StudyPrep AI / Legal

Privacy Policy

What we collect, who receives it, how long we keep it, and how to get it back or get rid of it.

Effective: August 11, 2026·Last updated: August 11, 2026

1. Introduction

StudyPrep AI ("we", "us", "our") operates the website studyprepai.app, the StudyPrep AI mobile apps, and the related services (the "Service"). This Privacy Policy explains what information we hold about you, who else can see it, how long we keep it, and what you can ask us to do with it.

We have written this in plain language on purpose. A policy you cannot read is not a disclosure. Where a section has to name something technical, such as a provider that processes your uploaded material, it names it specifically rather than hiding it behind a phrase like "our trusted partners". The specific names are the part that is worth anything to you.

By using StudyPrep AI you agree to the collection and use of information as described here. If you do not agree, please do not use the Service.

This policy applies to all users worldwide, with specific provisions for users in the European Economic Area and the United Kingdom (GDPR), Canada (PIPEDA and Quebec Law 25), and California (CCPA and CPRA).

Who is responsible. StudyPrep AI is the data controller for the information described here, and is operated from Quebec, Canada. For anything in this policy, write to support@studyprepai.app.

Person in charge of the protection of personal information. Quebec's Law 25 requires us to publish the title and contact details of the person who holds this role. At StudyPrep AI the role is held by the founder, who exercises the highest authority in the business, and who can be reached at support@studyprepai.app. Requests sent to that address about your personal information reach that person directly.

2. Information We Collect

Information you provide directly:

  • Account information: Your email address, and a password which is stored only as a hash, through Supabase Auth. If you sign in with Google or Apple, we receive the account identifier and email address that provider releases to us, and never your password.
  • Your age confirmation: A record that you confirmed you are sixteen or over, and when you confirmed it. See the age section below.
  • Documents you upload: Files such as PDF, DOCX, PPTX and TXT that you submit so we can generate study materials, and on the scanning path, the page images themselves.
  • What you write in the product: Notes, courses, decks, flashcard edits and study answers.
  • Billing information: Handled by our payment providers. We never see or store your full card number. On the web, Lemon Squeezy is the seller of record. In the mobile apps, Apple and Google are.
  • Communications: Messages you send through the contact form or by email, including anything you attach to them.

Information collected automatically:

  • Usage data: Pages visited, features used, session duration, and interactions with generated content such as flashcard grades.
  • Technical data: IP address, browser type, device type, operating system, and referring URL.
  • Rate limiting records: Your IP address and user agent, held so that abuse of the Service can be detected and traced.
  • Generation traces: A debugging copy of the text we sent to an AI model, which therefore contains part of your uploaded material. This is the most sensitive record we keep and it has the shortest life of anything derived from your documents.
  • Analytics: Product analytics through PostHog, and only after you have consented to analytics. Before you consent, PostHog is not loaded at all.
  • Error reports: Stack traces, URLs and breadcrumbs through Sentry, so that a crash can be fixed. These are currently anonymous: we do not attach your identity to them.
  • Consent and preferences: A first-party cookie named sp_consent recording your cookie choices, plus preference cookies for language, currency, theme and layout. The full list is in our Cookie Policy.

Information from the mobile apps:

  • Purchase receipts and subscription state, through RevenueCat, which links your app installation to your subscription.
  • Push notification tokens, through Expo, if you enable notifications.
  • Over-the-air update requests, through Expo, so the app can update without a store release.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide the Service: Processing your uploaded documents with AI models to generate study materials such as flashcards, multiple choice questions, glossaries, mind maps, summaries and audiobooks.
  • To manage your account: Authentication, billing, and subscription management.
  • To improve the Service: Analysing usage patterns to fix bugs, improve features, and develop new functionality.
  • To communicate with you: Sending transactional email such as account confirmation, password reset and billing receipts, and, where you have opted in, product updates.
  • To keep the Service safe: Detecting and preventing fraud, abuse and unauthorised access, including rate limiting.
  • To comply with legal obligations: Meeting our obligations under tax, accounting and data protection law.

