Studitory
Privacy Policy
Last updated: February 16, 2026
Studitory is committed to protecting personal information and supporting privacy, security and online safety in school settings.
1. Scope
This Privacy Policy explains how Studitory collects, uses, stores and discloses personal information for our online learning platform and related services used by students, families, schools and staff.
2. Information We Collect
- Account and profile data, including name, username, email, year level, school context and selected subjects.
- Learning activity data, including questions viewed, answers submitted, study progress, flashcards, and learning analytics.
- Support and communications data when you contact us.
- Technical and security data, including IP address, device/browser metadata, access logs and cookie/session data.
- Payment-related metadata for premium features (billing is processed by Stripe).
3. Cookies and Analytics
Studitory uses cookies and similar technologies only for user interface functionality (such as theme preferences and session management) and website traffic analytics. We do not use cookies for advertising or third-party tracking. We do not sell, rent or trade personal information to any third party. We may use anonymised and aggregated analytics data to monitor platform usage and improve our product. This data does not identify individual users.
4. How We Use Information
- Provide, maintain and improve the platform and learning features.
- Authenticate users, protect accounts and prevent abuse or misuse.
- Provide customer support and service communications.
- Generate educational feedback, including AI-assisted features where enabled.
- Produce anonymised, aggregated analytics to monitor platform usage and guide product improvements.
- Meet legal, regulatory, security and audit obligations.
5. AI Feature Processing
Some features use OpenAI (hosted on Microsoft Azure) to process educational content you submit (for example question text, responses, and associated images) to return marking, feedback or validation outcomes. We configure AI features for education use and do not permit use that conflicts with school safety requirements.
6. Service Providers and Infrastructure
We disclose personal information only where needed to deliver the service. Our key service providers include: Supabase (database and authentication), Microsoft Azure (AI processing and infrastructure), Vercel (application hosting), and Stripe (payment processing). Other providers may support analytics, OCR/document processing, and email delivery. All providers are bound by contractual and security controls appropriate to their role.
7. Cross-Border Handling
We aim to store and process school data in Australia where practical. Some approved service providers may process data in other jurisdictions. Where this occurs, we use contractual, technical and organisational safeguards designed to protect personal information.
8. Data Retention and Deletion
- We retain data for as long as needed for service delivery, legal obligations, dispute handling and security investigations.
- We apply data retention schedules for operational logs, account records and educational activity records.
- When retention periods expire, data is deleted or de-identified using controlled procedures.
- Upon verified request, we support deletion and export workflows, subject to legal exceptions.
9. Security Controls
- Encryption in transit for platform and API communications.
- Access controls, authentication protections and least-privilege administration.
- Monitoring, logging and incident response procedures.
- Regular patching and dependency maintenance practices.
10. Children and School Context
Studitory is designed for school contexts. We process student information under school, parent/guardian and applicable legal frameworks. Where required, we rely on schools or guardians to provide and manage permissions.
11. Your Rights
- Request access to personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion where lawful and operationally feasible.
- Request a copy/export of your personal information.
- Raise a complaint about privacy handling.
12. Data Breach and Incident Notifications
If we identify an eligible data breach, we will investigate, contain, remediate and provide notifications in accordance with applicable law and school contractual obligations.
13. Changes to this Policy
We may update this policy from time to time. We will update the Last updated date and publish the current version at this page.
Contact Us
If you have a privacy request or concern, contact us with enough detail for identity verification and response tracking:
