The short version. You can use the board — drawing, recording yourself, Studio and export — anonymously, and we collect almost nothing. If you sign in — with Google or with your email address — we store your email and profile basics so we can sync your projects. If you use AI features, your prompts and attached files are sent to Anthropic so they can generate a response; if you render a narrated video, the speaker notes are sent to Amazon Polly to be spoken. Recordings stay in your browser until you choose to download or share them — a share link puts that one video on a public URL. Microphone and camera are used only while you are recording, and only if you turn them on. If you subscribe to Pro, Dodo Payments handles the card — we never see it. We run our own first-party, cookie-free pageview counter (§2.7) and a product-activity log (§2.8) — no Google Analytics, no third-party tracker. We don't sell your data, and we don't train AI models on your content.

On this page

  1. Who this policy is from
  2. Data we collect
  3. How we use your data
  4. Legal basis (DPDP / GDPR)
  5. Third-party services we share data with
  6. How AI features handle your data
  7. Cookies & local storage
  8. Data retention
  9. Security
  10. International data transfers
  11. Your rights
  12. Children
  13. Changes to this policy
  14. Contact & data requests

1. Who this policy is from

This Privacy Policy explains how TeachBoard (an Indian sole-proprietorship, the "Data Fiduciary" / "Controller", referred to here as "we", "us") handles personal data when you use teachboard.app and related services (the "Service"). It applies to all users worldwide.

For the purposes of the EU/UK GDPR we are the controller of your personal data. For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary.

2. Data we collect

2.1 If you use the board anonymously

You can open teachboard.app and use the board — drawing, shapes, media import, recording yourself and Studio — without an account. In that mode:

2.2 If you sign in

There are two ways to sign in, and both create an account record holding your email address.

Google. When you sign in via Google OAuth, Google sends us — and we store — the following from your Google profile:

We do not receive your Google password and we do not request access to your Drive, Gmail, contacts, calendar or any other Google scope.

Email. You can instead sign in with just an email address. We email you a one-time code to prove you own the address, and store the address plus a timestamp. You may optionally set a password for faster sign-in afterwards; we store only a salted hash of it, never the password itself.

2.3 Content you create, record or upload

When you use the cloud features of TeachBoard (signed in), we store the projects you save:

Microphone and camera. When — and only when — you start a recording with them enabled, your browser captures your microphone and, if you switch it on, your camera. The same applies to a screen share you start mid-recording. These streams are mixed into the recording in your browser; they are never streamed to us live, and we do not access either device at any other time. You can tell the difference by your browser's own recording indicator, which is on only while you are recording.

Where recordings live. Finished takes are stored locally in your browser (IndexedDB) so Studio can work on them offline. They reach our servers only when you choose to: pressing Download or Share uploads the take so it can be converted to a standard MP4 (and, for Share, hosted). Recordings you never download or share never leave your machine.

2.4 Share links & public videos

If you copy a share link for a video, that video and a small metadata file (title, duration, creation date) are uploaded to our storage and served from our CDN at a public, unguessable URL, together with a public watch page. That means:

Downloading the MP4 instead of sharing it does not create a public URL: the file is converted and returned to your browser, and the uploaded copy is deleted as part of that step.

2.5 Subscription & billing data

If you subscribe to TeachBoard Pro, Dodo Payments processes the payment. We receive only:

We never see or store your full card number, CVV, UPI ID or bank credentials. Those live with Dodo Payments.

2.6 Technical & log data

Like any web service, our servers (and our infrastructure providers — see §5) automatically log:

2.7 First-party site analytics

So we can see which pages are visited and roughly how the Service is used, every page on teachboard.app includes a small first-party script (/track.js) that sends a single request per pageview to our own servers. For each pageview we record:

We do not store your raw IP address, raw User-Agent, cookies, or any other cross-session identifier as part of this analytics. We do not share this data with any third party — it is collected by, stored on, and read from our own AWS infrastructure only. The script respects the browser's Do Not Track signal and does not run if you have it enabled.

2.8 Product-activity events

So we can see where the product breaks or confuses people, the app records a small stream of coarse product events — for example: a page was drawn on, Create video was opened, a render started or failed, a quota limit was hit, a prompt was sent and what kind of thing the AI built. Each event carries the event type, a timestamp, a coarse browser family (e.g. "Chrome"), and short technical detail such as an error message.

Events from a signed-in user are attached to that account. Events from a visitor with no account are attached to the random per-browser identifier described in §2.1; if that visitor later creates an account, the two are joined so one person's session reads as one story. This log is used only by us, to run and fix the product — it is never shared, sold or used for advertising, and it does not record the content of your pages.

2.9 What we don't collect

3. How we use your data

We use the data described in §2 to:

For users in jurisdictions that require it (e.g. India under the DPDP Act, the EU/UK under the GDPR), we rely on the following grounds:

5. Third-party services we share data with

We rely on the following sub-processors / providers. Each has its own privacy policy; we only share the minimum data needed for the feature to work.

5.1 Google (sign-in)

Used for OAuth sign-in, when you choose that route. We receive your email, name, profile picture and a stable Google ID. We do not request additional scopes. If you sign in with an email address instead, Google is not involved at all.

