Privacy notice
Study Sheet uses personal information to run your account, revision workspace, optional AI study tools, and Friends features. The app does not contain advertising trackers, does not sell personal information, and does not use your study data for targeted advertising.
- Guest study data stays in this browser unless you export it or choose to import it into an account.
- Signed-in study data is privately synced through Supabase and cached on your device.
- AI runs only when requested and uses the learning data or source material you deliberately choose. Linked exam-paper PDFs are not sent automatically.
- Social profiles can be discovered by other signed-in users. Progress sharing is off by default.
- Messages are limited to accepted friends, but they are not end-to-end encrypted.
- Guest analytics remain aggregate and use a one-way browser hash. Signed-in operational reporting can be linked to an account.
- Two approved operators can view account details, selected subjects, numeric study totals, broad areas used, and last-active times, but not private writing or authentication secrets.
Who is responsible
Study Sheet is an independent project operated by Mohi and Franckie from the United Arab Emirates. It operates studysheet.org and is responsible for the personal information described in this notice. Privacy, support, security, and takedown requests can be sent to appspire.2@gmail.com.
This notice applies to the official Study Sheet deployment at studysheet.org. A person or organisation publishing a separate deployment is responsible for that deployment and must provide its own privacy information.
Information processed
The information processed depends on the features you choose to use.
- Account and authentication: email address, Supabase account identifier, authentication provider, session information, confirmation and recovery events, and profile details returned by Google or Discord when you choose that provider.
- Revision workspace: selected qualifications, subjects and papers; topic progress and notes; attempts, marks, targets, timing and reflections; mistakes, corrections and review dates; exam dates; weekly availability; planner entries; study activity; focus sessions; streaks; timer preferences; themes; and an active paper session or marking draft.
- AI study features: the selected qualification, subjects, boards and papers; topic progress and notes; attempt marks, dates and reflections; mistakes and corrections; targets and recent planner items; your prompt; pasted study text; text extracted in your browser from a PDF you choose; an audio or video file you deliberately upload for transcription; public YouTube captions, or the public title and description when no transcript is exposed; readable text fetched from a public HTTPS page you submit; limited source type, title and URL metadata; the type, status, time, model, token or audio duration, and estimated compute usage of each request; generated notes, explanations, quizzes, debriefs, flashcards, plans, suggestions, and Study Coach messages; and the usage count needed to apply the free monthly and abuse-prevention limits. The service sends a bounded subset relevant to the requested feature, not the entire saved workspace. Do not enter sensitive personal information, confidential or unreleased exam material, another person's information, or material you do not have the right to process.
- Social profile: tagged username, display name, character design, bio, school, year group, study goal, presence choice, last-active time, and social privacy choices. Avoid entering contact details, a precise location, or anything sensitive in profile fields.
- Owner operations: the two approved Study Sheet operator accounts can receive account ID, email address, authentication provider, signup, confirmation, sign-in and last-active times, display name, tagged username, selected subjects, overall subject percentages, setup status, enabled-feature list, and numeric totals for focus sessions, study completions, paper attempts and mistakes. They can also see broad app areas and limited feature signals used by a signed-in account during the selected reporting period. The routine owner directory does not include passwords, tokens, private messages, AI prompt or output text, topic notes, mistake or correction text, planner content, paper answers, reflections, or individual marks.
- Friends: profile searches, friend requests, accepted connections, declined-request cooldowns, removed connections, blocks, mutual-friend counts, and the progress categories you choose to share.
- Messaging: message sender and recipient, message text, sent time, read time, unread counts, and short-lived typing status. Messages are limited to 1,200 characters and can be exchanged only between accepted friends who are not blocked.
- Device, analytics, and service information: local browser identifiers used to separate guest and signed-in data, a random analytics key that is one-way hashed before storage, broad app areas opened, limited feature signals such as starting a focus session or sending a message, cached app files, and operational information such as IP address, browser type, request time, security events, and delivery records processed by the service providers listed below. Analytics events do not contain message text, task text, notes, marks, corrections, planner content, or paper answers. When an account is signed in, its limited events can be associated with that account for private operational reporting.
- Support: information you include when contacting the operator. Do not send passwords, authentication tokens, backup files, or private messages unless specifically and securely requested.
What other users can see
A Study Sheet social profile is designed for account discovery. Other signed-in users may find a discoverable profile by username, display name, or school and may see its tagged handle, display name, character, bio, school, year group, study goal, mutual-friend count, and presence information when activity sharing allows it. Do not use these fields to publish private or identifying details you do not want other signed-in users to see.
Accepted friends may exchange messages and see only the progress categories you enable. Subject percentages, seven-day study minutes, streak, and focus-timer status are separate switches and are off by default. Friends do not receive your notes, marks, corrections, planner entries, exam dates, task names, full activity history, email address, or complete private study state through the Friends interface.
