Privacy Policy
Last Updated: March 2, 2026
StudntX ("we," "us," or the "App") is committed to protecting your privacy. This Privacy Policy explains how your information is collected, used, disclosed, and safeguarded when you use the StudntX mobile application. StudntX is developed and operated by an independent developer.
Please read this Privacy Policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information You Provide Directly
| Data Type | Examples | Purpose |
|---|---|---|
| Account Information | Email address, first name, last name, display name, profile photo | Account creation and identification |
| Contact Information | Phone number (optional) | Account recovery, optional contact features |
| Educational Information | University name, academic calendar URLs (ICS feeds) | Syncing your class schedule and assignments |
| User-Generated Content | Reminders, study plans | Enabling productivity features |
1.2 Information Collected Automatically
| Data Type | Examples | Purpose |
|---|---|---|
| Device Information | Timezone, device type, operating system | Displaying times correctly, app compatibility |
| Usage Data | Feature interactions, session timestamps | Improving app functionality |
| Authentication Data | Login timestamps, session tokens | Securing your account |
1.3 Information from Third Parties
| Source | Data Received | Purpose |
|---|---|---|
| Google OAuth | Email, name, profile photo | Account creation/login |
| Microsoft Azure OAuth | Email, name, profile photo | Account creation/login (school accounts) |
| Your School's Calendar (ICS) | Course names, assignment titles, due dates, event descriptions | Populating your academic calendar |
2. How We Use Your Information
We use the information we collect to:
- Provide Core Services: Display your calendar, sync assignments, and manage reminders
- Power AI Features: Process your requests through our AI assistant to help with scheduling, study planning, and academic questions
- Enable Productivity Features: Help you organize your academic life with reminders and study plans
- Improve the App: Analyze usage patterns to fix bugs and develop new features
- Communicate with You: Send notifications about reminders and important updates
- Ensure Security: Detect and prevent fraud, abuse, and unauthorized access
3. AI Assistant & Data Processing
3.1 How the AI Works
Our AI assistant is powered by Google Gemini, a third-party AI service provided by Google LLC. When you interact with the AI assistant, your requests are processed through Google's Gemini API via our secure servers (Supabase Edge Functions). Before your first AI interaction, the app will ask for your explicit consent to share data with Google Gemini.
When you interact with the AI:
- Your messages are sent to our secure servers, which forward them to Google Gemini for processing
- The AI can access your calendar events, reminders, and study plans to provide relevant assistance
- Conversation history is stored to maintain context within a session
3.2 AI Limitations
The AI assistant:
- Does NOT provide medical, legal, or crisis counseling advice
- Does NOT have access to your private messages with other users
- Does NOT make decisions without your confirmation for actions like scheduling events
- Cannot access data outside of what the app explicitly provides
3.3 Data Sent to Google Gemini
When you use AI features, the following data is sent to Google Gemini (Google LLC):
- Your message/question
- Relevant calendar context (event titles, dates)
- Your first name (for personalization)
- Recent conversation history (for context continuity)
We do NOT send your email address, phone number, passwords, or private messages to Google Gemini.
Google's use of this data is governed by Google's Privacy Policy. Google may process data on servers located in the United States or other countries.
4. Information Sharing & Disclosure
4.1 We Share Information With:
| Recipient | Data Shared | Purpose |
|---|---|---|
| Supabase | All app data | Database hosting, authentication, server functions |
| Google Gemini (Google LLC) | AI conversation content, calendar context, first name | Processing AI assistant requests |
| Google/Microsoft | OAuth tokens | Authentication only |
| Apple | Purchase validation, subscription status | Processing in-app purchases |
| Sentry | Crash reports, error logs, device info | Error tracking and app stability monitoring |
| Resend | Email address (for support tickets only) | Sending support ticket confirmations |
| Expo | Push notification tokens | Delivering push notifications |
4.2 We May Also Disclose Information:
- With Your Consent: When you explicitly agree to share information
- For Legal Reasons: If required by law, court order, or to protect our rights and safety
- Business Transfers: In connection with a merger, acquisition, or sale of assets
4.3 We Do NOT:
- Sell your personal information to third parties
- Share your data with advertisers
- Use your data for targeted advertising
5. Payments & Subscriptions
5.1 How Payments Work
StudntX offers optional premium features through in-app subscriptions. All payments are processed through Apple's App Store.
