StudyAIBack

Privacy policy

Last updated: 27 August 2026

StudyAI turns your study material into tests, diagrams, flashcards and guides. This page explains, in plain language, what the service does with your data and what you can ask us to do about it.

Who is responsible for your data

Controller: Henoch Schmohe, self-employed professional (trabajador autónomo, Spain).

Tax ID (NIF): X4159627P

Registered address: Calle Hermandad de San Isidro 3, P1, 1A, 28670 Villaviciosa de Odón, Madrid, España

Contact: henoch@hsmart.dev

AI is part of the service

The questions, explanations, diagrams, flashcards, slides and recommendations are generated by an artificial intelligence system from the material you upload. You are interacting with AI, not with a teacher who has reviewed your syllabus.

The model used is Google Gemini (versions 2.5 Flash and 2.5 Pro), through the Gemini API. AI gets things wrong: always check generated questions and explanations against your official material before trusting them. This service does not replace proper exam preparation.

What we collect

Your account. Sign-in is through Google only. From it we store your name, your email address and the link to your profile picture, plus the identifiers and credentials Google issues to keep you signed in.

Your settings. The exam context you describe, your preferred language and your scoring mode.

Your study material. The text extracted from files you upload (PDF, Word, Excel, CSV or plain text), the text you paste, and the content of URLs you give us. The original file is not kept: its text is extracted and that text is stored along with the file name.

What gets generated and what you do. Topics, tests, questions, your answers, your scores, diagrams, flashcards and their reviews, guides and slide decks.

Usage counters. The number of AI requests and tokens your account uses, so the service can be kept within a workable budget.

⚠️ Only upload material you are entitled to use. If your notes contain other people's personal data or confidential information, do not upload them: they will pass through an AI provider and be stored in your account.

There is no advertising, no profiling and no third-party analytics or tracking cookies. The only cookies are the one that keeps you signed in and one that remembers your interface language.

Why we process it, and on what legal basis

  • To create your account, process your material and generate your tests and study materials: performance of the contract you enter into when you sign up (art. 6.1.b GDPR).
  • To count AI usage, apply the daily and monthly limits and prevent abuse: our legitimate interest in a service that is not abused and does not collapse under cost (art. 6.1.f GDPR).
  • To notify the controller by email of each new signup and when an account reaches 80% of its quota: legitimate interest in administering and sizing the service (art. 6.1.f GDPR). That notification includes your name and email address.

We do not sell your data and we do not use your material or your answers to train AI models.

Who else processes your data

These providers process data on our behalf, only to make the service work:

  • Vercel (hosting and server logs).
  • Neon (the PostgreSQL database holding your account, your material and everything generated from it).
  • Google (the Gemini API, which reads your material and generates questions, diagrams, flashcards, guides and slides; and Google Sign-In, which is the only way in).
  • Resend (delivery of the notification emails to the controller).

If you give a URL as a source, our server fetches it to extract its text. That request comes from our server, not from your browser.

Where your data is stored

The database is hosted in the European Union, in Amazon Web Services' Frankfurt region (eu-central-1).

Requests to the Gemini API and emails sent through Resend may be processed outside the European Economic Area. Those transfers rely on the European Commission's standard contractual clauses, which are part of the providers' terms.

Usage limits

Each account has, by default, a limit of 50 AI requests per day, 300,000 tokens per day and 2,000,000 tokens per month. They exist to keep the cost of the service under control and can be adjusted.

How long we keep it

Your account and everything in it stays for as long as your account exists, because your material and your test history are the point of the product.

There is currently no self-service delete button. Write to henoch@hsmart.dev from the address you signed up with and your account, your material and everything generated from it will be deleted within 30 days.

Your rights

You can ask for access to your data, correction of anything wrong, erasure, restriction of processing, portability of what you have uploaded and generated, and you can object to processing based on legitimate interest. Write to henoch@hsmart.dev and you will get an answer within one month.

If you are not satisfied, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (www.aepd.es), or to the supervisory authority where you live.

Age

This service is not aimed at children. If you are under 14, do not create an account without a parent or guardian.

Changes

If this policy changes in a way that matters, the date at the top changes with it. Significant changes will be announced in the app.