Niklaus AI — Privacy Policy

Last updated: 2 September 2026

1. Who this policy applies to

This Privacy Policy applies to anyone who uses Niklaus AI ("Niklaus", "the Service"), including visitors to the public website and registered account holders.

Niklaus is a Personal AI Academic Tutor. A registered user's work is organised into Projects and Assignments, where tools such as Explain My Brief, Ask Niklaus, Paraphrase, Grammar & Clarity, Presentations, Charts & Tables and Study Plan are available. Niklaus can also analyse an uploaded assignment brief and produce a full Academic Learning Example (the Standard Assignment or Fast Academic Example flow).

This Policy explains what information Niklaus collects, how that information is used, and the choices and rights available to users. It should be read together with the Niklaus Terms & Conditions.

2. Information Niklaus collects

Niklaus collects information in three main ways:

  • information a user provides directly, such as a username, password, and any assignment brief or the user's own academic work uploaded to a Project or Assignment
  • information generated by using the Service, such as Projects and Assignments, Ask Niklaus conversation messages, generated documents and presentations, and billing and KLAUS transaction records
  • limited technical information collected automatically to keep accounts and sessions secure, such as a security-hashed record derived from a network address and browser type

Each category is described in more detail in the sections below.

3. Account information

To create a Niklaus account, a user chooses a username and a password. Niklaus does not require a real name, a university student number, or an email address to create or use an account.

A password is never stored in a form that can be read back. It is transformed using the argon2id password-hashing algorithm before being stored, and the original password is not retained.

Where a user separately interacts with Niklaus's support, any information volunteered as part of that interaction (for example, details needed to identify an account or transaction) is used only to resolve that interaction.

4. Your Projects and Assignments

Inside Niklaus, a user's work is organised into Projects and Assignments. A Project is a workspace for one piece of academic work; an Assignment inside a Project represents one specific task — for example, writing a report from an assignment brief, or working on a piece of writing the user has already started.

Project and Assignment names, and their existence, are stored so a user's workspace persists between visits and can be organised, trashed and restored as described in section 16.

5. Uploaded assignment briefs and your own uploaded work

When a user uploads an assignment brief, or their own existing academic work, to an Assignment, Niklaus stores the original file privately (see section 14) so it remains available inside that Assignment — for example, so the user can re-download it or use it with a different tool later.

Niklaus also stores the text extracted from that file, used to power the AI tools described in this Policy, and basic file metadata such as the file name, file size, and a checksum used to verify the stored copy has not been altered.

Uploaded material is used to provide the feature requested with it — for example, to explain a brief, generate an Academic Learning Example, paraphrase a document, check grammar, create a presentation, a chart, or a Study Plan — and, where applicable, to run the automated quality checks described in section 13.

Niklaus does not use uploaded material to train its own AI models, and does not sell uploaded material to third parties.

6. Ask Niklaus conversations

Ask Niklaus lets a user have an ongoing conversation with Niklaus about a specific Assignment. Each message the user sends, and each reply Niklaus gives, is stored as part of that Assignment's conversation.

This history is stored so the conversation can persist between visits, so the user can return to it later, and so Niklaus can continue helping within that same Assignment.

A user can export a substantial Ask Niklaus reply to a Word document. Where that happens, the exported document is stored as a generated resource as described in the next section.

7. Generated resources and files

Using a Niklaus tool can produce a generated resource attached to an Assignment — for example, an Assignment Brief explanation, a tutoring export or Academic Learning Example from Ask Niklaus, a full Academic Learning Example, a paraphrased document, a grammar-corrected document, a presentation, a chart or table document, or a Study Plan/Gantt document.

Some tools save their result automatically once it is generated (for example, creating a Presentation). Others generate a result first and only save a copy once the user chooses to export it to a Word document (for example, Explain My Brief, Ask Niklaus, Paraphrase, Grammar & Clarity, Charts & Tables, and Study Plan). Either way, once saved, a resource is stored in the same private storage described in section 14 and can be re-downloaded from its Assignment.

Generated files are referenced from Niklaus's database by an internal file identifier, checksum and file size. Access to stored files is limited to the account that owns the Project and to Niklaus's own systems.

8. Account and authentication data

Niklaus's database records the following for each account:

  • an internal account identifier, username, and account status
  • an argon2id password hash (never the password itself)
  • session records used to keep a user signed in

A session record uses a securely generated session token that is itself stored only in hashed form, together with the session's creation time, last-active time, and expiry.

