Privacy Policy

Last updated: September 2026

Contents

  • 1. Controller and contact
  • 2. Overview
  • 3. Hosting and storage locations
  • 4. Account and sign-in
  • 5. Study content
  • 6. AI features
  • 7. Microphone, lecture recording and dictation
  • 8. Payments
  • 9. Emails
  • 10. Referral and ambassador programme
  • 11. Cookies and browser storage
  • 12. Statistics and product analytics
  • 13. Error monitoring
  • 14. Protection against abuse and costs
  • 15. Support, contact and bug reports
  • 16. Recipients
  • 17. Transfers to third countries
  • 18. Retention
  • 19. Your rights
  • 20. Obligation to provide data, automated decisions
  • 21. Minors
  • 22. Community
  • 23. Changes to this policy

1. Controller and contact

This policy explains which personal data we process when you use StudityAI (website and app), for what purpose, on which legal basis, who receives it and which rights you have.

The controller is Studity Tech GmbH & Co. KG, Seebergweg 1, 83730 Fischbachau, Germany, registered at Amtsgericht München under HRA 123175. It is represented by its general partner Smart Capital Beteiligungs GmbH (HRB 237810), which in turn is represented by Joachim Blum.

For any data protection question, contact us at:

datenschutz@studity.ai

2. Overview

StudityAI is a study platform: you upload study material, and AI features turn it into summaries, flashcards, quizzes and answers.

Your account and study data are stored in a database in London (United Kingdom); some service providers are located in the EU or the USA (sections 16 and 17).

We use no advertising trackers and do not sell data.

Product analytics with PostHog only runs if you agree in the cookie banner.

Your content is not used to train AI models.

3. Hosting and storage locations

The database, sign-in and server functions are run by Supabase (Supabase Pte. Ltd., Singapore) on Amazon Web Services servers in London (United Kingdom). The European Commission has issued an adequacy decision for the United Kingdom; access by Supabase companies outside it is covered by EU standard contractual clauses.

Uploaded files (PDFs, images, recordings, podcast episodes) are kept in a non-public store at Cloudflare (Cloudflare, Inc., USA, R2 service). The location of this store is currently not restricted to the EU. Files can only be retrieved through short-lived signed links.

Vercel Inc. (USA) delivers the website and app through a global network. This produces technically necessary access data (IP address, browser, requested address, time). The legal basis is Art. 6(1)(f) GDPR (secure and stable delivery).

4. Account and sign-in

For an account we process your email address, password (only as a hash), name, optional details such as university, subject and profile picture, language setting and sign-in times. The legal basis is Art. 6(1)(b) GDPR (contract).

You can also sign in with Google or GitHub. We then receive your name, email address and profile picture from that provider, and the provider learns that you sign in to StudityAI. The provider is responsible for its own processing.

To protect against automated sign-ups we use Cloudflare Turnstile. Technical characteristics of your browser and your IP address are sent to Cloudflare (Art. 6(1)(f) GDPR).

StudityAI may be used from the age of 16 (section 21).

5. Study content

We store what you create in StudityAI: spaces, documents, notes, flashcards, mind maps, highlights, exams, quiz results and chats. This is our core service (Art. 6(1)(b) GDPR).

If your documents contain data about other people, we only process it so you can study with it (Art. 6(1)(f) GDPR). You are responsible for being allowed to upload that content.

If you share a file or a space by link, anyone with the link can see the content until you end the share.

Content you delete is removed from the database and from file storage.

6. AI features

For summaries, chat answers, flashcards, quizzes, exam grading, text recognition, semantic search and podcasts we send the content needed (document text, images, chat history) to the Gemini API of Google LLC (USA) on the paid tier. Your name and email address are not part of these requests.

Under its terms, Google does not use this data to train its models and keeps requests for up to 55 days to detect abuse. The transfer is based on the standard contractual clauses in Google’s data processing terms.

From your quiz and exam results we derive weak spots to suggest suitable reviews. This analysis only serves your learning and has no legal or similarly significant effect on you.

The legal basis is Art. 6(1)(b) GDPR. AI answers are marked as such and may contain mistakes.

7. Microphone, lecture recording and dictation

Voice recordings are personal data. Three features access your microphone: chat dictation, live session recording and voice notes. For the transcript all three use your browser's speech recognition only (Web Speech API): no voice audio is sent to the Google Gemini API, and Google is not a processor for voice data on our behalf. The one exception for storage: the finished recording of a live session is kept in our non-public storage so you can listen to it again (see below). The microphone is only activated after you explicitly grant browser permission, and only while a recording you started is running.

