Back to Home

Privacy Policy

Last updated: April 2026

This Privacy Policy describes how SDPal ("we", "us", "the Service"), operated by shazaib, collects, uses, and protects your information when you use the SDPal Chrome extension, web app (app.getsdpal.com), and related services.

1. Information We Collect

Account Information: When you create an account, we collect your email address and a password. Passwords are hashed using PBKDF2 with a unique salt and are never stored in plain text.

Usage Data: We collect anonymized usage logs including which features you use, how often, and associated token/character counts. This helps us improve the service and manage costs. We do not track your browsing activity outside the SABIS E-Book or the SDPal web app.

Text Data: When you use AI features (summarize, quiz, explain, etc.), the selected text from your SABIS ebook or text you paste into the web app is sent to our secure backend for processing. This text is forwarded to a third-party AI provider (OpenAI) to generate results. For Read Aloud (text-to-speech), text is sent to OpenAI's TTS API. We do not permanently store your ebook text or audio output.

Payment Information: Payments are processed by Paddle (our merchant of record). We do not directly collect or store your credit card details, billing address, or other payment information. Paddle handles all payment processing and shares only your email and subscription status with us.

Activation Codes: If you use an activation code instead of a subscription, we store records of code redemptions, including the code used, your account, and the activation/expiry timestamps.

2. How We Use Your Information

  • To provide and operate the SDPal Chrome extension, web app, and AI features.
  • To authenticate your account and manage subscriptions.
  • To process activation codes and track subscription status.
  • To improve the service based on anonymized usage patterns.
  • To send essential account-related emails (verification, password reset).

3. Information Sharing

We do not sell, rent, or share your personal information with third parties, except:

  • AI Processing: Selected text is sent to OpenAI's API for processing. OpenAI's data usage policies apply to this data. We do not send your email, password, or account details to OpenAI.
  • Legal Requirements: We may disclose information if required by law or to protect our rights.

4. Data Storage & Security

  • Account data is stored in a secure database.
  • All connections use HTTPS/TLS encryption.
  • Passwords are hashed with PBKDF2 (100,000 iterations) with unique salts.
  • Sessions use secure, randomly generated tokens.
  • We do not store your ebook content or AI-generated results on our servers.

5. Cookies & Local Storage

SDPal uses browser local storage (chrome.storage for the extension, localStorage for the web app) to save your preferences, session tokens, and cached settings. We do not use third-party tracking cookies. The marketing website uses no cookies.

6. Data Retention

  • Account data is retained as long as your account is active.
  • Usage logs are retained for up to 90 days for service improvement.
  • You may request account deletion by emailing us (see Contact below).

7. Children's Privacy

SDPal is designed for students, including those under 18. We collect only the minimum information necessary to operate the service (email and password). We do not knowingly collect additional personal information from children. If you are a parent or guardian and believe your child has provided us with information beyond what is described here, please contact us.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data.
  • Withdraw consent for data processing (by discontinuing use).

9. Third-Party Services

SDPal relies on the following third-party services:

  • Cloudflare: Hosting, DNS, backend infrastructure, and database.
  • OpenAI: AI text processing and text-to-speech for study tools.
  • Paddle: Payment processing and subscription management (merchant of record).

Each service has its own privacy policy governing its data handling practices.

10. Changes to This Policy

We may update this Privacy Policy at any time. Changes will be reflected by the "Last updated" date above. Continued use of SDPal after changes constitutes acceptance.

11. Contact

For privacy-related questions or data requests, contact us at [email protected].