Privacy Policy
1. Who we are
StudySprit ("we", "us") provides an AI-powered study application for students. For questions about this policy or your data, contact support@studysprit.com.
2. What we collect
| Data | Why |
|---|---|
| Mobile number or email | To create and secure your account (via Firebase Authentication). |
| Birth year | To apply the 13+ age limit and to route under-18 accounts through stricter safety handling. |
| Parent/guardian email | Only if a parent or guardian contacts us about an account. |
| Your messages to the AI | To generate answers and to let conversations continue between sessions. |
| Study activity | Subjects, progress, Pomodoro sessions, quiz results, XP, levels and streaks. |
| Homework photos | Only if you use the Homework Scanner. Deleted automatically after 7 days. |
| Usage and crash data | To keep the app working and to control AI costs. We record request counts and token totals, not the content, for this purpose. |
We do not ask for your address, your school, your exam results or your payment details.
3. Who processes your data
To generate AI answers we send your question — and, for the Homework Scanner, your photo — to an AI provider:
| Provider | Used for |
|---|---|
| OpenAI | All users under 18, all image processing, and all safety checks. |
| DeepSeek | Text features for adult accounts only, where enabled. |
| Google Firebase | Sign-in, one-time passcodes and crash reporting. |
| OneSignal | Push notifications, where you have allowed them. |
| Razorpay | Subscription payments. Your card details go straight to Razorpay and never touch our servers — we store only whether a payment succeeded, its amount, and which plan it bought. |
4. Children and age
StudySprit is for students aged 13 and above. Accounts declaring an age under 13 are refused at sign-up and are not created.
We ask for a birth year so we can apply stricter handling to under-18 accounts. For a student under 18 we do not require a parent or guardian to approve the account before use. The protections that apply to them are technical rather than procedural, and are enforced on our server, not in the app:
- Their requests are processed by OpenAI only and never reach DeepSeek.
- The AI is instructed to keep everything age-appropriate for a school student, and not to give medical, legal or financial advice.
- Every message and every uploaded photo is checked by automated safety filters before and after the AI replies.
A parent or guardian can ask us to switch AI tools off for a student's account at any time, and that choice is honoured until they ask us to reverse it.
We would rather state this plainly than imply more than we do. India's Digital Personal Data Protection Act contemplates verifiable parental consent for processing a child's data. We currently operate an age declaration plus server-enforced safety controls, not a verified approval step.
5. Safety processing
Every message you send to an AI tool is screened before it is processed, and replies are screened as they are generated. If a message suggests self-harm or crisis, the app does not send it to an AI model at all — it shows Indian mental-health helplines instead. We keep a record that a check happened, its outcome, and a short excerpt, so we can review safety incidents and improve the system.
6. How long we keep things
- Chat history and study data — until you delete your account.
- Homework photos — 7 days, or immediately when you delete your account.
- Usage counts — retained in aggregate for cost and capacity planning.
7. Your rights
Under India's Digital Personal Data Protection Act and comparable laws, you can:
- Access and export your data — Settings → Export my data, as a JSON file.
- Delete your account and everything in it — in the app, or on our account deletion page.
- Switch off AI for a student's account — contact support, and it stays off until you ask us to reverse it.
- Correct your details — contact support for anything you cannot change in the app.
8. Security
All traffic uses HTTPS. AI provider keys are held only on our server and never shipped in the app. Every request is verified against your sign-in token before it is processed. Uploaded photos are stored behind access-controlled links, never guessable URLs.
9. What we do not do
- We do not sell or rent your personal data.
- We do not show personalised advertising.
- We do not use your conversations to train our own models.
10. Changes
If we change this policy in a way that materially affects you, we will tell you in the app before the change takes effect.
StudySprit