Privacy Policy

Pre-Launch / Private Beta Privacy Notice

Version1.1 — Pre-Launch / Private Beta
Effective date14 July 2026
OperatorEduintel LLC
Websitependlearn.com

This Privacy Policy explains how PendLearn handles account information, device information, temporary audio, encrypted offline recordings, transcripts, AI conversations, support information, and website data during the pre-launch beta. It is written as a layered notice: Sections 2 and 3 provide the practical summary; later sections provide detailed legal information.

1. Who we are and scope of this Policy

Eduintel LLC, a Wyoming limited liability company, operating the PendLearn brand ("PendLearn", "we", "us", or "our"), is responsible for the personal information described in this Policy unless a separate institutional agreement states otherwise. Our business address is 30 N Gould St Ste R, Sheridan, WY 82801, USA.

This Policy applies to the PendLearn website, waitlist, mobile application, wearable recorder, beta firmware, AI assistant, support channels, and related pre-launch services. It does not apply to third-party services that you use independently or to information processed solely by a university, employer, or other organization under its own policies.

When an institution provides PendLearn to users under a separate agreement, the institution may be the controller or business for some data and PendLearn may act as its processor or service provider. The institution should give users an additional notice explaining that relationship.

PendLearn is currently pre-launch. We will update this Policy before material changes to the production architecture or public commercial release.

2. Privacy summary

The main points are:

  • Recording begins only when the user starts a session or activates a supported live mode.
  • When the paired phone is connected, audio may be transmitted securely to the phone and temporarily processed to create a transcript. Under the default transcript-only model, temporary audio is deleted after successful processing.
  • When the phone is unavailable, audio may be temporarily stored in encrypted form on the pendant until the phone reconnects and synchronization is completed.
  • The pendant retains offline audio until successful transfer is confirmed. Temporary audio on the phone is deleted after processing, subject to limited retry, backup, security, and legal requirements.
  • If a live connection drops, the unsent portion may be temporarily stored on the pendant for later synchronization.
  • Transcripts are stored on the phone by default. Account, configuration, and synchronization functions may use Firebase. Cloud transcript synchronization will be identified in the app and, where offered, can be controlled through settings.
  • AI requests may send transcript excerpts, prompts, or user-selected attachments to providers such as OpenAI or Google Gemini.
  • PendLearn personnel do not routinely read private transcripts or AI conversations. Access is restricted to exceptional support, security, abuse, or legal needs.
  • We do not sell personal information or share it for cross-context behavioral advertising. We do not use private audio, transcripts, or AI conversations to train general-purpose AI models without explicit opt-in.
  • The current beta is for adults aged 18 or older.

3. How the pendant handles audio

PendLearn uses two principal audio paths depending on whether the paired phone is available. Audio is used temporarily to provide transcription and related features; under the default product model, the durable user-facing result is the transcript.

SituationWhat happens to audioWhat is retained by default
Phone connected — normal live pathAudio is transmitted securely to the paired phone and temporarily processed to create a transcript.Transcript and related organization data. Temporary audio is deleted after successful processing.
Phone unavailable — offline pathAudio is temporarily stored in encrypted form on the pendant. When the phone reconnects, it is securely synchronized and processed.Transcript. Offline audio remains only until successful transfer is confirmed; temporary phone audio may remain for a limited retry period.
Live connection dropsThe unsent portion may be temporarily stored on the pendant and synchronized later.Transcript after the stored remainder is processed.
Reflection ModeAudio is streamed to the connected phone for real-time processing and is not intended to be stored on the pendant.Transcript and AI interaction, unless a future optional audio-retention feature is clearly enabled by the user.

When connected, the pendant may send audio securely to the paired phone for temporary processing. When the phone is unavailable, the pendant may retain an encrypted recording until synchronization succeeds. We will not materially expand audio retention without updating this Policy and obtaining consent where required.

Normal recording sessions may skip silence. Reflection Mode may stream continuously while active. The device may use more than one microphone to improve capture or detect speech activity. PendLearn does not use audio to create a biometric voiceprint or identify a person by voice.

