Draft — not yet binding
This document is a working draft awaiting legal review. It describes how the platform behaves today, honestly and in plain language, but it has not been checked by a lawyer and it does not yet form an agreement between you and anyone. Passages shown like this are values nobody has decided yet.
Privacy Policy
Depthloom is a learning platform that builds a personalised roadmap for you and writes each lesson in it on demand. Doing that means handling three things that are personal to you: your account details, the material you bring, and the record of what you have learned.
The single most important thing on this page: what you write and what you upload is sent to third-party AI providers — Anthropic and OpenAI — so that it can be turned into a roadmap, a lesson, or an answer. That is not an optional feature you can switch off while continuing to use the platform; it is how the platform works at all. Section 2 says exactly what leaves and when.
1. Who this applies to
This policy describes how {{COMPANY_LEGAL_NAME}}, registered at {{REGISTERED_ADDRESS}}, handles information about the people who use Depthloom. It covers the web application, the roadmaps and lessons created inside it, the Teacher chat, and the materials people upload to ground their own learning.
It applies whether you signed up for yourself or were invited to somebody else’s roadmap. Where the two differ — and they do, because a roadmap owner can see some things about an invited learner — the difference is set out in section 6 rather than left to be inferred.
2. Your content is sent to AI providers
Depthloom does not write roadmaps or lessons itself. It sends your content to large language models operated by Anthropic and OpenAI, and what comes back is what you read. There is no version of the product where this does not happen.
What gets sent, and when:
- What you tell the Teacher. The interview that works out what you already know and what you want to reach — every message you write in it — is sent so that the next question and, eventually, the roadmap can be composed.
- What you upload. Documents and pasted text you add as materials are extracted into plain text, split into passages, and turned into numerical embeddings. The passages relevant to a lesson are sent along with the request to write it, so that the lesson is grounded in your material rather than in generic knowledge.
- Your roadmap and its lessons. Titles, module structure, the lesson currently being written and enough of the surrounding lessons for it to follow on coherently.
- Your answers and your questions. What you write in an assessment, and anything you ask the Teacher about a lesson you are reading, is sent in order to be marked or answered.
- Images you add to a lesson are sent when the model needs to see them to answer a question about them.
Anthropic and OpenAI are independent companies. Content sent to them is handled under their own terms and their own privacy commitments, which Depthloom does not control and cannot vary on your behalf. If your material is confidential — a client’s document, an employer’s internal notes, anything you are not free to disclose to a third party — do not upload it. The platform has no way to use it without sending it.
Which provider and which model handles a given piece of work is a routing decision made by the platform, and it changes as models are added or retired. Both providers named above should be assumed to be in scope for anything you write or upload.
3. What is collected
Four kinds of thing, and nothing beyond what each is described as here.
- Your account. Your email address, which is also how you sign in, and the name you choose to display. Nothing else is required to hold an account.
- What you build and what you do with it. The roadmaps composed for you, the modules and lessons inside them, which lessons you have opened and completed, and the answers you write to the questions and assessments in them. This is the record that lets the platform pick up where you left off and adapt what comes next; a learning platform that forgot your progress would have nothing to adapt to.
- Materials and images you upload. The original file or pasted text, the plain text extracted from it, the passages it was split into, and the embeddings computed from those passages. Images you add to your own lessons are stored alongside them.
- Usage records, for cost accounting. Every time a model runs on your behalf, the platform records which model it was and how many tokens the request and the response used. This is what the credit system is metered against — it is how your balance goes down by the right amount — and it is kept as an operational and billing record. These records describe the size and shape of a request, and the account it belongs to.
Ordinary technical information that any web service receives — the request itself, and whatever your browser sends with it — reaches the servers in the course of serving you a page.
4. Signing in, and why there is no password
Depthloom stores no passwords, because it has none. Signing in works by one-time code: you give your email address, a short code is sent to it, and entering that code creates your session. There is no password field, no password reset, and no stored password hash that could be stolen and cracked.
The consequence is worth stating plainly: access to your mailbox is access to your Depthloom account. Anyone who can read email sent to your address can sign in as you. If you share a mailbox, or leave one open, you have shared the account with it.
Once you are signed in, the session is held in a cookie your browser sends back on each request. It identifies your session and nothing more; it is not used to track you across other websites. If two-factor authentication is enabled on your account, the second factor is checked at sign-in in addition to the emailed code.
5. Payment
Payments are processed by Stripe. Card numbers, expiry dates and security codes are entered into Stripe’s own payment fields and go to Stripe directly. Depthloom does not receive, see or store card details.
What the platform holds is the result of a payment rather than the means of it: which plan you are on, whether the subscription is active, when the current period ends, and the credits a payment granted. Stripe handles the money and is the record of what you paid; its own privacy terms govern what it does with the details you give it.
7. Where it is kept, and for how long
Account details, roadmaps, lessons, progress and usage records are held in the platform’s own database. Uploaded files are held in object storage. Both are located in {{DATA_HOSTING_LOCATION}}. Content sent to the AI providers described in section 2 is additionally processed on their infrastructure, wherever that is, under their terms.
While your account is open, your content is kept so that you can use it — a roadmap you cannot come back to next month is not a roadmap. Records are retained for {{DATA_RETENTION_PERIOD}}.
You can delete a roadmap or a material yourself, from inside the product. Deleting a roadmap removes the files uploaded to it from object storage as well as the roadmap record. When an account is closed, its content is erased from live systems and from backups within {{DELETED_ACCOUNT_ERASURE_WINDOW}}. Content already transmitted to an AI provider before deletion is subject to that provider’s own retention, which Depthloom cannot reach into.
8. Your rights over what is held
You can ask to see what is held about you, to have it corrected, to have it exported, or to have it deleted. Write to {{DATA_REQUEST_EMAIL}} from the address on the account, and expect an answer within {{RIGHTS_RESPONSE_WINDOW}}.
The rights you have, and the conditions on them, come from {{DATA_PROTECTION_FRAMEWORK}}. This page does not claim compliance with any particular regime — that is a legal characterisation for the review this document is still waiting on, and asserting it before then would be exactly the kind of confident sentence a policy should not contain. What is described above is what the platform does.
If a request is handled badly, you may complain to {{COMPLAINT_AUTHORITY}}.
9. Changes to this policy
This policy changes when the platform does — a new provider, a new kind of upload, a different retention period. When something material changes, the date at the top of this page is updated and account holders are told before the change takes effect. Continuing to use Depthloom after that point means the current version applies to you.
10. Governing law
This policy is governed by {{GOVERNING_LAW}}, and disputes about it are dealt with as set out in the Terms of Use.
11. Contact
Questions about this policy, or about anything on it that is not clear, go to {{CONTACT_EMAIL}}. Requests about your own data go to {{DATA_REQUEST_EMAIL}}, as described in section 8. Post reaches {{COMPANY_LEGAL_NAME}} at {{REGISTERED_ADDRESS}}.