Privacy Policy
Last updated October 5, 2026
Tentaku is a desktop study app made by an independent developer. It’s built so that your lectures stay yours. This page lists everything that happens to your data — in the app and on this website.
1. No account, no telemetry
Tentaku has no sign-up, no analytics, no crash reporter and no auto-updater. The app contacts tentaku.app in two cases only. First, when you press “Check for updates” in About, it downloads our public version list (tentaku.app/versions.json) and sends nothing else. Second, when you redeem a promo code that has a use limit, it sends the code’s 8-character id, its label and — if you redeemed it offline — when you redeemed it, so its uses can be counted. That happens right away when you’re online, otherwise the next time you are. Our server sees your IP address with that request like any website does; we keep only a daily-salted hash of it for abuse control. Nothing else.
2. Where your data lives
Everything Tentaku stores is on your computer, in Documents/Tentaku, as plain files:
config.json— your settings, plus your secrets (AI API keys, OpenRouter key, license key and license state, calendar-feed links), encrypted with a key your operating system’s keychain protects. Where the operating system can’t provide that encryption (rare — for example some Linux setups without a keyring), those values are written in plain text.classes/<class>/sessions/<date-time>/— your recordings asaudio-NNNNN.wavpieces (16 kHz mono, about 115 MB per hour), plustranscript.txt,notes.md,notes-original.mdandhighlights.json. Recordings are kept until you delete them; Tentaku never deletes a recording. For an imported recording, Tentaku transcribes a temporary converted copy inside the session folder and removes that copy afterwards; your original file is left where it was.classes/<class>/—meta.json,files/<category>/…(documents you dropped in or fetched),cards.json,coursenotes.md,concepts.json,plan.json,tests.json,sites.json,lessons/,visuals/,digests/.deadlines.json(from your calendar feeds) andinbox.json(file names spotted in Downloads).- Outside that folder, the app keeps one small encrypted licensing file,
state.enc— on Mac in~/Library/Application Support/Tentaku/, on Windows in%APPDATA%\Tentaku\— holding when your trial started, which codes this computer has used, and recording counts for the Free limit. It holds no lecture content. - Exports — the Anki file, calendar .ics, note PDFs, class packs, the backup zip and the Claude connector bundle — are written to your Downloads folder.
3. What leaves your computer, and to whom
This is the complete list. Tentaku itself never receives any of it.
| Recipient | When | What is sent |
|---|---|---|
The AI provider you chose — Anthropic (api.anthropic.com), OpenAI (api.openai.com), Google (generativelanguage.googleapis.com) or OpenRouter (openrouter.ai) |
Every AI feature: live notes while recording (the latest ~9,000 characters of transcript every few minutes), final notes, highlights, catch-me-up, Q&A, flashcards, tidy, concept map, teach, weekly plan, practice tests, visuals, day digest and document filing | Text excerpts of transcripts, notes and documents (capped per request, roughly 4,000–24,000 characters), plus your question. Weekly-plan requests also include up to 8 deadline titles and dates from your calendar feed and up to 12 flashcard questions you’re weak on. Your API key is sent in a request header, never in the web address. Audio is never sent. Each provider’s own terms apply: Anthropic, OpenAI, Google Gemini API, OpenRouter. |
OpenRouter (openrouter.ai) | One-click sign-in | A one-time authorization exchange; Tentaku receives and stores an API key. You sign in on OpenRouter’s own page inside the app. |
Lemon Squeezy (api.lemonsqueezy.com) |
When you apply a Pro key, at each launch while online, every 24 hours while the app is open, and when you clear it | Your license key, a random per-install seat label and an instance id (app versions before 0.28.2 sent your computer’s name as the seat label). Not sent for the free trial or promo codes. |
| tentaku.app (us) | Only when you press “Check for updates” | A plain request for our public version list. Nothing about you is sent; our host sees your IP address as with any website. |
| tentaku.app (us) | Only when you redeem a promo code that has a use limit — right away if online, otherwise the next time you are | The code’s 8-character id, its label, and when you redeemed it if that was offline. Nothing about you, your notes or your recordings. |
| Your school’s calendar feed (whatever address you paste) | When you ask, 30 seconds after launch, and every 12 hours | A read-only request for the feed. No login, no credentials. The feed link is stored encrypted on your computer; the app shows only its host name. |
| Public course pages you add (any site) | When you click Watch or Check now, 30 seconds after every launch, and every 12 hours while the app runs | Requests for the page (up to 5 pages per class), up to 12 same-site pages one click deep per page, and the PDFs you click ⤓ Get on. No cookies, no login, no forms. |
| A local command (Ollama or similar) | If you choose “Local AI” | Nothing leaves your computer from Tentaku. |
