This is a draft and has not been reviewed by a lawyer. The list itself is accurate against the code. What each company does with data on its own account is governed by their terms, not ours, and you should read theirs as well as this.
Every company that sees any part of your data, what they see, and why they see it. If a service is not on this list, Lectavi does not send it anything.
| Service | What it receives | Why |
|---|---|---|
| Deepgram | Lecture audio, streamed live while you record | Turning speech into text. This is the only place audio goes. |
| OpenRouter | Transcript text, syllabus text, and your questions to the chat | Routing to a language model to write notes, claims, flashcards and practice questions. No audio. |
| The same text, via OpenRouter | The model itself. OpenRouter is a router, and Gemini is the model it currently routes to. | |
| Supabase | Your account, and synced sessions, notes, claims, flashcards and review history | Sign in, and making your notes available on another device. Audio and transcripts are never sent. |
| Stripe | Your email and payment details | Subscriptions. Lectavi never sees your card number. |
| GitHub | Nothing about you | Hosting the installer and the update feed. The app fetches these anonymously. |
| Wikimedia | Search terms taken from your lecture topics | Finding licence clean images for the visuals in your notes. |
These only receive anything if you choose to connect them, and only what is needed to read your own coursework.
| Service | What it receives | Why |
|---|---|---|
| Canvas | Your access token, and requests for your own courses | Reading your classes, assignments and deadlines. |
| An OAuth token you grant | Reading your calendar, and documents you choose to import. |