Privacy
What ClassPulse collects during a lecture, who can see it, and how long it is kept.
Effective 12 September 2026
The short version
- • Your lecture is transcribed to text while a session is running. The audio is never saved — not by us, not anywhere.
- • When you tap a reaction, it is recorded against your account, not thrown into an anonymous pile. That is what makes your personalised quiz possible.
- • Your instructor's dashboard shows counts, never names. They see “12 students are confused”, not which twelve. There is an important limit to that, and it is spelled out in what your instructor can see.
- • Session data is deleted about twelve months after the session ends.
- • You can delete your account and its data at any time from Settings.
Who is responsible
ClassPulse is built and operated by Secil Uluderya, an independent developer. It is not a company, and it is not operated by or on behalf of any university.
For anything in this document, including a request to see or delete your data, write to classpulses@gmail.com.
What is collected
What ClassPulse holds depends on how you use it.
If you sign up as an instructor
Your email address, your name, and optionally your institution. Plus the courses and sessions you create.
If you sign up as a student
Your email address, your name, and optionally your institution. Plus, for each session you join: which sessions you joined, every reaction you tapped and which moment of the lecture it was attached to, any written question you sent, and any quiz generated for you together with your answers and score.
If you join by code or QR without an account
Only the display name you type. No email address is collected and no password is set. A throwaway identity is created for that session.
One consequence worth knowing: because each such join creates a brand new identity, joining again later — or from a different phone — makes you a different participant as far as the system is concerned. Nothing links those visits together.
Technical error records
When something breaks, ClassPulse records what failed so it can be fixed. Those records can include your account identifier and the session you were in. They are visible only to the operator. If you delete your account, your identifier is removed from them.
What is not collected
Lecture audio is never stored. While a session runs, sound from the instructor's microphone is streamed straight to the transcription service and converted to text. The audio is not written to disk, not kept in a file, and not recoverable afterwards. Only the text transcript is saved.
There are no cookies for advertising or analytics, no tracking pixels, no third-party advertising networks, and no sale or sharing of data with advertisers. The only cookies are the ones that keep you signed in.
No video, no camera access, and no student microphone access. Only the instructor's device records sound, and only while they have started a session.
How the lecture is transcribed
Audio from the instructor's microphone is sent to Deepgram, a speech-to-text service, which returns the text as the lecture proceeds. Deepgram receives the spoken content of the lecture — which means anything said out loud in the room while a session is running, including anything a student says loudly enough for the instructor's microphone to pick up.
Deepgram does not receive any student's name, email address or account identifier. It receives sound and returns words.
How AI is used
ClassPulse uses Claude, made by Anthropic, to write the session summary, identify recurring difficult topics, and generate each student's personalised quiz.
What Claude receives: the text of the lecture transcript, the transcript passages a student flagged, and aggregate counts of how many people flagged each moment.
What Claude does not receive: no names, no email addresses, no account identifiers. The work of deciding which passages belong to which student happens before the request is sent, so the request itself carries content without identity.
What your instructor can see
This section is the one worth reading closely, because “ anonymous” is easy to assume and only partly true.
The dashboard shows counts, not names. When twelve people flag a passage as confusing, your instructor sees that twelve people did. The interface never displays who. This is deliberate and it is the core of the product: students should be able to admit confusion without singling themselves out.
But your reactions are not anonymous in the database. Each one is stored against your account, because it has to be — your personalised quiz is built from the moments you flagged, and that is impossible without knowing they were yours.
And there is a real limit to be straight about. To show a correct count, your instructor's browser is sent the underlying reaction records for the session, and those records contain account identifiers. The screen renders only totals, but an instructor willing to open their browser's developer tools could inspect the underlying data and, by comparing it against the attendance list, work out who flagged what.
No part of the interface offers or encourages this, and it takes deliberate effort. But it is possible today, so you should not treat a reaction as untraceable. If that matters to you, the honest advice is to treat reactions as visible to your instructor in principle and decide accordingly. Closing this gap properly is a known piece of outstanding work.
Separately and openly: your instructor can see who joined a session, by name, on the attendance list. Attendance is not anonymous and is not meant to be. Written questions you send are also attributed to you, so the instructor can answer you.
Who else can see it
An instructor may grant a colleague or teaching assistant co-teacher access to a course. An active co-teacher can see the same dashboards, analytics, transcripts and attendance lists as the course owner. They cannot be granted more than that, and only the course owner can add or remove them.
Other students never see your reactions, your questions, your quiz, or your results. The only thing shared back to students is aggregate: how many other people flagged the same moment.
Where the data is held
ClassPulse runs on Fly.io in the United States (New Jersey region). The database and accounts are hosted by Supabase, also in the United States. Transcription is by Deepgram and AI processing by Anthropic, both US companies.
This service is currently intended for use in the United States. It has not been assessed against the GDPR or UK data protection law, so if you are joining from the EU or the UK, be aware the protections specific to those laws have not been evaluated here.
How long it is kept
Session data — the transcript, reactions, written questions, quizzes and quiz answers — is deleted about twelve months after a session ends. Twelve months leaves room for cross-session teaching insights and for any dispute about a grade, without keeping lecture records indefinitely.
Account details are kept while your account exists. Technical error records are pruned on a rolling basis, typically within a month.
Deletion is carried out by the operator on a periodic basis rather than by an automatic nightly job, so the twelve months is approximate rather than exact to the day.
Your choices
Delete your account. Settings → Delete account. This removes your account, your reactions, your written questions, your quizzes and your quiz results. If you are an instructor, it also removes your courses and their sessions, including those transcripts.
Ask what is held about you. Write to classpulses@gmail.com and you will be told what there is and sent a copy.
Join without an account. Where your instructor allows it, joining by code or QR means no email address is collected at all.
Don't react. Reactions are voluntary. You can attend a session, read the transcript, and tap nothing.
One thing you cannot opt out of while attending: the lecture itself is transcribed whenever the instructor runs a session. That decision is the instructor's, not yours. If you object to a class being transcribed, that is a conversation to have with them or your institution.
A note on student records and FERPA
In the United States, records that identify a student and are kept by an educational institution are generally protected under FERPA. Some of what ClassPulse holds — which moments you found confusing, your quiz answers, your attendance — would plainly be that kind of record if your institution were holding it.
ClassPulse is currently operated by an independent developer rather than by an institution, and no agreement is in place making it an official record system for any university. If your institution intends to adopt it, that arrangement should be reviewed by the people there who handle student data before it is used as anything other than a voluntary classroom tool. That review has not yet happened.
This is stated plainly because pretending otherwise would not serve anyone.
How it is protected
Access rules are enforced in the database itself, not merely in the interface, so a request for data you are not entitled to is refused at the lowest level. Connections are encrypted. Administrative keys are held on the server and never sent to a browser. Passwords are handled by the accounts system and never stored by ClassPulse directly.
No system is perfect, and this one is maintained by one person. If you find a security problem, reporting it to classpulses@gmail.com is genuinely welcome.
Age
ClassPulse is built for higher education and is not directed at children under 13. If you believe a child under 13 has used it, write to the address above and the data will be removed.
Changes
If this document changes in a way that affects what is collected or who can see it, the effective date at the top will change and the change will be announced in the app. Continuing to use ClassPulse after that means the revised version applies.