1. What this policy covers
This Privacy Policy explains what InterStand collects when you use the website at interstandus.com, the web reader, and the InterStand browser extension for Google Chrome and Microsoft Edge; why we collect it; how long we keep it; and the choices you have. It is the privacy policy referenced in our extension store listings. nexaEd LLC, which operates InterStand, is the controller of the personal data described here.
It does not cover the websites you read with the extension, your browser, or the extension stores. Each of those has its own privacy policy.
2. Data we store
Account: your email address, display name, sign-in method, email verification status, account role, language and usage preferences, and a one-way hash of your password (never the password itself). If you continue with Google, we receive the email address and basic profile that Google shares.
Learning sessions: the text you selected, your question or chosen action, the AI answer, the language, timestamps, and the source (the page's address and title, or the document title). For a bounded period we also keep the surrounding context sent with your request. Elements and flashcards you create are derived from these sessions and keep only the site's domain as their source.
Web reader shelf: only metadata about the documents you open (title, category, reading progress, when you last opened it). The document content itself stays in your browser.
Billing: the customer, subscription, order, and invoice identifiers our payment providers give us, together with the amount, currency, product, status, and timestamps. We never store card numbers, CVV codes, or bank details.
Usage: which actions you ran, how they were funded (free allowance, plan allowance, or Points), and your Points balance and grants.
Messages: what you send through the contact form, cancellation feedback, and the extension uninstall survey, with the email address you provide.
Technical data: to keep the service available and to stop abuse, our servers process the IP address, browser type, requested route, and time of each request. Sign-in, registration, password-reset, contact, and survey requests are rate-limited by IP address with short-lived counters. Request logs are kept for a limited period, are used only for operations and security, and never contain learning content.
3. What the browser extension can access
The extension asks your browser for a small set of permissions, each with one job:
- Run on the websites you visit (all sites, the active tab, and scripting): the selection menu has to be available wherever you read, so the extension can load on any page and, when you open its popup, on the page already in front of you. It reads nothing until you select text and choose an action.
- Context menus: to offer InterStand actions in the right-click menu.
- Storage: to keep your sign-in token, settings, and tutorial progress inside the extension. In store terminology, the token is authentication information; it never leaves the extension except to reach our servers.
- Side panel and tabs: to open the answer panel, return you to the page you were reading, and finish sign-in in the tab where you approved it.
- Network access to interstandus.com only: the extension talks to no other server.
When you choose an action, the extension sends the selected text, a short passage around it, the page's address and title, the action, and any question you typed to InterStand. In store terminology this is website content, and it is the only website content the extension collects. The page's address and title are stored with your learning session; the surrounding passage is deleted after 30 days, and Elements keep only the site's domain. The extension never reads password, payment, or one-time-code fields, and it does not capture text from areas it recognizes as private.
The extension does not collect your browsing history, does not track the pages you visit, and does not read pages in the background. After you sign in, it reports three events so we can tell whether setup works: whether the tutorial was completed, whether a paywall notice was shown, and whether a request failed to reach our servers. These events carry no page content. When you remove the extension, your browser may open our farewell page; its address carries only the extension version and your language.
We use what the extension collects only to provide and improve the features you use. We do not sell it, use it for advertising, or use it to assess creditworthiness, and no one at InterStand reads your selected text or answers unless you ask us for help, we are investigating abuse or a security incident, or the law requires it: our staff tools have no screen that shows them, and the production database can only be reached from our own servers. InterStand's use of information received from the extension, and of information received from Google APIs when you sign in with Google, adheres to the Chrome Web Store User Data Policy and the Google API Services User Data Policy, including their Limited Use requirements, and to the corresponding Microsoft Edge Add-ons policies.
4. How we use it
We use this data to run the service: generate answers, keep your learning library, apply your allowances and Points, process payments, keep your account secure, answer your messages, and meet legal obligations such as tax and fraud-prevention records.
Where the GDPR or a similar law applies, we rely on our contract with you for running the service, on your consent for product-update emails, on legal obligations for billing and tax records, and on our legitimate interests for security, abuse prevention, and understanding how the service is used. We do not make decisions about you by automated means that have legal or similarly significant effects.
We also look at aggregated, anonymized usage to understand how InterStand is used and to improve it. Learning content (selected text, answers, Elements, flashcards) never enters logs, analytics events, or error reports. We do not use your learning content for research across users or to train models. If we ever start aggregate product research on learning content, it will use de-identified data and you will be offered a way to opt out.
Saving your learning history is not consent to personalization, advertising, or model training. Features that would use your history to personalize answers are off, and we will ask before enabling any.
5. AI processing and service providers
To generate an answer we send the selected text, your question, a short surrounding passage, and the page's address and title to our AI provider, currently OpenAI, through its API. The request does not contain your name, email address, or account identifier. Under the provider's API terms the content is not used to train its models; the provider may keep it for up to 30 days to monitor abuse.