5.2 Anthropic (AI)

When you ask the AI for anything — a lesson, a page, a chart or diagram, a math render, an edit — your prompt, attached files (if any) and a summary of the relevant part of your board are sent to Anthropic's Claude API to produce a response. Anthropic, by default on the API, does not use API inputs to train their models. See Anthropic's privacy policy.

If you are on Pro and you supply your own Anthropic API key, those requests are billed to your own Anthropic account. We store your key encrypted and use it only to make the calls you trigger; you can remove it at any time from Settings.

5.3 Amazon Web Services (AWS)

We host the Service on AWS (S3, CloudFront, Lambda, DynamoDB, etc.). Your account data, projects, math renders, shared videos and server logs are stored on AWS. AWS acts as our data processor.

5.4 Amazon Polly (AI narration)

When you render a video with the AI voice, the speaker notes for each page are sent to Amazon Polly — a text-to-speech service within AWS — which returns the spoken audio and the word timings we use to place captions. Only the narration text is sent; your drawings and images are not. Amazon Polly is covered by our AWS data-processing terms and acts as a processor; AWS states that content processed by Polly is not used to develop or improve its services where that opt-out is in effect, and we do not send Polly anything other than the narration you asked to be spoken.

5.5 Dodo Payments (billing)

Dodo Payments processes your subscription as merchant of record. They handle card data, tax calculation, invoicing and recurring billing. See Dodo's privacy policy on their website.

5.6 Freepik (icon & image search)

When you search for an icon or image from inside the board, your search query is sent to Freepik's API. Results shown in the panel are loaded directly from Freepik's CDN, which may log your IP and request metadata under their privacy policy.

5.7 Pexels (stock video search)

When you use the stock-video search, your search query is sent to Pexels' API. Video previews stream from Pexels' CDN, which may log your IP and request metadata under their privacy policy.

5.8 Other recipients

We may also disclose personal data: (a) to comply with a binding legal request or court order; (b) to enforce our Terms; (c) to protect the rights, property or safety of TeachBoard, our users or the public; or (d) in connection with a business transfer (merger, acquisition, asset sale), in which case we will give notice before personal data becomes subject to a different privacy policy.

6. How AI features handle your data

Because AI features are the most data-sensitive part of the Service, here is exactly what happens:

  1. You type a prompt (or attach a file) in the AI panel.
  2. Our backend forwards that prompt — together with the minimum context needed, such as a summary of your pages or a snapshot of the selected elements — to Anthropic's Claude API. Building a lesson makes several such calls: one to work out what you asked for, one to plan the storyboard, and one per page.
  3. Anthropic returns a response; our backend forwards it to your browser and stores it in your project history so you can refer back to it.
  4. For a math render, the model writes a Python script which is then executed on our server-side Manim + LaTeX renderer (AWS Lambda). The resulting MP4 / PNG is stored on AWS S3 and served back to you.
  5. For a narrated video, the speaker notes of each page are sent to Amazon Polly (§5.4), which returns the audio and word timings. The audio is mixed and the video is recorded in your browser — the finished video is not sent anywhere unless you download or share it (§2.3, §2.4).

We do not use your prompts, attachments or outputs to train any AI model. We do not give your content to Anthropic for model training; Anthropic's API default policy applies.

AI output is generated probabilistically and can be wrong. Check anything you are going to teach from before you publish it.

7. Cookies & local storage

We use a minimum of storage in your browser:

We do not use cookies for advertising, marketing or third-party analytics.

8. Data retention

9. Security

We take security seriously:

No system is 100% secure. If we discover a personal-data breach that is likely to result in significant harm, we will notify affected users and the relevant authorities in accordance with applicable law (including the DPDP Act and, where relevant, the GDPR's 72-hour notification requirement).

10. International data transfers

TeachBoard is operated from India. Our infrastructure providers (notably AWS, Anthropic and Dodo Payments) operate in multiple regions, including the United States and the European Union. This means your personal data may be transferred to, stored in or processed in countries other than your own.

Where we transfer personal data outside your jurisdiction, we rely on the safeguards offered by those providers (such as Standard Contractual Clauses for GDPR transfers) and limit the data shared to what is strictly necessary.

11. Your rights

Depending on where you live, you may have the right to:

To exercise any of these rights, write to us at xeonaicontact@gmail.com from the email associated with your account. We will respond within 30 days, or sooner where the law requires it.

If you believe we've mishandled your data, you also have the right to complain to your local data-protection authority — for users in India, that's the Data Protection Board of India once constituted under the DPDP Act.

12. Children

The Service is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please email xeonaicontact@gmail.com and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest revision. For material changes, we will give reasonable advance notice — for example by email or via an in-app notice — before they take effect.

14. Contact & data requests

For any privacy question, data-access request, deletion request or grievance under the DPDP Act:

Email
xeonaicontact@gmail.com
Subject prefix
[Privacy] — helps us route faster
Operator
TeachBoard (Indian sole-proprietorship)
Website
teachboard.app