Skip to content
Rebound AI
How it worksFounderFAQ
Sign inStart free

Legal

Privacy Policy

What Rebound handles, where it lives, and when any of it leaves your device, in plain English.

Last updated: September 28, 2026

Privacy PolicyTerms of ServiceSecurityCookie Policy

The short version

  • Your plan lives on your device first. When you sign in, it also syncs to records that only your account can read, so it follows you across devices.
  • Data is sent to an AI provider only when you use an AI feature, and only what that request needs. We do not train models on your work, and we do not let our AI providers train on it.
  • We do not sell your data. There are no ads, no advertising cookies, no cross-site tracking, and no third-party analytics scripts.
  • You can export your planner data and your calendar at any time, and you can delete all of it.

This policy explains what Rebound AI (“Rebound”, “we”, “us”) does with your information when you use the Rebound planner. Rebound is a calendar for students: you tell it your classes, commitments, and deadlines, it plans the work around your life, and it repairs the plan when things change.

1. Your account

Rebound accounts use email and password sign-in through Supabase, our authentication and database provider. Signing in happens between your browser and Supabase; Rebound never stores your password itself. You can add an optional display name. Password reset works by emailing you a link. A session cookie keeps you signed in, and that is its only job.

2. Your schedule and study data

The planner is local-first: your quiz answers, classes, busy times, tasks, routines, schedule, study sets, and assistant chat history are stored in your browser. When you are signed in, that same data is mirrored to your own record in our Supabase database so it syncs across your devices. Database access rules scope every record to the account that owns it, so other users cannot read your data. Notebooks (their sources and chat messages), extracted study-source text, and any original files you choose to back up are stored the same owner-scoped way; original files live in a private storage bucket that only your signed-in session can access. School calendars you subscribe to are stored in your account too (see section 4).

Some things deliberately stay on your device only and never sync: raw lecture audio and raw timestamped transcripts, Tutor conversation history, essay reviews you choose to save, in-progress assessment drafts, review-history logs, a small content-free record of how well scheduling performed, and accessibility or display preferences. Lecture notes or a study set sync only after you review and save them as ordinary Rebound study content.

3. AI features

Nothing is sent to an AI model until you use an AI feature. When you do, only the material needed for that request leaves your device:

  • Assistant and planning chat — your message plus the relevant parts of your schedule, so the answer can actually fit your week.
  • Syllabus import — text extracted from the PDF in your browser. The file itself is not uploaded.
  • Schedule scan and note photos — a downscaled photo of your timetable or notes, sent once for reading.
  • Essay review — the prompt, draft, and rubric text you submit.
  • Study tools (study sets, assessments, Tutor, explainers, audio recaps) — excerpts of the source text you have saved and selected.
  • Lecture transcription — if you use it, the audio you record and an optional bounded course/title spelling prompt are sent for transcription. A configured compatible service is enabled only after an operator verifies that audio, context prompts, and returned transcripts are not retained, logged, or used for training.

These requests go through Rebound’s own authenticated, rate-limited server. A feature may send the request directly to an Anthropic Claude model, or through OpenRouter to the model configured for that feature using an eligible zero-retention upstream host (or the explicitly pinned hosts). Structured-output OpenRouter requests require zero-data-retention routing and deny provider data collection; if no compatible route is available, the request fails. A failed OpenRouter request crosses to direct Anthropic only when Rebound has explicitly enabled that fallback. We send your content only to generate the response you asked for. Rebound’s servers do not keep copies of your photos or files after answering.

We do not use your content to train our own models, and we do not permit our AI providers to train their models on it. Every model- or attachment-generated planner change appears as a proposal and is applied only after you review it and press Apply. Nothing is written to your plan behind your back.

High-accuracy lecture capture

One optional feature works differently. While you record, Rebound saves short sections on your device. By default, Rebound sends each completed section through its authenticated server to OpenRouter’s Whisper Large V3 transcription model. An operator may instead configure a dedicated OpenAI-compatible transcription service. In that case, Rebound sends each completed section to that service and its configured model, not OpenRouter. After you stop, the timestamped transcript can be sent through the same server to a language model through OpenRouter, using zero-data-retention routing, to draft AI-generated notes, flashcards, and quiz questions linked to exact transcript excerpts.

OpenRouter’s transcription endpoint does not support per-request routing or data-policy controls. Rebound enables this default route only after an operator verifies that its production key is assigned an OpenAI-scope/account zero-data-retention guardrail and attests to that verification in the server environment. A compatible service is enabled only after an operator verifies its exact endpoint, model, and that audio, context prompts, and transcripts are not retained, logged, or used for training, then records a separate server attestation. Without the required attestation, either route fails closed. Rebound does not retain the audio, transcript, or generated draft on its servers; you review the draft before saving any of it to your synced study content.

Browser live captions are a separate, optional control and are off by default. If you enable them, your browser may send live microphone audio to its own speech-recognition service under the browser vendor’s privacy and retention terms. That service is outside Rebound’s zero-retention provider controls; Rebound does not receive its copy of the microphone audio.

