Last updated: [insert date before publishing]
This policy explains what personal data Studly ("we," "us") collects when you use the app, why, and what rights you have over it. It applies to anyone who creates a Studly account or uses the Service without one.
| Data | Why we collect it |
|---|---|
| Name, avatar, country | To personalize your profile and tailor driving/civics questions to your country |
| Email address or phone number | To create and secure your account, and to let you log back in |
| Password | Stored only as a secure hash (via Supabase Auth) — we never see or store it in plain text |
| Study activity (answers, streak, hearts, topic accuracy, diagnostic test usage) | To run the app's core features — scoring, streaks, and the "struggling with a topic" suggestions |
| Messages you send the AI tutor | Sent to Anthropic's Claude API to generate a response; not used to train Anthropic's models by default under their API terms |
| Payment status (Premium active, Exam Pass + expiry, Stripe customer ID) | To know what you've paid for. We do not receive or store your card number — Stripe handles that entirely |
| Friends list and chat messages | Currently stored only in your browser's local storage on your device, not on our servers |
We use a small number of subprocessors to run Studly. We don't sell your data to anyone.
| Provider | What they receive | Purpose |
|---|---|---|
| Anthropic | The exam/topic you're studying, your tutor questions, your interface language | Generates practice questions, images, and tutor answers |
| Stripe | Your email/phone (for the payment record) and payment details | Processes Premium subscriptions and Exam Pass purchases |
| Supabase | Your account and profile data | Hosts our authentication system and database |
Anthropic, Stripe, and Supabase may process data on servers outside your country, including outside the EU/EEA. Where that happens, transfers rely on the safeguards those providers offer (such as Standard Contractual Clauses). [Confirm and name the specific mechanism each provider uses before publishing.]
We keep your account and study data for as long as your account is active. If you delete your account, we delete your profile and associated study data within a reasonable period, except where we're required to keep records (e.g. payment records for tax/accounting purposes) for longer under law.
If you're in the EU/EEA (or a jurisdiction with similar protections), you have the right to:
To exercise any of these, contact us using the details below. You can also delete your own account directly from the Profile tab at any time.
Studly doesn't use advertising or tracking cookies. It uses your browser's local storage to keep you logged in and to cache app data (like hearts and streak) for speed. This stays on your device and isn't used to track you across other sites.
Studly can be used by minors with a parent or guardian's permission, consistent with our Terms of Service, but purchases must be made by an adult. We don't knowingly collect more data from children than described above, and a parent/guardian can contact us to review or delete a child's account.
Passwords are hashed, not stored in plain text. Data is transmitted over HTTPS. Payment card data never touches our servers — it's handled directly by Stripe, which is PCI-DSS compliant. No system is perfectly secure, and we can't guarantee absolute security of information you transmit to us.
We may update this policy as the Service changes. If changes are material, we'll make a reasonable effort to let active users know (e.g. in-app or by email).
Questions about this policy, or a request to access or delete your data? Contact: privacy@your-domain.com [replace with your real address before publishing]