1. Our principles
The operator of Lecue (“we”) follows applicable data-protection law and explains what data is needed and why.
- We collect only what is needed to provide and secure the service.
- Lecture audio and questions are not used for advertising profiles or marketing.
- We do not sell personal data or disclose it to unrelated third parties without consent or another lawful basis.
- AI answers are not used to make decisions that create legal or similarly significant effects for users.
2. Data we process
| Category | Data | When |
|---|---|---|
| Account | Email, Supabase user ID, sign-up and sign-in time | Account creation and sign-in |
| Google sign-in | Google account identifier, email, and profile details Google provides | When selected |
| Lecture use | Classroom and lecture titles, live transcript, questions, AI answers, sources, recorded time, and embeddings used to retrieve earlier lectures | While using a classroom |
| Voice | Microphone audio stream | During active recording |
| Personal AI | Selected provider and model; API key entered by the user | When selected, saved, or used |
| Technical | IP address, browser and device data, cookies, access time, security and error logs | Automatically during access |
| Payment | Product, amount, time, status, transaction ID, and refund history | When paid service launches |
| Support | Email, request, and response history | When contacting support |
3. Why we use it
- Identify users, maintain sessions, protect accounts, and prevent abuse.
- Transcribe speech, display the lecture, and answer from context available at question time.
- Search the web and show sources when current or independently verified information is needed.
- Send a request to the external AI provider the user selects.
- Measure recorded time, manage balances, and process future payments and refunds.
- Diagnose errors, respond to security incidents, improve quality, answer support requests, and meet legal obligations.
We do not use lecture content or questions for targeted advertising.
4. Storage and retention
Classroom and lecture records
Classroom names, lecture titles, transcripts, questions, and answers are linked to the member's account and stored in Supabase. To retrieve relevant earlier lectures from the same classroom, transcripts are grouped into passages and stored with numeric embeddings created by OpenAI. We do not store original audio on our server. The existing classroom streams audio to Deepgram; the separate Korean STT lab sends overlapping audio windows of up to 10 seconds to Cloudflare Workers AI.
Personal AI keys
If the user does not choose storage, the key remains only in the current browser tab and is used for the request. If the user selects “Save to my account,” the key is encrypted in Supabase Vault. Plaintext is never returned to the browser or shown on the account screen. The server decrypts it only to send an authorized request to the chosen provider. Key values are excluded from application logs and error responses. Users may replace or delete a saved key at any time.
Retention periods
- Account: until account deletion; deletion and backup propagation completed within 30 days where practicable.
- Saved personal AI key: until the user removes it or deletes the account.
- Classroom and lecture records, including retrieval embeddings: until the user deletes them or closes the account.
- Access and security logs: 3 months, or until an active security investigation ends.
- Support and dispute records: 3 years after resolution.
- Contract, cancellation, payment, and supply records: 5 years where Korean law requires it.
Records required by law are separated and used only for the required purpose.
5. Service providers and international processing
Data is sent over encrypted connections. Providers process it to deliver the function shown below. If a user selects a personal AI provider, the transcript up to question time, the question, and the key needed to authorize that request are sent to that provider.
| Provider | Purpose and data | Location and retention |
|---|---|---|
| Supabase, Inc. | Authentication, sessions, classroom and lecture record storage, and encrypted Vault storage for an optionally saved AI key | United States or selected project region; exact production region to be confirmed |
| Deepgram, Inc. | Live speech recognition: microphone stream, language, and model settings | United States; real-time processing and provider contract terms |
| Cloudflare, Inc. | Optional Korean STT lab: WAV audio windows of up to 10 seconds, Korean/model settings, and a short prior-transcript prompt | Cloudflare processing locations; request processing without an added storage service |
| OpenAI, L.L.C. | Default or user-selected answers and web search: transcript, question, randomized safety identifier, and personal key when applicable | OpenAI processing regions and API retention settings |
| Anthropic, PBC | User-selected Claude answers and search: transcript, question, and personal key | Locations and retention described by Anthropic and the user's API account |
| Google LLC | Optional Google sign-in; optional Gemini answers and Google Search | Locations and retention described by Google and the user's API account |
| Payment processor to be selected | Future payment and refund processing | To be confirmed before paid launch |
Default OpenAI Responses API calls use store: false. Retention and training choices for a personal provider follow the user's contract and account settings with that provider. Users can avoid an optional transfer by not selecting that function; core features affected by the transfer will then be unavailable.
6. Cookies and automatic collection
Supabase authentication cookies maintain sign-in and protect sessions. Blocking them may prevent account features from working. We currently use no targeted-advertising cookie or third-party advertising tracker. Any future analytics tool will be disclosed here with its data and opt-out method.
7. Your rights
Subject to applicable law, users may request access, portability, correction, deletion, restriction, withdrawal of consent, and account closure.
- Use available account controls or contact the privacy address below.
- We may verify identity before acting and will respond within the legally required period.
- A request may be limited where law requires retention or where another person's rights would be harmed; we will explain the reason.
Privacy request email: [add before public launch]
8. Deletion and security
Data is deleted when its purpose or retention period ends. Electronic records are deleted using methods intended to prevent practical recovery; legally retained records are separated and access-restricted.
- HTTPS and secure WebSocket encryption in transit.
- Short-lived speech-recognition tokens; production API secrets never exposed to the browser.
- Vault encryption for saved personal AI keys, no plaintext redisplay, and no key logging.
- Least-privilege operational access, environment-separated secrets, protected logs, and security updates.
- Purpose and security controls imposed on service providers.
9. Children
The current service has no verified parental-consent flow and does not accept accounts from children under 14. Users under the minimum age required in their country must not use the service without a legally valid consent process.
10. Contact, complaints, and changes
Privacy officer or team: [name or team]; contact: [email and phone]
Users in Korea may also contact the Personal Information Protection Commission, the Korea Internet & Security Agency privacy center at 118, or the Personal Information Dispute Mediation Committee.
We will normally post changes at least 7 days before they take effect. Material changes such as expanded collection or new disclosure will be announced at least 30 days in advance, and consent will be obtained where required.