Legal

Privacy Policy

Last reviewed: 2026-06-12 · Operator: StudyDeck (a sole proprietorship operated by Shan, India)
Draft for launch review. This policy is a faithful description of how StudyDeck handles data today, but should be reviewed by a lawyer familiar with India's Digital Personal Data Protection Act 2023, EU/UK GDPR, and US COPPA before the first paid signup. Material changes will be announced via in-app banner with a 30-day window.

StudyDeck (“we”, “us”) is a study-card application built for teachers and the parents/students they support. We minimise the personal data we collect to what's needed to run the product. Since May 2026 the app is cloud-first: your study content is stored on our servers, tied to your account, so it follows you across devices.

1. Who this policy covers

2. What we collect

Account data (server-side)

Study content (stored on our servers)

Operational data

Marketing-site analytics (cookieless, first-party)

Our public marketing pages (home, compare, install) carry a small first-party beacon so we can see the site's reach. It sets no cookie and sends nothing to third parties. Per visit we store: the page path, the referrer hostname (never the full URL), campaign tags from the link you clicked (utm_*), whether a buy / open-app button was clicked, a coarse country code, coarse device / browser / OS buckets, and a visitor token that is a one-way hash of IP + browser + the UTC date + a server secret. The token rotates every day, so it can count “unique visitors today” but cannot follow a person across days. Your IP address and raw user-agent are used transiently to derive these values and are never stored. Search-engine and AI crawlers are detected and counted separately by their public crawler name. The logged-in app, the kid kiosk and the student surfaces carry no analytics at all.

What we do not collect

3. How we use what we collect

4. AI features and providers

AI generation runs in one of two modes, depending on your plan:

By design, generation prompts instruct the model to use only the source material you pasted or uploaded. There are three narrow, deliberate exceptions, and they widen what the model may draw on to explain your material — never what it may talk about, and never the facts themselves:

Cross-customer caches (no personal data)

4a. Learning records, questions to the tutor, and voice

These features are off unless an operator has turned them on for your account, and each is a separate switch. They are described here because when they are on they involve more than “content you create”, and that deserves saying plainly rather than being folded into a general clause.

The answer log

When the learning-progress features are on, we record each answer a learner gives on a quiz, worksheet or flashcard: whether it was right, wrong, skipped or left unmarked, which question it was, which chapter, roughly how long it took, and — where the material carries one — which concept and which kind of thinking it tested. Over time this builds a picture of what a learner finds hard.

The learner is identified by the id you gave them inside your own account (“Student 2”, or whatever you called them). We do not collect a name, an email, an age or a device identifier for them, and the record is not linked to anything outside your account. It lives with the rest of your study content and is exported, retained and deleted with it (§7, §8).

Questions a learner asks the tutor

When the tutor is on, the learner's typed question is sent from our server to an AI provider along with the chapter material it is allowed to answer from, the recent back-and-forth so it can follow on, and a short summary of which ideas that learner has been getting wrong. As with every other managed AI request, the prompt and the response are logged on our server for support, abuse review and quality debugging (§2, §4). No name, email or age is sent.

The conversation itself is not stored as a transcript. It exists in the browser tab for the length of the session and is gone when the session ends — there is no conversation history surface, for the learner, for the account owner, or for us. What remains is the ordinary usage record: that a question was asked, when, and what it cost in credits. Not what was asked.

The tutor answers only about the chapter in front of the learner and declines anything else. It may illustrate using commonly-known examples, and may show a photograph fetched from Wikipedia, labelled as not being from the learner's own material.

Voice

Where the separate voice option is on, a learner can speak their question instead of typing it. The recording is held in memory, sent to the same managed transcription provider our other audio features use, and discarded. It is never written to our object storage, never stored as a file, and never kept as a row. What a learner said is not billing data: the usage record notes the size and format of the clip, never the words. The transcript appears in the text box for the learner to read and send themselves — nothing is asked on their behalf.

A recording of a child speaking is a different category of thing from text they typed, which is why it is a separate switch and named separately here.

5. Cookies and similar storage

6. Children (under 13) — COPPA

StudyDeck is designed to be operated by a teacher or parent. Children under 13 must not create their own accounts.

7. Data retention

8. Your rights

Under India's DPDP Act 2023, EU/UK GDPR, California's CCPA and similar regimes, you have rights to:

9. International transfers

StudyDeck servers are hosted in India. If you're in the EU/UK, data transfers fall under Standard Contractual Clauses; we offer a Data Processing Agreement to organisations that need one. Customers should request the DPA before processing personal data of EU/UK data subjects.

10. Security

If you discover a vulnerability, please report it privately to hello@theconsultant.chat. We'll respond within 5 business days.

11. Changes to this policy

Material changes are announced via an in-app banner with a 30-day notice window before they take effect. Minor clarifications are reflected in the “Last reviewed” date at the top.

12. Contact

Privacy questions: hello@theconsultant.chat
Operator: StudyDeck (sole proprietorship), India.
Grievance officer (DPDP Act): same email; we'll route to a designated officer once one is appointed.