To help detect abuse — for example, credential-stuffing or unusual login patterns — a session record also stores a one-way, keyed cryptographic hash of a truncated network-address prefix (the last part of the address is discarded before hashing, so the stored value cannot be reversed to a full IP address) and a similarly hashed summary of the browser/device "user agent" string. The raw IP address and raw user-agent text are never stored.

The same hashing approach is used for account-recovery codes and for rate-limiting and security-audit records, which record the type and outcome of an authentication event (for example, a login attempt) without storing the underlying credential.

9. Billing and KLAUS transaction information

Niklaus records each account's KLAUS balance and a ledger of KLAUS transactions — for example, a top-up, a reservation made when a generation begins, or a charge applied once a document is delivered.

Each ledger entry records the amount, a description of what it relates to, and the balance before and after the transaction, associated with the account's internal identifier.

This information is used to operate the KLAUS credit system described in the Terms & Conditions, to display Billing History to the account holder, and to investigate billing queries.

10. Payment providers

Purchases are processed by Stripe and/or PayPal, both of which operate their own hosted checkout or payment-approval flow.

When a user makes a purchase, Niklaus passes the relevant provider only the account's internal identifier and the product being purchased. Card details, bank details, and PayPal login credentials are entered directly with the payment provider and are not seen, collected, or stored by Niklaus.

Each payment provider processes payment information under its own privacy policy and terms.

11. How information is used

Niklaus uses the information described above to:

  • create and operate a user's account
  • process uploaded academic material and provide the requested AI tutoring feature
  • maintain a user's Projects and Assignments, including the Trash and restore behaviour described in section 16
  • keep an Ask Niklaus conversation available so it can continue within that Assignment
  • generate and store the resources a user requests
  • operate the KLAUS credit and billing system and process payments
  • maintain the security, integrity and availability of the Service, including detecting and preventing fraud, abuse and unauthorised access
  • respond to support queries
  • comply with legal and accounting obligations

Niklaus does not use this information for advertising, and does not sell personal information to third parties.

12. Lawful bases for processing

Where UK data-protection law applies, Niklaus relies on the following lawful bases:

  • performance of a contract — for information needed to create an account, process uploaded material, generate requested content, and process billing and payments
  • legitimate interests — for the hashed security and rate-limiting signals described in section 8, used to protect accounts and the Service from abuse in a way designed to minimise the information retained
  • legal obligation — for billing and transaction records that may need to be kept for accounting purposes

Niklaus does not rely on consent for the strictly necessary session cookie described in section 15, because that cookie is required for the Service to function.

13. AI and third-party service providers

Niklaus uses OpenAI to power its AI tutoring features. Depending on the tool being used, this can include the extracted text of an uploaded assignment brief or the user's own uploaded work, the Ask Niklaus conversation history for that Assignment, and the user's instructions — sent to OpenAI's API to produce the requested output (for example, an explanation, a chat reply, an Academic Learning Example, a paraphrase, a grammar correction, a presentation, a chart, or a Study Plan).

Niklaus sends OpenAI the extracted text and context relevant to the specific request being made, not a raw copy of every file stored in a user's workspace. The original uploaded files themselves remain in Niklaus's private storage (see section 14); they are not directly uploaded to OpenAI.

Niklaus also uses Eden AI, a third-party AI orchestration service, but only as part of the Standard Assignment and Fast Academic Example generation flow: Eden AI runs automated post-generation quality checks on a finished, generated document — including AI-content likelihood detection, similarity/plagiarism checking, and, where a limited number of sentences are flagged, a targeted rewrite for naturalness. Eden AI receives the generated document produced from the brief, not the original uploaded brief itself.

Eden AI is not used by Explain My Brief, Ask Niklaus, Paraphrase, Grammar & Clarity, Presentations, Charts & Tables, or Study Plan. Where Eden AI does perform a rewrite, that rewrite is carried out by routing the flagged text through OpenAI's own models via Eden AI's passthrough, so a readability-review pass still produces OpenAI's own wording rather than a different model's.

These providers process the content described above only to deliver the requested feature. They are not the user's educational institution and do not determine whether use of their output is permitted under the user's own institutional rules.

14. Hosting, database and storage providers

The Service is hosted on Vercel, including Vercel's own private object storage ("Vercel Blob") used to store uploaded files and generated resources. Niklaus's serverless functions run in Vercel's London ("lhr1") region.

Niklaus's database is provided by Neon, a managed PostgreSQL hosting service.

Access to a stored file is controlled through the authenticated Niklaus application — a file is only served to the account that owns the Project it belongs to, checked on every request. Niklaus does not expose storage keys, credentials or internal configuration to users.

