Privacy Policy
Effective and last updated: 8 August 2026
Unsuspendly is a macOS and Windows study app that reads text extracted from lecture slides, creates searches, and, only when you approve a run, updates matching flashcards in your own Anki collection. This policy describes the information processed when you use the app, website, licensing service, support, and billing features.
The short version: your original slide files and Anki collection are not uploaded to Unsuspendly. Text extracted from slide files, along with the lecture title and the instructions needed to analyze it, is sent through our Cloudflare-hosted service to Google's Gemini API. We store licensing, subscription, device-binding, and upload-count records. Searches, card data, run history, and local usage insights remain on your computer. We do not sell personal information, use it for targeted advertising, or include advertising or third-party analytics SDKs.
1. Who is responsible for your data
Unsuspendly is operated by Andrew Daoud, a Pennsylvania sole proprietor doing business as Unsuspendly ("Unsuspendly," "we," "us," or "our"). Unsuspendly is the controller of personal information used for licensing, support, and operation of the Service. Payments are processed by Stripe. Privacy questions and requests may be sent to support@unsuspendly.com.
2. Information we process
- Lecture input. When you use Upload Lecture, the app extracts text locally from each selected PDF or PowerPoint file. It sends the extracted text and your chosen lecture title to our service for concept identification. The original PDF or PowerPoint file is not sent. Optional subject and study-objective labels are used locally for organization and are not part of the lecture-analysis request.
- AI response. The service returns concept names and scope information. The app then maps those concepts to tags and searches locally. Google does not receive your Anki cards, tags, deck names, or review history from Unsuspendly.
- License and device information. We process the random license key issued for a trial or paid subscription and a salted, one-way hash derived from a machine identifier (or a random per-install fallback). We do not receive the underlying hardware identifier. We use the hash to provide one trial per device and bind a license to one device at a time. The service verifies modern license credentials using a secret-keyed one-way HMAC and an unrelated internal identifier rather than storing the customer-facing bearer value as its lookup key. Recoverable credential material is encrypted and limited to trial recovery and short-lived purchase delivery.
- Trial-abuse prevention. When a trial is requested, Cloudflare provides the connection IP address to our service. Our application immediately transforms it with a secret-keyed one-way HMAC and stores only that derived network identifier with the device hash and issuance time in our licensing database. We use a rolling 30-day history to limit repeated trial creation from the same network; raw IP addresses are not written to that database by our application. Cloudflare may separately process connection IP addresses in its operational and security systems as described below.
- Subscription and transaction records. We store Stripe customer, subscription, product, and Checkout-session identifiers; plan and subscription status; trial dates; device-transfer time; and record timestamps. Stripe processes checkout, receipts, and subscription billing, and collects checkout information such as your name, email, billing address, payment method, transaction details, device information, and IP address under its own policy. We do not receive or store your complete payment-card number.
- Usage allowance. We store the number of lectures successfully processed for each license in each UTC calendar month. We do not store which medical topics those lectures covered.
- Service and security data. Cloudflare and our upstream providers may process IP addresses, request timing, status, approximate location derived from IP, device or browser details, and operational or security diagnostics. Our application code does not deliberately write slide text, license keys, authorization headers, Anki data, or full payment objects to application logs.
- Support communications. If you contact us, we process your contact details and the contents of your message. Please do not send lecture files, a full license key, an Anki database, payment-card information, passwords, API keys, or patient information.
3. How we use information
We use information to provide and secure the Service; identify concepts in lecture text; issue and validate licenses and trials; enforce upload and device limits; process and reconcile subscriptions; provide support; prevent fraud and abuse; diagnose failures; comply with law; and establish or defend legal claims.
Where laws such as the GDPR or UK GDPR apply, our legal bases are performance of our contract with you, our legitimate interests in operating and protecting the Service, compliance with legal obligations, and consent where applicable. You may object to processing based on legitimate interests, although we may continue when we have compelling lawful grounds.
4. Lecture content and Google Gemini
Lecture text is routed through our Cloudflare Worker to the Google Gemini API. Our Worker forwards the request and returns the response; our code does not save slide text or the Gemini response to our database or object storage. They exist transiently while the request is processed.
Production access is configured through a paid Gemini API project. Under Google's current Gemini API Additional Terms, Google says it does not use prompts or responses submitted to paid services to improve its products. Google may still retain or process prompts, responses, usage details, and security information for a limited period for abuse prevention, security, legal compliance, and service operation, as further described in those terms and the Google Privacy Policy. Unsuspendly does not promise that Google provides zero data retention.
Do not submit protected health information, patient-identifiable information, confidential examination material, or other sensitive or confidential information. Unsuspendly is not designed as a HIPAA-enabled service and we do not enter into business associate agreements for the app.
