Legal
Privacy Policy
1. Introduction
Topodrive ("we," "us," "our," or "Socrates") is committed to protecting your privacy. This Privacy Policy (the "Policy") explains how we collect, use, store, share, and protect your personal information when you use our website (topodrive.top), application, and related services (collectively, the "Service").
This Policy applies to all users of the Service worldwide. By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, please do not use the Service. Capitalized terms not defined here have the meanings given in our Terms of Service.
We are based in Xi'an, Shaanxi, China. Depending on your location, different data protection laws may apply to the processing of your information. We will comply with applicable laws regarding the collection, use, and transfer of personal data.
2. Information We Collect
2.1 Information You Provide Directly
| Category | Examples | Purpose |
|---|---|---|
| Account Information | Email address, encrypted password, display name, avatar | Account registration and authentication |
| Profile Information | Preferred name, learning preferences, language settings | Personalizing your experience |
| Payment Information | Billing address, transaction records, last 4 digits of card | Subscription management and accounting |
| API Keys | LLM provider API keys (encrypted) | Routing inference requests to your chosen provider |
| Teaching Content | Session transcripts, diagnostic answers, knowledge graph data, notes | Delivering and improving the tutoring experience |
| Communications | Email content when you contact support | Customer support and service improvement |
2.2 Information Collected Automatically
| Category | Examples | Purpose |
|---|---|---|
| Usage Data | Session duration, features used, pages visited, feature interactions | Service optimization and product improvement |
| Device Information | IP address, browser type and version, operating system, device type, screen resolution | Service delivery, security, and analytics |
| Log Data | API request timestamps, error logs, performance metrics, request volumes | System monitoring, debugging, and security |
| Cookies & Similar Technologies | Authentication tokens, session identifiers, preference cookies | Authentication, session management, and basic analytics |
We do not collect or process sensitive personal information (health data, biometric data, genetic data, political opinions, religious beliefs, trade union membership, sexual orientation) unless you explicitly and knowingly provide it in teaching content in violation of Section 11 of our Terms of Service. We do not intentionally collect such data and request that you refrain from submitting it.
3. Legal Basis for Processing (GDPR & Similar Laws)
If you are located in the European Economic Area (EEA), Switzerland, the United Kingdom, or other jurisdictions with similar data protection laws, our processing of your personal data is based on the following legal grounds:
| Processing Purpose | Legal Basis |
|---|---|
| Account creation and management | Performance of a contract (Art. 6(1)(b) GDPR) |
| Subscription billing and payment | Performance of a contract (Art. 6(1)(b) GDPR) |
| Service delivery and operations | Performance of a contract (Art. 6(1)(b) GDPR) |
| Security and fraud prevention | Legitimate interest (Art. 6(1)(f) GDPR) |
| Analytics and product improvement | Legitimate interest (Art. 6(1)(f) GDPR) |
| Marketing communications (with opt-out) | Consent (Art. 6(1)(a) GDPR) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
You have the right to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
4. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service. Operating the Socrates teaching engine, processing your learning sessions, managing your account and subscription, and routing API requests to your chosen LLM provider.
- Improving the Service. Analyzing usage patterns, identifying common errors, optimizing teaching algorithms, and enhancing the user experience.
- Security & Compliance. Detecting and preventing abuse, fraud, or Terms of Service violations; responding to legal requests; maintaining system integrity.
- Communication. Sending service-related notices (billing reminders, service changes, security alerts); sending product updates and promotional content (with opt-out option); responding to support inquiries.
- Personalization. Tailoring teaching content, suggesting learning paths, and adapting difficulty levels based on your progress and preferences.
- Aggregate Analytics. Creating aggregated, anonymized statistical data for product planning and reporting. This data cannot identify you individually.
5. API Key Handling & Security
Your LLM provider API keys are among the most sensitive data we process. We handle them as follows:
- Encryption at Rest. API keys are encrypted with AES-256-GCM before they are stored. The application derives the encryption key from the server session secret; we do not expose the encrypted value to the browser.
- Encryption in Transit. API requests should be made over HTTPS. The exact TLS configuration depends on the deployment serving the Service.
- Limited Use. Keys are used solely to authenticate API requests to the LLM provider you have configured. We do not inspect, log, or store the content of API keys beyond authentication.
- Access Control. Decryption is performed server-side only when the Service needs to route a request to the provider you configured. The browser receives metadata and a masked hint, not the stored key.
- No Model Training. We never use your API keys or the data transmitted through them to train, fine-tune, or improve our own AI models.
- Deletion. You can delete or update keys through account settings. Account deletion removes the account's API-key records through the server-side deletion flow; any independent backups or legal retention requirements may follow different schedules.
- No Sharing. We do not sell, rent, or share your API keys with any third party except as required by law.