4. Personal information we collect

CategoryExamplesSource
Account and identity dataName, email address, account ID, authentication method, login tokens, country or language setting.You; Google or Apple sign-in providers.
Waitlist and beta dataEmail, role, institution, device interest, invitation status, survey responses, testing cohort, consent records.You; beta administrators.
Device and pairing dataPendLearn device ID, firmware version, app version, paired-phone identifier, Bluetooth state, battery level, charging state, recording count, mode, diagnostic events.Pendant and app.
Audio and recording metadataTemporary live audio, encrypted offline recordings, recording time, duration, synchronization status, and processing state.Pendant and app when you start a session.
Transcript and learning contentTranscripts, highlights, session titles, notes, summaries, search queries, explanations, exports, tags, and corrections.Generated from your session or entered by you.
AI conversation dataPrompts, questions, responses, selected transcript excerpts, uploaded photos or files, model/provider used, safety and quality signals.You, app, and AI providers.
Usage and diagnosticsFeature interactions, crash reports, latency, error codes, connection quality, storage state, performance metrics, approximate region derived from network data.App, website, device, and service providers.
Support and communicationsEmails, support requests, bug reports, interview notes, device returns, screenshots or files you choose to send.You and our support team.
Website and cookie dataIP address, browser, device type, pages viewed, referral source, necessary cookies, consent choices, optional analytics if enabled.Your browser and website providers.

Audio and transcripts can incidentally contain information about other people or sensitive topics. We do not ask users to record sensitive information, and we do not intentionally infer health, religion, political opinion, sexuality, ethnicity, or similar protected characteristics for advertising or profiling.

5. How we use personal information

We use personal information to:

  • Create and secure accounts; authenticate users; pair and manage devices.
  • Capture, protect, transfer, transcribe, organize, search, summarize, explain, export, and delete user content as requested.
  • Provide AI responses, Reflection Mode, highlights, reminders, and personalized learning features selected by the user.
  • Operate device synchronization, battery information, firmware updates, backups, crash recovery, and support.
  • Detect fraud, unauthorized access, malware, abuse, recording misuse, and threats to users or systems.
  • Measure reliability, diagnose errors, improve microphones, connectivity, transcription quality, accessibility, user experience, and battery performance.
  • Administer waitlists, beta invitations, surveys, device returns, research interviews, and launch communications.
  • Comply with legal obligations, respond to lawful requests, protect rights and safety, establish or defend legal claims, and enforce our Terms.
  • Send optional product news or marketing where permitted and according to your communication choices.

We do not use private content for targeted advertising, sell it, or use it to make decisions about your employment, credit, housing, insurance, education admission, healthcare, or other similarly significant matters.

Where the GDPR or UK GDPR applies, we rely on the following legal bases. The applicable basis depends on the feature and context.

PurposeTypical legal basisExplanation
Provide accounts, device functions, transcription, storage, export, and AI featuresPerformance of a contractProcessing is necessary to provide the Services you request under the Terms.
Optional marketing, non-essential cookies, optional research recordings, or optional model-improvement participationConsentYou may withdraw consent at any time without affecting prior lawful processing.
Security, fraud prevention, service reliability, limited diagnostics, product improvement, and defending claimsLegitimate interestsOur interests are to protect users and operate a safe, reliable pre-launch service. We assess necessity and user impact and provide objection rights where applicable.
Tax, accounting, regulatory, safety, consumer-protection, and lawful government requestsLegal obligationProcessing is required to comply with applicable law.
Urgent threats to life or physical safetyVital interestsUsed only where necessary in an emergency.

We do not intentionally process special-category data for our own independent purposes. If a future feature requires such processing, we will identify an Article 9 condition, such as explicit consent, and provide a separate explanation before processing begins.

7. Audio, transcripts, AI conversations, and human access

PendLearn personnel do not routinely listen to source audio or read private transcripts and AI conversations. Access controls should technically restrict content access to the user and authorized systems.

A limited number of authorized personnel or contracted service providers may access content only when reasonably necessary to provide support requested by you, investigate a security incident, diagnose a reproducible failure, comply with law, prevent serious abuse, or restore data. Where practical, we will ask for permission before support access and use redacted or de-identified data.

We maintain confidentiality obligations and role-based controls for people who can access production systems. Access may be logged and reviewed. During early beta development, some systems may not yet support every planned production control; we will limit beta data and update controls before public launch.