Other providers that process data for us:
- Google provides sign-in when you choose Continue with Google; we use the email address and basic profile it shares only to create your account and sign you in;
- Stripe and PayPal process payments and hold your payment details;
- Resend delivers our transactional emails (verification, password reset, contact replies) and any product-update emails you opt into;
- Cloudflare provides Turnstile (bot protection on forms) and Web Analytics on the marketing pages;
- Amazon Web Services hosts the service and its database in the United States.
These providers may process data in the United States and in other countries. We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share it only with providers that act on our instructions, when the law requires it, to protect the service against fraud or attack, or at your direction. If InterStand is ever transferred to a new owner, your data may be transferred with it, and we will tell you before that happens.
6. How long we keep it
- Surrounding context and detailed source evidence attached to a learning session are redacted 30 days after capture, even for saved sessions; the transcript (selected text, question, answer) stays.
- An unsaved learning session is kept for 180 days after its last activity, then removed. Sessions you save or archive stay until you delete them.
- Items you move to Trash can be restored for up to 30 days, then they are permanently deleted. Permanent delete removes them immediately.
- Unused generated Elements are removed 30 days after creation unless you interact with, save, or keep them.
- Account data is kept while your account exists. When you delete your account, sessions end immediately and permanent deletion runs after the 7-day recovery window.
- Payment records are kept as long as tax, accounting, and fraud-prevention rules require. Provider webhook summaries are content-free and are deleted after 30 days.
- Contact and survey messages are kept as long as needed to respond and for a reasonable period afterwards.
- Request and security logs are kept for a limited period and never contain learning content.
7. Cookies and browser storage
We use a small number of first-party cookies and browser storage entries, and no advertising cookies:
- a session cookie that keeps you signed in (HTTP-only, valid for up to 30 days);
- your interface language, stored in a cookie and in browser storage, set only when you choose a language yourself;
- a cookie that remembers which notices you dismissed so they do not come back;
- in the web reader, your document library, reading positions, and appearance settings in your browser's storage, so you can read without an account.
The browser extension stores your sign-in and settings inside the extension itself. Clearing browser storage does not delete your account data.
8. Analytics and privacy signals
On the marketing pages (home, plans, Points, how it works, contact, and these policies) a first-party beacon records page views and product events such as opening the reader or clicking a store link. It stores the route, the referring site's host, UTM campaign values, your language, your browser family, the country your connection appears to come from, and a coarse market segment. Referrers are shortened to their host, UTM values are filtered to a short safe alphabet, and no learning content is involved. Visitors who are not signed in are counted with a one-day hash of the IP address and browser type; the IP address itself is not stored, and the hash cannot be linked from one day to the next.
If your browser sends the Global Privacy Control or Do Not Track signal, the beacon sends nothing, whether or not you are signed in. Cloudflare Web Analytics, where enabled, runs on the marketing pages without cookies. Product pages (dashboard, learning library, account, payment) report nothing to third parties.
9. Emails
We send transactional emails that the service needs: email verification, password reset, replies to your messages, and billing notices such as a failed renewal payment.
Product-update emails are sent only if you opted in, either with the checkbox at registration or from the Account page. You can turn them off there at any time or with the unsubscribe link in any such email.
10. Your rights and controls
From your account you can:
- see and edit your profile, preferences, and email settings;
- review active sessions and sign out other devices;
- export your learning loops, Elements, flashcards, and review history as a machine-readable NDJSON file (Learning > Data Controls);
- delete individual sessions, Elements, and flashcards, restore them from Trash, or permanently delete a whole category;
- delete your account. Deletion signs you out everywhere, schedules permanent deletion, and can be cancelled within 7 days.
Depending on where you live, you may also have rights to access, correct, restrict, object to, or port your data, and to complain to a supervisory authority. To exercise a right that the product does not cover, or to have an account deleted that you can no longer sign in to, use the contact form; we will confirm that the account is yours before acting.
11. Security
Data travels over TLS and is stored in managed, encrypted infrastructure. The production database accepts connections only from our own servers. Passwords are stored only as salted one-way hashes. Every read, write, export, and deletion of learning data is checked against the signed-in account on the server; sensitive operations such as export require you to confirm your password again. Rate limits protect learning operations, exports, deletion requests, and public forms, and operational logs never contain learning content.
No system is perfectly secure. If we learn of a breach that affects you, we will notify you as the law requires.
12. Children
InterStand is not directed at children under 13 (or the higher age required where you live), and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the service changes. The date at the top shows the current version. For material changes we will give notice in the product or by email before they take effect.
14. Contact
Privacy questions and requests can be sent through the contact form or by email to support.interstand@gmail.com. We reply to the email address you give us.