6. Cookies & Similar Technologies
We use cookies and similar tracking technologies to operate and improve the Service. Here is how we use them:
| Type | Purpose | Duration | Opt-Out |
|---|---|---|---|
| Essential/Strictly Necessary | Authentication, session management, CSRF protection, security, remembering your cookie preferences | Session to 1 year | Cannot opt out (service will not function) |
| Preference | Remembering your settings, language, theme preferences | 1 year | Browser settings |
| Analytics | Only where an analytics feature is enabled for the deployment: page views, feature usage, or error tracking | As configured for the deployment | Browser settings or an available opt-out control |
| Marketing | Not currently used. If introduced, we will notify and seek consent. | N/A | N/A |
You can control cookies through your browser settings. Blocking essential cookies will prevent the Service from functioning. We do not use third-party advertising cookies, cross-site tracking, or behavioral advertising trackers.
When required by applicable law, we display a cookie consent banner and obtain your affirmative consent before placing non-essential cookies on your device. You can choose “Accept all” or “Essential only” in the banner, and your choice is remembered on this device.
7. Data Sharing & Third-Party Disclosure
We do not sell your personal information. We share your data only in the following limited circumstances:
| Recipient | Data Shared | Purpose | Safeguards |
|---|---|---|---|
| LLM Providers (OpenAI, Anthropic, etc.) | Session prompts and generated content (via your API key) | AI inference for teaching sessions | Governed by your agreement with the provider |
| Stripe | Payment card data, billing information | Payment processing | PCI-DSS compliant; we never store full card details |
| Hosting and storage providers | Data required to run the Service | Hosting, storage, and infrastructure operations | Provider and safeguards depend on the deployment |
| Support or email providers | Email address and support correspondence, when used | Support communications | Provider and retention depend on the channel used |
| Legal/Regulatory Authorities | As required by applicable law | Legal compliance | We will notify you unless legally prohibited |
We require all third-party service providers to enter into data processing agreements that contractually obligate them to protect your data and use it only for the specified purposes. We vet providers for security and compliance before engagement.
8. Data Storage, Transfer & Security
Storage Location. Your data is stored on secure servers located in China and/or other jurisdictions where we or our infrastructure providers maintain facilities. By using the Service, you consent to the transfer of your data to these locations.
Cross-Border Transfers. If we transfer your personal data from the EEA, UK, or Switzerland to countries not deemed adequate by the European Commission, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms under applicable law.
Security Measures. We implement the following technical and organizational security measures:
- HTTPS/TLS protection where configured by the deployment.
- AES-256-GCM encryption for stored API keys.
- Server-side authentication and authorization checks for account and key operations.
- Operational logging and monitoring where enabled by the deployment.
While we implement these measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
9. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
| Data Type | Retention Period | Rationale |
|---|---|---|
| Account information | While the account is active, then as required for deletion and legal obligations | Account operation and compliance |
| Session/teaching data | While needed to provide the Service, subject to account deletion and applicable obligations | Delivering the learning experience |
| Payment records | As required by the payment provider and applicable accounting or tax law | Billing, accounting, and compliance |
| Server logs | As needed for security, debugging, and operations | Service reliability and security |
| API keys | Until you update/delete them or delete the account, subject to independent retention requirements | Service functionality |
| Support correspondence | As needed to resolve the request and maintain service records | Support and dispute resolution |
| Analytics data | As configured for the deployment, and anonymized where appropriate | Product improvement |
When applicable retention periods expire, data is deleted or anonymized according to the systems and providers involved. We do not promise a universal deletion period for independent backups or third-party systems.
10. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data. We will respond to all legitimate requests within the timeframes required by applicable law (typically 30 days).
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of the personal data we hold about you. | Email hello@topodrive.top |
| Rectification | Correct inaccurate or incomplete data. | Account settings or email us |
| Deletion ("Right to be Forgotten") | Request deletion of your personal data. | Account deletion in settings or email us |
| Restriction | Restrict processing of your data in certain circumstances. | Email hello@topodrive.top |
| Data Portability | Receive your data in a structured, commonly used, machine-readable format. | Email hello@topodrive.top |
| Objection | Object to processing based on legitimate interests or for direct marketing. | Email hello@topodrive.top |
| Withdraw Consent | Withdraw consent where processing is based on consent. | Account settings or email us |
| Lodge Complaint | File a complaint with your local data protection authority. | Contact your local DPA (see Section 17) |
To exercise your rights, contact us at hello@topodrive.top. We may need to verify your identity before processing your request. We will not discriminate against you for exercising your rights. We aim to respond to all legitimate requests within 30 days. Complex requests may take up to 60 days with notice.
11. Children's Privacy
The Service is not directed at children under 13 years of age (or the equivalent minimum age in applicable jurisdictions). We do not knowingly collect personal information from children under 13.
If we learn that we have collected personal data from a child under 13 without verified parental consent, we will delete that information promptly. If you believe a child under 13 may have provided us with personal data, please contact us immediately at hello@topodrive.top.
