← back to home
privacy policy
last updated: july 11, 2026
studyall is built by a student, for students. we don't sell your data, we don't run ads, and we keep things
simple. this policy explains exactly what data we collect and how we use it.
1. data accessed
studyall accesses the following types of data:
google or discord account data (if you use that sign-in method):
- email address — used to create and identify your account
- display name — used to personalize your experience
- provider profile picture — optionally copied into private studyall storage and displayed
in your account interface
we do not access your google drive, google calendar, google contacts, gmail, or any other google services. we
only access the basic profile information provided during sign-in. for discord, we request the identify and
email scopes only.
data you provide directly:
| data type |
purpose |
| email address |
account creation and login |
| name |
personalization |
| country |
understanding our user base |
| exam board selection |
showing relevant study content |
| study progress |
tracking completed topics and notes |
| ai chat messages |
providing ai study assistance |
| profile picture (optional) |
displaying a private account avatar; uploads are resized and metadata is removed |
automatically collected data:
- ip address — for security and abuse prevention
- device and session information — browser user-agent, a pseudonymous ip-derived value,
session creation/expiry, security-challenge outcomes, and security events used to protect accounts and
prevent abuse
- local app data — theme, notification settings, cached study progress, and other app
state may be stored locally on your device
2. data usage
we use your data exclusively to provide and improve the studyall service:
- authentication — your email and google account data are used to log you in and identify
your account
- personalization — your name is displayed in the app, and your exam board selection
determines which study content you see
- progress tracking — your syllabus completion and notes reading progress are stored so
you can track your studies across sessions
- ai assistance — the messages and study context you submit are sent through our backend
to our configured ai inference provider; if you enable web search, search queries are also sent to our
search provider
- security — your ip address helps us detect and prevent abuse
we do not:
- use your data for advertising or marketing
- use your data to train ai models
- profile you for any purpose other than providing the study service
- use google user data for any purpose other than providing the studyall application
3. data sharing
we do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
third-party services we use:
- firebase / google cloud — verifies credentials and stores account and study data.
browser code does not directly read or write firestore. see the firebase privacy
information.
- vercel — hosts the studyall backend and processes api requests.
- upstash — stores short-lived verification, oauth, and rate-limit records.
- resend — delivers verification and password-reset messages.
- cloudflare — serves site/content infrastructure, runs Turnstile browser security
challenges for sign-in and account-recovery forms, and stores private profile pictures and temporary
account exports when those features are enabled. see Cloudflare's privacy
information.
- ai and search providers — the chat content and optional search query you choose to send
are processed by the configured providers to return a response. we do not intentionally include your
account email or display name in those requests.
we may share data if:
- required by law or legal process
- necessary to protect the rights, safety, or property of studyall or its users
4. data storage & protection
your data is stored securely using industry-standard practices:
- encryption in transit — all data transmitted between your device and our servers uses
https encryption
- secure authentication — firebase verifies supported credentials, while our backend controls
account admission, revocable application sessions, and authorization
- database security — browser firestore access is denied; our backend derives the account
data path from a validated, revocable session
- private media — profile pictures and exports are kept in non-public object storage and
accessed through short-lived links
local storage: studyall uses browser storage for cached app state and preferences. signing
out clears account-scoped cached data from that browser.
data location: our service providers may process data in more than one region under their
applicable terms and data-processing commitments.
5. data retention & deletion
how long we keep your data:
- your account data and study progress are retained as long as your account is active
- a newly created account that does not complete onboarding is automatically scheduled for deletion after
30 days; established accounts carried through a migration are not given a new abandonment deadline
- login sessions expire after 7 days, or after 90 days when you explicitly choose “remember me”
- email verification and reset codes expire after 10 minutes; the resulting one-time ticket expires after
one hour
- before delivery, a verification or reset message is held in a short-lived encrypted delivery record;
completed/suppressed records are deleted and interrupted records expire after about 9 minutes
- downloadable account exports expire after 24 hours
- switching from an uploaded profile picture to initials or a provider picture retains that upload so you
can use it again; it remains visible as a deletable stored upload and is removed when you choose
“delete uploaded picture” or delete your account
- a provider picture copied into private studyall storage may also be retained when you switch sources; the
stored provider copy remains separately deletable and is removed when you delete it or your account
- we do not retain data longer than necessary to provide the service
your right to delete:
you can export or permanently delete your account from account settings after confirming your identity. the
deletion flow immediately revokes access and begins removing associated data. failed cleanup steps are
retried automatically.
- open account settings, choose “delete account,” authenticate again, and enter the requested confirmation
- if you cannot access your account, contact privacy@studyall.io
upon account deletion, all your personal data, study progress, and ai chat history will be permanently
removed from our systems.
6. your rights
you have the right to:
- access and portability — download a copy of your account data from account settings
- correct — update your profile information in the app settings
- delete — request deletion of your account and data (see section 5)
- withdraw consent — stop using the service at any time
to exercise these rights, contact us at privacy@studyall.io.
7. cookies
studyall does not use cookies for advertising. we set strictly necessary, secure cookies for your login
session and oauth sign-in state, and use an additional request-verification header for state-changing api
calls. the session cookie is httponly, so browser scripts cannot read it. choosing “remember me” extends its
expiry to 90 days.
8. children's privacy
studyall is intended for people aged 13 and older. we do not currently collect date of birth or operate a
verified parental-consent workflow. if you believe a child under 13 has created an account or provided
personal information, contact us so we can investigate and delete it.
9. changes to this policy
we may update this privacy policy from time to time. if we make significant changes, we will notify you
through the app. continued use after changes means you accept the updated policy.
10. contact
questions or concerns about this privacy policy? contact us:
email: privacy@studyall.io
see also: terms of service