DRAFT — pending counsel review. Version 2026-08-08. This notice is written by the team from how the product actually works, in plain language. A lawyer has not signed off on it yet; the reviewed version will replace this one and, if anything material changes, you will be asked to agree again.
StudyBot helps students keep track of school — assignments, deadlines, announcements — and lets a parent see how it’s going without seeing the work itself. To do that we process personal data, some of it belonging to minors, so we hold ourselves to a high bar. This page explains, honestly, what we collect, why, for how long, and what you can do about it. It is written so a 15-year-old can read it. If anything is unclear, write to us.
1. Who is responsible
StudyBot is operated by Eli Gassert (sole trader / autónomo, Barcelona, Spain) while the Spanish company (S.L.) that will run StudyBot is being formed. Once registered, the S.L. takes over as the data controller and this notice will be updated to name it.
Contact for anything in this notice: privacy@mystudybot.app.
2. What we collect
Your account. Name, email address, date of birth (only to know whether a parent has to consent — see section 5), preferred language, timezone, and an optional phone number if you turn on WhatsApp reminders.
Your school connections. If you connect a school portal, we store the credentials you give us so StudyBot can check the portal for you. They are encrypted with per-user keys (envelope encryption) before they touch the database — nobody on the team can read them, and they are never shown again in the app.
What the scans find. Assignments, deadlines, and school announcements from portals you connect. If you connect a mailbox, we process whatever it contains — we do not only read “school email.” New messages are ingested and turned into feed items. AI labels each item school or not-school: not-school items stay out of your school feed, but we still store an AI-written summary (and, for a time, the message body). That can include personal mail, bank or credit notices, travel bookings, account alerts, college mail, and similar — anything that landed in the inbox we were given access to.
Academic performance data. Grades, GPA, report-card text, and similar performance information may appear as free text inside emails or portal pages we store (for example a “grade posted” notification). We do not claim that connecting StudyBot never involves academic performance data.
Messages. The reminders and digests we send you (WhatsApp, push, email) and your conversations with the StudyBot assistant. Message content is purged on a schedule; delivery metadata (sent/failed, when) is kept for reliability.
Consent records. Every time you (or your parent) agree to something — these terms, the privacy notice, a channel opt-in — we keep a record of what was agreed, which version, when, and on what basis. Deliberately, we do not store your IP address in consent evidence; we store a one-way fingerprint of the browser instead.
Usage events. Product analytics carry a one-way hash of your user id, never the id itself — a deleted account cannot be re-identified from its event trail.
Payments. If a parent pays for Pro, payment details go to Stripe, not to us. We store what plan is active and for whom.
We do not collect: precise location, contacts, photos, browsing history, or anything from your device beyond what you type into StudyBot.
3. Why we process it (and the legal basis)
- Running the service you asked for — building your feed, sending the reminders you configured, showing your planner (contract, art. 6(1)(b) GDPR).
- Channel opt-ins — WhatsApp and push notifications only ever start after you turn them on, and each opt-in and opt-out is recorded (consent, art. 6(1)(a)). You can turn either off at any time in You → Notifications.
- Parental consent for younger students — see section 5 (art. 8 GDPR, art. 7 LOPDGDD).
- School broadcasts — when your school sends official announcements through StudyBot, the school is the data controller for that and StudyBot is its processor, under a data-processing agreement with the school.
- Security and abuse prevention — rate limits, auth logs (legitimate interest, art. 6(1)(f), in everyone’s favour).
We never sell personal data and never use it for third-party advertising.
4. AI processing
StudyBot uses OpenAI models to classify feed items (is this an assignment? when is it due?), summarize messages, and power the assistant. What’s sent is the content being classified or the conversation you’re having — under a data processing agreement with OpenAI, with EU-residency endpoints where available and EU Standard Contractual Clauses for any transfer. Per OpenAI’s API terms, API data is not used to train their models. Scraped content is passed to the model inside strict delimiters with an instruction that it must never be followed as instructions — a defence against content that tries to manipulate the assistant.
5. Age and parental consent
If you are under 14 (the age Spanish law sets today for consenting to data processing yourself — LOPDGDD art. 7), StudyBot pauses before doing anything with your school accounts: we ask for a parent or guardian’s email, they get a link, and only when they consent does anything start. The age threshold is a single setting in our system — if Spanish law moves it (a change to 16 has been proposed), we can apply the new threshold the same day, and consents recorded before keep a note of the threshold that applied at the time.