The main caveat: in Chrome and Edge the browser itself transmits the audio to Google speech servers; in Safari recognition happens on-device. That transfer is made by your browser, not by StudityAI, and is governed by your browser vendor's own privacy terms. Firefox and Brave do not offer the Web Speech API, so there no transcript is produced at all.

Chat dictation: we receive only the resulting text, which you then submit yourself, plus the recording duration in seconds. The duration is used solely to enforce your plan's daily dictation limit (no audio, no text).

Live session recording: the transcript is produced entirely in your browser. On our servers (Supabase, London/UK) we store the transcript, chunk timestamps, duration, title and, if you create one, the AI summary. When you end a recording, we upload the audio to non-public storage at Cloudflare (R2) so you can listen to it again later. It can only be played through signed links that are valid for 15 minutes and that only you receive after signing in. The recording is deleted when you delete the session, the space or your account. If you create a summary, flashcards, a quiz or a mind map from the lecture, or ask the chat about it, the transcript (not the audio) is sent to Google Gemini (paid tier); Google does not use this data for training and keeps it only temporarily (up to 55 days) for abuse detection. Before your first recording you confirm once that the lecturer agreed to it; we store this confirmation with its timestamp in your profile.

Voice notes: we store the title, transcript and your questions/answers for a voice note in your account (Supabase, London/UK) so they survive signing out and switching devices. The audio recording itself stays on your device only (your browser's IndexedDB). If you ask a question about a voice note, the transcript is sent to our AI service (Google Gemini, paid tier) to answer it. Google does not use this data for training and keeps it only temporarily (up to 55 days) for abuse detection.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract), since speech recognition is exactly the feature you requested. Retention: until you delete the voice note or session in the app, or delete your account. Deleting your account under Settings → Delete account removes session transcripts, stored session recordings, voice-note data and the second counters for the dictation and session quotas. Voice recordings and transcripts are never used to train AI models.

8. Payments

Paid plans are processed by Stripe Payments Europe, Ltd. (Ireland), part of the Stripe, Inc. group (USA). You enter payment details (e.g. card number) directly with Stripe; we do not receive them.

We store your Stripe customer ID, plan, term, amounts and invoices (Art. 6(1)(b) and (c) GDPR). Stripe also processes data as a controller in its own right, for example for fraud prevention and anti-money-laundering checks.

We keep invoices and accounting records for 8 years (§ 147 German Fiscal Code) and business letters for 6 years (§ 257 German Commercial Code).

9. Emails

We send you emails that belong to the contract: sign-up confirmation, password links, purchase, cancellation and withdrawal confirmations (Art. 6(1)(b) and (c) GDPR).

As a customer you occasionally receive information about similar StudityAI offers (§ 7(3) German Unfair Competition Act, Art. 6(1)(f) GDPR). You can object at any time via the unsubscribe link in every such email, in your email settings or by emailing us, at no cost other than transmission costs at basic rates.

Emails are sent by Resend, Inc. (USA) via Amazon Web Services. Resend is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition.

Our mailboxes (e.g. datenschutz@studity.ai) are run by Zoho Corporation B.V. (Netherlands) in data centres in the Netherlands and Ireland; access by group companies outside the EU is possible and covered by standard contractual clauses.

10. Referral and ambassador programme

If you take part in the referral programme, we store your referral code, which accounts signed up through it, your commissions and payouts and any proof you submit.

For payouts we store the account holder, IBAN and optionally BIC or your PayPal address, solely to trigger the payout.

The legal basis is Art. 6(1)(b) and (c) GDPR. We keep payout records for 8 years (§ 147 German Fiscal Code).

11. Cookies and browser storage

We store information in your browser (cookies, localStorage, IndexedDB) or read it from there. Strictly necessary entries need no consent (§ 25(2) no. 2 TDDDG); everything else only with your consent (§ 25(1) TDDDG).

  • Sign-in (Supabase session, localStorage): keeps you signed in until you sign out – necessary.
  • Consent (studity_cookie_consent, localStorage): stores your choice in the cookie banner until you change it – necessary.
  • Settings and offline data (localStorage, IndexedDB): language, theme, cached content, voice notes on your device – necessary; study content is removed from the browser when you sign out.
  • Cloudflare Turnstile: checks at sign-up and in forms that a human is acting – necessary.
  • PostHog (cookie and localStorage “ph_…”): product analytics, 1 year – only with consent (section 12).

