Privacy Policy
Last Updated: September 30, 2026 • Effective Date: September 30, 2026
Introduction
Lykke ("we," "our," or "the Service") is operated by Lykke Technologies and consists of the Lykke web application at getlykke.com, the Lykke Knowledge Companion Chrome extension, and related APIs. The Service helps students organize course materials, take notes, and use AI to generate study tools such as flashcards, quizzes, study guides, summaries, infographics, and course wikis.
This Privacy Policy explains what information we collect, how we use it, how your content flows through our AI providers, and your rights regarding your data. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
If you sign in with Google or connect Google Calendar, Section 5, Google User Data, explains exactly what we access from Google, how we use, store, share and protect it, and how to delete it.
1. Information We Collect
Account & Identity
- Profile: Name, email, profile picture, institution (if provided)
- Authentication: Session tokens (we do not store passwords in plaintext)
- Preferences: Settings, selected classes, theme, notification preferences
Canvas LMS Data
When you connect Canvas:
- User Information: Canvas user ID, profile (name, email)
- Course Information: Names, codes, identifiers, descriptions, enrollment, term info
- Course Materials: Files (PDFs, docs), assignments, announcements, modules, calendar events, syllabus
- Course Roster: Names and roles of the instructors and classmates Canvas shows you, for course context (you can turn this off in the extension's settings)
Google Account & Calendar
- Sign in with Google: Name, email address, profile picture
- Google Calendar (optional): Events on your primary calendar and the email address of the connected Google account, only after you choose to connect it
- Details in Section 5
Your Study Content
- Notes: Text, rich content, block-level annotations on wikis
- Documents: Files you upload (PDF, DOCX, PPTX, images, etc.) and their extracted text
- Generated Materials: Flashcards, quizzes, summaries, infographics, study guides, wikis
- Chats: Prompts and responses exchanged with the AI study assistant
Web Clipper & YouTube
- Web Page Content: Text, titles, URLs you save via the clipper
- YouTube: Video URL, title, and transcript when you save a video
- Class Tags: Optional class associations you apply
- Timestamps: When content was saved
Usage & Analytics
- Product Analytics: Events (feature usage, clicks) via PostHog
- Diagnostics: Error reports, request logs, performance metrics
- Credits: AI generation credits consumed and remaining
- Optional AI-assistant learning signals: If you opt in through MCP settings, the assistant's reason for reading or searching a course is classified into a course topic and learning intent. Only that classification, your account id, course id, and time are stored for up to 30 days.
Technical Data (Local)
Stored in your browser / on-device:
- Cached course lists, documents, and notes for performance
- Sync timestamps and status
- Selected classes and filter state
2. How We Use Your Information
Primary Purposes
- Sync & Organize: Bring your Canvas and uploaded materials into your personal knowledge base.
- Search: Index your content so you can find and reference it semantically.
- AI Study Tools: Generate flashcards, quizzes, study guides, summaries, infographics, mind maps, practice problems, and course wikis from your selected sources.
- Conversational Study: Answer questions about your material in chat, with citations back to the original source.
- Personalization: Remember preferences, recent chats, and saved materials.
Specific Uses
- Content Processing: Extract text from PDFs, DOCX, images, and other uploads for indexing.
- Embeddings: Generate vector embeddings of your notes and documents to power semantic search and retrieval-augmented generation (RAG).
- Duplicate Prevention: Track which files have been uploaded to avoid redundancy.
- Quota Enforcement: Track credits consumed by AI generations.
- Opted-in Educator Insights: Summarize broad course topics explored through connected AI assistants for a course owner only after at least three students contribute; no individual MCP reason or request is shown.
3. Where Your Data Is Stored
Backend Services
- Primary API: api.getlykke.com
- File Storage: AWS S3 (
getlykke-assets) - Database: MongoDB
- Vector Database: Zilliz (Milvus Cloud)
Storage Details
Data Location
Data is stored on servers located in the United States, encrypted at rest and in transit (TLS/HTTPS).
Files You Upload
Files you upload, and files synced from Canvas, are stored in Amazon S3. Each file has its own web address with a long random part. We don't list or publish these addresses, but anyone who has a file's address can open it, for as long as we store the file. The same goes for pictures Lykke cuts from your PDFs to illustrate a course.
