← back to home

privacy policy

last updated: july 11, 2026

studyall is built by a student, for students. we don't sell your data, we don't run ads, and we keep things simple. this policy explains exactly what data we collect and how we use it.

1. data accessed

studyall accesses the following types of data:

google or discord account data (if you use that sign-in method):

  • email address — used to create and identify your account
  • display name — used to personalize your experience
  • provider profile picture — optionally copied into private studyall storage and displayed in your account interface

we do not access your google drive, google calendar, google contacts, gmail, or any other google services. we only access the basic profile information provided during sign-in. for discord, we request the identify and email scopes only.

data you provide directly:

data type purpose
email address account creation and login
name personalization
country understanding our user base
exam board selection showing relevant study content
study progress tracking completed topics and notes
ai chat messages providing ai study assistance
profile picture (optional) displaying a private account avatar; uploads are resized and metadata is removed

automatically collected data:

  • ip address — for security and abuse prevention
  • device and session information — browser user-agent, a pseudonymous ip-derived value, session creation/expiry, security-challenge outcomes, and security events used to protect accounts and prevent abuse
  • local app data — theme, notification settings, cached study progress, and other app state may be stored locally on your device

2. data usage

we use your data exclusively to provide and improve the studyall service:

  • authentication — your email and google account data are used to log you in and identify your account
  • personalization — your name is displayed in the app, and your exam board selection determines which study content you see
  • progress tracking — your syllabus completion and notes reading progress are stored so you can track your studies across sessions
  • ai assistance — the messages and study context you submit are sent through our backend to our configured ai inference provider; if you enable web search, search queries are also sent to our search provider
  • security — your ip address helps us detect and prevent abuse

we do not:

  • use your data for advertising or marketing
  • use your data to train ai models
  • profile you for any purpose other than providing the study service
  • use google user data for any purpose other than providing the studyall application

3. data sharing

we do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.

third-party services we use:

  • firebase / google cloud — verifies credentials and stores account and study data. browser code does not directly read or write firestore. see the firebase privacy information.
  • vercel — hosts the studyall backend and processes api requests.
  • upstash — stores short-lived verification, oauth, and rate-limit records.
  • resend — delivers verification and password-reset messages.
  • cloudflare — serves site/content infrastructure, runs Turnstile browser security challenges for sign-in and account-recovery forms, and stores private profile pictures and temporary account exports when those features are enabled. see Cloudflare's privacy information.
  • ai and search providers — the chat content and optional search query you choose to send are processed by the configured providers to return a response. we do not intentionally include your account email or display name in those requests.

we may share data if:

  • required by law or legal process
  • necessary to protect the rights, safety, or property of studyall or its users

4. data storage & protection

your data is stored securely using industry-standard practices:

  • encryption in transit — all data transmitted between your device and our servers uses https encryption
  • secure authentication — firebase verifies supported credentials, while our backend controls account admission, revocable application sessions, and authorization
  • database security — browser firestore access is denied; our backend derives the account data path from a validated, revocable session
  • private media — profile pictures and exports are kept in non-public object storage and accessed through short-lived links

local storage: studyall uses browser storage for cached app state and preferences. signing out clears account-scoped cached data from that browser.

data location: our service providers may process data in more than one region under their applicable terms and data-processing commitments.

5. data retention & deletion

how long we keep your data:

  • your account data and study progress are retained as long as your account is active
  • a newly created account that does not complete onboarding is automatically scheduled for deletion after 30 days; established accounts carried through a migration are not given a new abandonment deadline
  • login sessions expire after 7 days, or after 90 days when you explicitly choose “remember me”
  • email verification and reset codes expire after 10 minutes; the resulting one-time ticket expires after one hour
  • before delivery, a verification or reset message is held in a short-lived encrypted delivery record; completed/suppressed records are deleted and interrupted records expire after about 9 minutes
  • downloadable account exports expire after 24 hours
  • switching from an uploaded profile picture to initials or a provider picture retains that upload so you can use it again; it remains visible as a deletable stored upload and is removed when you choose “delete uploaded picture” or delete your account
  • a provider picture copied into private studyall storage may also be retained when you switch sources; the stored provider copy remains separately deletable and is removed when you delete it or your account
  • we do not retain data longer than necessary to provide the service

your right to delete:

you can export or permanently delete your account from account settings after confirming your identity. the deletion flow immediately revokes access and begins removing associated data. failed cleanup steps are retried automatically.

  • open account settings, choose “delete account,” authenticate again, and enter the requested confirmation
  • if you cannot access your account, contact privacy@studyall.io

upon account deletion, all your personal data, study progress, and ai chat history will be permanently removed from our systems.

6. your rights

you have the right to:

  • access and portability — download a copy of your account data from account settings
  • correct — update your profile information in the app settings
  • delete — request deletion of your account and data (see section 5)
  • withdraw consent — stop using the service at any time

to exercise these rights, contact us at privacy@studyall.io.

7. cookies

studyall does not use cookies for advertising. we set strictly necessary, secure cookies for your login session and oauth sign-in state, and use an additional request-verification header for state-changing api calls. the session cookie is httponly, so browser scripts cannot read it. choosing “remember me” extends its expiry to 90 days.

8. children's privacy

studyall is intended for people aged 13 and older. we do not currently collect date of birth or operate a verified parental-consent workflow. if you believe a child under 13 has created an account or provided personal information, contact us so we can investigate and delete it.

9. changes to this policy

we may update this privacy policy from time to time. if we make significant changes, we will notify you through the app. continued use after changes means you accept the updated policy.

10. contact

questions or concerns about this privacy policy? contact us:

email: privacy@studyall.io

see also: terms of service