Privacy Policy
Last updated: 14 August 2026This Privacy Policy explains how epictetus.world ("we", "us", "the Classroom") handles personal information when you use the website, create an account, complete the Intake, or use authenticated teaching sessions.
Information we process
- Account information — such as email address and authentication identifiers.
- Student profile information — information you provide during Intake, including name, age, work, prior reading, support network, and the difficulty that brought you to the Classroom.
- Conversation content — messages exchanged during the Intake and authenticated teaching sessions. Authenticated session history is stored so the student can return to previous work.
- Learning-state information — if enabled after the relevant database migration, saved passages, notes, and practice progress.
- Technical information — ordinary hosting, security, and request metadata generated when the service is used.
How we use information
We use this information to authenticate students, operate the Intake and teaching sessions, preserve account history, retrieve relevant primary-text references, protect the service, troubleshoot failures, and improve the product.
AI and retrieval providers
Messages may be sent to third-party AI services when needed to produce a response or retrieve relevant source material. The current application uses Anthropic's API for teacher responses and OpenAI's API for embeddings used in retrieval. Those providers process request data under their own commercial/API terms and privacy documentation.
Authenticated conversation history stored by the Classroom is separate from any temporary retention performed by an AI provider. Deleting or ending a teaching session does not by itself control a provider's independent retention obligations.
Storage and infrastructure
- Supabase provides authentication and the Postgres-backed student data layer, including profiles, sessions, and messages.
- Vercel hosts the web application and serverless API functions.
- Anthropic processes prompts and outputs used to generate teaching responses.
- OpenAI processes text used to create embeddings for retrieval.
The application uses Row Level Security for student-owned learning-state tables and keeps privileged database credentials on the server rather than in browser code.
Data retention
Authenticated student records and session history are retained in the Classroom database until deleted under the product's retention process or as otherwise required for legitimate operational or legal reasons. A production launch should define and publish a specific retention/deletion schedule before paid use begins.
Public dialogue
The anonymous public dialogue does not create a persistent Classroom account record. Messages still pass through the AI and retrieval infrastructure required to generate a response and therefore may be processed temporarily by those service providers.
Your rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or objection to certain processing of your personal information, as well as the right to complain to a competent supervisory authority.
Requests can be sent to hello@epictetus.world. We may need to verify identity before acting on a request.
Security
We use authentication, server-side secrets, access controls, and database policies intended to limit access to student information. No online service can guarantee absolute security.
Children
The service is not intended for children under 16, and we do not knowingly design the authenticated Classroom for use by children under that age.
Changes
We may update this policy when the product, providers, or legal requirements change. The date above identifies the current version.
Contact
Privacy questions can be sent to hello@epictetus.world.