The short version

We use only the details needed to run your learning plan.

Your private goal shapes the map. Your email and schedule control delivery. Your journey remembers where to continue.

Email is opt-in

A lesson arrives only after you choose a learning plan and ask us to deliver it. The lesson email always takes you back to the same point on your map.

Email verification protects your learning history

Verifying your email creates a lightweight authenticated identity. There is no password or separate signup form. You can delete the identity and its learning history from your library.

Every learning plan has its own controls

Use the secure management link in a lesson email to pause, reschedule, resume, or stop delivery without losing the map.

What the product stores

Six product record types support the learning flow.

InboxLearn stores a learning plan with its private source goal and public waypoint outline, your verified recipient email and Auth identity link, and a private journey copy with consent, delivery settings, pause history, and current waypoint.

Stored lesson records hold typed lesson intentions, ready lesson content, delivery state, and personal detours. An optional self-check answer is part of the fixed lesson. InboxLearn does not store your attempt, correctness, score, or answer reveal. Your raw goal stays private and is never part of the public plan.

Verified email commands are kept as small classified event records so the same reply is not applied twice. Raw reply bodies are discarded after safe classification. Durable bounce and complaint records prevent unsafe delivery.

A small set of product events is written to application logs using opaque record IDs. These events do not include your email, goal text, lesson text, detour question, or secure access links. They are not copied into the product database.

Service providers

The product depends on a small set of processors.

Supabase provides the database and email-link identity. Resend sends lessons. OpenAI generates plans, lessons, and detours. Trigger.dev runs background work. Vercel hosts the web application.

Retention and deletion

Temporary records expire, and durable learning data is yours to remove.

Unused verification journeys expire after 30 minutes. Orphan recipient and Auth identities are cleaned after a 24-hour grace period. Expired plan-generation input is deleted or scrubbed. Bounce and complaint evidence is retained for 90 days. Product event logs follow the hosting provider's operational log retention and are not retained as learner-history records.

The secure management link can delete one journey and its lessons, detours, place, and schedule. Account deletion removes all linked journeys and the Auth identity. A reusable public plan can remain because it contains no email address, raw goal, private journey copy, lesson body, or self-check answer.

Email controls

Want to pause, reschedule, or stop future email?

Every lesson email includes a secure link for that learning plan. It is the quickest way to pause until a date, resume, choose a new delivery time, stop, or delete that journey. You can also reply with ANSWER, NEXT, PAUSE, RESUME, STOP, or HELP. Lessons begin with a verified email because email delivery is part of the current product flow.

Open your learning library

Questions about these controls can be sent to lessons@inboxlearn.com.