What we do not do. We do not sell your personal information. We do not use your uploaded documents to train our own models, and we do not license them to anyone for that purpose.

Legal bases (GDPR): - Contract performance: Processing necessary to deliver the Service you signed up for. - Legitimate interests: Security monitoring, abuse prevention, and error reporting. - Legal obligation: Compliance with tax, accounting and data protection law. - Consent: Product analytics and marketing communications. You may withdraw consent at any time, and withdrawing it does not affect anything we did before you withdrew it.

4. Documents You Upload

This is the section that matters most, so it is the most specific one in this policy.

When you upload a document, the text we extract from it, and on the scanning path the page images, are transmitted to an AI provider so that your study materials can be generated. We choose which provider handles a request; you do not. The default today is Google Gemini. The Service is built to route to any of the following, and any of them may therefore receive your material:

  • Google, through the Gemini API.
  • OpenRouter.
  • Anthropic.
  • Alibaba Cloud, through DashScope on its international endpoint.
  • Moonshot AI.
  • Zhipu AI, through BigModel.

OpenRouter is an aggregator, and that means two sets of terms apply. OpenRouter does not run the model itself. It forwards your material to whichever underlying model serves the request, so OpenRouter's terms govern the routing and the terms of that underlying model provider govern the processing. A statement about "our AI provider's retention policy" that named only OpenRouter would be incomplete by construction, so we are not making one.

An operator-configured provider is possible. The Service supports an additional provider configured by us at runtime, restricted to a fully qualified HTTPS host on port 443. If we ever configure one, it becomes a recipient of your uploaded material and we will name it here before we route anything to it.

What this means for you in practice:

  • Do not upload documents containing sensitive personal data, confidential information, or material you do not have the right to share.
  • Each provider named above applies its own terms to what it does with the text while it holds it. We are documenting those terms provider by provider, and until that is complete this policy can tell you where your material goes but not what every provider does with it after that.
  • Generated study materials are stored in our database, associated with your account, and are yours to keep, export or delete.
  • You may delete your uploaded documents and generated content at any time. See Data Retention for exactly what happens when you do.

5. Where Your Material Is Processed

Most of the Service runs in the United States. Our database, file storage and authentication are hosted by Supabase in the East US region, and our website and API run on Vercel.

Our email is the exception, and it is in Canada. Anything you send to support@studyprepai.app or legal@studyprepai.app is delivered to a mailbox hosted by Zoho on their Canadian data centre, and it is stored there. That covers the message, your address and anything you attach. It is the only part of the Service held in Canada, and we mention it because we are operated from Quebec and it is worth knowing which part of your correspondence stays in the country.

Two of the AI providers listed above process outside the United States and the European Union, and you should know which:

  • Zhipu AI is reached at its BigModel endpoint, which is in mainland China.
  • Alibaba Cloud DashScope is reached at its international endpoint rather than its mainland China endpoint.

We have chosen to keep both available rather than quietly disable them, because disclosing a transfer is more honest than pretending the capability does not exist. Where we transfer personal data out of the European Economic Area or the United Kingdom to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses together with an assessment of the destination.

Being straightforward about the limit of that statement: the provider-by-provider terms review described in the previous section is not finished, and the transfer mechanism for each individual AI provider is part of it. If you are in the EEA or the UK and you would rather your material never reached a provider outside it, write to support@studyprepai.app before you upload, and we will tell you the current position rather than guess.

6. Audio and Text to Speech

There are two kinds of speech in this Service and they work differently. The difference decides whether your text leaves your device, so it is the first thing this section says.

Short text read aloud in the app stays on your device. When you press the speaker button on a flashcard or an exercise, the reading is done by your own device, using a voice already installed on it. That text is not sent anywhere. We check that the chosen voice is installed locally, and if no local voice is available for your language we tell you so and stay silent rather than use one that would transmit your text.

