Leitner
Version 2026-09-15

Privacy

What Leitner stores, who it goes to, and how to get it back or get rid of it. Written to be read, not to be survived.

The short version

  • What you upload is yours. It is never used to build anyone else's plan, never pooled, never used to train a model.
  • We do not keep the files you upload. We extract the text, use it to build your plan, and discard the file itself.
  • Your goal, your material and your questions are sent to the model provider that writes your lessons. That is the product; there is no version of it that does not do this.
  • There is no advertising, no ad network, and no tracking cookie. Analytics is off until you turn it on, and even then it is five named events and never anything you wrote.
  • You can export everything we hold, and delete the account and all of it, from your account settings.

Who we are

Leitner is operated by Ernest Laptiev, Heorhiivska 42, Kyiv, Ukraine, 08140. For anything about your data, write to contact@howdoistudy.com. Under the UK and EU GDPR we are the controller of the data described here.

What we store

  • Your account — your email address and the name you gave. If you signed up with a password we store a bcrypt hash of it and never the password. If you signed in with Google we store the link to that Google account instead, and there is no password.
  • What you tell us you want to learn — the goal, where you are starting from, how much time you have, any deadline, and the whole conversation that settled your plan.
  • Material you upload — documents, spreadsheets, slides, transcripts and images. We extract the text and store it in passages so your lessons can cite them. PDFs and images are read by our model provider, which means the file itself is sent to them to be read; nothing else you upload is. We keep the filename. We do not keep the original file.
  • What you do in a lesson — which exercises you answered, what you answered, whether it was right, and which misconception a wrong answer pointed at. That is what decides which lessons come back to you and when; a learning tool that does not record this cannot adapt.
  • Questions you ask — the conversation inside each lesson, and any passage you highlighted when asking.
  • Operating records — sign-in sessions, and what each generation cost us in model tokens.
  • If you turned analytics on — a row for each of the five events below, with the lesson or plan it happened in, how far through you were and how long it took. Nothing you typed. If you never turned it on, there are none of these.

Who else sees it

Three, and no others. We do not sell data and we do not share it for advertising.

  • The model provider that writes your lessons — Anthropic, or Anthropic models operated by Amazon Web Services, depending on how this deployment is configured. Your goal, the material you uploaded, and your questions are sent there to produce the plan and the lessons. Anthropic’s commercial terms do not permit training on data submitted through the API.
  • Amazon Web Services — hosting, the database, and the email that carries password reset links. Region: Ukraine.
  • Google — only if you choose to sign in with Google, and only to confirm who you are.

What we never do with your uploads

If you upload a textbook, a syllabus or your own notes, that material builds your plan and nobody else’s. It is scoped to your account in the database, not by convention. The structure Leitner derives while reading it — the names of concepts, which one has to be learned before which — is ours and may be reused to make other plans cheaper to build. The material itself is not.

Cookies and what is kept in your browser

One cookie: the one that keeps you signed in. It is strictly necessary — without it there is no way to know the plans are yours — so it does not need your consent and we do not pretend to ask for it.

Your browser also remembers your theme and whether the plan rail is folded. That never leaves your device.

There is analytics, and it is off unless you turn it on in your account settings. It uses no cookie and nothing in your browser: the record is a row in our database tied to your account, which is why turning it off actually stops it rather than merely stopping one copy of it.

If you do turn it on, what gets recorded is five things happening — a lesson opened, a lesson left before the end (with how far in you were and how long you had been there), a question asked, a plan edited, a block rated — and nothing you wrote. Not the question, not the edit, not the answer. Those are already stored above because the product cannot work without them; measuring is a separate purpose and it gets the count, not the text.

You can turn it back off in the same place, it takes one click either way, and nothing about the app behaves differently for someone who says no.

How long we keep it

Until you delete it. Deleting your account removes your plans, lessons, answers, progress, conversations and sign-in methods immediately — it is a real delete, not a flag. Backups roll off within 7 days.

Your rights

You can get a copy of everything we hold as a single file, and you can delete the account and all of it, from your account settings — no email, no waiting. You can also object to processing, ask us to correct something, or complain to your data protection authority (in the UK, the ICO; in the EU, your national authority).

Age

Leitner is built for students, and plenty of students are children. You need to be 13 or older to use it. If you are under 16, check with a parent or guardian first — in several countries they have to agree on your behalf — and they should read this page too.

We do not show advertising, we do not track you across other sites, and we do not use anyone’s work to train a model. Those are the defaults whatever your age.

Changes

This notice carries a version. When it changes in substance we ask you to accept the new one before you carry on — we do not treat consent to an older version as consent to this one. See also the terms.