5. Information that stays local
- Your Anki collection. Unsuspendly communicates with Anki through AnkiConnect at
127.0.0.1. We do not receive your cards, tags, decks, note content, or review history. - Local records. Derived searches, concept snapshots returned by Gemini, run history, affected card identifiers, settings, and usage insights are saved in the app's data folder on your computer.
- Your saved license key. It is stored using macOS Keychain on Mac or Electron secure storage backed by Windows DPAPI on Windows.
If you enable Anki synchronization after a run, Unsuspendly asks your local Anki installation to sync. Anki may then send collection changes to the sync provider you configured, such as AnkiWeb, under that provider's terms. Unsuspendly does not receive that synchronized content.
6. Website, cookies, and analytics
The Unsuspendly marketing website is static and does not set advertising cookies or load analytics or tracking scripts. When you follow a download, Stripe Checkout, customer portal, email, Anki, or other third-party link, that service may receive ordinary connection and device information and may use cookies under its own policy.
7. Service providers and disclosures
- Cloudflare hosts the website, Worker, database, downloads, and operational logs. Workers Logs may retain invocation and application logs for up to seven days, depending on the plan. See Cloudflare's Privacy Policy.
- Google processes lecture input and returns AI output through the Gemini API, as described above.
- Stripe processes payments, subscriptions, billing management, fraud prevention, and related records. See Stripe's Privacy Policy.
- Email and support providers process communications sent to our support address.
We may also disclose information when reasonably necessary to comply with law or valid legal process, protect users or the Service, investigate abuse, or complete a merger, financing, acquisition, or sale of assets. If ownership changes, this policy will continue to apply to transferred information unless you are notified otherwise.
We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. We have not done so during the preceding 12 months.
8. Retention
- Lecture text and AI responses: not intentionally persisted by our Worker or D1 database after the request completes. Google and Cloudflare retain data according to their terms and service settings.
- Operational logs: Cloudflare Workers Logs are retained for no more than seven days under the currently documented service limit.
- License, subscription, device, and usage records: retained while needed to provide the license, administer billing, prevent repeated trials or license abuse, resolve disputes, and meet legal, tax, accounting, and security obligations. Some records may remain after cancellation because cancellation does not erase transaction or fraud-prevention history.
- Trial network identifiers: used for a rolling 30-day anti-abuse window. Our application deletes records older than that window during trial-processing maintenance; provider logs and backups may follow their own limited retention cycles.
- Purchase-delivery ciphertext: new Checkout credential delivery expires after 24 hours, and a scheduled cleanup deletes expired redemption records. Trial recovery ciphertext is cleared after the trial expires.
- Support records: retained as long as reasonably needed to resolve the request, maintain a support history, and comply with legal obligations.
- Local app data: remains on your computer until you delete records using the app's controls, clear the app's data, or uninstall it. Deleting a local history entry does not reverse changes already made in Anki.
When information is no longer required, we delete or de-identify it where reasonably practicable. Backup, legal-hold, fraud-prevention, and transaction records may remain for a limited additional period.
9. Security
We use safeguards designed to protect information, including HTTPS, server-side API secrets, signed Stripe webhooks, HMAC-verified and device-bound licenses, encrypted time-limited credential recovery, restricted database access, and operating-system-protected local license storage. No security measure can guarantee absolute protection. Keep your license key confidential and contact us if you believe it has been exposed.
10. Your privacy choices and rights
You may ask us to provide access to, correct, or delete information associated with your license or transaction; object to or restrict certain processing; or request a portable copy where applicable. You may also withdraw consent for future processing when consent is the legal basis, lodge a complaint with your local data-protection authority, or appeal a refusal where local law provides that right.
Send requests to support@unsuspendly.com. To protect customers and license credentials, we may need to verify your identity using transaction information or limited license details. We will not discriminate against you for exercising applicable privacy rights. Deleting the server-side license record permanently disables that license and does not automatically delete records independently held by Stripe, Google, Cloudflare, your email provider, or your local computer.
11. Age and availability
Unsuspendly and its AI-assisted upload feature are intended only for people who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. The Service may be used only from countries and territories where Unsuspendly and its providers permit it.
12. International processing
Unsuspendly and its providers operate in the United States and other countries. Your information may therefore be processed outside your state, province, or country, where privacy laws may differ. Where required, providers rely on approved transfer mechanisms such as standard contractual clauses.
13. Changes
We may update this policy as the Service or law changes. We will update the date above and provide additional notice when required. If a change materially affects how the app processes information, we will ask app users to review the revised policy before continued use of the affected feature.
14. Contact
Privacy questions and requests: support@unsuspendly.com
Unsuspendly is an independent tool. It is not affiliated with, endorsed by, or sponsored by Anki, Ankitects Pty Ltd, or The AnKing.