Audiobooks are generated by a speech provider, so that text does leave your device. The text to be spoken is derived from the document you uploaded. Two paths exist:

  • The free path uses Microsoft Edge TTS. It is reached without an API key, which means without an account, which means no contract and no data processing agreement covers it. Every other recipient in this policy is reached under terms somebody agreed to. This one is not, and we keep it because it is what allows audiobooks to be free and to keep working when a paid provider is unavailable. If that is not acceptable to you, do not generate audiobooks from material you would not want handled that way.
  • The paid path uses OpenRouter, which forwards the text to whichever speech model serves the request. Where an audiobook is given a synchronised highlight that follows the words as they are spoken, the generated audio is sent to a transcription model to recover the timing of each word. That is a second transmission of the same derived text.

If you supply your own key. The Service can also speak text through OpenAI, Google Cloud Text-to-Speech, ElevenLabs, Amazon Polly, Microsoft Azure Speech, Deepgram or Play.ht. Every one of those paths requires a key that you supply. When you use one, your text goes to that provider under your own account and your own agreement with them, not ours.

7. Cookies and Local Storage

We use a small number of first-party cookies and a set of browser local storage entries. No third party sets a cookie on our domain during ordinary use of the Service.

Necessary. Your signed-in session, through Supabase Auth, and the sp_consent cookie that records the choices you made in the consent banner. These cannot be switched off without breaking sign-in or losing your consent choice.

Preferences. Language, currency, theme, Concept and navigation layout. These are read on the server so the page renders in the appearance you chose instead of flashing a default first.

Analytics. PostHog, and only if you accept analytics. Note that on the web PostHog stores its state in local storage rather than in a cookie, which is why you will not find an analytics cookie in your browser even when analytics is on.

Your choices. The consent banner appears on first visit and you can reopen it at any time from the footer to change your mind. Most browsers also let you refuse or delete cookies directly, though deleting the necessary ones will sign you out.

Every cookie and storage key we write is listed by name, purpose and lifetime in our Cookie Policy at /legal/cookies.

8. Sharing Your Information

We do not sell, rent or trade your personal information. We share it only as set out below. The three groups are separated because the difference matters legally: a processor acts only on our instructions, while a controller decides things for itself.

Processors, acting on our instructions:

  • Supabase: Authentication, the application database, and storage of the files you upload. Region: East US. Supabase holds more of your data than anyone else on this list.
  • Vercel: Website and API hosting. Receives every HTTP request, including IP address, user agent and URL.
  • Google, OpenRouter, Anthropic, Alibaba Cloud, Moonshot AI and Zhipu AI: AI generation from your uploaded material, as described above.
  • Microsoft, Amazon, ElevenLabs, Deepgram, Play.ht and OpenAI: Text to speech, as described above. Microsoft belongs in this list twice and only one of them is a processor. Azure Speech is reached with a key you supply, under your agreement. Edge TTS, the free audiobook path, is reached with no key and no agreement at all, so calling it a processor acting on our instructions would overstate the relationship. There are no instructions and there is no contract. It is named here because it receives your text, which is the only thing this list is for.
  • OpenRouter: Text to speech as well as AI generation, and the aggregator point above applies here too: it forwards the text to whichever speech model serves the request. Where an audiobook is given a synchronised highlight, the audio we generated is sent back to a transcription model to recover the word timings, which is a second transmission of the same derived text.
  • RevenueCat: Mobile subscription state, app user identifier and purchase receipts.
  • Trigger.dev: Background job processing for generation, receiving job payloads and logs.
  • Resend: Transactional email, receiving the recipient address and, for a contact enquiry, the full text of your message.
  • Zoho: Our business mailbox, hosted on their Canadian data centre. Everything you write to support@studyprepai.app or legal@studyprepai.app is delivered there and stored there, including attachments, which for a data request or a complaint can be the most sensitive thing you ever send us.
  • Upstash: Rate limiting, receiving IP addresses and user identifiers as keys.
  • PostHog: Product analytics, after consent.
  • Sentry: Error reports. Currently anonymous.
  • Expo: Mobile over-the-air updates and push notification tokens.