If you share a transcript, export a PDF, copy AI output, or allow another person to use your phone or account, that recipient may keep a copy outside PendLearn's control. Deleting the original from PendLearn does not delete copies held by others.

8. Local storage, Firebase, and cloud synchronization

The default product design stores transcripts on the user's phone. Offline recordings are deleted from the pendant after successful synchronization is confirmed, subject to normal storage cleanup processes.

PendLearn uses Firebase and related Google services for functions that may include account authentication, backend APIs, configuration, push notifications, crash reporting, synchronization state, and cloud storage. Account and operational data may therefore be stored in Firebase.

Transcript content is intended to remain local by default unless cloud synchronization, backup, multi-device access, institutional storage, or another cloud feature is enabled or clearly required by the selected service. The app will identify material cloud-content features and provide controls where reasonably available.

Local app data may be included in phone backups controlled by Apple, Google, the device manufacturer, or the user. Those backup systems are not fully controlled by PendLearn. Users should review phone backup settings if they require local-only handling.

Deleting the mobile app does not automatically erase the account, Firebase records, phone backups, or audio still stored on a disconnected pendant. Use the in-app deletion controls, synchronize or factory-reset the pendant where appropriate, and submit an account-deletion request if you want broader deletion.

9. AI providers and model training

To provide transcription and AI features, PendLearn may send prompts, transcript excerpts, temporary audio or derived text, and user-selected attachments to service providers. Current or planned providers include OpenAI and Google Gemini. We may use additional providers after appropriate review and will update this Policy or an in-app provider notice when the change is material.

We seek to use business or API arrangements, security settings, and contractual protections appropriate to the feature. Provider processing, retention, and location can differ by service configuration. We do not promise a provider-specific retention period unless it is stated in the app or a separate contract.

PendLearn does not use private audio, transcripts, or AI conversations to train general-purpose models without explicit opt-in. We will not instruct a third-party provider to use private content for its independent general-model training. If an optional improvement program is offered, it will be separate, voluntary, and revocable for future contributions.

We may use de-identified quality measurements, error rates, latency, language statistics, and user-submitted feedback to improve PendLearn, provided the information cannot reasonably be linked back to an individual.

10. How we disclose personal information

We disclose personal information only as described below. We do not sell personal information and do not share it for cross-context behavioral advertising.

RecipientPurpose and information
Cloud and infrastructure providersHosting, Firebase, databases, storage, authentication, notifications, monitoring, backups, and security.
AI and transcription providersAudio, transcript excerpts, prompts, attachments, and technical metadata necessary to generate the requested result.
Apple, Google, and app platformsAuthentication, app distribution, device notifications, diagnostics, purchases if introduced later, and platform security.
Support, email, survey, and analytics providersCommunications, beta research, necessary website operation, consented analytics, crash reporting, and customer support.
Professional advisers and auditorsLegal, accounting, insurance, security, compliance, financing, and due diligence under confidentiality duties.
Authorities and affected partiesWhen reasonably necessary to comply with law, protect rights and safety, investigate serious misuse, respond to valid legal process, or handle a security incident.
Corporate transaction partiesIn a merger, financing, investment, reorganization, asset transfer, or acquisition, subject to confidentiality and applicable notice requirements.
At your directionWhen you export, share, integrate, invite, or otherwise direct us to disclose information.

Service providers are expected to process personal information only for contracted purposes and under appropriate confidentiality, security, and data-protection terms. We remain responsible for selecting and managing providers as required by applicable law.

11. International data transfers

PendLearn, its users, and its providers may operate in different countries. Personal information can therefore be processed outside the country where it was collected, including in the European Economic Area, United Kingdom, United States, and other locations used by our service providers.

Where EEA or UK personal information is transferred to a country without an adequacy decision, we use an appropriate transfer mechanism where required, such as approved contractual clauses and supplementary safeguards. You may request information about applicable safeguards at hello@pendlearn.com.

No transfer mechanism eliminates every legal or governmental-access risk. We evaluate providers, minimize content transfers, use encryption where appropriate, and update our safeguards when legal requirements change.

