Rexa connected-experience privacy notice

Effective August 29, 2026. This notice supplements the King of the Curve Privacy Policy for the official Rexa ChatGPT connector.

Data used

After explicit OAuth consent, Rexa may read the connected learner's MCAT goal, target date, study preferences, aggregate category and subcategory performance, KOTC momentum totals, bookmark count, and minimized exam summaries. Published KOTC resources may also be searched and cited. Published educational Question of the Day (QOTD) resources may include their official answer keys.

Data excluded

The Rexa gateway never receives or stores your Firebase password; your browser sends it directly to Firebase Authentication. Rexa never returns learner-submitted answers or learner response history. Rexa also excludes payment methods, receipts, government identifiers, demographic fields, raw chat transcripts, private uploads, ad identifiers, email contents, and another learner's records.

Purpose and recipients

The gateway sends only requested minimized results to the connected ChatGPT experience so it can answer the learner's study question. King of the Curve operates the gateway and KOTC API; OpenAI processes tool results under the user's OpenAI terms and privacy settings.

Storage and retention

OAuth grant and token records contain a Firebase UID, granted scopes, revocation fingerprint, hashed opaque tokens, and expiration timestamps. Dynamic client registrations contain connector metadata but no learner identity. Recognized ChatGPT public-client registrations may persist so an existing connector remains usable; confidential, loopback, and unrecognized registrations expire within 30 days. For abuse prevention, rate-limit records retain only a one-way hash of the network source or connected learner key and a request count. The application stops using each counter within 25 hours; Firestore deletes it asynchronously after expiration, which may take approximately 24 additional hours. Firebase session and refresh tokens are not stored. Access tokens expire after one hour; refresh tokens rotate and expire after 30 days; authorization grants expire after 90 days. Operational logs omit raw tool queries, source documents, and tokens. Published resource caches are short-lived.

Control and deletion

Disconnect Rexa in ChatGPT to revoke the connected authorization family. You may also request deletion or support at support@kingofthecurve.org. A password reset, Firebase token revocation, account disablement, or account recreation forces Rexa to relink.