Controllers for your transaction, deciding for themselves:

  • Lemon Squeezy is the merchant of record for purchases made on the web. They are the seller, not our payment processor, and they receive your name, email, billing address and payment details under their own privacy policy.
  • Apple is the seller for purchases made in the iOS app.
  • Google is the seller for purchases made in the Android app.

Other circumstances:

  • Legal requirements: We may disclose information where required by law, court order or a governmental authority, or where we believe disclosure is necessary to protect our rights or the safety of our users.
  • Business transfers: In a merger, acquisition or sale of assets your data may transfer to the successor. We will notify you by email before that happens.

Our processors are contractually bound to process your data only on our instructions and to maintain appropriate security measures. The one exception is named plainly in the Audio section above, and we are removing it.

9. Data Retention

Every period below is the period our systems actually enforce, taken from the retention policy the nightly cleanup job runs. Where a commitment has no automated mechanism behind it, this section says so rather than implying one exists.

Your library is never deleted on a timer.

Documents you upload, the pages and text inside them, your notes, courses, decks, audiobooks and every generated study material are kept until you delete them. There is no expiry. When you do delete something, it spends ten days in Recently Deleted where you can restore it, and is then permanently erased along with its stored files.

Your account.

Kept while your account exists. When you delete your account it is soft-deleted immediately, you are signed out, and the record and its files are permanently erased ten days later. Our outer commitment is that this completes within 30 days, and in practice it is ten.

Records with a fixed life:

  • Generation traces, the debugging copy that contains part of your uploaded text: 90 days, and deleted immediately with your account rather than waiting for that window.
  • Payment webhook records from our billing providers: 90 days.
  • Rate limiting records, holding IP address and user agent: 90 days.
  • In-app notifications: 180 days.
  • Contact enquiries, including anything you wrote to us: 2 years.
  • Administrative audit log: 2 years, with the exception below.

Records that are kept indefinitely, and why.

Audit entries recording an account deletion, an erasure, a subscription change, a billing event, a refund or a payment are kept indefinitely. This is deliberate and it is worth understanding before you ask us to delete your account: when we erase you, we write a record that we did so, and that record has no user identifier attached to it. It exists so that your erasure can be proved to have happened. Deleting it would destroy the only evidence that we honoured your request.

Records that are anonymised rather than deleted.

Your subscription records, usage records and quiz results are not deleted when your account is. The link to you is removed and the record is kept as a financial or statistical record with no user attached. We hold billing records for seven years to meet tax and accounting obligations. That is a commitment we are making rather than a countdown a job is running.

Analytics.

We commit to holding product analytics for no more than 24 months. This one is a setting in the PostHog console rather than something our code enforces, so we are describing an operational commitment, not a mechanism.

What we cannot promise.

Once your material has reached an AI, scanning or speech provider, that provider's own retention terms apply to their copy of it. Nothing in our systems can delete data held by someone else. This is the single most important limitation in this policy and it applies to every product of this kind, including the ones that do not tell you.

To request deletion of your account and everything associated with it, use the deletion option in your account settings, or write to support@studyprepai.app.

10. Data Security

We implement industry-standard security measures to protect your information:

  • All data transmitted between your browser and our servers is encrypted using TLS.
  • Passwords are never stored in plain text. They are hashed by Supabase Auth.
  • Database access is restricted by row level security policies, so a user can only read their own rows even if the application layer is bypassed.
  • Outbound network calls from the Service are restricted to an allowlist of known provider hosts, so a compromised component cannot quietly send your data somewhere new.
  • Administrative access requires a second factor, and administrative actions are logged.

No method of transmission or storage is completely secure. In the event of a data breach affecting your rights or freedoms, we will notify you and the relevant supervisory authorities as required by applicable law, within 72 hours where GDPR requires it.

To report a security vulnerability, write to support@studyprepai.app.

11. Your Rights

Depending on where you live you may have the following rights. Whatever your location, we will do our best to honour any of them that you ask for.

