AI Study Mate

Privacy Policy

Last updated: 2026-07-04

AI Study Mate ("we", "us") provides an AI-assisted study platform, including note-taking, classroom capture, a knowledge base built from your course materials, and AI tutoring/solving features. This policy explains what we collect, why, and the choices you have. It applies to anyone who creates an account or otherwise uses the service, wherever in the world you are.

1. What we collect

Depending on which features you use, we collect:

  • Account data — email address, display name, password hash (or OAuth identity if you sign in with Google/GitHub/Microsoft), and preferences you set (language, theme, AI persona).
  • Content you provide — uploaded documents, photos of whiteboards/notes, classroom audio/video recordings you choose to capture, chat messages with our AI tutors, and any text/code you submit for solving or execution.
  • LMS integration data — if you connect Canvas, EdStem, or a similar school system, we store an OAuth access token (and, if the provider requires it, a refresh token) scoped to reading your assignments, announcements, and course roster. We do not request or store your school login password.
  • Usage and billing data— which AI models/features you use, token counts, and credit/wallet transactions, so we can meter usage and bill correctly (including when you supply your own API key — "BYOK").
  • Device and log data — IP address, browser/user-agent, and timestamps, collected for security, abuse prevention, and debugging.

2. How we use it

  • To operate the core product: process your course materials into a searchable knowledge base, generate study aids, answer questions, and grade/tutor your work.
  • To bill you accurately for AI usage and maintain your credit balance.
  • To keep the service secure and investigate abuse, fraud, or violations of our Terms.
  • To communicate with you about your account (service emails, security notices) — we do not send marketing email without your consent.
  • To improve the product using aggregated, de-identified usage patterns. We do not sell your personal data or your course content to third parties, and we do not use your private study content to train third-party foundation models.

3. Who we share it with

We use a limited set of third-party processors to run the service. Each only receives what it needs to do its job:

  • AI providers (e.g. OpenAI, Anthropic, Google, Qwen/ Alibaba, ByteDance, Zhipu, and others you or we select) receive the text/images/audio you submit for that specific request, in order to generate a response. If you supply your own API key, that request goes directly from our backend to that provider under your account with them, subject to their own privacy terms.
  • Payment processing (Stripe) receives what is needed to process a purchase or donation. We do not store your full card number ourselves.
  • Transactional email providers receive your email address and message content for account verification, password resets, and service notices.
  • LMS providers (Canvas, EdStem, etc.) receive standard OAuth API calls to fetch your course data — nothing beyond what the integration is scoped to read.

We do not sell personal data. We disclose data to law enforcement only when legally required to do so.

4. Data retention

We keep your account and content for as long as your account is active. If you delete a file, note, or recording, we remove it from active storage promptly and from backups on our normal backup rotation cycle. If you close your account, we delete your personal data and content within a reasonable period, except where we are required to retain records (e.g. billing records for tax/accounting purposes).

5. Your rights

Wherever you are, you can ask us to:

  • Access or export a copy of your data.
  • Correct inaccurate account information.
  • Delete your account and associated content.
  • Withdraw consent for optional features (e.g. classroom recording) at any time — this does not affect the core study/solving features.

If you are in the EU/EEA, UK, or another jurisdiction with a comparable data protection framework, these map to your rights of access, rectification, erasure, restriction, and portability under applicable law (e.g. GDPR). To exercise any of these, use the contact details below.

6. Security

We use encryption in transit (TLS) and at rest for sensitive fields (including your stored API keys), role-based access controls, and routine backups. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you as required by applicable law.

7. Children's privacy

AI Study Mate is intended for students of an age to independently manage their own study workflow (typically secondary school and above). We do not knowingly collect data from children under 13 (or the minimum age required by your local law) without appropriate consent. If you believe a child has provided us data without proper consent, contact us and we will delete it.

8. Changes to this policy

We may update this policy as the product changes. We will update the "Last updated" date above, and for material changes we will make a reasonable effort to notify active users in-product or by email.

Contact

For any privacy question, data access/export/deletion request, or to report a concern, contact privacy@aistudymate.academy.