Last updated: March 1, 2026
Topodrive ("we," "us," "our," or "Socrates") is committed to protecting your privacy. This Privacy Policy (the "Policy") explains how we collect, use, store, share, and protect your personal information when you use our website (topodrive.top), application, and related services (collectively, the "Service").
This Policy applies to all users of the Service worldwide. By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, please do not use the Service. Capitalized terms not defined here have the meanings given in our Terms of Service.
We are based in Xi'an, Shaanxi, China. Depending on your location, different data protection laws may apply to the processing of your information. We will comply with applicable laws regarding the collection, use, and transfer of personal data.
| Category | Examples | Purpose |
|---|---|---|
| Account Information | Email address, encrypted password, display name, avatar | Account registration and authentication |
| Profile Information | Preferred name, learning preferences, language settings | Personalizing your experience |
| Payment Information | Billing address, transaction records, last 4 digits of card | Subscription management and accounting |
| API Keys | LLM provider API keys (encrypted) | Routing inference requests to your chosen provider |
| Teaching Content | Session transcripts, diagnostic answers, knowledge graph data, notes | Delivering and improving the tutoring experience |
| Communications | Email content when you contact support | Customer support and service improvement |
| Category | Examples | Purpose |
|---|---|---|
| Usage Data | Session duration, features used, pages visited, feature interactions | Service optimization and product improvement |
| Device Information | IP address, browser type and version, operating system, device type, screen resolution | Service delivery, security, and analytics |
| Log Data | API request timestamps, error logs, performance metrics, request volumes | System monitoring, debugging, and security |
| Cookies & Similar Technologies | Authentication tokens, session identifiers, preference cookies | Authentication, session management, and basic analytics |
We do not collect or process sensitive personal information (health data, biometric data, genetic data, political opinions, religious beliefs, trade union membership, sexual orientation) unless you explicitly and knowingly provide it in teaching content in violation of Section 11 of our Terms of Service. We do not intentionally collect such data and request that you refrain from submitting it.
If you are located in the European Economic Area (EEA), Switzerland, the United Kingdom, or other jurisdictions with similar data protection laws, our processing of your personal data is based on the following legal grounds:
| Processing Purpose | Legal Basis |
|---|---|
| Account creation and management | Performance of a contract (Art. 6(1)(b) GDPR) |
| Subscription billing and payment | Performance of a contract (Art. 6(1)(b) GDPR) |
| Service delivery and operations | Performance of a contract (Art. 6(1)(b) GDPR) |
| Security and fraud prevention | Legitimate interest (Art. 6(1)(f) GDPR) |
| Analytics and product improvement | Legitimate interest (Art. 6(1)(f) GDPR) |
| Marketing communications (with opt-out) | Consent (Art. 6(1)(a) GDPR) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
You have the right to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
We use the information we collect for the following purposes:
Your LLM provider API keys are among the most sensitive data we process. We handle them as follows:
We use cookies and similar tracking technologies to operate and improve the Service. Here is how we use them:
| Type | Purpose | Duration | Opt-Out |
|---|---|---|---|
| Essential/Strictly Necessary | Authentication, session management, CSRF protection, security | Session to 1 year | Cannot opt out (service will not function) |
| Preference | Remembering your settings, language, theme preferences | 1 year | Browser settings |
| Analytics | First-party analytics: page views, feature usage, error tracking | Up to 26 months | Browser settings or opt-out link in cookie banner |
| Marketing | Not currently used. If introduced, we will notify and seek consent. | N/A | N/A |
You can control cookies through your browser settings. Blocking essential cookies will prevent the Service from functioning. We do not use third-party advertising cookies, cross-site tracking, or behavioral advertising trackers.
When required by applicable law, we display a cookie consent banner and obtain your affirmative consent before placing non-essential cookies on your device.
We do not sell your personal information. We share your data only in the following limited circumstances:
| Recipient | Data Shared | Purpose | Safeguards |
|---|---|---|---|
| LLM Providers (OpenAI, Anthropic, etc.) | Session prompts and generated content (via your API key) | AI inference for teaching sessions | Governed by your agreement with the provider |
| Stripe | Payment card data, billing information | Payment processing | PCI-DSS compliant; we never store full card details |
| Cloud Infrastructure (AWS) | All stored data (encrypted) | Hosting and infrastructure | Data processing agreement, encryption at rest |
| Email Service Provider | Email address, support correspondence | Transactional emails, support communications | Data processing agreement, limited retention |
| Legal/Regulatory Authorities | As required by applicable law | Legal compliance | We will notify you unless legally prohibited |
We require all third-party service providers to enter into data processing agreements that contractually obligate them to protect your data and use it only for the specified purposes. We vet providers for security and compliance before engagement.
Storage Location. Your data is stored on secure servers located in China and/or other jurisdictions where we or our infrastructure providers maintain facilities. By using the Service, you consent to the transfer of your data to these locations.
Cross-Border Transfers. If we transfer your personal data from the EEA, UK, or Switzerland to countries not deemed adequate by the European Commission, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms under applicable law.
