Back

Privacy Policy

Last updated August 14, 2026

1. Who we are

AgoFact is operated by MakeWithMe Inc (d/b/a AgoFact), a Delaware corporation in the United States (“we”, “us”). This policy explains what we collect when you use www.agofact.com and our related services, why we collect it, who else sees it, and the choices you have.

AgoFact lets you chat with an AI that turns your course materials into interactive study apps, and lets you publish those apps for other students. Doing that means your content passes through AI model providers and other service providers; this policy names them.

Where your data lives. We are a US company and our infrastructure runs in the United States. Your information is stored and processed there, wherever you are using AgoFact from. Questions about anything in this policy go to kero@agofact.com.

2. Information we collect

Account data. Your email address; a password, stored only as a cryptographic hash and never in plain text; an optional display name, username, and profile picture; the school we infer from your email domain and any school you tell us yourself; whether your email is verified; and a Stripe customer reference if you subscribe. If you start as a guest before signing up, we hold a temporary guest account and the prompts you typed, so your work is not lost when you create a real account.

Sign in with Google. If you sign in with Google we receive the profile information you authorize: your email address, your name and profile picture, and a stable Google account identifier (the Google sub). Sign-in requests identity permissions only — we never receive your Google password, and we do not read Gmail. Connecting Google Drive is a separate, optional step that grants access only to the specific files you pick in Google’s own picker, never your whole Drive.

Academic email. If you verify a school address, we store that address separately from your login email along with its verification status.

Uploaded study materials. The files, notes, and images you upload or import (from Google Drive or Notion), the text we extract from them, and the AI-written summaries we generate from that text. Extracted full text is encrypted at rest with an application-layer key in addition to our providers’ own storage encryption.

Chat transcripts. The prompts and messages you send, the AI’s replies, and the study apps built from them, kept with your account so your chats and apps persist between sessions.

Practice work and grading. When you use practice essays or question sets, we store the answer text you submit, the score and marks the AI grader assigns, and the written feedback it produces.

Grade verification. This is the most sensitive thing we handle, so we will be blunt about it. If you choose to verify grades for your creator profile, you upload an academic transcript or grade report. That document is sent to an AI model, which reads the transcript, extracts the student name printed on it, and extracts the grades in order to check them against what you claimed. We keep the verification outcome — including the name read off the document and the per-course result — as a fraud-prevention record. This flow is entirely optional; if you never request grade verification, you never send us a transcript.

Payment and payout data. Payments run through Stripe. Card numbers never touch our servers. We store your Stripe customer reference, your subscription status, and a ledger of payment events. If you join the creator revenue-share program, Stripe Connect collects identity-verification (KYC) and banking details directly from you; we store only your connected-account status and the payout requests and transfers.

Referral relationships. If you arrive through a referral link, a first-touch cookie records which link brought you here, and we record who referred you when you sign up.

Things you send us on purpose. Feedback you submit (free text, plus your email so we can reply) and requests to add a school (your email and the school name).

Usage telemetry. Product analytics events, searches you run in discovery, interactions with published apps, error reports, bot- detection signals, IP address (for rate limiting and abuse prevention), and browser and device information. We also keep a per-user record of AI usage — which model processed your content, token counts, and what it cost us — for billing, quota, and cost control.

3. How we use your information

We use what we collect to:

  • create and operate your account, and verify school affiliation where eligibility requires it;
  • run the core product — chat, document extraction, and building, storing, and serving your study apps. Doing this means sending your prompts and relevant materials to AI model providers (see section 4);
  • grade practice work and generate feedback, and personalize what we recommend to you;
  • operate publishing, discovery, ratings, referrals, and creator earnings, including verifying grade claims;
  • process payments, subscriptions, and creator payouts;
  • send transactional email (verification links, build notifications) and product and study emails you can unsubscribe from (see section 9);
  • measure and improve the product, including analytics and advertising measurement (see section 5);
  • keep the service secure — preventing abuse, fraud, and automated scraping — and comply with legal obligations.

We do not sell your personal information, and we do not use data obtained through Sign in with Google or Google Drive for advertising.

