BAP AI Tutor Privacy Policy

Last updated: May 1, 2026

Effective date: May 1, 2026

Policy URL: https://bap.best/privacy

The short version. BAP is an AI-assisted study platform for college students. We collect the information needed to run the service (your account, the coursework you upload, the chats you have with the tutor, and how you use study groups), we send selected content to AI providers under no-training contracts so the tutor can answer you, and we charge a subscription through Stripe. We do not sell your personal information, we do not share it for cross-context advertising, and we do not let our AI providers train their models on your content. We honor data-subject rights including access, deletion, correction, and portability for users in the United States, the EU/UK, and elsewhere.

1. Who this policy covers

This policy explains how BAP, Inc., a Delaware corporation ("BAP," "we," "us," "our"), collects, uses, shares, and protects information about people who use the BAP service. It applies to:

The BAP AI Tutor — Smart Importer Chrome extension is governed by a separate, narrower policy at bap.best/privacy-extension. Where the extension transfers content into your BAP account, this policy then applies to that content.

BAP is operated from the United States. Our service is intended for college and university students aged 18 and older. See Section 10 for how we handle younger users.

2. Information we collect

We collect only what we need to operate the service, satisfy our legal obligations, and protect users. The categories below describe what we collect, where it comes from, and why.

2.1 Account and identity information

2.2 Coursework and content you provide

2.3 Service-provider authentication tokens

2.4 Usage and device information

2.5 Billing information

2.6 Communications and support

2.7 Information we do not collect

3. How we use information

We use the information described above only for the purposes listed below. Where our basis under EU or UK GDPR matters, we identify it.

Purpose What we use GDPR lawful basis
Create and operate your account; authenticate you Email, display name, password (via Firebase), Google account ID Performance of a contract (Art. 6(1)(b))
Provide AI tutoring, study-plan generation, and content retrieval Files you upload, imported LMS content, your messages, course embeddings Performance of a contract (Art. 6(1)(b))
Run study groups and peer features Display name, content you choose to share, group membership Performance of a contract (Art. 6(1)(b))
Charge for and manage subscriptions Stripe customer ID, plan status, country, currency Performance of a contract; legal obligation (tax) (Art. 6(1)(b), (c))
Enforce plan limits and prevent abuse Usage events, IP address, account activity Legitimate interests (Art. 6(1)(f))
Secure the service and detect fraud Logs, IP, audit events, authentication signals Legitimate interests; legal obligation (Art. 6(1)(f), (c))
Send transactional and security emails Email, account events Performance of a contract (Art. 6(1)(b))
Comply with FERPA-aligned recordkeeping when we work with schools Audit log, consent records Legal obligation; legitimate interests (Art. 6(1)(c), (f))
Verify age and obtain parental consent where required Hashed date of birth; parental email and consent token Legal obligation (COPPA); consent (Art. 6(1)(c), (a))
Improve the BAP product Aggregated, de-identified usage data Legitimate interests (Art. 6(1)(f))

What we do not do. We do not use your account information, your coursework, your AI-tutor conversations, or your study-group content for advertising. We do not use your information to assess your creditworthiness, eligibility for lending, or eligibility for insurance. We do not make consequential decisions about you using AI: BAP does not assign grades, make admissions decisions, allocate scholarships, or make employment decisions.

4. AI tutoring and how your content is processed

When you ask the BAP tutor a question or generate a study artifact, BAP sends the content needed to answer the request to one or more AI service providers. As of the date of this policy, those providers are:

No model training on your content. BAP accesses these providers through their commercial APIs under terms that prohibit them from using your content to train their general-purpose foundation models. We do not opt in to any "improve the model" or "share for training" setting on these APIs. If we ever change which providers we use or expand the list, we will update this section before the change takes effect.

What gets sent. The provider receives only what is needed to produce the response you asked for: your prompt, the relevant retrieved passages from your course materials, and prior turns in the same conversation. The provider does not receive your account email, your billing information, or your study-group membership.

Limits on automated processing. AI output is not authoritative. The tutor can be wrong. You are responsible for verifying important facts before relying on them, especially for graded assignments and exams. We do not use AI to make consequential decisions about you (see Section 3).