5.2 Payment Information We Collect
| Data Type | Collected By | What We See |
|---|---|---|
| Credit card details | Apple | We do NOT see or store your payment details |
| Purchase receipts | Apple | Transaction ID, product purchased, purchase date |
| Subscription status | Apple | Active/expired, renewal date, subscription tier |
5.3 What We Do NOT Have Access To
- Your credit card number, CVV, or billing address
- Your Apple ID password
- Your complete purchase history outside of StudntX
5.4 Subscription Management
- View/Cancel Subscriptions: Manage through your device's App Store settings
- Refunds: Contact Apple directly; we cannot process refunds
- Billing Issues: Contact Apple Support
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account Data | Until you delete your account |
| Calendar Events | Synced events refresh periodically; deleted when you disconnect your calendar |
| AI Conversations | Retained for session continuity; older conversations may be archived |
| Deleted Accounts | Data is permanently deleted within 30 days of account deletion |
7. Your Rights & Choices
7.1 Access & Portability
You can view all your data within the app, including your profile, calendar events, and reminders.
7.2 Correction
You can update your profile information at any time through the app settings.
7.3 Deletion
You can delete your account at any time through Profile > Delete Account or Help Center > Delete Account. This will:
- Permanently delete your profile and all associated data
- Cancel all scheduled reminders
7.4 Notification Preferences
You can manage notification permissions through your device settings.
7.5 Calendar Disconnection
You can disconnect your school calendar at any time, which will stop syncing and remove imported events.
8. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption: Data is encrypted in transit (TLS/SSL) and at rest
- Authentication: Secure OAuth 2.0 authentication with Google and Microsoft
- Access Controls: Row-level security ensures users can only access their own data
- Secure Infrastructure: Hosted on Supabase with enterprise-grade security
- API Security: All API endpoints require authentication
While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
9. Children's Privacy
StudntX is intended for users who are 13 years of age or older. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us at the email below. We will take steps to delete such information.
For users between 13-18, we encourage parental guidance when using social features.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own, including the United States where our service providers (Supabase, Google) operate.
By using the App, you consent to the transfer of your information to these countries, which may have different data protection laws than your jurisdiction.
11. California Privacy Rights (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it's used
- Delete your personal information
- Opt-out of the sale of personal information (we do not sell your data)
- Non-discrimination for exercising your privacy rights
To exercise these rights, contact us at the email below or use the in-app account deletion feature.
12. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have additional rights:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Request limited processing of your data
- Portability: Receive your data in a structured, machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time
Legal Basis for Processing:
- Contract: Processing necessary to provide our services
- Consent: For optional features like AI assistance
- Legitimate Interests: For security and service improvement
13. Third-Party Links & Services
The App may contain links to third-party websites or services (e.g., your school's learning management system). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy in the App
- Updating the "Last Updated" date at the top
- Sending a notification for significant changes
Your continued use of the App after changes constitutes acceptance of the updated policy.
15. Summary of Key Points
| Topic | Summary |
|---|---|
| What we collect | Account info, calendar data, AI conversations |
| Why we collect it | To provide calendar sync, AI assistance, and productivity features |
| Who we share with | Supabase (hosting), Google Gemini (AI), OAuth providers |
| Your control | Delete account anytime, manage notifications, disconnect calendar |
| Security | Encryption, row-level security, secure authentication |
| Children | Not for users under 13 |
| Payments | Processed by Apple; we don't see card details |
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
This Privacy Policy is effective as of March 2, 2026.