← Back to Studly
Studly

Privacy Policy

Last updated: [insert date before publishing]

Before you publish: this is a template built around what Studly's code actually does — it isn't legal advice. A lawyer or DPO should confirm the legal-basis wording, the subprocessor list, and international-transfer language against your real company details, and you should have signed Data Processing Agreements with Anthropic, Stripe, and Supabase before relying on this.

1. Who this policy covers

This policy explains what personal data Studly ("we," "us") collects when you use the app, why, and what rights you have over it. It applies to anyone who creates a Studly account or uses the Service without one.

2. What we collect

DataWhy we collect it
Name, avatar, countryTo personalize your profile and tailor driving/civics questions to your country
Email address or phone numberTo create and secure your account, and to let you log back in
PasswordStored only as a secure hash (via Supabase Auth) — we never see or store it in plain text
Study activity (answers, streak, hearts, topic accuracy, diagnostic test usage)To run the app's core features — scoring, streaks, and the "struggling with a topic" suggestions
Messages you send the AI tutorSent to Anthropic's Claude API to generate a response; not used to train Anthropic's models by default under their API terms
Payment status (Premium active, Exam Pass + expiry, Stripe customer ID)To know what you've paid for. We do not receive or store your card number — Stripe handles that entirely
Friends list and chat messagesCurrently stored only in your browser's local storage on your device, not on our servers

3. Legal basis for processing (GDPR)

4. Who we share data with

We use a small number of subprocessors to run Studly. We don't sell your data to anyone.

ProviderWhat they receivePurpose
AnthropicThe exam/topic you're studying, your tutor questions, your interface languageGenerates practice questions, images, and tutor answers
StripeYour email/phone (for the payment record) and payment detailsProcesses Premium subscriptions and Exam Pass purchases
SupabaseYour account and profile dataHosts our authentication system and database

5. International data transfers

Anthropic, Stripe, and Supabase may process data on servers outside your country, including outside the EU/EEA. Where that happens, transfers rely on the safeguards those providers offer (such as Standard Contractual Clauses). [Confirm and name the specific mechanism each provider uses before publishing.]

6. How long we keep your data

We keep your account and study data for as long as your account is active. If you delete your account, we delete your profile and associated study data within a reasonable period, except where we're required to keep records (e.g. payment records for tax/accounting purposes) for longer under law.

7. Your rights

If you're in the EU/EEA (or a jurisdiction with similar protections), you have the right to:

To exercise any of these, contact us using the details below. You can also delete your own account directly from the Profile tab at any time.

8. Cookies and local storage

Studly doesn't use advertising or tracking cookies. It uses your browser's local storage to keep you logged in and to cache app data (like hearts and streak) for speed. This stays on your device and isn't used to track you across other sites.

9. Children's privacy

Studly can be used by minors with a parent or guardian's permission, consistent with our Terms of Service, but purchases must be made by an adult. We don't knowingly collect more data from children than described above, and a parent/guardian can contact us to review or delete a child's account.

10. Security

Passwords are hashed, not stored in plain text. Data is transmitted over HTTPS. Payment card data never touches our servers — it's handled directly by Stripe, which is PCI-DSS compliant. No system is perfectly secure, and we can't guarantee absolute security of information you transmit to us.

11. Changes to this policy

We may update this policy as the Service changes. If changes are material, we'll make a reasonable effort to let active users know (e.g. in-app or by email).

12. Contact

Questions about this policy, or a request to access or delete your data? Contact: privacy@your-domain.com [replace with your real address before publishing]