Embeddings and retrieval. We compute numeric "embeddings" of your course materials and store them in our retrieval database (Chroma). Embeddings let the tutor find the right passage to cite when you ask a question. Embeddings are derived from your content and are protected by the same access controls.

If you do not want a particular file to be available to the AI tutor, do not upload it to your BAP workspace. You can also delete a file at any time, which removes it from the AI retrieval index. See Section 7.

5. How we share information and our service providers

We share information only with the categories of recipients below, only for the purposes shown, and only under written agreements that require them to protect your information and use it solely on our instructions.

Recipient Role Why
Google LLC (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Vertex AI, Gemini) Hosting, database, file storage, authentication, AI inference Run the BAP backend and serve AI responses
Anthropic, PBC AI inference Power BAP tutor, study plan, and explanation features
Stripe, Inc. Payment processing Charge subscriptions; process refunds; meet tax obligations
OVHcloud US, LLC Application hosting Run the BAP application servers
Email transport provider (Google Gmail SMTP for transactional mail) Email delivery Send sign-in, password reset, and parental-consent emails
Apple Inc. iOS app distribution Distribute the BAP iOS app and process App Store payments where applicable
Your school, when your school contracts with BAP Education-records partner Receive aggregated, opt-in instructor-visible analytics for the courses you enroll in (see Section 11)
Other BAP users you choose to interact with Peer collaborators Display your shared content in study groups and shared workspaces
Legal, regulatory, and law-enforcement authorities Compliance recipients Respond to lawful requests and protect rights and safety
An acquirer or successor Corporate-transaction recipient Continue providing the service if BAP merges, is acquired, or sells substantially all assets — subject to this policy

We do not sell your personal information. Under California, Colorado, Connecticut, Virginia, Texas, Maryland, and other state privacy laws, "sale" means disclosing personal information for monetary or other valuable consideration, and "sharing" means disclosing it for cross-context behavioral advertising. We do neither.

We do not run third-party advertising on the service. We do not embed advertising pixels (including from Meta, Google Ads, TikTok, LinkedIn, Snap, X/Twitter, or any other ad network) on the signed-in BAP product.

6. Cookies and similar technologies

We use a small number of cookies and local storage entries that are strictly necessary to operate the service:

We do not use cookies or local storage for advertising, cross-site tracking, retargeting, or analytics-vendor profiling. We do not embed third-party tags such as Google Analytics, Meta Pixel, LinkedIn Insight Tag, or TikTok Pixel on the BAP application.

Global Privacy Control (GPC) and "Do Not Track." Because we do not sell or share your personal information for cross-context behavioral advertising, GPC signals do not change how we process your information; we already do not engage in those practices. We do not respond to legacy "Do Not Track" headers because there is no consensus standard for them.

7. Your choices and account controls

8. U.S. state privacy rights

If you live in a U.S. state with a comprehensive consumer-privacy law — including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia — you have the rights summarized here. Some of these laws give residents additional or differently-framed rights; we honor whichever rights apply to you.

How to exercise these rights. Email [email protected] with the subject line "Privacy request" and tell us which right you are exercising. We will verify your identity by matching your request to the email associated with your BAP account; we may ask additional verification questions for sensitive requests. We respond within forty-five (45) days and may extend by another forty-five (45) days if reasonably necessary, with notice to you.

California-specific notes.

Maryland Online Data Privacy Act (effective Oct. 1, 2025). We collect only the personal data reasonably necessary and proportionate to provide the BAP service to you. We do not sell sensitive data. We do not use the personal data of consumers we know to be under 18 for targeted advertising and we do not sell the personal data of those consumers.

Nevada (NRS Chapter 603A). Nevada residents can submit a verified request directing us not to make any future "sale" of their covered information to [email protected]. We do not sell covered information.

9. EU, UK, and Swiss rights

If you are in the European Economic Area, the United Kingdom, or Switzerland, the following rights apply under the EU GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection, as applicable.

Controller. BAP is the controller for the processing described in this policy. Our contact details are in Section 17. We have not appointed a Data Protection Officer because our processing does not meet the thresholds in Art. 37; for any data-protection question, write to [email protected].

EU/UK representative. BAP does not currently maintain establishment in the EU or UK. If you are an EU/UK user and need an in-region representative, contact us at [email protected]; we will identify a representative if your circumstances require one under Art. 27.