All users: - Access: Request a copy of the personal data we hold about you. - Correction: Request correction of inaccurate data. - Deletion: Request deletion of your data. - Portability: Request your data in a machine-readable format.

EEA and UK users (GDPR): - Restriction: Request that we restrict processing of your data. - Objection: Object to processing based on legitimate interests. - Withdraw consent: Where processing is based on consent, withdraw it at any time. - Complain: Lodge a complaint with your local supervisory authority, for example the CNIL in France or the ICO in the United Kingdom.

California users (CCPA and CPRA): - Know: Know what personal information we collect and how it is used. - Delete: Request deletion of your personal information. - Correct: Request correction of inaccurate personal information. - Opt out of sale or sharing: We do not sell or share personal information as those terms are defined in the CCPA. - Non-discrimination: We will not treat you differently for exercising your rights.

Canadian users (PIPEDA and Quebec Law 25): - Access and correction: Access and correct your personal information. - Withdrawal of consent: Withdraw consent to collection or use. - Portability (Quebec): Request transfer of your data to another organisation. - Automated decisions (Quebec): Be informed where a decision about you is based exclusively on automated processing. We do not currently make any such decision about you.

To exercise any of these rights, write to support@studyprepai.app. We will respond within 30 days, or 45 where the law permits an extension and we tell you why. There is no charge for a reasonable request.

12. International Data Transfers

StudyPrep AI is operated from Quebec, Canada, and most of the Service runs in the United States. Your data will therefore be transferred to and processed in countries other than your own.

When we transfer personal data from the EEA or the UK to a country without an adequacy decision, we rely on Standard Contractual Clauses approved by the European Commission, and on the UK Addendum where the transfer is from the United Kingdom.

The section above headed Where Your Material Is Processed names the two AI providers that process outside the United States and the European Union, and states plainly which part of the transfer assessment is still in progress.

By using the Service you acknowledge that your data may be transferred to and processed in these countries.

13. Age Requirement

StudyPrep AI is for people aged sixteen and over. When you create an account you confirm that you are sixteen or older, and we record that confirmation and its date with your account.

We chose sixteen rather than thirteen deliberately. Sixteen is the highest digital consent age any EU member state sets under GDPR Article 8, so a single worldwide rule clears every one of them, and it puts the Service entirely outside the scope of the United States Children's Online Privacy Protection Act. The alternative was a patchwork of parental consent rules that we would have implemented badly. We would rather turn away some legitimate younger students than pretend to a safeguard we had not built.

This is a confirmation, not a verification. We ask, we record the answer, and we do not check it against any document or third-party service.

If you believe someone under sixteen has created an account, write to support@studyprepai.app and we will close it and delete the associated information promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Where a change is material we will:

  • Send an email to your registered address at least 14 days before it takes effect, and
  • Post the updated policy on this page with a revised effective date.

The effective date at the top of this page is the date the version you are reading took effect. If you want to know what this policy said on a particular day, write to support@studyprepai.app and we will tell you.

Your continued use of the Service after the effective date of a revised policy constitutes acceptance of the change.

15. Contact Us

StudyPrep AI, operated from Quebec, Canada.

There are two addresses, and the difference is who is writing rather than what about:

  • support@studyprepai.app for anything you write to us yourself: your account, your data, a deletion request, a refund, a security concern, or a question about this policy.
  • legal@studyprepai.app for formal notices sent on behalf of an organisation: legal correspondence, copyright and takedown notices, and enquiries from regulators.

If you are unsure, use support@studyprepai.app. We will move it internally rather than send you elsewhere.

Both addresses are mailboxes hosted by Zoho on their Canadian data centre, so whatever you write to us is stored there as well as read by us.

You can also use the contact form at /contact, which sets the right subject and response window for you.

We aim to respond to privacy enquiries within 30 days, and usually much sooner.

EEA and UK users: you have the right to lodge a complaint with your national supervisory authority at any time, and you do not have to contact us first.