4. Canvas, calendar feeds, and other imports

  • Canvas — you paste a personal access token and school URL. They are kept in session storage for the current browser tab, are not synced to your account, and are cleared after a successful sign-out. Each Canvas request sends the token to Rebound’s authenticated proxy, which validates the HTTPS Canvas host and allowed path, forwards the request, and does not retain or log the token.
  • Calendar links you import once (.ics) — Rebound’s server fetches the link (browsers can’t, for technical reasons) and hands the calendar text straight back to your browser, which parses it locally. Nothing is retained server-side.
  • School calendars you subscribe to — so the calendar can stay up to date while the app is closed, the link and a snapshot of its events are stored in your account, scoped to you. The link can’t be read back from the browser, and the snapshot leaves out the link and the calendar’s raw event IDs. Rebound’s server refreshes it about once a day and when you open the app. Removing the subscription, or deleting your account, deletes both.
  • Quizlet links — a public set page is fetched once so it can be converted into flashcards on your device.

One-time calendar, syllabus, and timetable imports show you a preview first, and nothing from them enters your plan until you approve it. A school calendar you subscribe to keeps its events in sync on its own.

5. Cookies and data on your device

Rebound uses essential cookies only: the Supabase session cookies that keep you signed in. There are no advertising cookies and no cross-site tracking. On your device, the app uses browser storage (localStorage) for your planner data and preferences, and IndexedDB for larger device-only records such as lecture recordings and saved essay reviews. Canvas credentials use tab-scoped sessionStorage instead of device-wide localStorage. See the Cookie Policy for details.

6. Error monitoring

When something breaks, the app can send an error report to Sentry, an error-monitoring service, so crashes can be found and fixed. Sentry is configured not to attach personal information by default; these reports are about what went wrong in the code, not about profiling you.

7. Who we share data with

We share your information only with the service providers we need to run Rebound, and only for that purpose:

  • Vercel — application hosting and delivery.
  • Supabase — authentication, database, and file storage.
  • AI providers (Anthropic, and OpenRouter with the upstream models it routes to) — processing for the features described in section 3.
  • Sentry — error reporting and diagnostics.
  • Cloudflare — Turnstile bot protection on the sign-in, sign-up, and password-reset forms.

We do not sell your personal data, and we do not share it with advertisers or data brokers. We may disclose information if we are legally required to, or where it is necessary to protect the safety of a person or the integrity of the service.

8. What’s public and what isn’t

Nothing in your account is public by default, and the signed-in app is excluded from search engines. If you explicitly publish a study set, Rebound creates a separate sanitized copy behind an unlisted link: it contains the study material itself and excludes your identity, your source files, your results, and your planner data. You can refresh or revoke the link at any time; revoking kills it immediately.

9. Keeping, exporting, and deleting your data

Your data is kept until you remove it. From Settings → Data you can export your calendar (.ics) or your planner data (JSON: your profile and onboarding answers, classes, commitments and events, tasks, routines, reminders, schedule, study sets with their review history and quiz results, and chat; device-only records such as lecture recordings and drafts are not included), and Reset planner and study data permanently clears your profile, classes, routines, schedule, study sets, and chat. When you are signed in, the reset syncs to your account and other devices too. Signing out clears sensitive device-only recordings, drafts, and credentials; local planner data remains until you reset it.

To delete your login and owner-scoped cloud data, open Settings → Data → Delete account, then type DELETE to confirm. If that control is unavailable, email hello@reboundai.dev and we will delete the account for you. Backups and logs may keep copies for a short period before they age out on their normal cycle.

10. Your rights

Depending on where you live you may have legal rights over your personal data. Rebound is built so you can exercise the important ones yourself:

  • Access and export. Settings → Data offers Export data (JSON) for your planner data and Export calendar (.ics) for your upcoming schedule.
  • Correction. Everything in the planner is directly editable in the app.
  • Deletion. Use Reset planner and study data or Delete account, or ask us to delete your account.
  • Objection and restriction. You can decline AI features and still use the planner; write to us for anything else.

To make a request you cannot complete in the app, email hello@reboundai.dev. We may need to confirm you control the account before acting.

11. Students and minors

Rebound is built for students and is intended for people aged 13 and over. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe a child under 13 has created an account, contact us and we will delete the account and its data. If you are under 18, please review this policy with a parent, guardian, or teacher before uploading course material.

12. Changes to this policy

We will update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects how we handle your information, we will give notice in the app before it takes effect.

13. Contact

Questions, requests, or complaints about privacy: hello@reboundai.dev.

Rebound AI

The AI calendar that tells you when to do the work.

hello@reboundai.dev

Product

  • How it works
  • Features
  • FAQ

Company

  • Founder story
  • Contact
  • Sign in

Legal

  • Privacy Policy
  • Terms of Service
  • Security
  • Cookie Policy

© 2026 Rebound AI

Built by a student, for students.

Rebound