Privacy Policy
Last updated: 2 October 2026 · Applies to all Corvo users, in the UK, EU and US
Plain English summary: Corvo turns your lecture slides into study notes, flashcards and quizzes, either by reading them from your Canvas or Moodle account (read-only) or from files you upload yourself. To do that, we send lecture text to our AI provider, Anthropic. We store your account details, your generated study material and your study progress in the EU. We don't sell your data, we don't use advertising trackers, and you can delete everything yourself at any time.
1. Who we are
Corvo is a study tool for university students in the UK, EU and US. For UK and EU users, Corvo is the data controller for the personal data described in this policy under UK GDPR. Corvo is registered with the UK Information Commissioner's Office (ICO). For US users, Corvo is the "business" under applicable US state privacy laws (see section 10). For any privacy question, contact support@itscorvo.com.
2. What data we collect and why
| Data | Why we collect it | Legal basis |
|---|---|---|
| Email address and password login | Creating your account, signing you in, and sending you service emails (for example about your trial or billing) | Contract |
| Profile details: name, university, course and year of study | Personalising your notes and study plans to your course and level | Contract |
| Canvas or Moodle connection: your institution's address and the access token you provide | Reading your courses, modules, lecture files, course pages, assignments, announcements and calendar on your behalf. Read-only: Corvo never posts, submits or changes anything in your learning platform. | Contract |
| Course and module information | Organising your notes by course, showing your deadlines, and checking for new lecture files | Contract |
| Lecture content: text and diagrams from your lecture files, from Canvas/Moodle or uploaded by you | Text is sent to Anthropic's API to generate your notes, flashcards and quizzes. We don't keep a copy of the original lecture file; we keep the notes we generate, which can include diagrams taken from your slides. | Contract |
| Lecture audio recordings (optional) | If you record a lecture to add to your notes, the audio is sent to Groq to be transcribed, and the transcript is sent to Anthropic to update your notes. We don't store the audio or the transcript, only the updated notes. | Contract |
| Research Assistant files, web sources and chats (optional) | Documents you upload and web pages you add are stored privately so you can search and cite them, and your questions and answers are kept as your project's chat history. Content is sent to Anthropic to answer your questions. | Contract |
| Generated study material and progress: notes, flashcards, review history, quiz results, revision plans, folders and cheat sheets | Showing you your study material and running spaced repetition so we know which cards are due | Contract |
| Calendar information: a calendar feed link (optional), and deadlines and events you add yourself | Showing your timetable and deadlines in one place | Contract |
| Sync records: names and IDs of the files we've processed | Avoiding processing the same file twice, and showing you a history of what was synced | Legitimate interest |
| Notification email and preferences (optional) | Sending you the email updates you choose. You can change or turn these off at any time. | Consent |
| Payment information | Processing your subscription. Card details are handled entirely by Stripe: we never see or store your card number. | Contract |
| Referral or society code (if you use one) | Applying the reward or pricing that comes with the code | Contract |
| Feedback and support messages | Responding to you and fixing problems you report, including the page you were on and your browser type | Legitimate interest |
3. What we do not collect or do
- We don't use advertising cookies, tracking pixels or third-party analytics
- We never ask for your Canvas, Moodle or university password
- We don't read your email inbox
- We don't sell your data or share it for marketing
- We don't build advertising profiles
- We don't write anything back to Canvas or Moodle
4. Cookies and local storage
Corvo uses your browser's localStorage to keep you signed in and to remember interface preferences such as your theme. This stays on your device. When you enter card details, Stripe's payment form may set its own cookies, which are needed to process payments securely and prevent fraud. We don't use any other cookies.
You can clear this at any time by signing out or clearing your browser's site data for itscorvo.com.