6. Who we share data with (sub-processors)
Only what each provider needs, only to run the service:
| Provider | What for | Where |
|---|---|---|
| Railway | Hosting + database | Region not yet verified in writing — confirmed in the DPA before any school contract; we do not claim EU hosting here |
| OpenAI | AI classification & assistant | US/EU (DPA + SCCs; no training on API data) |
| Meta (WhatsApp Business Cloud API) | WhatsApp reminders & digests | EU/US |
| Twilio | Message delivery (fallback provider, only if activated) | EU/US |
| Stripe | Payments (parents) | EU/US |
| Resend | Transactional email (verification, invites) | US (SCCs) |
| SMTP relay | Alternative email route, only if a deployment is configured to use one | Depends on the relay; not in use today |
| Sign in with Google, and Google Classroom / Gmail if you connect them | EU/US (DPA + SCCs) | |
| Web push services (Google, Mozilla, Apple) | Delivering a push notification to your device — your own browser chooses which one | Wherever your browser vendor operates; the payload is encrypted to your device |
| Sentry | Crash reports so we can fix what broke | EU region |
| PostHog | Which features get used — event name plus a one-way code, no tracking | EU cloud |
| Redis | A short memory of your WhatsApp conversation — your last messages and the bot’s replies — so it can answer “what did I just ask?”. It forgets the whole thread 30 minutes after your last message. Also holds rate-limit counters | Our own hosting, same region caveat as Railway |
During the transition to the WhatsApp Cloud API, some existing users’ messages are delivered through a self-hosted WhatsApp gateway (WAHA) on our own infrastructure (same hosting-region caveat as Railway) — no new opt-ins go through it, and it is being retired on September 15, 2026.
The full, dated sub-processor list is published in the compliance pack and schools are notified before a new sub-processor is added.
7. How long we keep things
Retention is enforced by automatic daily jobs, not by promises:
- Raw scraped content (page text, email bodies): nulled after 90 days. The feed item keeps title, AI summary, and dates for the life of the account — including summaries of non-school mail and any academic performance text that was summarised. The retention clock does not erase those summaries on the 90-day body purge.
- Dismissed feed items: deleted after 90 days.
- Message content (reminder texts, AI conversation topics): purged after 90 days; delivery metadata stays.
- If you don’t accept updated terms: scanning freezes immediately, and after 30 days (with a warning email ~7 days before) stored portal credentials are deleted and scraped feed bodies are stripped. Your account itself stays until you delete it.
- If you delete your account: self-service deletion exists and is being re-verified end to end; when it completes, data is erased in cascade — see section 8. Until that re-verification finishes, write to privacy@mystudybot.app if you need erasure urgently.
- Consent records: kept while the account exists, as legal evidence that we had permission during the time we processed data.
The exact windows and what each job does are documented in our retention policy (compliance pack).
8. Your rights
All of these are self-service, today, in the app:
- See and export everything — You → Your data, your call → Download my data gives you a complete JSON copy (right of access and portability).
- Delete everything — Delete my account on the same page is the intended path to erase your account and its data. That path is mid rebuild and re-verification; if anything fails or you need erasure urgently, write to privacy@mystudybot.app and we will complete it.
- Withdraw consent — turn off WhatsApp or push in You → Notifications (recorded as a revocation); disconnect a portal at any time.
- Correct something — edit your profile in the app, or write to us.
- You also have the rights to restriction and objection, and you can complain to the Spanish supervisory authority, the AEPD (aepd.es), though we’d appreciate the chance to fix things first: privacy@mystudybot.app.
9. Parents and sharing
A parent linked to a student’s account sees category-level status only — “on top of it”, “heavy week” — never the student’s actual assignments, messages, or feed. The student controls what categories are shared and can revoke a parent link at any time. Schools see only aggregate numbers, and any count smaller than 5 people is hidden entirely so small groups can’t be identified.
10. Names that appear in shared calendars
When a class shares deadlines, entries are minimized by default — subject labels rather than teachers’ full names. If you are named in someone’s shared entry and want it removed, write to privacy@mystudybot.app and we will remove it (art. 14 and 21 GDPR).
11. Changes to this notice
Each version has a number (top of this page) matching the version you agreed to. If we change anything material, the app raises the consent wall again and asks you to re-agree — quietly editing the rules is not something this system can do.
Version 2026-08-08 · Operated from Barcelona, Spain · privacy@mystudybot.app