Privacy Policy

Last updated: July 16, 2026

This policy explains what personal data AI Study Assistant (“we”, “the Service”) collects, why, and who it is shared with. We collect only what is needed to run the Service and never sell your data.

1. Who is responsible

The operator of AI Study Assistant is the data controller. For any privacy request, contact studyassistant.privacy@gmail.com.

2. What we collect

  • Account data — email, optional display name, and a hashed password (or your Google account identifier if you sign in with Google). Managed by our authentication provider, Supabase.
  • Your study material — the documents, notes, text, images, and links (e.g. YouTube URLs) you upload, plus the parsed content and AI-generated artifacts we derive from them (summaries, quizzes, concept graphs, tags).
  • Usage & progress data — quiz scores, the answers you write, and study progress, stored in our own database to power your analytics dashboard. This is first-party only; we run no third-party analytics or advertising trackers.
  • Feedback reports — if you send a bug report or idea through the in-app widget, we store your message along with the page you sent it from and your browser’s user-agent string, so we can reproduce the problem.
  • Server logs — our hosting provider records standard request logs, which include your IP address. Our own application logs record identifiers such as your user ID, along with the titles, filenames and tags of material you upload. The contents of your documents are never written to logs.
  • Essential cookies — see section 5.

3. Why we can process it (legal basis)

We process your account data and study material to perform our contract with you — i.e. to provide the Service you signed up for (Art. 6(1)(b) GDPR). Feedback reports and server logs are processed under our legitimate interest in keeping the Service secure and working (Art. 6(1)(f) GDPR). If we ever want to use your data for anything beyond running the Service — such as training our own models or marketing — we will ask for your separate, explicit consent first.

4. Who we share it with (sub-processors)

To provide the Service we send data to the following processors. They act on our instructions and may store data in the United States, transferred under appropriate safeguards (e.g. Standard Contractual Clauses).

  • Vercel — hosting. Serves the application and processes every request, including your IP address and user-agent, in its infrastructure logs.
  • Supabase — database, file storage, and authentication (hosts your account and material, and sends account emails such as password resets). Supabase also records sign-in IP addresses in its own audit log.
  • Groq — receives your material content to answer your questions about it and to generate study artifacts, and receives images you upload in order to extract text from them.
  • Google (Gemini API) — receives your material content when you generate a quiz from it.

Content sent to these AI providers is used to return a result to you and is subject to their respective terms; we do not authorize them to train on your content.

When you add material by link, our servers fetch that URL — or, for a YouTube link, its transcript — from the internet on your behalf. The request comes from us, not from your browser, and carries no identifier of you. Be aware that the site at the other end will see a request from our servers.

5. Cookies

We use only strictly necessary cookies to keep you signed in (sb-access-token and sb-refresh-token). These are required for the Service to function and are exempt from consent requirements, so we do not show a cookie banner. We also store your theme preference locally in your browser. We set no analytics, marketing, or tracking cookies.

6. How we protect it

Traffic to the Service is encrypted in transit with TLS, and your data is encrypted at rest by our infrastructure providers. Uploaded files live in a private storage bucket, partitioned per user, that is not reachable by public URL. Session cookies are httpOnly, so they cannot be read by scripts in your browser. Access to your material is scoped to your account, and only the operator can read incoming feedback reports.

No service can promise perfect security, but we aim to hold only what the Service needs in order to work.

7. How long we keep it

We retain your account and material for as long as your account is active. When you delete a material, we remove the original file you uploaded, its parsed text, and everything derived from it — quizzes, questions, your answers, concept-graph links, and progress snapshots. This is immediate and cannot be undone.

Until you delete it, material is kept indefinitely: we hold both the original file and the text extracted from it. To close your account entirely, email us (see section 8) and we will delete it together with all associated data. Backups and provider logs are purged on their normal cycles.

8. Your rights

Under the GDPR and similar laws you can request access to, correction of, export of, or deletion of your personal data, and object to or restrict its processing. To exercise any of these, email studyassistant.privacy@gmail.com. You also have the right to lodge a complaint with your local data protection authority.

9. Age requirement

The Service is not intended for children. You must be at least 16 years old to create an account, or the minimum age at which you can consent to online services in your country, if that is higher. We do not knowingly collect data from children below that age; if you believe a child has given us their data, email studyassistant.privacy@gmail.com and we will delete it.

10. Changes to this policy

We may update this policy as the Service evolves. Material changes will be reflected by the “Last updated” date above.