A file's address is shown to you and to people who can see the file in Lykke, such as classmates in a synced Canvas class. Some providers in Sections 4 and 6 receive it so they can read the file. If you publish a course built from your files, the course links to them, so anyone reading it, search engines included, can open them.
Embeddings
Vector representations of your notes and documents are stored in Zilliz to power semantic search and source retrieval during AI chat.
4. AI Providers & What We Send Them
For ordinary study generations and chat turns, Lykke sends portions of your selected study content and your prompt to third-party AI providers. If you opt in to MCP learning signals, an AI model also classifies the reason your connected assistant gives for reading or searching a course; that reason is not stored in the learning signal. Educator summaries are generated from grouped course topics and counts, without individual reasons or requests. We do not send other users' content to fulfil your request.
Your private MCP activity history records tool names, connected app or API key labels, times, outcomes, durations, and the brief reasons supplied by your assistant for up to 30 days. Recording is enabled by default and can be paused or cleared in Settings → AI assistants → MCP activity. Raw tool arguments and results are excluded from this history; successful course reads may include their course identifier. These reasons are visible only to you and are separate from optional educator summaries and shared learning snapshots.
Learning records remain private unless you explicitly select evidence cards and create an expiring sharing link. Anyone with that link can see the selected snapshot and the profile fields you chose; you can revoke the link. Raw tool reasons, prompts, answers, and private conversations are excluded. Daily preparation is off by default; when enabled, selected synced teaching sources are sent to an AI provider to generate source-cited questions, and the preparation is retained for 30 days.
| Provider | Model(s) | Features | What We Send |
|---|---|---|---|
Google Gemini Google LLC | gemini-2.5-pro, gemini-flash-latest | Study material generation (flashcards, quizzes, summaries, study guides, infographics), course wiki generation, chat responses, and reading uploaded files other tools can’t (Word, PowerPoint, Excel and CSV files, and some PDFs) through the Gemini Files API. Google deletes files sent this way within 48 hours. | Prompts, selected notes, selected document text/files, chat history for the current session. |
OpenAI OpenAI, via Azure | gpt-4o (chat), text-embedding-3-large (embeddings) | Chat / generation fallback, semantic search embeddings, and reading the text in images you upload. | Prompts and content snippets for chat; text of your notes and documents for embedding; the web address of each image you upload, which Azure OpenAI uses to download it. |
Anthropic (via OpenRouter) Anthropic, delivered through OpenRouter, Inc. | claude-3.5-sonnet (default) | Chat / generation fallback. | Prompts and content snippets from selected sources. |
Perplexity Perplexity AI, Inc. | sonar | Web search with citations inside AI chat. | Search queries you issue. Your private notes and documents are not sent. |
Mistral AI Mistral AI | mistral-ocr-latest | Reading the text in PDFs that have no usable text layer, such as scans. | The web address of a PDF you upload or sync; Mistral downloads the file from it. |
Model training
We use these providers through their paid API tiers. Under current provider terms (OpenAI, Anthropic, Google for API/Vertex, Perplexity API), content submitted through the API is not used to train their foundation models by default. If a provider changes its policy, we will update this section. Content is retained by each provider per their own retention policy — typically short-term for abuse monitoring.
Why multiple providers?
We route different features to the model best suited to the task and fall back across providers for reliability. The table above lists the primary use for each.
5. Google User Data
This section covers the data Lykke receives from Google APIs when you sign in with Google or connect Google Calendar: what we access, and how we use, store, share, protect, keep and delete it.
Limited Use. Lykke's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access
- Sign in with Google. Google shares your name, email address and profile picture with Lykke. We use them to create your account and sign you in.
- Google Calendar (optional). Only when you choose Connect Google Calendar, Lykke asks Google for permission to see the events on your calendars (
https://www.googleapis.com/auth/calendar.events.readonly), and for the email address of that Google account so Lykke can show which account is connected. This permission is read-only: Lykke cannot create, change or delete your events, or answer invitations. Google's permission covers all of your calendars, but Lykke only reads events on your primary calendar. - If you connected Google Calendar before October 1, 2026, Lykke asked then for permission to change your events too, and Google may still list that permission. Lykke no longer uses it. To narrow it to read-only, disconnect on the Calendar page and connect again.
