Privacy Policy

Last updated: August 11, 2025

1. Information We Collect

Personal Information

When you create an account with StudyBuddy, we collect:

  • Google Account Information: Name, email address, profile picture
  • Profile Data: Grade level, school name, bio (optional)
  • Account Metadata: Creation date, last login, preferences

Google Classroom Data

When you connect your Google Classroom, we access:

  • Course Information: Course names, descriptions, teacher names
  • Assignment Data: Titles, descriptions, due dates, point values
  • Grade Information: Assignment grades, overall course grades
  • Submission Status: Whether assignments are turned in, returned, or graded
  • Class Materials: Links to documents, videos, and other resources

Usage Information

We automatically collect:

  • Technical Data: IP address, browser type, device information
  • Usage Analytics: Pages visited, features used, time spent on platform
  • Error Logs: Technical errors and performance data
  • Study Assistance Interactions: Questions asked to our AI tutor

2. How We Use Your Information

Primary Service Functions

  • Dashboard Display: Show your courses, assignments, and grades
  • Schedule Management: Organize your academic calendar
  • Study Assistance: Provide personalized AI tutoring based on your assignments
  • Progress Tracking: Monitor your academic progress and performance

Platform Improvement

  • Feature Development: Analyze usage patterns to improve our service
  • Bug Fixes: Identify and resolve technical issues
  • Performance Optimization: Enhance speed and reliability

Communication

  • Service Updates: Notify you about important changes or new features
  • Support: Respond to your questions and provide assistance
  • Security Alerts: Inform you about security-related issues

3. Data Sharing and Disclosure

We DO NOT sell your personal information.

Limited Sharing

We may share your information only in these specific circumstances:

  • Service Providers: Third-party services that help us operate (e.g., Google Cloud, Firebase)
  • Legal Requirements: When required by law, court order, or legal process
  • Safety: To protect the safety of users or prevent illegal activity
  • Business Transfers: In the event of a merger or acquisition (with user notification)

Google Classroom Integration

Your Google Classroom data is accessed through Google's secure APIs. We do not share this data with any third parties except as necessary to provide our services.

4. Data Security

Protection Measures

  • Encryption: Data is encrypted in transit and at rest
  • Access Controls: Strict limits on who can access user data
  • Secure Infrastructure: Hosted on Google Cloud with enterprise-grade security
  • Regular Audits: Periodic security reviews and updates
  • Authentication: Secure Google OAuth for account access

Incident Response

In the event of a data breach, we will notify affected users within 72 hours and provide information about the incident and remediation steps.

5. Your Rights and Choices

Account Control

  • Access: View all data we have about you
  • Update: Modify your profile information at any time
  • Delete: Request deletion of your account and associated data
  • Download: Export your data in a portable format

Google Classroom Permissions

  • Revoke Access: Disconnect Google Classroom integration at any time
  • Selective Permissions: Control which Google services we can access
  • Data Refresh: Choose how often we sync your classroom data

Communication Preferences

  • Email Settings: Control what notifications you receive
  • Opt-out: Unsubscribe from non-essential communications

6. Data Retention

Retention Periods

  • Active Accounts: Data retained as long as your account is active
  • Inactive Accounts: Deleted after 2 years of inactivity
  • Deleted Accounts: Most data deleted within 30 days
  • Legal Requirements: Some data may be retained longer if required by law

Backup Retention

Data in our backup systems is automatically deleted according to our backup retention schedule, typically within 90 days.

7. Children's Privacy

Age Requirements

  • Minimum Age: Users must be at least 13 years old
  • Parental Consent: Users under 13 require verifiable parental consent
  • COPPA Compliance: We comply with the Children's Online Privacy Protection Act
  • Educational Use: Designed for educational purposes in compliance with FERPA

8. International Users

Data Transfers

StudyBuddy is based in the United States. If you are accessing our service from outside the US, your data may be transferred to and stored in the US. We ensure appropriate safeguards are in place for international data transfers.

Regional Compliance

  • GDPR: European users have additional rights under GDPR
  • CCPA: California residents have specific privacy rights
  • Other Laws: We comply with applicable regional privacy laws

9. Third-Party Services

Google Services

StudyBuddy integrates with Google services (Authentication, Classroom, Cloud). Google's privacy practices are governed by their own privacy policy.

AI Services

Our AI tutoring feature uses Google's Gemini AI service. Study assistance requests are processed according to Google's AI service terms and privacy policies.

10. Cookies and Tracking

Necessary Cookies

  • Authentication: Keep you logged in securely
  • Preferences: Remember your settings
  • Session Management: Maintain your session state

Analytics

We use analytics to understand how our service is used and to improve user experience. You can opt out of analytics tracking in your account settings.

11. Changes to This Policy

Policy Updates

  • Notification: We'll notify you of significant changes
  • Effective Date: Changes take effect 30 days after notification
  • Continued Use: Using StudyBuddy after changes means you accept them
  • Version History: Previous versions available upon request

12. Contact Us

Privacy Questions

If you have questions about this Privacy Policy or our data practices:

  • Email: everett.hurder@gmail.com

Data Protection Officer

For GDPR-related inquiries, contact our Data Protection Officer (me) at: everett.hurder@gmail.com


Summary of Your Rights

You have the right to:

  • Know what personal information we collect and how we use it
  • Access and update your personal information
  • Delete your account and associated data
  • Control your Google Classroom integration
  • Opt out of non-essential communications
  • Request a copy of your data
  • File a complaint with privacy regulators