Where we stand. Cadenza opens the first week of September with paid plans. Course data is only ever read with your consent, through a read-only Quercus token you generate and can revoke yourself. We are separately working with the University of Toronto and Instructure (Canvas) on institutional single sign on, which will replace the token step. Everything below is how we handle your data.
Privacy.
The short version. This is how we handle your data.
What Cadenza stores
Your email, the school and program you give us at signup, your Quercus course data pulled via a read-only API token you generate yourself, and the notes and plans Cadenza builds from that data. We also store what you produce while using Cadenza: the answers you type into practice and exams, your chat history with the AI tutor, and your progress through a course. If you buy a paid plan, we store the customer and subscription identifiers Stripe gives us, but never your card details, which stay with Stripe.
What we never do
We never sell your data. We never use your coursework to train outside models, and the AI providers we rely on are contractually barred from training on it either. We do not hand your data to anyone except the service providers listed below who help run Cadenza, and only so they can do that job. If you ask us to export or delete your account, we do both.
Where it lives
Your data is stored with Supabase (our database) and Vercel (our hosting). Both run in the United States today: the database in Oregon (Amazon Web Services us-west-2) and the application servers in San Francisco, behind a global content delivery network. Traffic between you and Cadenza is encrypted in transit with HTTPS, and the database and our file storage are encrypted at rest by Supabase.
To be precise about what that means, because most policies are vague here: your Quercus token gets an extra layer. Cadenza encrypts it with AES-256-GCM before storing it, so it is unreadable in the database without a key we hold separately. Your other data, including course content, notes, chat history, and typed answers, sits in ordinary database columns protected by access controls rather than by a second layer of encryption from us.
We plan to move the database to Supabase's Canadian region in Montréal before any institutional launch. We do not currently claim Canadian data residency. Your Quercus token is revocable by you at any time from inside Quercus, and the moment you revoke it, Cadenza loses all future access.
To be precise about what that means, because most policies are vague here: your Quercus token gets an extra layer. Cadenza encrypts it with AES-256-GCM before storing it, so it is unreadable in the database without a key we hold separately. Your other data, including course content, notes, chat history, and typed answers, sits in ordinary database columns protected by access controls rather than by a second layer of encryption from us.
We plan to move the database to Supabase's Canadian region in Montréal before any institutional launch. We do not currently claim Canadian data residency. Your Quercus token is revocable by you at any time from inside Quercus, and the moment you revoke it, Cadenza loses all future access.
How AI features use your data
To power its AI features (study plans, practice questions, grading, chat, and summaries), Cadenza sends your course materials and the answers you type to AI providers that process them on our behalf. There are two, and we would rather name both than say "our AI partner".
Most of that work is done by OpenAI. Separately, when a course PDF has little or no machine-readable text, such as a scan or a slide deck that is mostly images, Cadenza sends that whole file to be read by Anthropic's Claude models, which we reach through the Vercel AI Gateway. We judge that by how much text we can pull out of the file, so a sparse but perfectly readable slide deck can take this path too. Both act as processors: under their API terms, neither uses your content to train its models.
On retention: OpenAI may keep the text sent to and received from its API for up to roughly 30 days to monitor for abuse, and then deletes it. That short window is sometimes called prompt memory. Anthropic and the Vercel AI Gateway apply their own retention terms to the files routed through them. Where Cadenza uploads a whole document rather than text, that uploaded file persists until it is deleted, and today one of our two upload paths does not delete it afterwards, so a syllabus sent for reading can sit at OpenAI until we remove it. If you would rather this content were not processed this way, you can skip the AI features, though most of Cadenza depends on them.
Most of that work is done by OpenAI. Separately, when a course PDF has little or no machine-readable text, such as a scan or a slide deck that is mostly images, Cadenza sends that whole file to be read by Anthropic's Claude models, which we reach through the Vercel AI Gateway. We judge that by how much text we can pull out of the file, so a sparse but perfectly readable slide deck can take this path too. Both act as processors: under their API terms, neither uses your content to train its models.
On retention: OpenAI may keep the text sent to and received from its API for up to roughly 30 days to monitor for abuse, and then deletes it. That short window is sometimes called prompt memory. Anthropic and the Vercel AI Gateway apply their own retention terms to the files routed through them. Where Cadenza uploads a whole document rather than text, that uploaded file persists until it is deleted, and today one of our two upload paths does not delete it afterwards, so a syllabus sent for reading can sit at OpenAI until we remove it. If you would rather this content were not processed this way, you can skip the AI features, though most of Cadenza depends on them.
Who processes your data
Running Cadenza means a small set of trusted companies process your data on our behalf. Each is a processor bound by contract to act only on our instructions. They are not parties we sell to or share your data with for their own purposes:
- Supabase: database, login, and file storage (United States).
- Vercel: application hosting, basic aggregate usage analytics, and the AI Gateway that routes some AI requests (United States).
- OpenAI: most of the AI processing behind study plans, practice, grading, chat, and summaries (United States).
- Anthropic: reading scanned or image-only course documents that cannot be read as text (United States).
- Stripe: payment processing for paid plans (United States).
- Resend: transactional email, such as sign-in and account notices (United States).
Education records and the law
Your Quercus course data can count as an education record. Cadenza only ever reads it with your consent, through a read-only token you generate and can revoke, and it pulls course structure (titles, dates, week layout, reading lists) only, never your grades, your submitted work, or other students' information. As a Canadian project serving UofT students, we hold ourselves to Ontario's FIPPA and Canada's PIPEDA, and to the spirit of FERPA's protections for education records. We do not claim any certification, audit, or approval from the University of Toronto, and Cadenza is an independent project, not affiliated with or endorsed by UofT or Instructure.
What your professors see
Nothing you do inside Cadenza is visible to them. Cadenza only reads your course materials, and it never writes, submits, or posts anything back to Quercus.
One honest caveat rather than a blanket promise: Cadenza reads Quercus using your own token, and Canvas keeps its own access logs that instructors can view. Those logs can show that course files or pages were accessed by your account. They show nothing about Cadenza or how you study, and we cannot suppress them, so we would rather you hear it from us.
One honest caveat rather than a blanket promise: Cadenza reads Quercus using your own token, and Canvas keeps its own access logs that instructors can view. Those logs can show that course files or pages were accessed by your account. They show nothing about Cadenza or how you study, and we cannot suppress them, so we would rather you hear it from us.
Your controls
You can export or delete all of your data at any time by emailing support@studycadenza.com, and we complete deletions within two business days. Deleting your account removes your personal data and the work tied to it. One exception, stated plainly: some AI-generated material is built once per course and shared by everyone taking it, so it is not yours alone and it remains after your account is gone. It contains nothing personal about you. This is separate from the sixty day window in our Terms: that window is the time you have to export your data after you cancel a paid plan, or if Cadenza ever winds down, and it is not a delay on deletions you request.
Questions or a proper policy
The plain-English summary above is how we operate, and it is binding on us. A longer formal policy will follow as our institutional agreements come together. If anything here is unclear, or you want specifics we have not covered, write to support@studycadenza.com.
Last updated August 2026