- For each event on your primary calendar, Lykke receives the title, description, location, start and end time and time zone, video-meeting link, organizer and guests (their names, email addresses and RSVP responses), recurrence, status, and Google's link to the event.
- Lykke does not access your list of calendars, your other calendars, their sharing settings or your Calendar settings.
How we use it
Lykke uses Google Calendar data only for calendar features you can see in Lykke:
- Showing your events and invitations on the Calendar page, alongside your courses and study plans.
- Lykke doesn't make changes to your calendar. To add an event or a study block, Lykke opens Google Calendar's own event page with the details filled in, and the event is saved only if you press Save there. You answer invitations and delete events in Google Calendar.
- Listing up to five upcoming events (title and time) in Lykke's optional weekly email. You can turn that email off under Settings → Notifications, or with the unsubscribe link in any email.
We do not use Google user data for advertising, sell it, or use it to determine creditworthiness or for lending. We do not use it to develop, improve or train AI or machine-learning models.
Your calendar and AI
- Lykke's AI features never receive your Google Calendar data. Your events are not sent to Google Gemini, OpenAI, Anthropic (via OpenRouter), Perplexity or any other AI provider listed in Section 4, and they are not used in chats, study tools or anything Lykke generates.
- If you connect your own AI assistant to Lykke through Lykke's MCP connector, it can make a Google Calendar link for an event you ask for, which you open and save yourself. It cannot read or change your calendar, and Lykke sends it none of your Google Calendar data.
How we store it
- Google tokens. When you connect, your browser receives only a one-time code from Google. Lykke's server exchanges that code for the tokens that let it reach your calendar, so the tokens never reach your browser. Our application encrypts them before saving them, with a key that is kept on our servers and not in the database, and they are never written to our logs.
- Your events. Lykke keeps a copy of the events on your primary calendar in our database (MongoDB Atlas), covering 30 days in the past to 12 months ahead, plus any later changes. This copy lets the Calendar page load quickly and show new invitations. While your calendar is connected, Lykke refreshes it from Google about every five minutes.
How we share it
We do not sell Google user data, and we do not transfer it to advertisers, data brokers or information resellers. We share Google Calendar data only:
- with the providers that host Lykke, Amazon Web Services (our servers) and MongoDB Atlas (our database), which store and process it only to run Lykke;
- with Google, which delivers our weekly email through Gmail;
- when needed for security (for example, investigating abuse) or to comply with applicable law; or, with your explicit prior consent, as part of a merger, acquisition or sale of assets.
Our product analytics (PostHog) records that you connected Google Calendar and the domain of the connected account (for example, school.edu). It never receives your events.
How we protect it
- Encryption in transit. Traffic between your browser, Lykke's servers, our database and Google's APIs is encrypted with HTTPS/TLS.
- Encryption at rest. Our database and its backups are encrypted at rest, and Google tokens get a second layer of encryption from our application before they are saved.
- Tokens stay on our servers. Google tokens are used only by our servers to call Google, and are never sent to your browser or to any other service.
- Per-account access. Every calendar request is tied to your signed-in Lykke account, and Lykke only returns the events stored for that account.
- Least access. Lykke asks Google only for read access, and calls the Google Calendar API only to read your primary calendar for the features listed above.
- Restricted staff access. Only a small number of authorized Lykke engineers can access our production servers and database, and only to operate and support the service.
- No human reading. No one at Lykke reads your Google Calendar data unless you ask us to (for example, in a support request), it is necessary for security (for example, investigating a bug or abuse), the law requires it, or the data has been aggregated for internal operations.
- Breach notification. If we learn that your data was accessed without authorization, we will notify you as required by law.
How long we keep it, and how to delete it
- Lykke keeps your Google tokens and the copy of your events only while your Google Calendar is connected.
- Disconnect at any time. On the Calendar page, choose Disconnect. Lykke asks Google to revoke its access and immediately deletes the stored tokens and every copied event from our database.