12. Statistics and product analytics

Vercel Web Analytics and Speed Insights (Vercel Inc., USA) measure without cookies which pages are visited and how fast they load: page, referrer, country, operating system, browser and device type. Visitors are recognised by a hash that is discarded after 24 hours. We remove identifiers and parameters from the addresses first. The legal basis is Art. 6(1)(f) GDPR (improving reach and loading times); you can object (section 19).

We only use PostHog (PostHog Inc., USA; servers in Frankfurt am Main) if you click “Accept” in the cookie banner (Art. 6(1)(a) GDPR, § 25(1) TDDDG). A cookie and localStorage entries (1 year) are then set and usage data is sent: pages visited, clicks on buttons and links, events such as sign-up or purchase and, if you are signed in, your pseudonymous user ID. We only send server-side events (e.g. a purchase) if your consent is stored in your account. There is no screen recording. PostHog Inc. can access the data from the USA; standard contractual clauses apply. PostHog keeps the events for up to one year.

You can withdraw your consent at any time with effect for the future, via “Cookie settings” in the footer, in the app settings or here. We then delete the PostHog entries in your browser immediately; on our servers the withdrawal takes effect within 5 minutes.

13. Error monitoring

To detect and fix errors we use Sentry (Functional Software, Inc., USA) with storage in the EU region Frankfurt am Main. When an error occurs, the error message, technical trace, requested address, browser, operating system and app version are sent, and for signed-in users also the pseudonymous user ID. We do not send IP addresses or content; your use of the app is not recorded.

The legal basis is Art. 6(1)(f) GDPR (stable and secure operation). You can object (section 19). Sentry keeps error events for at most 90 days.

14. Protection against abuse and costs

To protect against attacks, automated requests and excessive use of the AI features, we count requests per IP address and per account. We delete the IP-based counters after 2 hours, blocks 30 days after they expire and block logs after 90 days.

At sign-up we check whether the domain of your email address can receive email and is not a disposable-mail provider. For this we only look up the domain part (e.g. “example.com”) through Google’s DNS service.

The legal basis is Art. 6(1)(f) GDPR (security, protection against abuse and costs).

15. Support, contact and bug reports

If you write to us through the contact form or by email, or report a bug in the app, we process your details (name, email address, message, optionally a screenshot) to handle your request (Art. 6(1)(b) or (f) GDPR).

We delete requests once they are resolved and no retention obligation applies.

16. Recipients

These service providers process data on our behalf (Art. 28 GDPR) or as controllers in their own right. We have concluded Art. 28 GDPR agreements with all processors.

  • Supabase Pte. Ltd. (Singapore), hosted at AWS in London: database, sign-in, server functions – processor; UK adequacy decision, standard contractual clauses.
  • Google LLC (USA): Gemini API for AI features – processor; standard contractual clauses.
  • Cloudflare, Inc. (USA): R2 file storage, DNS, Turnstile – processor; Data Privacy Framework and standard contractual clauses.
  • Vercel Inc. (USA): delivery of website and app, Web Analytics, Speed Insights – processor; standard contractual clauses.
  • PostHog Inc. (USA), servers in Frankfurt: product analytics, only with consent – processor; standard contractual clauses.
  • Functional Software, Inc. (Sentry, USA), EU region Frankfurt: error monitoring – processor; standard contractual clauses.
  • Stripe Payments Europe, Ltd. (Ireland): payments – processor and controller for its own obligations; Data Privacy Framework and standard contractual clauses for Stripe, Inc. (USA).
  • Resend, Inc. (USA): sending emails – processor; Data Privacy Framework and standard contractual clauses.
  • Zoho Corporation B.V. (Netherlands): mailboxes – processor; standard contractual clauses for access outside the EU.
  • GitHub, Inc. (USA): sign-in with GitHub (controller) and storage of encrypted backups (processor; GitHub cannot read the backups).
  • Google (sign-in with Google) – controller.
  • The maker of your browser (e.g. Google for Chrome, Apple for Safari): speech recognition in the browser when you use the microphone (section 7).
  • jsDelivr (Prospect One, Poland; delivered via Cloudflare and Fastly): loads two program libraries when you import Anki decks; your IP address and browser details are transmitted.

17. Transfers to third countries

For the United Kingdom, an adequacy decision of the European Commission applies (renewed in December 2025).

