Privacy Policy
This policy explains what StudyAI collects from you, why it is collected, and which other companies process it on our behalf. It covers the StudyAI website and the study app you sign in to.
What StudyAI is
StudyAI is a study workspace. You upload your own course material as PDF files, and StudyAI answers your questions about it, writes summaries, and generates quizzes and flashcards from it.
Everything the product does is tied to a single student account. Your material is used to answer your questions, not anyone else's.
Information you give us
Account details: the email address and password you sign up with. Sign-in is handled by our authentication provider, Supabase, which stores your password as a hash. Your password is never kept in StudyAI's own tables.
Profile details: the display name you choose, your preferred interface language, and whether you have finished onboarding.
Study content: the courses you create, the PDF files you upload, the questions you send to the AI chat, and the summaries, quizzes and flashcards you generate.
Information created while you study
Processing a file produces extracted text, text chunks, and numeric embeddings of those chunks. They are stored against your account and the course you uploaded the file to.
Your quiz answers, flashcard ratings, scores, and the topic and chapter mastery figures calculated from them are stored so the app can show your progress and recommend what to study next.
We keep counters of metered actions — messages sent, quizzes generated, documents processed — to apply plan allowances and to stop abuse.
Server logs record requests and errors so the service can be operated and debugged.
How your uploaded files are stored
Uploaded PDFs go into a private storage bucket. They are not reachable from a public URL, and each file is stored under a path that begins with your account identifier, which is what the storage access rules match on.
When you open or download one of your own files, the server first checks that the file belongs to you, then issues a signed link that stops working after 60 seconds.
Database rows for courses, documents, chunks, chats, summaries, quizzes and flashcards are protected by row-level security policies, so a row is readable only by the account that owns it.
How AI processing works
To answer a question, StudyAI searches the chunks of your own material for the passages most relevant to it, then sends those excerpts together with your question to a third-party model provider, Anthropic, which produces the answer.
To make that search possible, chunk text is sent to an OpenAI-compatible embeddings endpoint, which returns the numeric vectors that are stored with your account.
Scanned or image-only PDFs may be transcribed by sending page images to a vision-capable model from the same generation provider.
Retrieval is scoped on the server to your account and to the course you are working in, so material belonging to another student is never placed in your prompt.
StudyAI does not build or train models of its own on your material. What each provider may do with the data sent to it is governed by that provider's own terms.
Companies that process data for us
Supabase — database, authentication and file storage.
Anthropic — the models that generate answers, summaries, quizzes, flashcards and page transcriptions.
An OpenAI-compatible embeddings provider — turns text chunks into the vectors used for search.
Inngest — runs document processing in the background.
Stripe — payments and subscription management.
These are international services, so your data may be processed on servers outside the country you are in.
Payments
Card details are collected by Stripe on pages Stripe itself hosts. StudyAI never receives or stores your card number.
What we store is the Stripe customer and subscription identifiers linked to your account, the plan, the subscription status, the trial end date and the current period end date. That is what the app reads to decide whether your subscription is active.
Cookies and local storage
StudyAI sets the session cookies its authentication provider needs to keep you signed in, and one cookie that remembers the interface language you chose. Your light or dark theme preference is kept in your browser's local storage, not on our servers.
StudyAI does not use advertising cookies and does not sell your data.
Analytics and error reports
StudyAI may send product-usage events and error reports to analytics and monitoring providers. Those payloads are assembled from a fixed allow-list of technical fields plus an opaque account identifier, and counts are grouped into ranges rather than sent exactly.
Document text, chunk content, chat messages, quiz answers, file titles, email addresses and display names are not on that allow-list and are not sent.
Deleting your material
Deleting a document removes the stored file from the private bucket and deletes its database rows, including the extracted text chunks and their embeddings.
Deleting a course permanently removes the course and the records linked to it: its documents, chunks, chat sessions and messages, summaries, quizzes and flashcards. The stored copies of the files themselves are removed when you delete the documents, so delete the documents first if you want their files removed at the same time.
There is no self-service account deletion in the app yet. To have your account and everything in it removed, write to the address at the bottom of this page and we will delete it.
Otherwise we keep your data for as long as your account exists.
Security
StudyAI is served over HTTPS. Uploaded files sit in a private bucket, database access is restricted per account by row-level security, and API keys and other secrets stay on the server and are never sent to the browser.
No online service can promise perfect security. If you think someone else has reached your account, change your password and contact us.
Your choices
You can change your display name and interface language in Settings, delete individual documents and courses whenever you want, and cancel your subscription from the billing portal.
You can also ask us for a copy of the data held about your account, or ask us to correct or delete it, using the contact address below.
Changes to this policy
If this policy changes, the updated version is published on this page and the date at the top changes with it.
Contact
For anything about this document, write to us at: