PRIVACY POLICY FOR DAFi

Last updated: September 23, 2026

DAFi (“DAFi,” “we,” “our,” or “us”) is committed to protecting the privacy and personal information of its users (“you” or “your”).

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use DAFi’s websites, applications, educational features, artificial intelligence features, Model Context Protocol (“MCP”) integrations, and related services (collectively, the “Services”).

DAFi operates from Québec, Canada, and processes personal information in accordance with applicable privacy laws.

By using the Services, you acknowledge the practices described in this Privacy Policy.

1. Information We Collect

The information we collect depends on how you use DAFi.

Account and Profile Information

We may collect information such as:

  • name;
  • email address;
  • username;
  • preferred language;
  • time zone;
  • school or educational institution;
  • education level;
  • account type;
  • account settings and preferences; and
  • account creation information.

Educational Content

When you use DAFi, we may process educational content that you create, record, upload, import, or otherwise provide, including:

  • course names and course codes;
  • notes and written content;
  • lecture recordings and other audio files;
  • lecture transcriptions;
  • documents and PDFs;
  • images and photographs;
  • presentations;
  • text files;
  • links and source URLs;
  • course summaries;
  • key takeaways and course outlines;
  • revision materials;
  • flashcards;
  • quizzes and practice questions;
  • practice examinations;
  • assignments;
  • deadlines;
  • academic events; and
  • other educational materials.

Users are responsible for ensuring that they have the right to record, upload, or otherwise process content belonging to other people, including lectures, documents, images, and other educational materials.

Learning and Progress Information

We may process information about how you use DAFi for studying, including:

  • quiz results;
  • answers submitted to quizzes;
  • correct and incorrect answers;
  • scores;
  • explanations;
  • flashcard activity;
  • revision activity;
  • learning progress;
  • study activity;
  • learning trends;
  • recommended revisions;
  • concepts identified as needing additional review; and
  • other information relating to your use of DAFi’s educational features.

Academic Calendar Information

If you use DAFi’s academic planning features, we may process information such as:

  • exams;
  • assignments;
  • presentations;
  • academic deadlines;
  • event titles;
  • event descriptions; and
  • event dates.

Subscription Information

We may process information relating to your subscription and access to DAFi, including:

  • subscription status;
  • subscription plan;
  • billing or subscription platform;
  • next billing or renewal date;
  • cancellation status;
  • feature availability;
  • feature usage; and
  • remaining feature quotas.

Payment transactions may be processed by third-party payment providers or application marketplaces. DAFi does not need to receive or store your complete payment card number when payment information is handled directly by an authorized payment processor.

Communications

When you contact us, we may process:

  • your name;
  • email address;
  • messages;
  • customer support requests;
  • troubleshooting information; and
  • other information you voluntarily provide.

Technical, Usage, and Security Information

We may collect limited technical information necessary to operate, protect, troubleshoot, and improve the Services, including:

  • IP address;
  • device type;
  • browser type;
  • operating system;
  • application version;
  • authentication events;
  • error and diagnostic information;
  • security events;
  • feature interactions; and
  • timestamps associated with account, security, or system activity.

We seek to limit this information to what is reasonably necessary for legitimate operational, security, reliability, analytics, and troubleshooting purposes.

2. How We Use Personal Information

We may use personal information to:

  • create and manage DAFi accounts;
  • authenticate users;
  • provide DAFi’s features and Services;
  • record, transcribe, analyze, and organize course material;
  • create summaries and structured notes;
  • generate revision materials, flashcards, quizzes, practice examinations, explanations, and other educational content;
  • personalize the study experience;
  • track learning progress;
  • provide study recommendations;
  • maintain academic calendars and deadlines;
  • administer subscriptions;
  • respond to customer support requests;
  • communicate important service information;
  • protect DAFi and its users against fraud, misuse, unauthorized access, and security threats;
  • diagnose technical issues and maintain service reliability;
  • analyze and improve the operation and usability of DAFi;
  • comply with applicable legal obligations; and
  • establish, exercise, or defend legal rights where necessary.

We do not sell users’ educational content or personal information.

We do not use information obtained through the DAFi MCP integration for third-party behavioral advertising.

3. Artificial Intelligence Processing

DAFi uses artificial intelligence and other automated technologies to provide certain educational features.

Depending on the feature used, information processed through AI systems may include:

  • text;
  • course notes;
  • audio and transcriptions;
  • documents;
  • images;
  • questions and answers;
  • educational materials;
  • study activity; and
  • other content supplied by the user.