4. How AI processing works

AgoFact is built on AI models operated by third parties. Your content goes to them only to produce the output you asked for.

  • Routing. Chat, app building, extraction, and grading are routed through the Vercel AI Gateway to model providers — today Anthropic (Claude), Google (Gemini, used for document extraction and as the current build model), and xAI (Grok). We also call Anthropic directly for some build work. Which models we use changes over time as better ones ship.
  • Files. Study files used in a build may be forwarded to Anthropic’s Files API so later rebuilds do not have to re-upload them.
  • Build sandboxes. Study apps are built by an agent running in an isolated micro-virtual-machine on Amazon Web Services in the US (Oregon, us-west-2), which receives the study text needed for that build.
  • Usage records. For every AI call we keep a record tied to your account: which provider and model ran, token counts, and cost. This is metadata about the call, not a second copy of your content.
  • Grade verification. Transcripts you submit are read by an AI model as described in section 2.

AI output can be wrong. Treat study apps, summaries, and grades as study aids to check, not as authoritative answers.

5. Who we share information with

We share information with service providers that process it on our behalf, under their own terms and our contracts with them. As of the date above, the full list is:

  • Vercel — hosting, Vercel Blob file storage, web analytics, BotId bot protection, and AI Gateway routing.
  • Neon — our Postgres database (account data, content, transaction records).
  • Amazon Web Services (us-west-2) — build-worker microVMs, S3 storage, and Secrets Manager.
  • Our managed Redis provider — short-lived caching, queues, and rate-limit counters keyed by account or IP.
  • Anthropic, Google, and xAI — AI model inference, via the Vercel AI Gateway and (for Anthropic) directly.
  • Stripe and Stripe Connect — subscription payments and creator payouts, including payout KYC held by Stripe.
  • Resend — delivery of our transactional and product emails.
  • PostHog (US cloud, served through a first-party /ingest proxy on our domain) — product analytics and error tracking. Analytics events are tied to your account. We do not send the content of your prompts or study materials to analytics.
  • Google — Sign in with Google, and the Google Drive file-scoped picker if you connect Drive.
  • Notion — importing the pages you select, if you connect Notion.

We may also disclose information when required by law, to protect the rights and safety of users and the public, or in connection with a merger, acquisition, or sale of assets, with notice to you.

Advertising pixels. Four advertising pixels load on every page of AgoFact, for logged-out visitors and signed-in users alike. They are:

  • Google Ads (tag AW-18249871770) — page views, plus conversion events when you sign up, complete your first build, or purchase. Purchase conversions include the amount, currency, and a transaction reference so Google can deduplicate them.
  • Meta Pixel (ID 1389876356440751) — page views, plus registration and build-start events.
  • Reddit Pixel (ID a2_jgzp7opd0p1p) — page visits and build-start events.
  • OpenAI Ads pixel (the oaiq measurement tag) — build-start events, and a registration event keyed by your internal AgoFact user id, which is sent so the same signup cannot be counted twice. That identifier is an opaque AgoFact account id, not your email or name.

These pixels also set or read their own cookies and identifiers, and each platform may use them to attribute conversions and build advertising audiences under its own privacy policy. We do not sell your personal information in the ordinary sense of the phrase — nobody pays us for your data. But sharing conversion data with advertising platforms may count as “sharing” or “targeted advertising” under some US state privacy laws, so we say so plainly here. Section 7 describes how to limit it.

6. What becomes public when you publish

AgoFact is partly a public library, so publishing is a real disclosure. When you publish a study app, the following become publicly accessible on the web, indexable by search engines, and visible to other AgoFact users:

  • the app itself, playable in the browser;
  • its title and description;
  • the creation prompt — the original prompt you typed to build the app is shown on the listing. Do not put anything private in a build prompt you intend to publish;
  • the preview image and an AI-written summary used for search;
  • course, professor, and term information attached to the listing;
  • your public creator profile at /u/your-username — display name, username, avatar, school, your published apps, and any grade badges you verified;
  • ratings and reviews other students leave.

Other users can fork a published app into their own workspace and adapt it there. If you ask us to take a listing down we will stop new access to it, but forks already made by other users remain in their accounts. Uploaded files and images are stored at long, unguessable web addresses: they are not listed publicly, but anyone holding the exact link can open the file, so treat a file link like the file itself.