12. Retention and deletion

We retain personal information only for as long as needed for the purposes described in this Policy, including service delivery, user instructions, security, backups, dispute resolution, and legal obligations. The following are our intended pre-launch retention rules; shorter deletion may apply when technically possible or when you delete data.

DataTypical retention
Live audio on the phoneTemporary processing only. Deleted after successful transcription, normally promptly and generally within 24 hours.
Offline encrypted audio on the pendantUntil successful transfer to the paired phone is confirmed, or until the user deletes or factory-resets the recording. Routine storage cleanup may follow.
Temporary received audio on the phoneUntil transcription and verification are complete. If processing fails, it may remain for retry for up to 7 days unless the user deletes it sooner.
Transcripts, notes, and AI conversationsUntil the user deletes them, disables a relevant cloud feature, or deletes the account, subject to limited backup and legal retention.
Account and authentication dataFor the life of the account, then normally deleted or de-identified from active systems within 30 days after a valid deletion request.
Waitlist and beta recordsUntil the beta or launch communication purpose ends, and generally no longer than 24 months after the last meaningful interaction, unless consent is renewed or deletion is requested.
Diagnostics and security logsGenerally up to 12 months; longer where needed to investigate an incident, prevent abuse, or meet legal obligations.
Support communicationsGenerally 24 months after closure, unless a longer period is needed for warranty, safety, legal claims, or user-requested follow-up.
BackupsDeleted through normal rotation, generally within 90 days after deletion from active systems, unless legally preserved.

A deletion request may not remove information that we must retain by law, information needed to establish or defend legal claims, de-identified information, or copies held independently by recipients. We will explain a lawful exception when required.

Deletion may involve secure logical deletion followed by routine storage cleanup. Limited residual copies may remain temporarily in backups or technical systems until normal deletion cycles complete, unless a longer retention period is required by law.

13. Security

PendLearn uses administrative, technical, and physical safeguards appropriate to the nature of the information and the pre-launch risk. Measures may include encryption where appropriate, secure communications, access controls, authentication, logging, backups, testing, and controlled deletion. We do not publish detailed security architecture in this Policy because doing so could reduce security and disclose confidential implementation information.

Security measures evolve and no product can guarantee absolute security. Beta firmware and software may contain defects. Users should keep the phone operating system and PendLearn app current, install required firmware updates, use a device passcode, protect account credentials, avoid untrusted computers, and keep exported transcripts secure.

If we confirm a personal-data breach, we will investigate, mitigate, document, and notify affected people and regulators when required by applicable law. Security concerns can be reported to hello@pendlearn.com.

14. Your privacy choices and rights

Depending on your location, you may have the right to access, correct, delete, restrict, object to, or receive a portable copy of personal information; withdraw consent; opt out of marketing; appeal a refusal; and complain to a regulator.

The application is intended to let users delete individual transcripts and AI conversations, export transcripts to PDF, manage cloud synchronization where offered, disable optional analytics or marketing, and request account deletion. Additional export formats may be introduced later.

To exercise a right, use the in-app controls or contact hello@pendlearn.com. We may need to verify your identity and relationship to the account. We will not discriminate against you for exercising a privacy right.

A request does not automatically remove audio still located on a disconnected pendant, copies in a phone backup, or exports shared outside PendLearn. You may need to reconnect or factory-reset the pendant and manage phone or cloud-backup settings.

We may deny or limit a request where permitted by law, including where we cannot verify identity, the request would adversely affect another person's rights, the information is legally protected, or retention is required. We will provide an explanation and appeal information where required.

15. EEA, UK, and Swiss information

Controller: Eduintel LLC, a Wyoming limited liability company, operating as PendLearn. Business address: 30 N Gould St Ste R, Sheridan, WY 82801, USA. Privacy contact: hello@pendlearn.com.

You may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent at any time. Where processing is based on legitimate interests, you may object based on your particular situation. Direct-marketing objections are honored at any time.

We aim to respond to verified requests within one month, subject to lawful extensions. You may lodge a complaint with the data-protection authority in your country of residence, place of work, or place of the alleged infringement. We encourage you to contact us first so we can try to resolve the concern.

If PendLearn is required to appoint a Data Protection Officer, EU representative, or UK representative as the business and launch regions develop, the applicable contact details will be published in this section and in the website Legal Notice.