DAFi may use third-party technology and artificial intelligence service providers where necessary to provide these features.

Where reasonably possible, DAFi limits information transmitted to such providers to information necessary to provide the requested functionality.

AI-generated content may contain errors. Users should verify important information and should not treat AI-generated educational content as professional, legal, medical, financial, or other specialized advice.

4. DAFi MCP and AI Assistant Integrations

DAFi may allow users to connect their DAFi account to compatible artificial intelligence assistants and platforms, including ChatGPT, through the Model Context Protocol (“MCP”).

The MCP integration allows an authenticated user to intentionally retrieve and interact with information contained in their DAFi account through a compatible AI assistant.

Authorization

An AI assistant does not automatically receive unrestricted access to a DAFi account.

The user must authenticate and authorize the connection.

MCP requests are processed within the permissions available to the authenticated account and the capabilities of the relevant DAFi tools.

Users may revoke or disconnect an MCP connection. Once authorization has been revoked, that connection can no longer make new authenticated requests to the user’s DAFi account.

Information Received Through MCP

When a user asks ChatGPT or another compatible AI assistant to interact with DAFi, DAFi may receive information necessary to perform the requested operation, such as:

  • a question or instruction;
  • search keywords;
  • a task-specific portion of conversational context intentionally provided to the DAFi tool;
  • a course, note, quiz, or other resource identifier;
  • dates or search filters;
  • parameters required to perform the request;
  • authentication and authorization information; and
  • limited technical information necessary to authenticate, secure, or troubleshoot the request.

DAFi’s MCP integration is not designed to retrieve, reconstruct, or collect a user’s complete ChatGPT or other AI-assistant conversation history.

DAFi processes only information intentionally provided to its MCP tools as necessary to perform the requested operation.

Information DAFi May Return Through MCP

Depending on the user’s request and the DAFi functionality available, DAFi may return information from the authenticated user’s account to the connected AI assistant.

This may include:

  • account and educational profile information, such as name, username, preferred language, school, education level, or time zone;
  • courses, course names, and course codes;
  • note titles and related metadata;
  • notes and full course content;
  • course summaries;
  • key takeaways;
  • course outlines;
  • transcripts;
  • academic events and deadlines;
  • source information associated with a note, such as file names, source types, creation dates, or source URLs;
  • flashcard activity;
  • quiz results;
  • quiz questions and answer choices;
  • answers submitted by the user;
  • correct answers and explanations;
  • learning progress and study statistics;
  • study and revision recommendations;
  • subscription status;
  • feature availability and usage quotas; and
  • other DAFi information directly relevant to the user’s request.

Functional resource identifiers, such as identifiers used to select a particular course, note, quiz, or quiz attempt, may be returned when they are necessary to perform a requested operation.

MCP Data Minimization

DAFi’s MCP tools are designed to request and return only information reasonably necessary to perform the function requested by the user.

DAFi seeks to:

  • use narrowly scoped tool inputs;
  • limit search results where appropriate;
  • retrieve a particular course, note, resource, or result rather than automatically returning an entire account;
  • avoid unrelated personal information;
  • avoid unnecessary technical metadata; and
  • avoid broad collection of conversational context.

Information that is not necessary to satisfy the user’s request should not be included in an MCP response.

Information Not Intended to Be Returned Through MCP

DAFi does not intentionally return the following as part of ordinary MCP responses:

  • passwords;
  • payment card numbers;
  • API keys;
  • OAuth secrets;
  • access tokens;
  • authentication credentials;
  • multi-factor authentication or one-time-password codes;
  • internal security credentials;
  • unrelated internal logs;
  • unnecessary debugging information;
  • unnecessary request, session, or trace identifiers; or
  • unrelated personal information.

DAFi’s MCP functionality is not designed to collect or process payment card information, government identification numbers, protected health information, passwords, authentication secrets, or similar restricted information.

Users should not intentionally submit such information through DAFi MCP requests.

5. Sharing and Disclosure of Information

DAFi does not sell personal information.

DAFi does not disclose personal information to third parties for their independent advertising purposes.

However, personal information may be processed or communicated to service providers where necessary to operate DAFi.

These categories of recipients may include:

  • hosting and cloud infrastructure providers;
  • database and storage providers;
  • artificial intelligence and machine-learning providers;
  • transcription and document-processing providers;
  • payment and subscription providers;
  • application marketplaces;
  • analytics and performance providers;
  • security and fraud-prevention providers;
  • customer communication and support providers; and
  • other technical service providers necessary to operate the Services.