10. Children and minors

BAP is intended for users 18 and older. We do not direct the service to children under 13 and we do not knowingly collect personal information from children under 13 without verifiable parental consent.

The BAP signup flow asks for date of birth. Based on the answer:

For minors aged 13 to 17:

We comply with the Children's Online Privacy Protection Act (COPPA) and the FTC's 2025 amendments to the COPPA Rule, including the requirement of separate verifiable parental consent for third-party disclosures and the data-retention limits in 16 CFR § 312.10.

11. Education records and FERPA

The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records held by schools. BAP, as a service offered directly to students, generally does not hold "education records" within FERPA's meaning when a student voluntarily uploads their own coursework. The student is making the disclosure; the school is not.

Where a school contracts with BAP to provide the service to its students, BAP operates as a "school official" under 34 CFR § 99.31(a)(1)(i)(B). In that role:

Instructor visibility is opt-in. Even where your school uses BAP, an instructor cannot see your individual progress unless you choose to share it. The default is private. Consent changes are recorded in the audit log.

Aggregate analytics. Where your school uses BAP, instructors may see aggregated, privacy-thresholded analytics about cohort performance. We suppress aggregates that fall below the threshold needed to prevent re-identification of individual students.

NY Education Law § 2-d. Section 2-d applies to NY pre-K–12 educational agencies and their contractors. BAP is offered to higher-education users and is not a § 2-d "third-party contractor" for any K–12 agency unless we sign a contract that brings us within scope, in which case the K–12-specific Parents' Bill of Rights, data security and privacy plan, and 8 NYCRR Part 121 obligations attach.

12. How long we keep information

We retain information only as long as needed to provide the service and to meet our legal, accounting, and security obligations. Specific schedules:

If you ask us to delete your account, we complete deletion within thirty (30) days, except for the records above that we are required to retain. Backups are purged on the schedule above; we do not restore deleted accounts from backup except where necessary to investigate a security incident.

13. Security

We use a layered set of administrative, technical, and physical safeguards to protect your information.

Breach notification. If we determine that a security incident has compromised your personal information, we will notify you and, where applicable, regulators in the time required by law, including New York General Business Law § 899-aa, California Civil Code § 1798.82, and other applicable state and EU/UK breach-notification laws.

No system is perfectly secure. You can help by using a strong, unique password, enabling multi-factor authentication on your Google account if you sign in with Google, and reporting anything suspicious to [email protected].

14. International data transfers

BAP is operated from the United States, and our service providers are predominantly U.S.-based. If you access BAP from outside the United States, your information will be transferred to and processed in the United States.

For users in the European Economic Area, the United Kingdom, or Switzerland, BAP transfers personal data to the United States under the following safeguards:

You can request a copy of the SCCs that apply to your data by emailing [email protected].

15. Third-party sites and integrations

BAP links to and integrates with services we do not operate, including learning-management systems (Gradescope, Canvas/Instructure, Brightspace/D2L, Blackboard, Google Classroom), Google sign-in, Stripe checkout, and Apple App Store distribution. When you interact with those services, their own privacy policies and terms apply. We are not responsible for their practices.

16. Changes to this policy

We may update this policy from time to time. When we make a material change, we will update the "Last updated" date at the top, post the new policy at https://bap.best/privacy, and where required by law notify you by email or in the application before the change takes effect. Continuing to use BAP after the effective date of an update constitutes acceptance of the updated policy.

We maintain a change log of material revisions and can provide a prior version on request.

17. Contact and how to exercise rights

Privacy contact. Email [email protected] for any privacy question or to exercise a right. Use the subject line "Privacy request" for data-subject requests so we can route your message correctly.

Security contact. Email [email protected] to report a security issue. We support coordinated disclosure and will not pursue good-faith security research conducted within the bounds of our security policy.

General support. Email [email protected].

Operator. BAP, Inc., a Delaware corporation. For privacy questions and legal notices, contact [email protected].

This policy is the complete privacy notice for the BAP web application and the BAP iOS application. The Chrome extension is governed by a narrower companion policy at bap.best/privacy-extension. Where the extension imports content into your BAP account, this policy applies to that content from the moment it reaches BAP.