Shello 拾貝Shello 拾貝
Language: English
English繁體中文(香港)繁體中文(台灣)简体中文
HomeBooksHow it worksAboutSign in

Learn

BooksSign in

Shello

How it worksAbout
HomeBooksNotebookReviewMastery map
AccountHow it worksAbout
HomeBooksNotebookReviewMastery map

Learn

HomeBooksReview

Your learning

NotebookMastery mapAccount

Shello

How it worksAbout

Shello Privacy Policy

Working draft — not a lawyered instrument. Written for Shello's Phase-0 test cohort and TestFlight / Play Internal Testing submission. No lawyer has reviewed this policy; it needs legal review before Shello launches publicly, and it may change before then. Anything inside `[BRACKETS]` is an open question or an unmade business decision, not a typo — see `docs/policies/README.md` for the full list and who's resolving each one.

In short: we collect your account info, your lesson transcripts, and a learner profile that helps the tutor teach you better. Lessons are processed by AI providers we've checked for data-retention terms, and conversation content is never used to train a model without your opt-in. No ads, no data sales, no third-party trackers. You can export everything, any time. Deleting your account removes your personal information immediately; we keep only anonymized transcripts afterward, because they're what makes the tutor better — not you, specifically.

What we collect

  • Account basics — your email address, and a display name if you set one.
  • Lesson transcripts — the text of your conversations with the tutor.
  • Your learner model — which concepts you've studied and how well you've demonstrated you know them, plus a trait profile the tutor reads before every lesson to personalize its teaching: your pace, how concrete you like explanations, how you respond to difficulty, and any goals you've told us about.
  • Usage records — for every AI call made on your behalf, we log how many tokens it used and what it cost, for billing accuracy and cost control. These records don't contain your conversation content — only metadata about the call.
  • Session and return events — first-party records of when you open Shello and come back to it, used only to measure whether the product is actually working (things like week-4 return and retention). We don't use a third-party analytics vendor for this, and nobody outside Shello sees it.

How your lessons are processed

Shello's tutor runs on AI language models. To generate a response, your conversation is sent to whichever company hosts the model ("a model host"). Here's specifically what we do and don't do with that.

Our primary host is Fireworks AI, running the DeepSeek model. Fireworks operates a zero-data-retention posture by default: it doesn't store your prompts persistently, and even the short-lived cache used to make responses faster and cheaper lives only in volatile memory for a matter of minutes — around fifteen, in our own measurement — before it's gone. Fireworks doesn't use your conversations to train DeepSeek or any other model. We verified these terms directly on our account as of 2026-08-15.

If our primary host is unavailable, a lesson can fail over to the same DeepSeek model running on a different infrastructure host, or, in a more degraded case, to Anthropic's Claude. Fail-over only happens between lessons, never in the middle of one — a conversation is never interrupted partway through by a change of model.

Anthropic's Claude is also used, when enabled, for a few specific internal functions — testing and scoring tutor quality against practice transcripts, performing the anonymization rewrite of your transcripts if you delete your account (see Deleting your account below — that step does process your real conversation content, once, in order to remove your personal details from it), and serving as the degraded-but-safe fallback described above. The same no-training rule applies to all of it.

Across every host, your conversation content is never used to train any AI model unless you explicitly opt in. That's a standing promise, not a vendor default — it's why we picked hosts whose own terms let us keep it.

What we don't do

No ads. We don't sell your personal data, to anyone, for any reason. No third-party tracking or advertising cookies.

Signing in and where your session lives

You sign in with a magic link sent to your email — no password to leak. Once you're in, your session token is stored locally on your device: in the operating system's secure credential storage on phones, and in the browser's local storage when you use the authenticated app's web version. It's sent back to our server with each request to prove it's you; it isn't a tracking cookie, and nothing else reads it. Our sign-in system also records standard technical data with each session — your IP address and browser/device type — the way any authentication system does, for security purposes like detecting abuse.

Logging

Our servers don't put personal data in logs. Prompts — the text sent to and from the AI models — are only logged in our own development environment, never in production. That's a hard engineering rule, not a policy aspiration.