5. Who we share your data with
We use the following services to run Corvo. Each acts as our data processor under its data processing terms with us, and only handles your data to provide its service to Corvo:
| Processor | What they handle | Where |
|---|---|---|
| Supabase | Database, file storage and sign-in. Stores your account, study material and Research Assistant files. | EU (Ireland) |
| Vercel | Hosting. Processes every request to the app. | EU West |
| Anthropic | AI generation. Receives lecture text, announcements, transcripts, Research Assistant content and your chat questions to generate notes, flashcards, quizzes, summaries and answers. Under Anthropic's commercial terms, this content isn't used to train its models. | USA |
| Groq | Speech-to-text. Receives lecture audio you choose to record, only to transcribe it. | USA |
| Stripe | Payments and subscriptions. PCI-DSS Level 1 certified. We receive your subscription status, never your card details. | UK |
| Resend | Sending emails, such as trial reminders, billing notices and the updates you've opted into. | USA |
| Upstash | Short-lived caching and rate limiting to keep the app fast and protect it from abuse. Cached data expires within minutes. | USA |
Where a processor handles data outside the UK or EU, the transfer is covered by standard contractual clauses or the UK International Data Transfer Addendum. We don't share your data with anyone else. Your university's Canvas or Moodle is a source we read from on your instruction; we never send data back to it.
6. How long we keep your data
- While your account is active: we keep your data so we can provide the service. You can delete individual notes, flashcards, Research Assistant projects and files yourself at any time.
- When you delete your account: we cancel any active subscription and immediately and permanently delete your account and everything linked to it, including your study material, uploaded files, course list, Canvas/Moodle connection, sync history and feedback messages. Copies may remain in encrypted database backups until those backups expire, within 30 days.
- If you cancel your subscription: your account and data stay until you choose to delete them.
- Payment records: invoices and payment records are kept by us and Stripe for as long as the law requires (normally six years in the UK).
7. Your rights under UK GDPR
- Access: ask for a copy of the data we hold about you
- Rectification: ask us to correct inaccurate data
- Erasure: delete your account and all its data yourself from inside the app (Settings → Delete Account), or email us
- Portability: ask for your data in a machine-readable format
- Objection: object to processing based on legitimate interest
- Restriction: ask us to pause processing while a concern is resolved
- Withdraw consent: turn off optional emails at any time in Settings
To use any of these rights, email support@itscorvo.com. We'll respond within one month.
If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO), the UK's data protection regulator.
8. Data security
- All data is sent over HTTPS
- Your Canvas or Moodle access token is encrypted at rest (AES-256-GCM), kept on our servers only, and never sent back to your browser
- Every request for your data requires you to be signed in, and database row-level security means accounts can only reach their own data
- Research Assistant files are kept in private storage that is never publicly accessible
9. Your learning platform and your university
Corvo is a personal tool. You choose to connect it to your own Canvas or Moodle account, and you can revoke that access at any time from your learning platform's settings (in Canvas: Account → Settings → Approved Integrations). We have no data-sharing agreement with any university and never send data back to your institution.
Some universities restrict connecting third-party tools to their learning platform. If yours does, you can still use Corvo by uploading your lecture files yourself.
10. US students: FERPA and state privacy laws
Because you, not your university, choose to connect Corvo and control that connection, Corvo is not acting as your institution's "school official" under the Family Educational Rights and Privacy Act (FERPA). We apply the same data minimisation and security practices described in this policy to every student, wherever they are.
California and other US states. If you're a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, to delete it, and to opt out of its sale. Corvo does not sell personal information and has not done so in the past 12 months. We honour the equivalent rights for residents of other US states with comparable laws (such as Virginia, Colorado and Connecticut). To use these rights, email support@itscorvo.com.
11. Children
Corvo is for university students aged 18 and over. We don't knowingly collect data from anyone under 18. If you believe we have, contact support@itscorvo.com and we'll delete it.
12. Changes to this policy
If we make material changes to this policy, we'll email you and update the "Last updated" date at the top of this page.
Questions? Email support@itscorvo.com · Terms of Service · Accessibility Statement