Privacy Policy
Effective August 18, 2026
1 · Information we collect
Account information · your email, display name, account dates, sign-in provider, and an encrypted password hash if you use email and password. Signup asks for a birth year only to confirm eligibility; LanderOS does not save the birth year.
Workspace content · notes, topics, flashcards, study activity, calendar items, tasks, plans, preferences, saved memories, corrections, and other content you choose to create. LanderOS is local-first, and signed-in accounts also send a compressed workspace snapshot to our service for recovery and sync.
Files, images, and audio · files you attach or ask LanderOS to process, including saved voice memos. Live dictation audio sent for transcription is handled transiently by our server and is not intentionally saved as an attachment unless you choose a workflow that saves the original file.
AI interactions and service records · prompts, relevant workspace context, and files are processed when you invoke an AI feature. We also keep content-free operational records such as route, model, token or duration estimates, latency, status, account id, plan, and email so we can enforce limits, diagnose failures, and account for provider costs.
Billing information · Stripe collects payment details. We receive identifiers, plan, transaction, subscription, and status information, but not your full card number.
Optional product analytics · if you opt in from Settings, we record selected product events such as a feature being opened or an exam being completed. Autocapture and session replay are disabled, and these events are designed not to include note text, prompts, filenames, subject names, or typed content.
2 · How we use information
- Provide local workspace, sync, sharing, and recovery features.
- Run the AI, voice, document, research, and finance tools you request.
- Authenticate accounts, process payments, and enforce plan limits.
- Send account, security, billing, and opted-in digest email.
- Prevent abuse, investigate errors, and improve reliability.
3 · Service providers
Supabase · account database, synced workspace data, and private attachment storage. Stripe · checkout, subscriptions, and payment records. Vercel · app hosting, request delivery, and aggregate web analytics.
Anthropic and OpenAI · AI generation, embeddings, image understanding or generation, transcription, and text-to-speech when the requested feature needs them. We send only the content and context needed for that request. Their handling is governed by the API service terms and settings applicable to our accounts.
Resend · account and opted-in lifecycle email. Sentry · production error monitoring with session replay disabled. PostHog · optional product analytics with autocapture and session recording disabled.
Research and market-data sources · Semantic Scholar, OpenAlex, arXiv, PubMed/NCBI, and Finnhub receive the search terms or symbols needed when you use those tools. A source site may also receive ordinary browser information if you open its link.
We do not sell personal information, share notes for targeted advertising, or use your workspace to train a LanderOS model.
4 · Sharing and communications
A note or class pack is accessible to people with its share link only after you deliberately create that link. You can revoke shared content or delete your account.
Verification, password-reset, billing, and security messages are transactional. The weekly study digest is off by default and can be enabled or disabled in Settings. Digest messages include an unsubscribe link. We do not send automatic win-back marketing.
We may disclose information when required by law, to protect users or the service, or as part of a business transfer subject to appropriate notice and protections.
5 · Retention and deletion
Workspace content and saved attachments remain until you remove them or delete the account. Web-clipper content remains staged until it is imported, for no more than 30 days, or until the account is deleted. Dictation audio that is only transcribed is not intentionally retained by LanderOS after the request completes.
Account deletion removes the primary account, workspace, memories, attachments, shares, queued clips, device tokens, and usage records. Deletion stops and returns an error if that cleanup cannot complete, so you can retry or contact support. Historical API-cost records are stripped of account id and email. Payment-provider records, security logs, legal records, and provider backups may remain for the periods required by law, fraud prevention, accounting, or provider backup cycles.
6 · Your choices and rights
You can export your workspace from Settings → Workspace → Export, control analytics and digest email in Settings, revoke share links, remove individual content, or delete your account from Settings → Account → Delete.
Depending on where you live, you may also have rights to access, correct, delete, or receive a copy of personal information, or to appeal a request decision. Contact support@lander-os.com. We may need to verify that the request belongs to you.
7 · Cookies and security
We use first-party sign-in and security storage needed to operate the service. We do not use third-party advertising cookies. We use access controls, private storage, encryption in transit, password hashing, rate limits, and restricted administrative access. No system can guarantee absolute security, so report suspected account compromise promptly.
8 · Children
LanderOS is for people age 13 and older. Users age 13 through 17 need permission from a parent or legal guardian. We do not knowingly collect personal information from a child under 13. A parent or guardian who believes a child under 13 created an account should contact us so we can investigate and delete the data.
9 · Changes and contact
We may update this policy as the service changes. For a material change, we will provide notice in the app or by email before it takes effect when required. Questions or privacy requests can be sent to support@lander-os.com.