Your data: export first, delete if you want to

Export, any time

You can export a complete copy of your data as a JSON file, whenever you want, from inside the app — no waiting, no support ticket. We'd rather you leave with your data than not leave at all.

Deleting your account

Deletion is self-serve, from inside the app, and happens in two stages.

The first stage is immediate and complete, every time. We permanently delete your authentication records, your trait and relationship profile, your flashcards, your notes and highlights, and which chapter version you were studying. Your email and display name are replaced with a random, meaningless identifier. The human-readable summaries of what you got right or wrong on each concept — the kind that read like "differentiated x² correctly but couldn't explain what the answer meant" — are deleted here too; those were written as a receipt for you, and they leave with you.

The second stage anonymizes your lesson transcripts, rather than deleting them. Here's why, stated plainly: the tutor is tuned on practice transcripts with simulated learners, not on yours — but anonymized real transcripts are how we check that the teaching works, and they're the record this project accumulates over time. So instead of destroying them, we rewrite them — through an AI process, not a person, running on one of the model hosts described above under the same no-training terms — to strip out names, places, and other personal references while keeping the pedagogical content intact. Once that finishes, your account is irreversibly de-identified: there's no path back from an anonymized transcript to you. The underlying structured record of your learning evidence — which concept, what kind of evidence, when, whether you met it through tutoring or reading — stays, because it's what the tutoring system and the retention research are built on; it's disconnected from your identity and can't be traced back to you. Billing-ledger entries (tokens used, cost) are kept for financial recordkeeping, linked only to the anonymized account, never to your name again.

If the anonymizing step can't finish right away — a system limit, a temporary outage — the first stage still completes in full regardless, and nothing is left half-exposed. Just ask again: the same delete request will pick up and finish the job. It's built to retry, not to fail partway and stay that way.

The Phase-0 retention study

If you're part of Shello's Phase-0 test cohort, your learning outcomes are being measured — whether this actually teaches anything is the question the whole test exists to answer. That measurement runs under its own separate, explicit consent, gathered when you were recruited into the cohort; it isn't buried in this policy. The data from that study is first-party only — we don't share it with, or receive it from, any outside research partner or vendor.

Part of that measurement is mode assignment. While you're in the cohort, chapters open in different modes — some leading with the tutor, some with the text — so the two ways of learning can be compared fairly. The mode a chapter opens in is never a lock: switching is one tap, your choice always wins, and both the assignment and your choice are recorded as part of the study.

Your rights

Wherever you are, you can ask us to:

  • See what personal data we hold about you (access)
  • Get a copy of it — self-serve already, see Export above
  • Correct anything that's wrong
  • Delete your account and personal data — also self-serve, see above

For learners in the EU/EEA and UK, these map to your rights under GDPR Articles 15–17. If Shello ever launches a mainland China service, it will run as a fully separate deployment, and China's Personal Information Protection Law (PIPL) will govern it — no learner data crosses the border between the two, by design. That service doesn't exist yet.

To exercise anything beyond what's self-serve in the app, contact us: [CONTACT EMAIL].

Audience and age

Shello is built for adults and older students learning by choice. It isn't directed at children, and we ask that you not use it if you're under 13 — the minimum for this test phase; some jurisdictions may require a higher age, which legal review will settle. A children's product may exist someday, but it doesn't today, and it would need its own consent model and its own version of this policy.

Uploaded books — coming later

Shello will eventually let you upload your own books so the tutor can teach from them. That feature isn't live yet, but we're stating the rule now, before it ships: anything you upload stays strictly private to you. It's processed only to provide the service to you, and there's no path — in the code or otherwise — for another account to read it. This is enforced by the database itself, not only by application logic.

Who's behind this, and where to go

Shello is operated by [OPERATOR ENTITY], under the laws of [GOVERNING LAW]. Questions about this policy, or anything above: [CONTACT EMAIL].

Free to read, no account. Sign in to learn with the tutor.

PrivacyTermsFeedbackNotebookWhat's new