In jurisdictions where a higher age of consent applies (e.g., 16 in certain EU member states), we comply with local age requirements and will seek parental consent where required.
12. AI Teaching Data & Automated Processing
Teaching Data Flow. When you use Socrates for a learning session, your conversation content, diagnostic answers, and knowledge graph data are sent to the LLM provider you have configured via your API key. This is necessary to generate educational responses. This processing is governed by the LLM provider's terms and privacy policy.
No Model Training. We do not use your session data, teaching content, or API keys to train, fine-tune, or improve our own AI models. Your data is used solely to deliver the teaching session you have requested.
Automated Decision-Making. Socrates uses algorithms to: (a) adapt teaching difficulty based on your diagnostic answers; (b) recommend learning paths; (c) identify knowledge gaps. These automated decisions are integral to the tutoring experience and do not produce legal effects concerning you. If you wish to contest an automated decision, contact us at hello@topodrive.top.
Human Review. We do not routinely review individual teaching sessions. Session data may be accessed by our team on a need-to-know basis for debugging, quality assurance, or responding to your support requests. Any such access is logged and audited.
Profiling. We do not engage in profiling for marketing or advertising purposes based on your teaching data.
13. Sensitive Personal Information
We do not request or require sensitive personal information (such as health data, biometric data, genetic data, political opinions, religious beliefs, trade union membership, sexual orientation, or criminal records) to provide the Service. You should not submit sensitive personal information through the Service.
If we become aware that sensitive personal information has been submitted in violation of this policy, we will delete it promptly. We are not liable for any consequences arising from your submission of sensitive personal information in violation of this Policy.
14. Data Security Incidents
In the event of a data security incident that compromises your personal data, we will:
- Notify you without undue delay (typically within 72 hours of becoming aware) via email and/or a notice on the Service.
- Provide a description of the nature of the breach, the categories and approximate number of data subjects and records concerned.
- Communicate the name and contact details of the privacy contact or other contact point where more information can be obtained.
- Describe the likely consequences of the breach and the measures we have taken or propose to take to address it.
- Notify relevant supervisory authorities as required by applicable law.
We maintain a documented incident response plan and conduct regular tabletop exercises to ensure readiness. Security incidents are investigated by our security team, and lessons learned are incorporated into our security processes.
15. Privacy Contact
If you have questions about this Policy or our data practices, please contact:
Privacy contact
Topodrive
Xi'an, Shaanxi, China
Email: hello@topodrive.top
For general privacy inquiries: hello@topodrive.top
We will handle privacy requests within the timeframes required by applicable law.
16. Changes to This Privacy Policy
We may update this Policy from time to time. When we make material changes, we will notify you by email (to the address associated with your account) and/or through a prominent notice on the Service at least 14 days before the changes take effect.
We encourage you to review this Policy periodically. The date of the most recent update is shown at the top of this page. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy. If you do not agree, you may delete your account before the effective date.
For changes that require your consent under applicable law, we will obtain your affirmative consent before implementation.
17. Complaints & Supervisory Authorities
If you are located in the EEA, Switzerland, or the UK, you have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal data violates applicable law. We encourage you to contact us first so we can attempt to resolve your concern informally.
Contact your local data protection authority through: https://edpb.europa.eu/about-edpb/about-edpb/members_en (for EU/EEA).
If you are in China, you may contact the Cyberspace Administration of China (CAC) or local equivalents in Shaanxi Province.
18. Specific Provisions for Chinese Users
For users in the People's Republic of China, the following additional provisions apply under the Personal Information Protection Law (PIPL):
- Personal Information Inventory. A complete inventory of the personal information we collect is available upon request by emailing hello@topodrive.top.
- Consent. We obtain separate, informed consent for the processing of sensitive personal information and for cross-border data transfers where required.
- Third-Party Sharing List. A detailed list of third parties with whom we share personal data is available on request.
- Automated Decision-Making. You have the right to request an explanation of automated decision-making methods and to refuse the use of automated decision-making for marketing or information推送.
- Deletion Requests. We process deletion requests in accordance with applicable law and the verification needed to protect the account.
19. Specific Provisions for California Users (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
- Right to Know. You may request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share data.
- Right to Delete. You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to Opt-Out. We do not sell your personal information. We have no actual knowledge of selling personal information of minors under 16.
- Right to Non-Discrimination. We will not discriminate against you for exercising any of your CCPA/CPRA rights.
- Right to Correct. You may request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information. We do not use sensitive personal information for purposes beyond those necessary to provide the Service.
To exercise your California rights, contact us at hello@topodrive.top. We will verify your identity before processing your request and respond within the timeframe required by applicable law.
20. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email (General): hello@topodrive.top
Support: help@addtech.site
Address: Topodrive, Xi'an, Shaanxi, China