SymbioLearn is a study tool. You put your own course material into it, and it turns that material into concepts you can learn from. This policy explains what we hold, why we hold it, who else processes it and what you can ask us to do about it. It is written to be read.
SymbioLearn is operated by Thabani M. Takwena from South Africa. For anything in this policy, write to hi@symbiolearn.com.
What we hold
Your account. Your email address, your name if you give one, and the identifiers our sign-in provider creates for you. We never see or store your password.
Your modules and sources. The names you give your modules, any exam date you set, and the files and links you add as Sources. Uploaded files are kept in private storage. We also keep the text extracted from each Source, split into passages, together with numeric representations of those passages that make search work.
Your concepts. The concepts we derive from your Sources, the alternative names for them, and the exact place in each Source that each one came from.
Your learning record. Every Lesson, Quick Quiz, flashcard review, mistake and difficulty rating, with the time it happened and the result. This is the part of SymbioLearn that decides what Today brings back, so it is the part we keep most carefully.
Your Lessons. The length of each Lesson, which Sources it drew on, the written record of what was said during it, and the summary produced from that record. We do not keep the audio.
Your plan and payments. Which plan you are on, your remaining Voice Lesson minutes and the history of how they were spent or bought, and the subscription and payment records our payment provider sends us. We never receive or store your card details.
Product analytics. Which parts of SymbioLearn you use and when, so we can tell what is working. These events are designed to carry behaviour rather than content. See "What we never do" below.
Technical logs. Ordinary server and error logs, including IP address and browser, kept short term for security and debugging.
Why we are allowed to hold it
We process your account, module, source and learning data because performing our contract with you requires it. Without it there is no product.
We process payment records because the law requires us to keep them.
We process analytics and logs on the basis of our legitimate interest in running a working, secure service, using the narrowest data that answers the question. Where the law in your country requires consent instead, we ask for it.
How your material is processed
To turn a Source into Concepts, to write a quiz question, to run a Lesson or to analyse one afterwards, we send your material to an AI processing provider, which does the language work and returns structured output to us.
What that involves depends on the feature. It can include the file itself, a link you added, passages retrieved from your Sources, the Concept being worked on, and parts of a Lesson conversation. We send the material and context the requested feature needs, and nothing is sent for a feature you have not used.
Our AI provider's paid API terms state that content submitted through it is not used to train or improve their models, and is not reviewed by people except where they are legally required to. We do not train any model on your material, we do not build a shared model out of what students upload, and we do not use one student's material to answer another student's question. Search over your passages is restricted to you, and to the module you are working in, before any result is returned.
How we share information
We use service providers to run SymbioLearn. They process personal information only where their service requires it, under contract, and none of them may use it for their own purposes.
| Type of provider | Why we use them | What they may process |
|---|---|---|
| Authentication | Sign-in, account security and sessions | Account details and sign-in information |
| Cloud database and storage | Store your account, modules and the files you add | The information and files you save in SymbioLearn |
| AI processing | Turn your material into Concepts, quizzes, Flashcards and Lessons | The learning material and context a requested feature needs |
| Infrastructure and background processing | Host the application and run import and analysis jobs | Technical request information and the data a job needs |
| Payments | Subscriptions, top-ups and invoices | Billing and transaction information. Card details go to the payment provider, never to us |
| Product analytics | Show us which parts of the product are used | Product usage events and technical information |
We may change providers over time. The companies currently behind each of these categories are named on our Service Providers page.
Beyond that, we share personal information only when the law requires it, when it is needed to establish or defend a legal claim, or, if SymbioLearn is ever sold or merged, with the acquirer, who would be bound by this policy. We do not share it with anyone else.
How long we keep it
Your content stays until you delete it or close your account.
Deleting a Source removes the stored file and its passages. Concepts that other Sources still support survive, which is the point of the product.
Deleting your account removes your modules, Sources, concepts, learning record and Lessons within 30 days, apart from backups, which age out within a further 30 days.
Payment records are kept for as long as tax and accounting law requires, currently five years. Technical logs are kept for up to 90 days.
Your rights
Wherever you live, you can ask us to give you a copy of what we hold, correct anything wrong, delete your account and its contents, or export your data.
If you are in the European Economic Area or the United Kingdom, the GDPR also gives you the right to object to processing we base on legitimate interest, to ask us to restrict processing, and to complain to your data protection authority. If you are in South Africa, POPIA gives you equivalent rights and the Information Regulator hears complaints.
Write to hi@symbiolearn.com and we will answer within 30 days. We do not charge for this.
Where your data is
SymbioLearn is hosted in the United States and Europe, and our providers operate internationally, so your data crosses borders. Transfers out of the EEA and the UK rely on the European Commission's standard contractual clauses, which our providers have in place.
Security
Everything travels over encrypted connections and is encrypted at rest by our database and storage provider.
Access to your rows is enforced in the database itself, by row-level security tied to your account, not only by our application code. Keys that can bypass those rules exist only on our servers and are never sent to a browser. Uploaded files are served through short-lived signed links rather than public URLs.
No system is perfect. If a breach affects you, we will tell you and the relevant regulator within the time the law allows, and we will tell you what actually happened.
Cookies and browser storage
We use cookies from our sign-in provider to keep you signed in. These are essential and the product cannot work without them.
We store your light or dark theme choice, and any plan you build in the free study planner, in your own browser rather than on our servers.
Our analytics provider measures use of this site only, and does not follow you around other websites.
Children
SymbioLearn is built for university students and is not directed at children. You need to be at least 16 to hold an account, or the minimum age of digital consent in your country if that is higher. If we learn that we hold a younger person's account, we delete it.
Changes
If we change this policy in a way that affects you, we will email you before it takes effect rather than quietly editing the page. The date at the top always reflects the current version.