- From your Google Account. You can also remove Lykke's access at myaccount.google.com/connections. Lykke can then no longer read your calendar. At its next sync, usually within five minutes, Lykke finds its access removed and deletes the stored tokens and every copied event. It keeps only the email address of that Google account, so the Calendar page can offer Reconnect; choose Disconnect to delete that too.
- Deleting your account. When you ask us to delete your Lykke account at hello@getlykke.com, we also ask Google to revoke Lykke's access, and delete your Google tokens and stored events.
- Backups. Deleted data can remain in our encrypted database backups for a limited time, until those backups expire.
6. Other Third-Party Services
Accessed on your behalf via your own auth. We do not store Canvas passwords.
File storage for uploaded documents and generated assets.
Primary database for user, class, note, and material records.
Vector database storing embeddings of your notes and documents for semantic search.
Product analytics: usage events and feature flags. Does not include your study content.
Auth and real-time signalling where applicable.
Fetching transcripts and metadata when you save a YouTube video.
Reads web pages you add as course sources when we can’t load them, or find their links, ourselves. It receives the page’s web address, or the address of an image you add as a source.
Reads events on your primary calendar, only if you connect Google Calendar. See Section 5.
Data We Do NOT Share
- ✕ Sell your personal information
- ✕ List or publish your private notes or files. File links are unlisted, not locked: see Files You Upload.
- ✕ Use your content for advertising
- ✕ Share with your institution beyond what you already have in Canvas
- ✕ Train our own or third-party foundation models on your content
7. Chrome Extension Permissions
| Permission | Why We Need It |
|---|---|
| storage | Keep your Lykke sign-in, chosen school, course selection, sync progress and preferences on your computer. |
| tabs | Read tab addresses to recognise your Canvas and its sign-in pages, so the extension shows the right guidance and never runs on sign-in pages. Browsing history is not collected or sent. |
| scripting | Show the Lykke guide on Canvas pages, read the page you choose to save, and read Canvas through an open Canvas tab when needed. |
| activeTab | Save the page or video you are viewing, only when you click Save. |
| identity | Sign in with Google. |
| Canvas sites (*.instructure.com and school Canvas domains) | Read the courses you choose to sync, read-only, with the Canvas session you already have. We never see or store your Canvas password. |
| api.getlykke.com | Communicate with the Lykke backend. |
| *.amazonaws.com, *.inscloudgate.net, *.instructure-uploads.com, *.canvas-user-content.com | Read a course file you chose to sync from where Canvas stores it. |
| Other sites (optional) | Asked one site at a time, only if you enable Lykke on a Canvas site that is not built in. |
8. Your Data Rights
- Access: View all collected data by logging into your Lykke account.
- Delete: Delete individual notes, documents, classes, or generated materials from the app. Request full account deletion via hello@getlykke.com (Settings → Delete Account starts that email).
- Remove synced Canvas content: On the web under Settings → Canvas (and in the extension from version 2.1, under Settings → Privacy & data), remove one synced course or everything you synced. Your files from those courses are deleted from Lykke, you leave their classes, and the courses stop syncing. Canvas itself is not changed.
- Disconnect: Unlink Canvas from the Extension settings or the web app. Disconnect Google Calendar on the Calendar page, which revokes Lykke's access and deletes the stored tokens and events (see Section 5).
- Export: Request a portable copy of your data via support.
- Opt-Out of Analytics: You can disable product analytics from your account settings.
- AI-assistant Learning Signals: Sharing is off by default. You can turn it on or off in MCP settings; turning it off removes your stored learning signals.
- Uninstall: Remove the Chrome extension at any time.
Additional Information
Data Retention
Active user data is retained while your account is active. Deleting an item removes it from our primary database and invalidates associated embeddings. Backups may retain data for a limited period. Inactive accounts (2+ years) may be flagged for deletion with notice.
Security
HTTPS/TLS encryption, encrypted at rest, scoped access tokens, strict access controls, CSRF protection, and no plaintext password storage.
Children's Privacy
Intended for students 13+. We do not knowingly collect information from children under 13.
Contact
Privacy & Support: hello@getlykke.com
By using Lykke, you acknowledge that you have read and understood this Privacy Policy.
Lykke Technologies