These providers may only receive information reasonably necessary to perform services for DAFi and are subject to applicable contractual, confidentiality, and privacy obligations.

ChatGPT, OpenAI, and Other Connected AI Platforms

When a user intentionally connects DAFi to ChatGPT or another external AI assistant and asks that assistant to access information stored in DAFi, DAFi may transmit information necessary to fulfill that request to the external AI platform.

For example, if a user asks ChatGPT to explain a DAFi course note, DAFi may return the relevant note or portion of that note to ChatGPT so that ChatGPT can respond.

Once information has been transmitted to an external AI platform at the user’s request, the external platform processes that information according to its own applicable terms, privacy policy, retention practices, and user controls.

Users should review the privacy practices and settings of any external service they choose to connect to DAFi.

Legal Disclosures

DAFi may disclose information where reasonably necessary to:

  • comply with applicable law, regulation, legal process, or lawful governmental request;
  • investigate or prevent fraud or misuse;
  • respond to a security incident;
  • protect the rights, property, or safety of DAFi, its users, or others; or
  • establish, exercise, or defend legal claims.

Business Transactions

If DAFi is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, information may be transferred as permitted by applicable law and subject to appropriate safeguards.

6. Legal Grounds and Consent

DAFi collects, uses, and communicates personal information only where permitted by applicable law.

Depending on the circumstances, this may include:

  • obtaining consent from the user;
  • processing information necessary to provide Services requested by the user;
  • processing permitted or required by applicable law;
  • fulfilling contractual obligations; and
  • complying with legal requirements.

Where processing requires consent, users may withdraw their consent subject to applicable legal and contractual restrictions.

Withdrawing consent may prevent DAFi from continuing to provide functionality that requires the relevant information.

7. Data Retention

DAFi retains personal information only for as long as reasonably necessary to provide the Services, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, protect users, and enforce agreements.

The following retention periods apply unless a longer period is required by law or reasonably necessary in connection with a security incident, dispute, or legal proceeding.

Account and Educational Information

Account information and educational content are generally retained while the user’s DAFi account remains active.

Following an account deletion request, information stored in active systems is scheduled for deletion within 30 days, subject to applicable legal requirements and limited backup exceptions.

Backups

Information deleted from active systems may remain in encrypted or access-restricted backups for up to 90 days before being overwritten or deleted through normal backup cycles.

MCP Data

DAFi does not create a separate permanent copy of educational content solely because that information was returned through an MCP request.

Limited MCP security, request, and diagnostic records may be retained for up to 30 days where necessary for security, fraud prevention, debugging, reliability, or abuse investigation.

Information relating to a specific security incident may be retained longer where reasonably necessary to investigate or resolve the incident or comply with applicable law.

Authentication or authorization records associated with an MCP connection may be retained while the connection remains authorized and for a limited period afterward where necessary for security or legal compliance.

Customer Support

Customer support communications may generally be retained for up to 24 months after resolution of the relevant request unless longer retention is reasonably necessary for a dispute or legal requirement.

Transaction and Accounting Information

Transaction, tax, accounting, and related records may be retained for up to 7 years where required or reasonably necessary for accounting, tax, fraud-prevention, chargeback, or legal purposes.

Marketing Preferences

Marketing information may be retained until the user unsubscribes or withdraws consent.

DAFi may retain limited suppression information afterward in order to ensure that an unsubscribe request continues to be respected.

When information is no longer required, DAFi will delete, securely destroy, or, where permitted by law, anonymize the information in accordance with applicable requirements.

8. Security Measures

DAFi uses reasonable technical, administrative, and organizational measures designed to protect personal information against unauthorized access, loss, theft, alteration, disclosure, or misuse.

These measures may include:

  • encryption of information during transmission;
  • authentication controls;
  • access restrictions;
  • infrastructure and network safeguards;
  • monitoring for suspicious or unauthorized activity;
  • security and reliability controls; and
  • limiting access to personnel and providers who require information for legitimate operational purposes.

No information system can guarantee absolute security.

Users are responsible for protecting their login credentials and should notify DAFi if they believe their account has been compromised.

9. Privacy and Security Incidents

DAFi maintains procedures for responding to privacy and security incidents.

Where required by applicable law, DAFi will notify affected individuals and applicable regulatory authorities when a confidentiality or security incident presents the level of risk requiring notification.

