Privacy Policy
Effective September 6, 2026 · Last updated September 6, 2026
This policy explains what [LEGAL ENTITY NAME — e.g. StudentHubAI LLC, or your full legal name if sole proprietor] (“StudentHubAI”, “we”, “us”) collects when you use https://studenthubai.app, why we collect it, who else processes it, and the control you have over it.
1. What we collect
Information you give us
- Account details: your name, email address and password. Passwords are stored only as a salted hash, never in readable form.
- Your study content: notes, uploaded files, lecture audio, essays, flashcards, homework photos, chat messages with the AI assistant, and everything the Service generates from them.
- Optional profile details such as your school or classes, if you choose to add them.
- Support messages you send us.
Information we collect automatically
- Usage data: which features you use and how often, so we can see what is working and control AI costs.
- Page visits: the page visited, the referring site, and any referral or creator code in the link. We store a one-way hash of your IP address and browser type as a visitor identifier. We do not store your raw IP address in our own analytics.
- Device and log data generated by our hosting provider in the ordinary course of serving the site.
Payment information
Subscriptions are processed by Stripe. Your card number is submitted directly to Stripe and never reaches our servers. We receive only your billing email, subscription status and the last four digits and brand of your card.
2. How we use it
- To provide the Service, including generating AI output you request.
- To create and secure your account, and to authenticate you.
- To take payment and manage your subscription.
- To send you service emails: trial reminders, receipts, password resets and important changes.
- To send occasional product emails, which you can opt out of at any time.
- To measure usage, enforce fair-use limits and control AI spending.
- To detect abuse, fraud and security incidents.
- To comply with law.
If you are in the UK, EU or another region with similar law, our legal bases are: performing our contract with you (providing the Service and billing), our legitimate interests (security, abuse prevention, product improvement), your consent (non-essential cookies and marketing email), and legal obligation (tax and accounting records).
3. AI providers and your content
AI features work by sending your input to a third-party AI provider, which returns a result. That means the text, images or audio you submit to an AI feature leaves our systems and is processed by the provider named in the table below.
We do not sell your content, and we do not use it to train AI models. We use these providers under commercial terms that do not permit them to train their models on our customers’ data. Providers may retain input briefly to detect abuse, under their own policies.
Please do not paste information into AI features that you would not want processed by a third party, such as government identifiers, health records or financial account numbers.
4. Who else processes your data
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We use the following service providers, each of which processes data only to perform its function for us:
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Website and application hosting | IP address, request metadata |
| Supabase | Database, authentication and file storage | Account details, your study content |
| Stripe | Subscription payments | Email, billing details, payment method (held by Stripe, never by us) |
| OpenAI | AI generation (notes, tests, essays, homework help, speech) | The text and images you submit to AI features |
| Groq | Lecture and audio transcription | Audio you record or upload |
| Resend | Transactional and product emails | Email address, name |
We may also disclose information where legally required, to enforce our Terms, to protect the safety of a person, or to a buyer if the business is sold, in which case this policy continues to apply until you are notified of a replacement.
5. How long we keep it
- Account and study content: for as long as your account is open.
- After you delete your account: we delete your content within 30 days, except where we must keep records longer.
- Billing records: retained as long as tax and accounting law requires, typically seven years.
- Lecture audio: deleted from storage once transcription completes. The transcript stays in your account until you delete it.
- Visit analytics: retained in aggregate. These records contain a hashed identifier, not your identity.
6. Your rights and how to use them
Whoever and wherever you are, you can ask us to:
- Give you a copy of the personal information we hold about you.
- Correct information that is wrong.
- Delete your account and the data in it.
- Stop sending you marketing email.
- Restrict or object to certain processing, or ask us to transfer your data elsewhere.
To make a request, email support@studenthubai.app from the address on your account. We respond within 30 days. We will never charge you for a request or give you a worse service for making one.
California residents have the right to know, delete, correct and opt out of sale or sharing under the CCPA as amended. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for purposes requiring a right to limit. You may use an authorised agent, and we will verify the request through your account email.
If you are in the UK or EU you may also complain to your local data protection authority, though we would appreciate the chance to put things right first.
7. Students and schools
StudentHubAI is a consumer product. You sign up directly, as an individual, and we have no relationship with your school. We are not acting as a “school official” under FERPA, we do not receive education records from your institution, and nothing you do here is reported to it.
If your institution adopts StudentHubAI for its students in future, that arrangement would be governed by a separate agreement and you would be told.
8. Children
The Service is not intended for children under 13, and we do not knowingly collect their personal information. If we learn we have, we delete it. Parents and guardians who believe a child under 13 has given us information should contact support@studenthubai.app.
9. Security
We protect data in transit with TLS, isolate accounts at the database level so one user cannot read another’s rows, keep private uploads in non-public storage, and restrict administrative access to the operator of the Service.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and any regulator as the law requires.
10. Where your data is processed
We operate from the United States and our providers process data in the United States and other countries. If you use the Service from outside the US, you understand your information is transferred there, where privacy law differs. Where required, our providers rely on Standard Contractual Clauses or an equivalent safeguard.
11. Cookies
We use a small number of cookies and similar technologies. They are listed individually, with their purpose and lifetime, in our Cookie Policy.
12. Changes to this policy
We will post any update here and change the date at the top. If a change materially affects how we handle your information, we will tell you by email or in the product before it takes effect.
13. Contact
For any privacy question or request:
[LEGAL ENTITY NAME — e.g. StudentHubAI LLC, or your full legal name if sole proprietor]
[POSTAL ADDRESS — street or PO Box, city, state, ZIP. Required by law in marketing emails.]
support@studenthubai.app