Privacy Policy

Last updated 29 August 2026

Wait, Professor is a single-purpose app: you name a topic, and it builds you a course. It collects what it needs to do that, keep your courses waiting for you next time, and see which parts of the app people actually use — nothing else. The app carries no advertising, no advertising identifier and no tracking of any kind. This website is different, and deliberately so: it carries an advertising pixel, because ads are how people find the app. See Advertising and cookies below.

What we collect

Your account

You sign in with Google, with Apple, or with an email address and password. We store the email address and the provider’s account identifier so we can recognise you on your next launch. If you use Sign in with Apple and choose to hide your address, we only ever see Apple’s private relay address. We never receive your Google or Apple password.

What you type and what you learn

The topics you enter, the syllabus and lesson content generated for them, which steps you asked Mila to re-explain, and which lessons you finished. This is stored against your account so a course you started is still there when you come back, and so reopening a lesson doesn’t have to regenerate it.

Your subscription

Apple handles the purchase; we never see your card details. From Apple we receive the transaction identifiers for your subscription, the product you bought, its renewal or expiry date, and whether it came from the sandbox or production environment. The app also stamps your account identifier onto the purchase so a subscription follows your account onto any device you sign in on. If you subscribe on this website instead, Dodo Payments handles the purchase and we never see your card details there either; from Dodo we receive the customer and subscription identifiers, which plan you bought, its status, and the end of the period you have paid for. The account identifier travels with that purchase for the same reason.

A device label

The app sends a per-install identifier (derived from Apple’sidentifierForVendor) alongside purchase requests. It is a diagnostic label attached to a subscription record, never an identity — access is always decided by your signed-in account, not by your device.

How you use the app

The app records which screens you reach and which actions you take — a course built, a lesson opened or finished, Mila asked for plainer words, the plans looked at — each tagged with your account identifier so we can tell one person using the app twenty times from twenty people using it once. It records the fact of an action, never the content: the topics you type and the lessons you read are not sent to our analytics provider. This is how we work out which parts of the app help and which get in the way.

Request logs

Our servers write one line per API request: the route, the HTTP method, the response status, how long it took, and the device label above. Access tokens, transaction payloads, and request and response bodies are deliberately excluded.

What we don't collect

No location, contacts, photos, microphone, camera, or health data — the app never asks for those permissions. No advertising identifier, and no tracking of any kind inside the app. We do not use your courses or questions to train any model of our own, and we never sell personal information. We do share a purchase with Meta for advertising measurement, which some laws describe as sharing for cross-context behavioural advertising — that is set out in full below, and it is limited to the website.

AI-generated content

Everything we generate is text.A course is a syllabus and written lessons, and that is the whole of it. Nothing in the app or on this website generates images, video or audio, so nothing here can produce a person’s likeness: no image or face generation, no face swapping, no voice cloning, and no synthesis of any real person’s face, body or voice.

Thorne and Mila, the two characters who teach the courses, are fixed illustrations drawn for this app — the same drawings every time, not generated, and not based on any real person. We never take a photo, a recording or a likeness as input, because there is no feature that would accept one.

Who else sees it

We use seven service providers, each for one job:

  • OpenAI — generates lessons. The topic you type and the lesson context around it are sent to their API. It is sent through a business API account, which is not used to train their models.
  • Supabase — hosts the database and the sign-in system holding your account, courses, and subscription records.
  • Apple — processes the subscription and tells our server when it renews, lapses, or is refunded.
  • Vercel — hosts this site and the API the app talks to.
  • Dodo Payments — the merchant of record for subscriptions bought on this website. They take the payment, handle tax and invoicing, and tell our server when the subscription renews, lapses or is refunded.
  • Amplitude — product analytics. Receives the usage events described above, and nothing you type or read.
  • Meta — advertising measurement on this website only. Receives the fact that a purchase happened and what it was worth, so we can tell which ads pay for themselves. Never anything you type or learn.

Beyond those, we disclose data only where the law requires it. Data is processed in the United States and the European Union depending on the provider.

How long we keep it

Your account, courses, and lessons are kept until you delete them. Delete account, on the profile page in the app, erases your account, your courses, and every lesson in them straight away, and cannot be undone. Subscription records are kept without your account attached, because they are the transaction history we and the payment processor — Apple or Dodo Payments — are both required to be able to reconcile. Request logs are short-lived operational records and are not used to build a profile of you.

Your choices

Delete account, on the profile page in the app, removes everything we hold about you without asking anyone. Write to tim@waitprofessor.com to get a copy of your data, correct it, or have it deleted for you instead. We answer from the address you signed up with, and aim to act within 30 days. Depending on where you live you may also have the right to object to processing or to complain to your local data protection authority.

Where you cancel depends on who sold it to you. A subscription bought in the app is managed by Apple — cancel or change it in Settings on your device. One bought on this website is managed by Dodo Payments, through the billing portal we link you to from the app. Either way, cancelling stops future generation but leaves the courses you already built visible.

Advertising and cookies

This website carries the Meta advertising pixel. It sets two first-party cookies, _fbp and _fbc, which identify your browser and the ad you arrived from. They are what lets us tell whether an ad we paid for led to a subscription, and stop showing ads to people who already subscribed.

When you subscribe on this website we also report that purchase to Meta from our server, not only from your browser, because browsers and ad blockers drop the browser half often enough to make the numbers meaningless. That report contains the amount charged, the two cookies above, and your email address and account identifier hashed — put through a one-way function on our server so Meta can match it against an account they already have without us handing over the address itself. It never contains anything you type, learn, or ask Mila to explain.

We do not serve the pixel to readers in the UK, the EEA or Switzerland, because there it would need your consent first and we would rather not ask than trade a worse page for a better number. Everywhere else you can turn it off in your Meta ad settings, or by blocking third-party scripts and cookies in your browser — nothing on this site stops working if you do.

The other cookies here are the ones the site cannot work without: your sign-in session from Supabase, and Dodo’s own during checkout. The answers you give in the two-question flow before checkout are held in your browser for that visit only, and travel with your purchase so we know which kind of learner bought.

Children

Wait, Professor is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has given us data, write to us and we will delete it.

Changes

If this policy changes in a way that affects what we collect or who we send it to, we will update the date at the top and note the change here before it takes effect.

Contact