| Claude, ChatGPT or Gemini (whichever you pick) | Only when you click “Ask in Claude / ChatGPT / Gemini” | Nothing is sent by Tentaku. It first shows you exactly what it will copy (and lets you edit it), then copies your question and the notes you chose to your clipboard and opens that service’s page (claude.ai, chatgpt.com or gemini.google.com) in your browser. Nothing goes anywhere until you paste and send it there yourself, under your own account; that service’s terms and privacy settings apply — some consumer chat apps can use conversations to improve their models unless you turn that off. For Claude, if you tick the option, Tentaku opens the Claude app with just your question (up to 1,000 characters) in the link; your notes stay on the clipboard. Tentaku never reads the reply. |
| An AI app on your computer you connect Tentaku to (for example the Claude desktop app, Gemini CLI, Cursor, VS Code or LM Studio) | Only if you add Tentaku’s connector to that app and ask it something | The app reads lecture notes, transcripts (up to ~120,000 characters per lecture), deadlines and flashcards through Tentaku’s connector, on your computer, after the app’s own approval prompts. What it reads is then processed by that app’s AI provider under your account. With LM Studio it stays on your computer only if the model you run there is local. The connector can add flashcards and append notes; it never edits or deletes anything. |
4. Local processing
Tentaku captures microphone audio only while you record. It writes the audio to disk in 10-second pieces and transcribes it with a built-in engine (whisper.cpp) on your computer. Pausing with ⏸ Break turns the microphone fully off — nothing is captured and your computer’s microphone indicator goes out — until you press Resume.
5. Downloads folder
Downloads auto-filing is off until you turn it on (Home asks once; Settings → Recording & notes changes it anytime). When it’s on, Tentaku watches only your Downloads folder and looks only at the names of files you download. A course document whose name matches a class is copied into that class — the download itself stays put — with an ↩ undo; anything unclear shows on Home for you to pick. This runs entirely on your computer; nothing about your downloads leaves it.
6. Retention
Everything stays until you delete it. Deleting Documents/Tentaku removes your notes, recordings and settings; uninstalling the app doesn’t delete that folder. The small licensing file (state.enc, see section 2) stays until you delete it too; it holds no lecture content. To remove everything: free your Pro seat (Settings → License → Apply with an empty box), quit Tentaku, delete Documents/Tentaku and the Tentaku application-support folder, on Mac also delete the “Tentaku Safe Storage” item in Keychain Access, then delete the app. Step by step: Help.
7. Class packs
A class pack contains everything in a class folder except audio: transcripts, notes, documents, cards, map, plan, tests, lessons, visuals and the list of watched sites. Anyone you send one to can read it.
8. Children
Tentaku is made for college students and is only for people 18 or older. It isn’t directed to anyone under 18, and we don’t knowingly collect information from anyone under 18. If you believe someone under 18 has given us information, email us and we’ll delete it.
9. This website
- Analytics. Cloudflare Web Analytics: cookieless, aggregate page-view counts. No cookies, no third-party trackers, no advertising.
- Notify list. If you ask to be told when the download is public, we store your email, the computer type you picked and timestamps. You confirm by clicking a link we email you (double opt-in); unconfirmed sign-ups are deleted after 7 days. You can unsubscribe anytime from any email: your address is then deleted and only a salted hash is kept, so the address can’t be added again by someone else.
- Student discount. Your .edu email is used once to send you a code. We keep only a salted hash of it and your school’s domain, for 30 days, to prevent repeat requests, then delete them.
- Contact. There’s no contact form. Email reaches us at help@tentaku.app.
- Purchases. Lemon Squeezy processes payments as merchant of record under its own privacy policy. We receive order events with the plan bought, an order id and a subscription id — never payment details.
- Subscription emails. If you subscribe to a yearly plan, we send you the renewal terms when you subscribe and a notice before each renewal, as the law requires. We read your subscription email address from Lemon Squeezy at the moment we send and don’t store it.
- Support payments. If you chip in on the Support page, Stripe processes the payment under its own privacy policy. We receive your name, email, the amount, the date and your card’s country — never card details — and keep these records as long as tax law requires. We don’t share them with anyone else.
- Email delivery. Codes and notify emails are sent through Resend, with open and click tracking turned off.
- Hosting and logs. The site runs on Cloudflare. Our server logs keep salted, daily-rotated IP hashes for up to 30 days for abuse control.
A daily job on our server performs every deletion described in this section. We don’t sell personal information.
10. Who we are and contact
Tentaku is made and run by Robert Smalls, a sole proprietor in New York, who is responsible for this policy. Privacy questions: help@tentaku.app.