Privacy Policy
Last updated: October 2, 2026
Socratopia is developed and operated by SocraLab LLC. This policy explains what data we process when you use the Desktop App, Android App, online learning services, official website, Library, and forum; why we process it; where it is stored; and the choices and rights available to you. We follow the principles of specific purpose, transparency, and data minimization.
1. Data we process
1.1 Learning data and files kept only on your device
Depending on your platform and sync mode, the following data stays on your device and is not uploaded as Cloud Sync data:
- In Desktop Local Only mode: profiles, companion settings, worlds, storylines, lesson conversations, progress, journals, notes, flashcards, group chat, and pet data
- On Desktop and Android: original PDF, EPUB, Markdown, and Word (.docx) textbook files you import
- On Android: locally derived textbook text, pages, and indexes. Backups you explicitly export are password-free ZIP files containing original textbooks; keep them private and share them only deliberately.
- Device-local lesson audio recordings and voice caches
To generate a companion reply, relevant classroom context still passes briefly through our model-proxy service and is sent to an AI provider for that request. This does not enable Cloud Sync or upload your entire local dataset.
1.2 Learning data in Cloud Sync and online services
When you enable Cloud Sync on the Desktop App, use the Android App, or use online learning services, we store the data needed to provide cross-device learning, including:
- Profiles, avatars, companion settings, and worlds
- Lesson conversations, progress, journals, flashcards, group chat, and pet data
- Library-book registration, table of contents, and learning position
- Sync state, conflict versions, and a limited History Archive
Original files for textbooks you import and local lesson audio are not uploaded through Cloud Sync. History Archive retains only a limited number and total volume of older versions; it is not permanent or unlimited backup storage.
1.3 Account and device data
- Email address, system-generated account ID, sign-in sessions, and verification-code records
- Device identifier, device name, platform, sync mode, and recent activity and sync times
- Subscription status, text compute, reward compute, Voice Pack balance, bookshelf, and transaction records
- Unlocked books, referral relationships, and limited linkage data needed to prevent reward abuse
1.4 Operations, communications, and payments
- IP address, request time, browser or app version, device platform, and necessary security logs
- A coarse region inferred from the IP address (mainland China or other regions), used only to choose the initial currency display; we do not request device location or use this to restrict access
- Model source, feature source, token usage, latency, and success or error status; routine operational logs do not record conversation text
- Messages, attachments, and contact information you submit to support
- AI Book Finder search text, request time, search-policy and catalog versions, result counts, and success/error status across clients. These diagnostic records do not attach email addresses, names, or full recommendations; the search text itself may still contain personal information you enter
- Payment status, order identifiers, and billing period; full payment-card details are handled by the payment provider and are not stored by us
2. How we use data
We use data only as needed to provide and maintain Socratopia, including to:
- Authenticate sign-in, manage devices, provide account entitlements, process payments, and answer support requests
- Generate companion replies, post-lesson summaries, flashcards, journals, and other learning features you choose to use
- Provide online learning, Cloud Sync, device handoff, conflict protection, and history recovery
- Meter text and voice usage and prevent fraud, attacks, automated registrations, and reward abuse
- Monitor errors, availability, performance, security, and service stability
- Improve teaching rules and software performance through automated quality signals within the strict boundaries in the next section
3. Our commitments for cloud conversation content
Learning conversations can contain deeply personal experiences, thoughts, and uncertainties. We treat the original text as sensitive learning data and make these commitments:
- Without your explicit permission, our employees, contractors, and researchers will not read, label, quote, summarize, or manually distill your conversations. This does not include content you voluntarily send to support or specifically authorize us to inspect. Access required by law, a serious security incident, or the protection of someone's vital interests is limited to what is strictly necessary
- We do not use conversations to train or fine-tune models, create training datasets, conduct academic research, publish papers, or carry out other research activities. We will not use them for research without your explicit permission even if we first plan to anonymize or de-identify them
- Our systems may perform automated quality processing without showing the original conversation to a person—for example, checking whether a teaching flow operated as intended, measuring error and feature-success rates, or producing quality signals that contain no identifiable excerpts—to improve teaching rules and software performance
- Automated quality processing does not create advertising or personality profiles, provide conversations to outside researchers, or turn the original text into a human-readable analytics corpus
- If we ever need to use conversation content beyond these boundaries, we will explain the new use clearly in advance and obtain separate or explicit permission where applicable law requires it; we will not bury a material change in fine print
4. Service providers and sharing
We do not sell or rent personal information, and we do not serve targeted advertising based on learning content. The following categories of providers receive data to provide product features; their applicable terms also govern retention and any additional processing:
- AI model providers receive the context needed to generate a reply, which may include your nickname, profile information, companion settings, and classroom or group-chat content relevant to that reply. Their applicable terms govern processing, retention, and service improvement. We cannot give a blanket assurance that every provider excludes requests from model improvement or training
- Voice providers receive companion text that must be converted to speech when you enable Companion Voice
- Cloud and network providers: Alibaba Cloud hosts core account, cloud-learning, sync, and model-proxy services; Cloudflare provides DNS and network services; Vercel hosts the official website
- Email providers deliver sign-in codes, support replies, and necessary account notices
- Payment providers: Stripe and the payment methods it supports process website subscriptions and top-ups; Google Play processes subscriptions and voice-credit purchases in the Google Play Android app. We verify purchase receipts and process renewals, refunds, and entitlement updates through Google's services
5. Official website and Agora forum
5.1 Official website
socratopia.app does not serve third-party advertising or install advertising trackers. Hosting and network providers may still process standard access logs for security, delivery, and operations.