16. California and other US state notices

This section supplements the rest of the Policy for residents of California and US states with similar comprehensive privacy laws. PendLearn may not currently meet every statutory applicability threshold, but we provide the following transparency and rights where reasonably practicable.

Categories of personal information collected or planned include identifiers; customer records; internet or electronic-network activity; geolocation limited to coarse network-derived region if used; audio information; educational or professional information voluntarily provided; inferences based on user-selected learning preferences; and sensitive personal information contained incidentally in user content or credentials.

We collect and use these categories for the business and commercial purposes described in Sections 5 and 6, and disclose them to the categories of recipients described in Section 10. We retain them according to Section 12.

PendLearn does not sell personal information and does not share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics for advertising. Therefore, we do not currently provide a "Do Not Sell or Share" link. If our practices change, we will provide the legally required opt-out mechanism.

Subject to applicable law, residents may request to know/access, correct, delete, or obtain a portable copy; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive information; and appeal a denial. Authorized agents may submit requests where permitted, subject to verification.

We do not knowingly collect personal information from children under 13, and the current beta does not permit users under 18. We do not offer financial incentives in exchange for personal information during the pre-launch phase.

17. Other regional rights

Residents of Canada, Brazil, Australia, New Zealand, Singapore, Japan, South Korea, and other jurisdictions may have additional rights concerning notice, access, correction, deletion, consent withdrawal, objection, portability, complaints, and cross-border transfers.

We will interpret requests consistently with the law that applies to the requester and will provide locally required information or remedies. Where local law requires a specific representative, grievance officer, consent form, or regulator contact, we will add it before launching in that jurisdiction.

This global Policy does not replace institution-specific notices, data-processing agreements, or local terms required for a particular university, employer, public authority, or regulated deployment.

18. Cookies and similar technologies

The website and app may use strictly necessary technologies for sign-in, security, session management, language, consent choices, load balancing, and fraud prevention. These are used because they are necessary to provide the requested service or for legitimate security purposes.

Optional analytics, advertising, or similar non-essential technologies will be disabled until the user makes a valid choice where consent is required. The website will provide a cookie or privacy setting when optional technologies are introduced.

Browser controls may block cookies, but blocking necessary technologies can prevent sign-in or other functions. App permissions, advertising identifiers, and notification permissions can be managed through the phone operating system.

19. Children and minors

The current pre-launch beta is intended only for adults aged 18 or older. It is not directed to children, and we do not knowingly allow minors to create accounts.

If we learn that a minor has provided personal information in violation of this Policy, we will take reasonable steps to suspend the account and delete the information, subject to legal obligations and protection of the minor. A parent or guardian may contact hello@pendlearn.com.

Before offering PendLearn to high-school students or other minors, we will implement a separate age-appropriate program that may include verified guardian consent, school authorization, child-friendly notices, restricted AI features, stronger default retention limits, and jurisdiction-specific protections.

20. Automated decision-making

PendLearn uses automated systems to transcribe audio, generate summaries and explanations, organize content, detect technical failures, and apply safety controls. These systems can make mistakes.

PendLearn does not use solely automated processing to make decisions that produce legal or similarly significant effects concerning users, such as admission, grading, employment, credit, housing, insurance, or healthcare eligibility. Users and institutions must not treat PendLearn output as an authoritative automated decision.

Where a future feature involves legally regulated profiling or significant automated decisions, we will provide a specific notice, meaningful information about the logic and consequences, and applicable human-review or opt-out rights before enabling it.

21. Changes to this Policy

We may update this Policy as the beta evolves, providers change, new features launch, or laws develop. The effective date and version appear at the beginning.

We will provide prominent notice of material changes through the app, website, or email. If a change requires consent, it will apply only after valid consent. Earlier versions may be archived for reference.

22. Contact and complaints

Privacy requests, questions, and complaints: hello@pendlearn.com

General support, legal notices, and security reports: hello@pendlearn.com

Controller: Eduintel LLC

Business address: 30 N Gould St Ste R, Sheridan, WY 82801, USA

Website: pendlearn.com

You may also complain to the data-protection or consumer-protection authority that has jurisdiction where you live or work. We ask that you contact us first so we have an opportunity to address the concern.