Privacy
How your study data is handled.
Public content is available without an account. Once you sign in, this notice describes what the application keeps, why it is used, and how to request access or deletion.
Last updated: July 27, 2026
What we collect
Public study pages need no account. When you create an account we receive your identity through WorkOS and store the account link plus any profile details you add — display name, target exam, target score, and test date.
As you use the tools we store submitted practice-attempt records, private learning-notebook entries you choose to save, private AI tutor conversations, subscription state, and support or correction messages you submit. Tutor prompts, the context you select, generated responses, and the selected model and reasoning-effort settings are stored in your owner-scoped saved chats and sent to OpenAI when needed for the response; chat content is not used for application analytics. If you connect ChatGPT, the application stores OpenAI's managed Codex credential in a private server directory isolated to your Keiko account; that credential is not placed in browser storage, your profile, tutor history, analytics, or the application database. Payment card entry is handled on Stripe-hosted Checkout rather than by this application.
Why we use it
To run the product you asked for: saving progress, showing your dashboard, checking practice answers on the server, gating premium features, and replying to support or correction requests.
We do not sell your data, and we do not build advertising profiles. Progress figures are computed only from your own attempts — there is no hidden scoring model.
Who processes it
WorkOS provides Keiko authentication, Supabase hosts the application database, and Stripe processes payments and subscription billing. OpenAI provides the separately connected ChatGPT account and processes tutor prompts, selected context, and generated responses. Keiko's authenticated server starts OpenAI's device-code sign-in, manages the resulting Codex credential, and relays each tutor request.
OpenAI and the open-source Codex runtime are external dependencies with their own terms and privacy information. Do not put payment details, passwords, or other unnecessary sensitive information into tutor or support messages.
Cookies and sessions
Signed-in Keiko sessions use a secure, http-only session cookie so the server can recognise you between requests. A browser preference key remembers your light/dark theme. ChatGPT device sign-in does not put the ChatGPT credential in browser storage; the browser receives only a short-lived one-time code and connection status. The application does not currently configure third-party advertising or analytics cookies.
Your choices
You can disconnect ChatGPT from the tutor page to clear Keiko's server-side Codex credential for that connection, delete individual saved tutor chats, view and edit your profile and learning notebook, delete individual notebook entries, and request a copy or deletion of account data by emailing support@keiko.study. The application does not yet provide a self-service account-deletion control, so support must verify and process that request; some billing or security records may need to be retained. Saved practice attempts and notebook entries are not deleted merely because you upgrade, downgrade, cancel, or let Pro expire; saved tutor chats follow the same retention rule. Attempts kept only on one browser after an account allowance is full are not part of the account record or export.
Changes
If this notice changes materially we will update the date above and, for signed-in users, surface the change in-product. Continued use after an update means you accept the revised notice.
Questions about your data? Email support@keiko.study.