Privacy Policy
Last updated 31 August 2026
Practix helps students turn their own lecture material into a practice exam or a short quiz. This page explains, in plain terms, what happens to the things you put into it.
The short version: your coursework is never uploaded to a Practix server, and neither is your AI provider key. Both go straight from your browser to the AI provider you have chosen.
Documents you upload
PDFs you add are opened and read inside your browser. Practix extracts the text locally and the file itself never leaves your device — it is not uploaded to, stored on, or logged by any Practix server.
The extracted text is sent directly from your browser to whichever AI provider you selected — OpenRouter, Anthropic, OpenAI or Google — so it can write and grade your questions. That text is subject to that provider's own privacy policy. Practix does not receive a copy.
Your AI provider API key
Practix runs on a bring-your-own-key basis. You can save a key for OpenRouter, Anthropic (Claude), OpenAI (GPT) or Google (Gemini). Each key is saved in your browser's local storage and is sent directly from your browser to that provider's own API with each request. It is never proxied through, or logged by, a Practix server.
If — and only if — you sign in and enable settings sync, your key is also stored so it can follow you to another device. In that case it is encrypted with AES-256-GCM before it reaches the database, using a secret held only in the server environment. Anyone with database access alone, including a leaked database backup, cannot recover it.
You can clear any stored key at any time from AI Settings.
Data kept in your browser
Practix stores the following in your browser's local storage. It stays on your device, and clearing your browser data removes it permanently:
- Your AI settings, including your API keys and chosen models.
- An in-progress exam attempt, so a refresh does not destroy a timed run.
- A record of which topics you have answered correctly, used to weight future practice exams toward your weak areas.
- Your light or dark theme preference.
Accounts
You can use Practix without an account. Signing in is optional and does one thing: it lets your AI settings follow you across devices.
Accounts are handled by Supabase Auth. If you sign in with Google, Google shares your email address and basic profile information with Practix; Practix stores your email address and a user identifier. Practix never receives your Google password. You may also sign in with an email magic link, in which case only your email address is stored.
Practix does not use your Google account for anything other than identifying you at sign-in.
Who else is involved
- The AI provider you choose — OpenRouter, Anthropic, OpenAI or Google — receives the extracted text of your documents and your questions and answers, in order to generate and grade them. Only the provider you have selected receives anything.
- Supabase — provides authentication and, if you enable sync, stores your encrypted settings.
- Vercel — hosts the site and processes standard server request logs.
- Google — only if you choose to sign in with Google.
Practix runs no advertising, no third-party analytics, and no tracking pixels. Your data is not sold or shared for marketing.
Deleting your data
Clearing your browser's site data removes everything stored locally. To delete a synced settings record and the account behind it, contact us at the address below and it will be removed.
Changes
If this policy changes materially, the date at the top of this page will change with it.
Contact
Questions about privacy, or a deletion request: hello@studio4any.com