5.2 Agora forum
Posts, comments, companion settings, world settings, display names, and avatars that you publish on the forum are public and may be viewed or copied by others. Report details and contact email are used only to handle the report. The forum also keeps access logs for security and provides a more detailed forum-specific privacy notice.
6. Cookies and local storage
The official website does not use advertising cookies. The Desktop App, Android App, and online learning services use necessary local storage, session cookies, or operating-system secure storage for sign-in state, device identity, interface preferences, and feature state. On Android, the app also uses Android Keystore and app-private storage to protect the session and local textbook vault. These technologies operate the product and are not used for cross-site advertising tracking.
7. Retention and deletion
7.1 Learning data
You control Local Only data directly. Cloud learning data is kept while the account remains active and as needed to provide the service. You can delete individual items in the product or contact us to request deletion of cloud account data. Account-deletion requests are ordinarily completed within 30 days.
7.2 History versions and backups
Sync history is pruned automatically by version count and total storage; it does not preserve every old version forever. Infrastructure backups used for disaster recovery may remain for a limited cycle and are then overwritten or deleted according to the backup rotation.
7.3 Account, log, and transaction records
Sign-in sessions, verification codes, security logs, and operational metadata are retained only as long as needed for their respective purposes. Payment, refund, and financial records may be kept longer to meet tax, accounting, anti-fraud, and dispute-resolution requirements.
7.4 AI Book Finder diagnostics
Search text is retained for 30 days in a separate encrypted diagnostic store for restricted authorized personnel to diagnose search issues and evaluate recommendation accuracy, not for advertising profiles, model training, or academic research. Records older than 30 days are excluded from queries and deleted during automatic cleanup. We do not create dedicated backups of these records. Copies included in infrastructure backups may persist longer, remain access-restricted, expire through the existing backup rotation, and are not used for routine analysis. After a backup is restored, expired records must be removed before diagnostic use. Personal information must be removed before diagnostic export; temporary exports remain subject to the original retention deadline. This does not change our commitments concerning classroom conversations above.
8. International processing
SocraLab LLC operates in the United States, and our core account and cloud-learning infrastructure is currently located in Hong Kong. AI, voice, email, payment, and network providers may process data in other countries or regions. We limit transfers and use contractual, security, or consent mechanisms as required by applicable law.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete personal information; withdraw consent; object to or restrict certain processing; and complain to a supervisory authority. You can turn off Cloud Sync on a desktop computer so future data on that computer remains local. Turning the switch off does not automatically erase data already in the cloud; delete it in the product or contact us if you want it removed.
10. Children
Socratopia is intended for users aged 13 and over across Desktop, Cloud, and Android, including Google Play. We do not currently collect dates of birth or automatically verify age; this target audience is not proof that an individual user meets local consent requirements. A user who is below the age of independent consent where they live should use the service only after a guardian has read and agreed to this policy; for example, a user under 14 in mainland China requires guardian consent. If we learn that we collected a child's personal information without required guardian consent, we will take steps to delete it or stop processing it.
11. Security
We use HTTPS, access controls, operating-system secure storage, Android Keystore and app-private storage, file-path isolation, sync-version protection, backups, and security logging. Human access to original cloud conversation text is restricted to authorized circumstances and the minimum necessary scope. No internet service can guarantee absolute security; if a security incident may affect your rights, we will take remedial and notification steps required by applicable law.
12. Changes to this policy
We may update this policy as the product and legal requirements change. Updates appear on this page with a revised Last updated date. We will provide additional notice for new categories of data, material new purposes, or other significant changes, and will obtain consent before processing when applicable law requires it.
Contact us
To exercise a data right or ask about privacy, automated processing, or security, contact:support@socratopia.app