Security Measures. We implement the following technical and organizational security measures:
While we implement these measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
We retain your personal data only as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
| Data Type | Retention Period | Rationale |
|---|---|---|
| Account information | Duration of account + 30 days | Account operation and grace period for reactivation |
| Session/teaching data | Duration of account | Delivering learning experience; deleted on account deletion |
| Payment records | 5 years after transaction | Tax and accounting legal obligations |
| Server logs | 90 days | Security monitoring and debugging |
| API keys | Duration of account + 30 days (deleted on deletion) | Service functionality; securely deleted upon account deletion |
| Support correspondence | 2 years after resolution | Service improvement and dispute resolution |
| Analytics data (anonymized) | Indefinitely (anonymized) | Product improvement; cannot identify individuals |
When retention periods expire, data is securely deleted or irreversibly anonymized. Deletion may take up to 30 days from our backup systems following the end of the retention period.
Depending on your jurisdiction, you may have the following rights regarding your personal data. We will respond to all legitimate requests within the timeframes required by applicable law (typically 30 days).
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of the personal data we hold about you. | Email hello@topodrive.top |
| Rectification | Correct inaccurate or incomplete data. | Account settings or email us |
| Deletion ("Right to be Forgotten") | Request deletion of your personal data. | Account deletion in settings or email us |
| Restriction | Restrict processing of your data in certain circumstances. | Email hello@topodrive.top |
| Data Portability | Receive your data in a structured, commonly used, machine-readable format. | Email hello@topodrive.top |
| Objection | Object to processing based on legitimate interests or for direct marketing. | Email hello@topodrive.top |
| Withdraw Consent | Withdraw consent where processing is based on consent. | Account settings or email us |
| Lodge Complaint | File a complaint with your local data protection authority. | Contact your local DPA (see Section 17) |
To exercise your rights, contact us at hello@topodrive.top. We may need to verify your identity before processing your request. We will not discriminate against you for exercising your rights. We aim to respond to all legitimate requests within 30 days. Complex requests may take up to 60 days with notice.
The Service is not directed at children under 13 years of age (or the equivalent minimum age in applicable jurisdictions). We do not knowingly collect personal information from children under 13.
If we learn that we have collected personal data from a child under 13 without verified parental consent, we will delete that information promptly. If you believe a child under 13 may have provided us with personal data, please contact us immediately at hello@topodrive.top.
In jurisdictions where a higher age of consent applies (e.g., 16 in certain EU member states), we comply with local age requirements and will seek parental consent where required.
Teaching Data Flow. When you use Socrates for a learning session, your conversation content, diagnostic answers, and knowledge graph data are sent to the LLM provider you have configured via your API key. This is necessary to generate educational responses. This processing is governed by the LLM provider's terms and privacy policy.
No Model Training. We do not use your session data, teaching content, or API keys to train, fine-tune, or improve our own AI models. Your data is used solely to deliver the teaching session you have requested.
Automated Decision-Making. Socrates uses algorithms to: (a) adapt teaching difficulty based on your diagnostic answers; (b) recommend learning paths; (c) identify knowledge gaps. These automated decisions are integral to the tutoring experience and do not produce legal effects concerning you. If you wish to contest an automated decision, contact us at hello@topodrive.top.
Human Review. We do not routinely review individual teaching sessions. Session data may be accessed by our team on a need-to-know basis for debugging, quality assurance, or responding to your support requests. Any such access is logged and audited.
Profiling. We do not engage in profiling for marketing or advertising purposes based on your teaching data.
We do not request or require sensitive personal information (such as health data, biometric data, genetic data, political opinions, religious beliefs, trade union membership, sexual orientation, or criminal records) to provide the Service. You should not submit sensitive personal information through the Service.
If we become aware that sensitive personal information has been submitted in violation of this policy, we will delete it promptly. We are not liable for any consequences arising from your submission of sensitive personal information in violation of this Policy.
In the event of a data security incident that compromises your personal data, we will:
We maintain a documented incident response plan and conduct regular tabletop exercises to ensure readiness. Security incidents are investigated by our security team, and lessons learned are incorporated into our security processes.
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our compliance with data protection laws. If you have any questions about this Policy or our data practices, please contact:
Data Protection Officer
Topodrive
Xi'an, Shaanxi, China
Email: dpo@topodrive.top
For general privacy inquiries: hello@topodrive.top
We will acknowledge receipt of your inquiry within 5 business days and respond substantively within 30 days.
We may update this Policy from time to time. When we make material changes, we will notify you by email (to the address associated with your account) and/or through a prominent notice on the Service at least 14 days before the changes take effect.
We encourage you to review this Policy periodically. The date of the most recent update is shown at the top of this page. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy. If you do not agree, you may delete your account before the effective date.
For changes that require your consent under applicable law, we will obtain your affirmative consent before implementation.
If you are located in the EEA, Switzerland, or the UK, you have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal data violates applicable law. We encourage you to contact us first so we can attempt to resolve your concern informally.
Contact your local data protection authority through: https://edpb.europa.eu/about-edpb/about-edpb/members_en (for EU/EEA).
If you are in China, you may contact the Cyberspace Administration of China (CAC) or local equivalents in Shaanxi Province.
For users in the People's Republic of China, the following additional provisions apply under the Personal Information Protection Law (PIPL):
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
To exercise your California rights, contact us at hello@topodrive.top or call +86 (029) [phone]. We will verify your identity through email verification before processing your request. We aim to respond within 45 days (extendable by an additional 45 days with notice).
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email (General): hello@topodrive.top
Email (DPO): dpo@topodrive.top
Support: help@addtech.site
Address: Topodrive, Xi'an, Shaanxi, China
© 2026 Topodrive. All rights reserved.