Messages are not public and database access is restricted to their participants, but they are stored by Supabase and are not end-to-end encrypted. Removing a friend prevents either person from reopening the conversation through the app, but does not immediately erase the stored message history. Blocking removes the connection, prevents new contact, and hides the accounts from one another in discovery.
Approved Study Sheet operators can use a private account directory to monitor adoption, reliability, and support. It includes account email and provider, selected subjects, overall percentages, numeric study totals, broad areas used, and signup, sign-in, sync, and last-active times. It does not provide passwords, tokens, private messages, AI prompt or output text, topic notes, mistake or correction text, planner content, paper answers, reflections, or individual marks. Other students cannot access this operator directory.
How AI processing works
When you deliberately request an AI feature, Study Sheet sends a bounded selection of the learning fields or source material needed for that request to Cloudflare Workers AI. Depending on the tool, this can include selected subjects, boards and papers; topic progress and notes; attempt marks, dates and reflections; mistakes and corrections; targets and recent planner items; your prompt; pasted text; text extracted in your browser from a PDF you selected; or an audio or video file you deliberately upload for transcription. The original PDF file is not uploaded and Study Sheet does not OCR it. A recording upload is sent to Cloudflare only to produce the requested transcript and is not added to the Study Sheet library. If you submit a public YouTube or webpage URL, the Study Sheet server fetches available public captions or readable page text for that request. When a YouTube video exposes no transcript, Study Sheet may use only its public title and description to create a clearly labelled topic guide. Study Sheet does not download a YouTube video. It does not upload, OCR, or send a linked exam-paper or mark-scheme PDF. Opening an external paper remains a separate direct connection between your browser and its source.
The model returns automatically generated study material. Study Sheet stores the resulting output, limited source type, title and URL metadata, and associated usage record in Supabase for the signed-in account so it can be reopened and counted against the applicable allowance. Study Sheet does not intentionally store the raw recording, pasted text, extracted PDF text, webpage text, caption transcript, or recording transcript in the saved AI artifact, although Cloudflare and the external source can process request and operational information under their own retention practices. AI output can be inaccurate. It is used to support revision and is not used to make legal, employment, admissions, grading, credit, or another similarly significant decision about a person.
How information is used
- To create and secure accounts, complete authentication, and send confirmation or recovery email.
- To provide, personalise, save, restore, and sync the revision workspace.
- To calculate progress, study suggestions, streaks, and timer status from the information you enter.
- To generate requested notes, flashcards, quizzes, explanations, debriefs, revision plans, and Study Coach answers; retain them in your account; apply plan allowances; and prevent unsafe or abusive AI use.
- To provide profile discovery, friend requests, selected progress sharing, presence, messaging, read status, and typing indicators.
- To prevent abuse using access controls, CAPTCHA, blocks, request limits, message limits, and diagnostic records.
- To understand adoption, active use, subject coverage, feature use, and which broad product areas need improvement.
- To monitor signed-in account activity, investigate faults, and respond to account support requests using the limited owner directory described above.
- To investigate faults, respond to requests, enforce the Terms, protect rights, and comply with legal obligations.
Study suggestions, generated answers, performance insights, and progress summaries are planning aids. Study Sheet does not use personal information to make legal, employment, admissions, grading, credit, or other similarly significant decisions.
Legal grounds
Where applicable law requires a legal basis, information is processed to provide the service and AI features you request; with your consent for optional choices such as progress sharing; for the legitimate interests of operating, measuring, and securing the service; and where necessary to comply with legal obligations or protect legal rights. You can choose whether to request an AI feature and can change social sharing choices at any time. Withdrawing a choice does not affect processing that was lawful before it was changed.
Local storage, cloud sync, and backups
Guest study data and results from public checklists and free tools are stored in browser local storage, while the guest-session choice and temporary course or paper preselection are stored for the browser session. Public tool inputs and results are not synced to an account unless you deliberately continue in Study Sheet and enter or import them there. A separate random analytics key is stored locally and one-way hashed by the database so aggregate active-browser and broad feature-use counts can be produced without uploading guest study content. Local data remains on that browser profile until you reset it, clear site data, or remove the browser profile.
For a signed-in account, the app keeps a local cache for resilience and syncs a versioned copy of the study state to that user's study_profiles record in Supabase. Row-level security restricts the full record to the authenticated user. A separate owner-only database function derives the limited account and numeric study summary described above without returning the full study-state document. Conflict checks help avoid silently replacing a newer copy from another device.
The installable app caches same-origin interface files for performance and limited offline reopening. It does not place third-party paper PDFs in the Study Sheet service-worker cache.
