Privacy
Plain English, no legalese. Questions: [email protected].
What we store
Your account (email, name, password hash), your study profile (level, goal, subjects), your conversations with the teachers, and the study material they help you create — plans, flashcards, notes, and imported sources. Teachers also remember durable facts you tell them; you can see and delete every one of these in Settings.
Google account information
Google sign-in gives us your Google account identifier, email address, name, and profile image so we can create or identify your student.study account. If you separately choose Connect Google in Settings, Google also gives us OAuth access and refresh tokens for the Calendar and Drive features described below.
Google Calendar
The Calendar permission allows student.study to view and edit events on Google calendars you own. We use it only to create the study sessions and study-plan events you explicitly request in your primary calendar, with their titles, descriptions, dates, times, and reminders. The app does not list, read, display, or analyse your existing calendar events.
Google Drive and Docs
The Drive permission lets student.study create Google Docs you explicitly request and manage files created by, or deliberately shared with, this app. We send Google the requested document title and content. We do not browse, read, or search unrelated files already in your Drive.
Google data storage and deletion
OAuth access, refresh, and identity tokens are encrypted at rest with authenticated encryption. We also store the granted scopes, token expiry, Google account identifier, and identifiers or links returned for requested events and documents. We keep this information while your Google connection is active. Disconnecting Google in Settings revokes the authorization and deletes the stored tokens. Events and documents already created in your Google account remain there until you delete them.
Google API Limited Use
student.study's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models.
What we never do
We don't sell your data, we don't show ads, and we don't lock your notes away if you cancel. Payments are handled by Stripe; we never see your card number.
AI processing
Your messages are sent to an AI model provider to generate teacher responses. We send only what's needed for the conversation: your message, relevant study context, and the memories you've allowed. Our providers don't train their models on your conversations.
Cookies
We use one essential cookie to keep you signed in. No tracking cookies, no third-party analytics pixels, no cookie banner theatre.
How long we keep it
As long as you have an account. Delete your account in Settings and everything goes with it — conversations, notes, memories, tokens. Stripe keeps invoice records as long as tax law requires; that part isn't up to us.
Your rights
Under UK GDPR you can ask for a copy of your data, ask us to correct it, or ask us to delete it. Most of this you can do yourself in Settings; for anything else, email [email protected] and we'll sort it within 30 days. If you're unhappy with how we handle it, you can complain to the ICO.
Changes
If this policy changes in a way that matters, we'll tell you by email before it takes effect — not bury it in a changelog.
Last updated: 12 July 2026