DAFi may maintain records of privacy incidents as required by applicable law.

10. Cookies and Similar Technologies

DAFi may use cookies and similar technologies for purposes such as:

  • maintaining user sessions;
  • authentication;
  • remembering settings;
  • protecting the Services;
  • understanding application or website usage;
  • measuring performance; and
  • improving functionality and reliability.

Users can control certain cookies through browser or device settings.

Disabling essential cookies or similar technologies may prevent parts of the Services from functioning properly.

Where required by applicable law, DAFi will provide appropriate notice or consent mechanisms for non-essential tracking technologies.

11. Your Privacy Rights

Subject to applicable law, users may have the right to:

  • request access to personal information DAFi holds about them;
  • request correction of inaccurate or incomplete information;
  • obtain information about how their personal information has been used or communicated;
  • request deletion of personal information where applicable;
  • withdraw consent where processing is based on consent;
  • request information in a structured technological format where applicable;
  • manage applicable account and privacy settings;
  • disconnect an MCP or external AI integration;
  • unsubscribe from marketing communications; and
  • submit a privacy question or complaint.

DAFi may take reasonable steps to verify the identity of a person making a privacy request.

Certain rights may be subject to exceptions or limitations under applicable law.

Requests can be submitted to:

admin@dafi-ai.com

12. Privacy Officer

DAFi has designated a person responsible for overseeing the protection of personal information and responding to privacy inquiries and requests.

Privacy Officer
DAFi
Québec, Canada
admin@dafi-ai.com

Questions, complaints, requests for access or correction, and other privacy inquiries may be directed to the Privacy Officer.

13. Children and Minors

The minimum age required to use DAFi is governed by DAFi’s Terms and Conditions and applicable law.

DAFi is not directed to children under the age of 13.

Where applicable law requires consent from a parent or person with parental authority for the collection, use, or communication of a minor’s personal information, DAFi will process that information in accordance with those requirements.

In Québec, specific consent requirements apply to personal information concerning minors under the age of 14.

If DAFi becomes aware that personal information has been collected from a child contrary to applicable legal requirements, DAFi will take appropriate steps to delete or otherwise address that information.

Parents or persons exercising parental authority may contact DAFi regarding privacy concerns involving a minor.

14. International and Cross-Border Processing

DAFi operates from Québec, Canada.

Some service providers used to operate DAFi may process or store personal information outside Québec or outside Canada.

As a result, information may be subject to the laws applicable in the jurisdiction where it is processed.

Where required by applicable law, DAFi assesses relevant privacy factors and implements appropriate safeguards before communicating personal information outside Québec.

Users may contact DAFi’s Privacy Officer for additional information regarding cross-border processing of their personal information.

15. Automated Processing

DAFi uses automated processing and artificial intelligence to provide educational functionality, including:

  • organizing course material;
  • generating summaries;
  • generating revision materials;
  • generating flashcards and quizzes;
  • evaluating quiz performance;
  • identifying concepts for additional revision;
  • calculating learning progress; and
  • providing study recommendations.

These features are designed to assist users with their studies.

Where applicable law provides specific rights relating to decisions based exclusively on automated processing, DAFi will provide the information and rights required by law.

16. Educational Institutions

DAFi may also be provided through or used in connection with a school, university, college, or other educational institution.

Where an institution provides access to DAFi or uses DAFi services, the institution and DAFi may have separate responsibilities regarding personal information according to their respective roles, the applicable agreement, and applicable law.

An institution’s access to information stored in DAFi, if any, depends on the applicable service, permissions, agreement, and legal requirements.

17. Changes to This Privacy Policy

DAFi may update this Privacy Policy from time to time to reflect:

  • changes to our Services;
  • new DAFi functionality;
  • new AI or MCP integrations;
  • changes in service providers;
  • changes in our privacy practices; or
  • legal and regulatory requirements.

Material changes will be communicated as required by applicable law.

The “Last updated” date at the beginning of this Privacy Policy identifies the most recent revision.

DAFi will update this Privacy Policy when new MCP tools, data categories, or AI integrations materially change how personal information is collected, used, communicated, or retained.

18. Contact Us

If you have questions or concerns about this Privacy Policy, wish to exercise a privacy right, or have a complaint regarding DAFi’s handling of personal information, please contact:

Privacy Officer
DAFi
Québec, Canada
admin@dafi-ai.com

Effective Date: September 23, 2026