JSON backups and Excel exports are created in your browser and downloaded where you choose. They may contain names, notes, marks, corrections, dates, and study history. Study Sheet does not separately upload the exported file, but restoring while signed in places the restored study state into normal cloud sync. Store exports carefully.
Service providers
- Cloudflare hosts and protects the website, provides Workers AI for user-requested AI study features, and may process the submitted learning fields plus network, request, security, output, and diagnostic information needed to provide those services.
- Supabase provides authentication, account storage, private study sync, Friends data, messages, presence, realtime updates, AI outputs and usage records, database security, and aggregate product analytics storage.
- Brevo sends transactional account email and processes sender, recipient, delivery, bounce, and related email records.
- hCaptcha processes browser, device, network, interaction, and challenge information needed to detect automated or abusive authentication attempts.
- Google or Discord processes an authentication request under its own notice when you choose that provider.
- GitHub processes information you voluntarily submit to the public project issue tracker.
These providers can process information in countries outside the United Arab Emirates. Study Sheet relies on their service terms, security measures, and available transfer safeguards and limits the information sent to what is needed for each service. Applicable data-protection rules continue to apply to international transfers.
External papers, learning resources, and communities
Study Sheet provides metadata and links to exam boards, paper archives, notes providers, educator channels, publishers, libraries, and lawful open-book services. It does not host the linked paper, note, video, or textbook files and does not bypass source access controls. Permissions held for specified exam material are used only within their documented scope; they do not mean that every linked paper is licensed for every use or that an exam board endorses Study Sheet.
When you open an external link, video destination, or paper inside the in-app viewer, your browser connects directly to the external provider. That provider can receive standard connection information such as your IP address, browser details, referrer, and request time and may use its own storage technologies. The provider's privacy notice and terms then apply.
The Partner Communities directory contains curated links to independently operated Discord servers. Study Sheet can receive aggregate link-use signals but does not receive or control activity inside those servers. Discord and each server operator are responsible for their own rules, moderation, membership, and information practices.
Retention
- Guest data remains until it is reset or browser data is cleared.
- Signed-in study state, social profile, connections, blocks, progress snapshots, and messages generally remain until the relevant item is changed or the account is deleted.
- Saved AI outputs remain in the signed-in account until the output is deleted using the feature's delete control or the account is deleted, subject to limited security, legal, and backup retention. Deleting an output does not restore the monthly allowance used to generate it.
- AI usage-event records, including request identifier, feature, units, status, and timestamps, remain to apply allowances, investigate misuse, and operate the service, generally until the account is deleted.
- Removing a friend stops access through the app but does not by itself erase stored messages. Account deletion removes records linked to that account through database deletion rules.
- A typing indicator expires after a few seconds. Its expired database status may remain until it is updated or the account is deleted.
- Declined-request records can remain to enforce safety cooldowns. Rate-limit, authentication, email-delivery, security, and infrastructure logs remain according to operational needs, provider policies, and legal requirements.
- Deduplicated product analytics events can remain for up to 13 months. The stored visitor value is a one-way hash. Guest reporting remains aggregate; events recorded while signed in can appear in the private owner directory as broad per-account usage totals and last-use times.
- Files you export remain wherever you save or share them.
Security
Study Sheet uses encrypted transport, authentication, row-level database security, narrow database functions, access restrictions, rate limits, CAPTCHA, blocking tools, and conflict-aware saves. No internet service or storage system can guarantee absolute security. Use a unique password, protect access to your email account, sign out on shared devices, and report suspected account misuse promptly.
Your choices and rights
- Use guest mode without creating an account.
- Choose whether guest progress is imported into an account. It is not attached automatically.
- Edit your study information and social profile in the app.
- Keep progress categories private, accept or decline requests, remove friends, and block or unblock accounts.
- Download a JSON backup or Excel export and reset study data from Settings.
- Choose whether to use AI features and delete saved AI output using the controls provided for that feature.
- Delete a signed-in account from Settings. Keep any export you need before deletion.
- Request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where applicable by emailing the operator.
Requests may require reasonable identity verification. Some information may be retained where required for security, legal claims, or other lawful obligations. The UAE's official data-protection overview explains the federal framework and relevant individual rights.
Young users
Study Sheet is intended for students, including some users who may be under 18. If you are under 18, review this notice with a parent or guardian and obtain any permission required where you live. Use only a first name or nickname, add only people you know, and do not place contact details, a precise location, school timetable, passwords, or sensitive personal information in your profile, messages, notes, or AI requests. Parents and guardians can contact the operator about a young person's information.
Changes and contact
This notice may change when the service, providers, or legal requirements change. Material changes will be reflected by updating the date above and, where appropriate, by an in-app notice.
For privacy, support, security, or takedown requests, email appspire.2@gmail.com. Public project reports may also be opened at GitHub Issues, but issues are public. Never post an email address, account detail, backup, private message, or other personal information there.