personalized explanations
- Track your progress and generate performance analytics
- Improve our question database and learning algorithms
3.2 Personalize Your Experience
- Recommend practice questions based on your performance
- Identify topics that need more practice
- Adapt difficulty levels to your skill level
- Provide targeted feedback and study suggestions
3.3 Process Payments
- Process subscription payments through Stripe
- Manage subscription status and billing cycles
- Send payment receipts and invoices
3.4 Communicate With You
- Send essential account notifications (password resets, security alerts)
- Provide subscription and billing information
- Respond to your support requests
- Send important service updates
3.5 What We Do NOT Do
- We do NOT sell your personal information to third parties
- We do NOT share your data with advertisers
- We do NOT use your data for targeted advertising
- We do NOT disclose student performance data to schools or universities without explicit consent
4. AI Tutor
Our AI tutor is powered by Anthropic's Claude API. Here is important information about how it works:
4.1 Conversation Storage
Your conversations with the AI tutor are stored in our database and are tied to specific practice questions. This allows you to revisit explanations and continue conversations where you left off.
4.2 Quality Improvement
We may review AI tutor conversations to improve the quality of explanations and identify areas where the AI can be enhanced. Any such review is conducted to improve the Service and is not used for advertising or sold to third parties.
4.3 AI-Generated Content
Responses from the AI tutor are generated by artificial intelligence and are not reviewed by humans in real-time. While we strive for accuracy, AI responses may occasionally contain errors. The AI tutor is designed to assist with learning, not to replace professional tutoring or guarantee specific contest results.
4.4 Data Sent to Anthropic
When you use the AI tutor, your messages and the relevant question context are sent to Anthropic's servers in the United States for processing. Anthropic's privacy practices are governed by their own privacy policy. We have agreements in place to protect your data.
5. Data Sharing and Disclosure
5.1 Third-Party Service Providers
We share your information with the following third-party service providers who help us operate our Service:
- Supabase - Database hosting and user authentication (servers in US/Canada)
- Anthropic - AI tutor functionality via Claude API (US-based)
- Stripe - Payment processing (PCI-DSS compliant)
- Vercel - Website hosting and delivery (global edge network)
These providers are contractually obligated to protect your data and may only use it to provide services to us.
5.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid legal requests, such as:
- Court orders or subpoenas
- Government or law enforcement requests
- To protect our rights, privacy, safety, or property
- To investigate potential violations of our Terms of Service
5.3 Business Transfers
If QtpiAI is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service before your information becomes subject to a different privacy policy.
5.4 No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
6. Children's Privacy
Our Service is designed for students, including those under 18 years of age. We take the privacy of minors seriously.
6.1 Parental Consent
For users under 18 years of age, we require parental or guardian consent before creating an account. Parents or guardians are the account holders and are responsible for managing their child's account.
6.2 Parental Rights
Parents and guardians have the right to:
- Review their child's personal information
- Request correction of inaccurate information
- Request deletion of their child's account and data
- Refuse further collection or use of their child's information
- Receive a copy of their child's data
To exercise these rights, please contact us at the email address provided below.
6.3 PIPEDA Compliance (Canada)
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal privacy law. This includes:
- Obtaining meaningful consent for data collection
- Limiting collection to what is necessary for identified purposes
- Using data only for the purposes for which it was collected
- Keeping data accurate, complete, and up-to-date
- Protecting data with appropriate security safeguards
- Being open about our privacy practices
- Providing access to personal information upon request
6.4 COPPA Compliance (United States)
For users in the United States, we comply with the Children's Online Privacy Protection Act (COPPA). For children under 13:
- We require verifiable parental consent before collecting personal information
- Parents can review, modify, or delete their child's information at any time
- We collect only the information necessary to provide the Service
- We do not condition participation on disclosure of more information than necessary
6.5 Data Minimization for Minors
We limit the personal information collected from minors to what is necessary to provide our educational services. We do not require real names—users may use a display name of their choosing.
7. Data Retention
7.1 Active Accounts
We retain your personal information for as long as your account remains active and as necessary to provide you with our Service.
7.2 Account Deletion
When you delete your account:
- Your personal information (email, display name, profile data) is deleted within 30 days
- Your practice history and AI conversation data are deleted within 30 days
- Anonymized, aggregated data may be retained for analytics and service improvement
- We may retain certain information as required by law or for legitimate business purposes (e.g., fraud prevention, resolving disputes)
7.3 Payment Records
Transaction records may be retained for up to 7 years to comply with tax and accounting requirements.
7.4 Backup Systems
Deleted data may persist in backup systems for up to 90 days before being permanently removed.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
8.1 Right to Access
You can request a copy of the personal information we hold about you.
8.2 Right to Correction
You can request that we correct inaccurate or incomplete personal information. You can also update most of your information directly in your account settings.
8.3 Right to Deletion
You can request deletion of your account and personal information. You can also delete your account directly from your account settings.
8.4 Right to Data Portability
You can request an export of your data in a commonly used, machine-readable format.
8.5 Right to Withdraw Consent
Where we rely on consent to process your data, you can withdraw that consent at any time.
8.6 How to Exercise Your Rights
To exercise any of these rights, please contact us at the email address below. We will respond to your request within 30 days. We may need to verify your identity before processing certain requests.
8.7 Complaints
If you have concerns about how we handle your data, you may file a complaint with us. Canadian users may also file a complaint with the Office of the Privacy Commissioner of Canada. Users in other jurisdictions may contact their local data protection authority.
9. Security
We take the security of your personal information seriously and implement industry-standard measures to protect it:
- Encryption - All data transmitted between your browser and our servers is encrypted using TLS/SSL
- Password Security - Passwords are hashed using secure algorithms; we never store plain-text passwords
- Secure Authentication - We use secure session management and offer email verification
- Access Controls - Access to personal data is limited to authorized personnel who need it to perform their job functions
- Infrastructure Security - We use reputable cloud providers with strong security practices and compliance certifications
- Regular Monitoring - We monitor our systems for security threats and vulnerabilities
While we implement these safeguards, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
10. International Users
QtpiAI is operated from Canada. If you access our Service from outside Canada, please be aware that your information may be transferred to, stored, and processed in Canada and the United States, where our servers and third-party service providers are located.
By using our Service, you consent to the transfer of your information to these countries, which may have different data protection laws than your country of residence.
We take steps to ensure that your data receives an adequate level of protection in the jurisdictions in which we process it, including through contractual arrangements with our service providers.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons.
When we make changes:
- We will update the "Last updated" date at the top of this page
- For significant changes, we will notify you via email or a prominent notice on our Service
- We encourage you to review this policy periodically
Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
QtpiAI Privacy Team
Email: privacy@qtpiai.com
We will respond to your inquiry within 30 days.
For Canadian users with unresolved privacy concerns, you may also contact the Office of the Privacy Commissioner of Canada:
Office of the Privacy Commissioner of Canada
Website: www.priv.gc.ca
Phone: 1-800-282-1376