Crosscheck

Privacy policy

In force September 8, 2026. Version 2026-09-08.

The short version

  • Your notes, uploads, flashcards and review history stay in your own browser. They are never uploaded to a Crosscheck server.
  • The account is an email address and a password, and that is all it is for.
  • Nothing is sold. There is no advertising, no analytics and no tracking script on this site.
  • When you use Study Buddy or ask Crosscheck to write practice material, the parts of your material needed to answer go to a model provider. Nothing else leaves your device on its own.

Who runs Crosscheck

Crosscheck is built and run by Johnson Digital Solutions, a sole proprietorship in California, United States. Write to Isaacj.business2025@gmail.com with anything on this page.

Crosscheck is not affiliated with, endorsed by, or acting for any school, university or learning management system, Canvas and Instructure included.

What stays on your device

Everything you study from is kept in your own browser storage, on the device in front of you:

  • Files you upload: notes, slides, PDFs, Word documents, a syllabus, and photographs. A photograph is sent once to be read, described below, and what is stored afterwards is the text that came back. The picture itself is not kept, here or anywhere.
  • The text pulled out of them, and the concepts and highlights drawn from that text.
  • Flashcards, quizzes, word problems, matching sets, and every answer you have given.
  • Your review history and scheduling data, which is what makes the spacing work.
  • The profile you fill in: name, school, major, year, and what you are working toward this term.
  • Class events, and the address of any calendar feed you connected.

None of it is uploaded to a Crosscheck server. There is no copy we could read even if we wanted to, and no administrator screen that shows a student’s material, because it was never sent.

That cuts both ways, so it is worth being blunt: material held only in a browser is private by construction and is not backed up. Clearing site data, studying in a private window, or moving to another browser or device leaves it behind. Settings has an export to CSV, Markdown and a JSON archive. That export is your backup.

What we do hold

Three things, all of them with Supabase, the account and database provider:

  • Your account. Email address, an encrypted password, when the account was made and last used, and the record that you accepted this policy and when. Supabase runs the sign in itself and your password never reaches our code.
  • Feedback you send. If you use the feedback form in Settings: your message, whether you marked it an idea, a problem or praise, which screen you were on, your email address and your account id.
  • Nothing else. There is no uploads bucket, no table of your study material and no record of what you studied.

When you use an AI feature

Five features need a language model: Study Buddy, generated flashcards and quiz questions, generated word problems, the class research that works out what a course usually covers, and reading a photograph. They are the only reason your material would ever leave the device, and they run only when you ask for them.

Reading a photograph is the one worth pausing on, because it is the only one that happens while you are adding material rather than after. Every other upload is read here in the browser and nothing leaves: a PDF is parsed on your machine, a Word file is unzipped on your machine. A photograph of handwriting or a whiteboard cannot be, so the picture itself is sent to the model to be transcribed, and whatever else is in the frame goes with it. The upload screen says so before you choose a file. If a photo has something in it you would rather not send, crop it first or type the part you need.

What goes: the passages of your own material relevant to the request, the class name and code, the concepts already pulled out, and the profile details that shape an answer, meaning your school, year, major and goal. Study Buddy also sends the conversation so far so the reply follows on.

Where it goes depends on whose key is paying:

  • Your own key. Connect one in Settings and the request runs on your account with the provider you chose, under their terms rather than anyone else’s.
  • The shared key. With no key of your own, the request runs on the one the operator pays for. Today that is Google Gemini on the free tier. Google states that free tier prompts may be used to improve their products, so treat the shared key as something another person could read, and do not send anything through it you would not want reviewed. Crosscheck names the model that answered, and connecting your own key is the way past this.

No prompt, answer or conversation is stored on our server. Study Buddy writes the conversation back to your browser, not to us.

Your own model key

A key you connect in Settings is held in your browser on that device. It travels with each request so the server can build one client from it, is used, and is dropped. It is never written to a database, a log or a file. Removing it in Settings removes it.

The calendar import

Canvas will not let a browser read a calendar feed directly, so a feed address you paste is fetched by our server for you and handed straight back to your browser. The address and the events are stored on your device. We keep neither the feed nor what is in it.

Cookies and tracking

Crosscheck sets the cookies Supabase needs to keep you signed in. That is the entire list. No analytics package, no advertising pixel, no session recorder, no third party script running in your browser. Fonts are served from Crosscheck itself, so reading this page does not tell a font company you were here.

We do not sell personal information, we do not share it for advertising, and we never have.

Who else is involved

  • Supabase holds the accounts database and runs sign in. United States.
  • Vercel hosts and serves the app. Like any web host it keeps ordinary request logs, which include IP addresses, timestamps and browser user agent, to run the service and defend it from abuse.
  • Model providers receive only what an AI feature sends, described above: Google, or Anthropic when the operator has a Claude key in place, or whichever of Google, Groq, OpenAI or Anthropic you connected yourself.

Nobody else receives anything.

How long things are kept

Your account and the record of this acceptance last until you close the account. Feedback is kept for as long as it is useful, because it is what the next version gets built from, but it stops being attached to you: closing an account clears both your account id and the email address from anything you sent, leaving the words on their own. Hosting logs follow the host’s own retention, measured in days. Study material has no retention period here, because we never had it.

Deleting things

  • Your study material: Settings can erase everything on the device. Clearing site data in your browser does the same.
  • Your account: Settings, then Close account. It runs at once and cannot be undone. The account is deleted, your local material is wiped, and any feedback you sent stays with your account id and email address cleared from it.
  • Anything else: write to the address below and ask. You can ask what we hold, ask for a copy, ask for a correction, or ask for deletion.

Security

Everything travels over HTTPS. Passwords are hashed by Supabase and never reach our code. The database enforces row level security, so a signed in student can read their own feedback and nothing else, and no administrative key that could step around those rules exists in the app or its environment. Closing an account runs through a function that reads your id from your own session, so it is structurally unable to delete anyone else.

The honest limit: no system is perfect, and the strongest protection here is that your material never leaves your device to begin with.

Students, schools and FERPA

Crosscheck is a tool you choose for yourself. It is not a school service, we hold no contract with your institution, and we are not a school official under FERPA. What you bring is your own copy of your own coursework.

If a class or a school policy limits sending course material to an AI service, that is yours to check and follow, and connecting your own key does not change it.

Age

You need to be 13 or older to make an account. If you are under 18, read this with a parent or guardian. We do not knowingly collect anything from a child under 13, and if you believe we have, write to us and it will be deleted.

Your rights

Wherever you live you can ask what we hold, ask for a copy, ask for a correction and ask for deletion. Most of it you can do yourself in Settings without asking anyone, and we will never treat you worse for asking.

California residents: we do not sell or share personal information, we do not use it for targeted advertising, and we do not profile you, so there is nothing here to opt out of.

In the EU or the UK: we process your account because it is needed to provide the service you signed up for, and we run an AI feature on your instruction each time you use one. You can withdraw by closing the account, and you may complain to your local supervisory authority.

If this policy changes

The version and date at the top say which policy you agreed to. If it changes in a way that matters, Crosscheck stops and asks you to read and accept the new one before you carry on. A small correction that does not change what happens to your data gets a new date and no interruption.

Contact

Isaacj.business2025@gmail.com. It is a small operation, and a real person reads it.

Back to sign in