Privacy Policy
Last updated: September 21, 2026
1. Who is responsible for your data
StudyLoom is operated by Lokesh Sehgal, an individual sole proprietor based in Haryana, India, who is the controller of the personal data described here. Contact: hello@studyloom.io.
2. What we collect
Account data: when you sign in with Google we receive your name, email address and profile picture, and your Google account identifier.
Your study material: files, images and topics you submit, the text we extract from them, and the mind maps, flashcards and quizzes generated from them, including your flashcard review history and quiz attempts.
Usage data: which generations you run and when (used to apply plan limits and credits), technical details such as model used, size of input and cost, and study days for your streak. We keep server logs for reliability and security.
Preferences: your study goal, daily goal, streak goal, and theme choice.
Billing data: payments are handled by Paddle. We receive your Paddle customer and subscription identifiers, plan, and status — never your full card number.
3. How we use it
To provide the service (generate your study sets, schedule reviews, apply plan limits and credits), to take and manage payments, to keep the service secure and prevent abuse, to fix bugs and understand cost and performance, and to answer your messages. We do not sell your personal data and do not use your study material for advertising.
4. AI processing
To generate study sets we send the text of your material (or the topic you typed, or an image you upload) to our AI provider, OpenAI, through its API. Under OpenAI’s API terms, data sent through the API is not used to train its models, and it may be retained for a limited period for abuse monitoring. Do not upload material you are not allowed to share with a service provider.
5. Who else handles your data
Google (Firebase Authentication) — sign-in.
Supabase — database and file storage for your account, uploads and generated study sets.
OpenAI — AI generation, as described above.
Paddle.com Market Limited — payments, tax and invoicing, as Merchant of Record; Paddle is an independent controller of the payment data it collects.
Amazon Web Services — hosting for the application servers.
These providers process data under their own terms and security practices, and may do so in countries outside yours.
6. Cookies and local storage
We use only what is needed to run the service: Firebase stores your sign-in session in your browser, and we remember your theme and small interface preferences locally. We do not use advertising or cross-site tracking cookies.
7. How long we keep it
Your account data, uploads and generated study sets are kept until you delete them or your account. Deleting a study set from your history also removes its stored copy. Records of past generations (a count and cost, without your content) and billing records are kept for as long as needed to apply plan limits, prevent abuse and meet accounting and legal obligations.
8. Your rights
Depending on where you live (for example under the GDPR, UK GDPR or India’s DPDP Act) you can ask us to access, correct, export or delete your personal data, object to or restrict certain processing, and withdraw consent. Email hello@studyloom.io from your account address. You can also complain to your local data-protection authority.
9. Security
Data is encrypted in transit; your files and study sets are stored in private, per-user areas that only your signed-in account can read, and payments never touch our servers. No system is perfectly secure, so we cannot promise absolute security.
10. Children
StudyLoom is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes
We will update this policy as the product changes and change the date above; where a change is material we will tell signed-in users.