7. Cookies and tracking

We use a session cookie to keep you signed in, short-lived state and nonce cookies to secure sign-in and connection flows, a first-touch referral cookie, PostHog analytics cookies, and the cookies and identifiers set by the four advertising pixels listed in section 5.

We do not have a cookie consent banner or an in-app cookie manager today, and the advertising pixels load without asking first. We would rather say that than pretend otherwise. Your controls are:

  • your browser’s cookie settings, private browsing, or a tracker-blocking extension — these block the pixels outright;
  • your ad settings at each platform (Google Ads settings, Meta ad preferences, Reddit ad personalization, OpenAI ad settings), which control how each platform uses what it receives;
  • emailing kero@agofact.com to ask us to exclude your account from ad measurement.

Blocking the session cookie will stop you from staying signed in.

8. How long we keep things

We keep your information for as long as your account is active and as long as we need it to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. We delete account data on request (see section 9).

Some records outlive a deletion request, and you should know which: payment and payout records we are required to keep for tax and accounting; grade-verification outcomes, which exist to prevent fraud in the creator program; and apps other users forked from your published listings before removal, which belong to them. Where a provider holds a copy on our behalf — for example files stored with Anthropic’s Files API — we ask them to remove it as part of deletion.

9. Your rights and choices

Access, correction, and deletion. Email kero@agofact.com from your account email address to ask for a copy of your data, a correction, or deletion of your account and its data. We will verify the request and act on it within the time applicable law requires. To be clear about the current state of the product: there is no self-serve delete or export button yet — these requests are handled by a person, by email.

Marketing email — this one is self-serve. By creating an account you agree to receive product and study emails from us. Every one of those emails carries a one-click unsubscribe link (and supports your mail client’s built-in unsubscribe button); clicking it stops them immediately, with no login required. Transactional email — address verification and build notifications — is part of the service and is not covered by that opt-out.

South Africa (POPIA). For users in South Africa, MakeWithMe Inc is the responsible party under the Protection of Personal Information Act, 2013, and our information officer is reachable at kero@agofact.com. You have the right to request access to, correction of, or deletion of your personal information, to object to processing, and to complain to the Information Regulator (South Africa) at www.inforegulator.org.za.

United States. If you live in a state with a comprehensive privacy law, you may have rights to know, access, correct, and delete your personal information, to opt out of “sharing” for cross-context advertising, and not to be discriminated against for exercising them. Use the same email address above; for advertising specifically, section 7 lists the controls that take effect immediately.

10. Children and users under 18

AgoFact is available to people aged 13 and over. If you are between 13 and 17, you may use AgoFact only if a parent or legal guardian has reviewed our Terms and this policy and consented to your use of the service; by creating an account you confirm that they have.

We do not knowingly collect personal information from children under 13. If we learn that an under-13 account exists, we delete it and its data. If you believe a child under 13 has given us personal information, email kero@agofact.com and we will remove it.

11. International transfers

Students use AgoFact from South Africa, the United States, and elsewhere, but our infrastructure and our providers process and store data in the United States. Using AgoFact means your personal information is transferred to and processed in the US, where privacy laws differ from those in your own country. Our providers are bound by contractual protections, and this policy applies to your information wherever it is processed.

12. Security

We encrypt data in transit, rely on our infrastructure providers’ encryption at rest, and add application-layer encryption for extracted document text. Study apps are built inside isolated micro-virtual-machines rather than a shared environment, and access to production data is limited to the people who need it. Passwords are stored only as hashes, and card details are held by Stripe rather than by us.

No method of transmission or storage is perfectly secure. If you find a vulnerability, please report it to kero@agofact.com rather than disclosing it publicly.

13. Changes to this policy, and contact

We may update this policy as the product changes. When we do, we will update the date at the top of this page, and for material changes we will give additional notice in the product or by email. Continuing to use AgoFact after a change means the updated policy applies to you.

Questions, requests, or complaints go to kero@agofact.com. MakeWithMe Inc, d/b/a AgoFact, is a Delaware corporation in the United States.