Privacy Policy
Last updated: August 11, 2025
This Privacy Policy explains how StudyBuddy collects, uses, and protects your personal information. We are committed to protecting your privacy and ensuring transparency about our data practices.
1. Information We Collect
Personal Information
When you create an account with StudyBuddy, we collect:
- Google Account Information: Name, email address, profile picture
- Profile Data: Grade level, school name, bio (optional)
- Account Metadata: Creation date, last login, preferences
Google Classroom Data
When you connect your Google Classroom, we access:
- Course Information: Course names, descriptions, teacher names
- Assignment Data: Titles, descriptions, due dates, point values
- Grade Information: Assignment grades, overall course grades
- Submission Status: Whether assignments are turned in, returned, or graded
- Class Materials: Links to documents, videos, and other resources
Usage Information
We automatically collect:
- Technical Data: IP address, browser type, device information
- Usage Analytics: Pages visited, features used, time spent on platform
- Error Logs: Technical errors and performance data
- Study Assistance Interactions: Questions asked to our AI tutor
2. How We Use Your Information
Primary Service Functions
- Dashboard Display: Show your courses, assignments, and grades
- Schedule Management: Organize your academic calendar
- Study Assistance: Provide personalized AI tutoring based on your assignments
- Progress Tracking: Monitor your academic progress and performance
Platform Improvement
- Feature Development: Analyze usage patterns to improve our service
- Bug Fixes: Identify and resolve technical issues
- Performance Optimization: Enhance speed and reliability
Communication
- Service Updates: Notify you about important changes or new features
- Support: Respond to your questions and provide assistance
- Security Alerts: Inform you about security-related issues
3. Data Sharing and Disclosure
We DO NOT sell your personal information.
Limited Sharing
We may share your information only in these specific circumstances:
- Service Providers: Third-party services that help us operate (e.g., Google Cloud, Firebase)
- Legal Requirements: When required by law, court order, or legal process
- Safety: To protect the safety of users or prevent illegal activity
- Business Transfers: In the event of a merger or acquisition (with user notification)
Google Classroom Integration
Your Google Classroom data is accessed through Google's secure APIs. We do not share this data with any third parties except as necessary to provide our services.
4. Data Security
Protection Measures
- Encryption: Data is encrypted in transit and at rest
- Access Controls: Strict limits on who can access user data
- Secure Infrastructure: Hosted on Google Cloud with enterprise-grade security
- Regular Audits: Periodic security reviews and updates
- Authentication: Secure Google OAuth for account access
Incident Response
In the event of a data breach, we will notify affected users within 72 hours and provide information about the incident and remediation steps.
5. Your Rights and Choices
Account Control
- Access: View all data we have about you
- Update: Modify your profile information at any time
- Delete: Request deletion of your account and associated data
- Download: Export your data in a portable format
Google Classroom Permissions
- Revoke Access: Disconnect Google Classroom integration at any time
- Selective Permissions: Control which Google services we can access
- Data Refresh: Choose how often we sync your classroom data
Communication Preferences
- Email Settings: Control what notifications you receive
- Opt-out: Unsubscribe from non-essential communications
6. Data Retention
Retention Periods
- Active Accounts: Data retained as long as your account is active
- Inactive Accounts: Deleted after 2 years of inactivity
- Deleted Accounts: Most data deleted within 30 days
- Legal Requirements: Some data may be retained longer if required by law
Backup Retention
Data in our backup systems is automatically deleted according to our backup retention schedule, typically within 90 days.
7. Children's Privacy
Age Requirements
- Minimum Age: Users must be at least 13 years old
- Parental Consent: Users under 13 require verifiable parental consent
- COPPA Compliance: We comply with the Children's Online Privacy Protection Act
- Educational Use: Designed for educational purposes in compliance with FERPA
8. International Users
Data Transfers
StudyBuddy is based in the United States. If you are accessing our service from outside the US, your data may be transferred to and stored in the US. We ensure appropriate safeguards are in place for international data transfers.
Regional Compliance
- GDPR: European users have additional rights under GDPR
- CCPA: California residents have specific privacy rights
- Other Laws: We comply with applicable regional privacy laws
9. Third-Party Services
Google Services
StudyBuddy integrates with Google services (Authentication, Classroom, Cloud). Google's privacy practices are governed by their own privacy policy.
AI Services
Our AI tutoring feature uses Google's Gemini AI service. Study assistance requests are processed according to Google's AI service terms and privacy policies.
10. Cookies and Tracking
Necessary Cookies
- Authentication: Keep you logged in securely
- Preferences: Remember your settings
- Session Management: Maintain your session state
Analytics
We use analytics to understand how our service is used and to improve user experience. You can opt out of analytics tracking in your account settings.
11. Changes to This Policy
Policy Updates
- Notification: We'll notify you of significant changes
- Effective Date: Changes take effect 30 days after notification
- Continued Use: Using StudyBuddy after changes means you accept them
- Version History: Previous versions available upon request
12. Contact Us
Privacy Questions
If you have questions about this Privacy Policy or our data practices:
- Email: everett.hurder@gmail.com
Data Protection Officer
For GDPR-related inquiries, contact our Data Protection Officer (me) at: everett.hurder@gmail.com
Summary of Your Rights
You have the right to:
- Know what personal information we collect and how we use it
- Access and update your personal information
- Delete your account and associated data
- Control your Google Classroom integration
- Opt out of non-essential communications
- Request a copy of your data
- File a complaint with privacy regulators