Legal

Privacy Policy

Last reviewed: 2026-06-12 · Operator: StudyDeck (a sole proprietorship operated by Shan, India)
Draft for launch review. This policy is a faithful description of how StudyDeck handles data today, but should be reviewed by a lawyer familiar with India's Digital Personal Data Protection Act 2023, EU/UK GDPR, and US COPPA before the first paid signup. Material changes will be announced via in-app banner with a 30-day window.

StudyDeck (“we”, “us”) is a study-card application built for teachers and the parents/students they support. We minimise the personal data we collect to what's needed to run the product. Since May 2026 the app is cloud-first: your study content is stored on our servers, tied to your account, so it follows you across devices.

1. Who this policy covers

2. What we collect

Account data (server-side)

Study content (stored on our servers)

Operational data

Marketing-site analytics (cookieless, first-party)

Our public marketing pages (home, compare, install) carry a small first-party beacon so we can see the site's reach. It sets no cookie and sends nothing to third parties. Per visit we store: the page path, the referrer hostname (never the full URL), campaign tags from the link you clicked (utm_*), whether a buy / open-app button was clicked, a coarse country code, coarse device / browser / OS buckets, and a visitor token that is a one-way hash of IP + browser + the UTC date + a server secret. The token rotates every day, so it can count “unique visitors today” but cannot follow a person across days. Your IP address and raw user-agent are used transiently to derive these values and are never stored. Search-engine and AI crawlers are detected and counted separately by their public crawler name. The logged-in app, the kid kiosk and the student surfaces carry no analytics at all.

What we do not collect

3. How we use what we collect

4. AI features and providers

AI generation runs in one of two modes, depending on your plan:

By design, every generation prompt instructs the model to use only the source material you pasted or uploaded — never outside knowledge.

Cross-customer caches (no personal data)

5. Cookies and similar storage

6. Children (under 13) — COPPA

StudyDeck is designed to be operated by a teacher or parent. Children under 13 must not create their own accounts.

7. Data retention

8. Your rights

Under India's DPDP Act 2023, EU/UK GDPR, California's CCPA and similar regimes, you have rights to:

9. International transfers

StudyDeck servers are hosted in India. If you're in the EU/UK, data transfers fall under Standard Contractual Clauses; we offer a Data Processing Agreement to organisations that need one. Customers should request the DPA before processing personal data of EU/UK data subjects.

10. Security

If you discover a vulnerability, please report it privately to hello@theconsultant.chat. We'll respond within 5 business days.

11. Changes to this policy

Material changes are announced via an in-app banner with a 30-day notice window before they take effect. Minor clarifications are reflected in the “Last reviewed” date at the top.

12. Contact

Privacy questions: hello@theconsultant.chat
Operator: StudyDeck (sole proprietorship), India.
Grievance officer (DPDP Act): same email; we'll route to a designated officer once one is appointed.