15. Cookies

Niklaus sets one cookie: a session cookie used to keep a signed-in user logged in. This cookie is strictly necessary for the Service to work — it is not used for advertising, analytics, or tracking — and is marked HttpOnly (not readable by page scripts) and Secure.

Niklaus does not use Google Analytics or any other third-party analytics, advertising, or tracking script, and does not set any non-essential cookies.

16. Retention, Trash and deletion

When a user deletes a Project or an Assignment, it is not removed immediately. It moves to Trash, where it stays fully recoverable for 30 days.

While something is in Trash, its content — including any uploaded files, generated resources, and, for an Assignment, its Ask Niklaus conversation — is hidden from the user's normal workspace but is not deleted. Using Restore within the 30-day grace period brings it back exactly as it was.

Deleting an Assignment only affects that Assignment; it never deletes the Project it belongs to. Deleting a Project also moves its Assignments to Trash together with it, and restoring the Project restores those Assignments too, unless one of them had already been individually deleted before the Project was.

If a Project or Assignment is still in Trash 30 days after it was deleted, it is scheduled for permanent cleanup. Permanent cleanup removes the Assignment or Project record, its generated resources, and the underlying files from Niklaus's private storage. Where a stored file cannot be removed on a given attempt, Niklaus retries rather than treating the item as fully deleted while a copy still exists in storage.

Financial, billing, and security/audit records — for example, KLAUS transaction history, purchase records, and the security and rate-limiting signals described in section 8 — are not affected by Project or Assignment deletion or by permanent cleanup, and are retained separately as described in this Policy.

Niklaus has not set a fixed retention period for billing and transaction records; they are kept for as long as reasonably necessary for accounting, tax, and fraud-prevention purposes.

Account records are kept for as long as an account remains active, so a user can continue to access their account and their workspace.

17. Security

Niklaus applies a number of technical measures to protect account information, including:

  • hashing passwords with argon2id, a modern password-hashing algorithm, rather than storing them in plain text
  • storing session tokens, recovery codes, and IP/user-agent security signals only in hashed form rather than in plain text
  • serving the Service over HTTPS
  • restricting administrative access to account and billing records to a small, named set of individuals who must separately authenticate before that access is granted

No method of storing or transmitting information is completely secure, and Niklaus cannot guarantee absolute security.

18. Your data-protection rights

Subject to applicable law and its usual exemptions, a user may have the right to:

  • request access to the personal information Niklaus holds about them
  • request that inaccurate information be corrected
  • request erasure of their information
  • request that processing be restricted
  • object to processing carried out on the basis of legitimate interests
  • request a portable copy of information provided to Niklaus

Some of these can be exercised directly in the product today: deleting a Project or Assignment, with the Trash and restore behaviour described in section 16, is self-service and does not require contacting Niklaus.

Other requests — for example, a full copy of the personal information Niklaus holds, correcting account-level information, or deleting an entire account — currently require contacting Niklaus using the support options made available through the Service, because Niklaus does not yet provide a fully self-service tool for those requests.

19. Account and data deletion

A user can delete individual Projects and Assignments themselves at any time, using the Trash and 30-day recovery process described in section 16.

Deleting an entire Niklaus account is not yet a self-service action in the product. A user may request that their account and associated personal information be deleted by using the support options made available through Niklaus AI.

Where Niklaus acts on a validated account-deletion request, it removes or anonymises the personal information associated with that account, subject to any information it is required to retain for legal, accounting, tax, or fraud-prevention purposes (for example, certain billing/transaction records).

20. International processing and transfers

Some of the third-party providers described in this Policy — including OpenAI, Eden AI, Stripe, and PayPal — may process information outside the United Kingdom.

Where that happens, the relevant provider processes that information under its own privacy policy and applicable data-transfer safeguards.

21. Children's data

Niklaus does not knowingly collect personal information from children below the age at which they may lawfully use the Service without parental or guardian consent, as described in the Terms & Conditions.

Niklaus does not currently operate an age-verification system beyond the account and eligibility rules described in the Terms & Conditions.

22. Changes to this Privacy Policy

Niklaus may update this Privacy Policy where reasonably necessary due to changes to the Service, the providers it uses, or applicable law.

Material changes may be communicated through the Service.

23. Complaints and ICO rights

Users experiencing a problem with how their information is handled may use the support options made available through Niklaus AI.

Users in the United Kingdom also have the right to complain to the Information Commissioner's Office (ICO), the UK's independent regulator for data-protection rights, at ico.org.uk.