Transfers to the USA are based on the adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, and additionally on the EU standard contractual clauses (Art. 46(2)(c) GDPR). You can request a copy of the standard contractual clauses.

18. Retention

We keep account and study data as long as your account exists. If you delete your account (Settings → Delete account), we delete it immediately with all content and files. Data we are required to keep, such as invoices (8 years), is excepted.

Encrypted database backups are deleted after 30 days; until then, deleted data may still be contained in them.

Other periods: IP-based counters 2 hours, Vercel visitor hash 24 hours, Google logs of AI requests up to 55 days, Sentry error events at most 90 days, PostHog events up to 1 year, business letters 6 years, invoices and accounting records 8 years.

We delete waitlist entries when you unsubscribe or when we no longer need the waitlist after launch.

19. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20).

Withdrawal: you can withdraw consent at any time with effect for the future (Art. 7(3) GDPR), for PostHog via “Cookie settings”. This does not affect the lawfulness of processing before the withdrawal.

RIGHT TO OBJECT (Art. 21 GDPR): where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. You can object to the use of your data for direct marketing (section 9) at any time without giving reasons; we will then no longer use it for that purpose.

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany.

Send requests about your rights to:

datenschutz@studity.ai

20. Obligation to provide data, automated decisions

Without an email address and password (or sign-in via Google/GitHub) we cannot create an account; for a purchase we need the details Stripe asks for. All other details are optional.

There is no decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR).

21. Minors

StudityAI may be used from the age of 16. Adults can buy paid plans; at 16 or 17 only with parental consent.

22. Community

The community features are currently switched off; no community data is collected. If we switch them on, this section applies:

The community is optional. If you use it, we process the following additional data. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) for your profile, friendships and messages, Art. 6(1)(f) GDPR for block lists and abuse prevention, and Art. 6(1)(c) GDPR for reports we have to handle under the Digital Services Act.

Public profile: username, display name, profile picture, short bio, university, subject, join date, streak and the number of your followers and followed accounts. These details are visible to every signed-in user. You can set your profile to private in the settings; it is then no longer retrievable outside your own account. Your email address, your plan and your study content are never public.

Friendships and follows: we store who sent a friend request to whom, whether it was accepted, declined or withdrawn, the timestamp, and who follows whom. Your friend list is the precondition for direct messages being delivered at all.

Direct messages: we store the message text, the timestamp, the participants and the read status. Messages are encrypted in transit and at rest, but not end-to-end encrypted: technically we could read them. We only do so where a report or an official order requires it. Messages are not analysed for advertising and are not used to train AI models.

Block lists: we store whom you have blocked and when. Only you can see the list. The blocked person is not notified; for them, requests and messages are simply blocked in both directions.

Reports: when you report content or a profile, we store the reported item, the reason, your free text, your user ID and the timestamp. Reports are visible to our moderation, not to the reported person. If we take action, the person concerned receives a statement of reasons (Art. 17 DSA). It says what the decision is based on, not who reported it.

Posting study material to the community is currently switched off, on the server as well as in the client. No upload or download data is therefore created at present. If we open this later, we will extend this section beforehand.

Storage location: all community data sits in the same Supabase database in London, United Kingdom, as the rest of your data; section 5 of this policy applies. Inside the database the tables are protected by row level security: other people's messages, block lists and reports cannot be retrieved by other accounts.

Retention and deletion: you can remove individual items yourself at any time: end a friendship, unfollow, withdraw an open report, set your profile to private. If you delete your account under Settings → Delete account, your profile, the messages you sent, friendships, follows, block lists, notifications and your reports are deleted with it. Messages other people sent you belong to their account and stay there until that person deletes them or their account. Statutory retention obligations and ongoing proceedings remain unaffected.

23. Changes to this policy

We update this policy when our processing or the law changes. The version published here applies; its date is shown at the top.

Back to top
StudityAIStudityAI

Tools for students who want to achieve more.

Made in Europe
support@studity.ai

Product

  • Chat
  • Mind maps
  • Quizzes
  • Exam calendar
  • Prices
  • Study by subject
  • Comparisons

Company

  • About
  • Blog
  • Careers
  • Affiliate
  • Releases
  • Contact

Legal

  • Imprint
  • Privacy policy
  • Terms & Cancellation
  • Withdraw from contract
  • Cancel contracts here
  • Community guidelines

© 2026 Studity Tech GmbH & Co. KG · All rights reserved