Last updated: 25 August 2026

Privacy Policy

Translation provided for information only. This is a contract governed by French law: in case of any discrepancy, the French version prevails. Read the French version

This policy explains what data StudiAI collects, why, and how you can exercise your rights under the GDPR.

1. Data controller

The data controller is Perform Code SAS, publisher of the StudiAI service, 216 rue Clémenceau, 59139 Wattignies (France), registered with the Lille Métropole Trade and Companies Register under number 942 543 943.

For any request relating to your data: [email protected].

2. Data collected

To run StudiAI, we collect the following categories of data:

  • Account data: email address, password hashed with Argon2 (never stored in plain text), first name, year of birth, language preference.
  • Study profile: school or university level, subjects, revision goals, learning preferences.
  • Content: the course materials and documents you upload (PDF, images, text), the content generated from them (quizzes, study sheets, summaries, revision plans, diagrams), conversations with the assistant, written work and homework submitted for correction.
  • Usage data: credits consumed, features used, progress through revision plans, quiz results.
  • Billing data: customer identifier and payment history processed by Stripe (web) or Apple (iOS). StudiAI never stores bank card numbers.
  • Third-party login identifiers: technical identifier and email provided by Google, Discord or Apple if you choose an OAuth login (“Continue with…”).
  • iOS device data: Apple DeviceCheck attestation token (anti-abuse) and push notification token, if you enable notifications.
  • Referrals: referral code, referrer/referee link, status of the reward.
  • Login and security log: timestamp, truncated IP address, browser or device (user agent).
  • Proof of consent: each acceptance of the Terms of Use and each marketing opt-in or opt-out is logged (timestamp, document version, truncated IP, user agent) in order to meet our evidentiary obligations.
  • Newsletter sign-up without an account: if you enter your email address in the form in the footer of the site, that address alone is recorded with our emailing provider. No account is created and no other data is collected on that occasion.

No sensitive data within the meaning of Article 9 of the GDPR (health, opinions, religion, etc.) is deliberately collected. We invite you not to include any in the documents you upload or in your conversations with the assistant.

3. Purposes and legal bases

Your data is processed for the following purposes:

  • Providing the service (uploading, content generation, corrections, chat, revision plans, web/iOS synchronisation) — performance of the contract.
  • Managing subscriptions, credit packs, billing and referrals — performance of the contract and legal obligation (accounting).
  • Sending transactional emails (address verification, login code, security, payment confirmation, inactivity warning) — performance of the contract; these emails are essential and do not require your consent.
  • Sending marketing emails (newsletter, revision tips, new features, offers) — explicit and separate consent, collected at sign-up, from your settings or through the newsletter sign-up form of the site, which you can withdraw at any time in one click from the unsubscribe link in each email (compliant with RFC 8058) or from your settings.
  • Securing accounts, preventing fraud, abuse and bots (Turnstile, DeviceCheck, login log), and granting the free credits only once per device by means of a hashed technical fingerprint — legitimate interest.
  • Measuring audience in an aggregated and cookie-free way, and improving the service — legitimate interest.
  • Keeping proof of consent and invoices — legal obligation.

No data is used for advertising profiling purposes, nor sold to third parties.

4. Processing by the AI

The course materials you upload, your questions to the assistant and the written work you submit are transmitted to our AI model provider, Anthropic, for the sole purpose of generating the content you request (quizzes, study sheets, summaries, corrections, plans, chat replies). This processing is based on the performance of the service.

Safeguards applied:

  • No account identifier (email, first name, user identifier) is transmitted with the content; only the document or the question and the necessary educational context are.
  • In accordance with our contractual terms with Anthropic, your data is not used to train its models.
  • Transfers to the United States are covered by the Data Privacy Framework and the Standard Contractual Clauses.
  • Generated content is stored in your StudiAI space and you can delete it at any time.

5. Automated decisions and AI-generated content

The corrections, marks, quiz scores and recommendations produced by StudiAI are indicative educational aids. They produce no legal effect and no similarly significant effect on you: they replace neither your teachers’ assessment nor a decision of your institution. You are therefore not subject to a decision based solely on automated processing within the meaning of Article 22 of the GDPR.

In accordance with Article 50 of Regulation (EU) 2024/1689 on artificial intelligence, the content generated by StudiAI is labelled as produced by an AI. It may contain errors, approximations or omissions: always check it against your course materials and your own judgement.

6. Processors and recipients

Your data is shared only with the technical processors necessary for the operation of the service:

  • Railway Corp. (United States) — hosting of the API, the database and the files; Standard Contractual Clauses and Data Privacy Framework.
  • Anthropic (United States) — processing of course materials, questions and written work in order to generate content; DPF and Standard Contractual Clauses; no training of the models on your data; no account identifier transmitted.
  • Stripe (United States) — payments, billing and VAT on the web; DPF.
  • Apple (United States) — iOS in-app purchases, Sign in with Apple, DeviceCheck and push notifications; DPF.
  • RevenueCat (United States) — validation of iOS in-app purchases; DPF.
  • Brevo (France) — sending of transactional emails and, if you have consented to them, of marketing emails.
  • Cloudflare Turnstile (United States) — anti-bot protection of the authentication forms; DPF.
  • Google and Discord — only if you choose to log in through one of these services (OAuth).
  • Umami — cookie-free audience measurement, self-hosted on our infrastructure.
  • Discord (internal webhooks) — notification of our support team when a ticket is opened: only the account identifier and the content of the ticket are transmitted, never your email.

No resale to a third party, no sharing for commercial purposes. Public authorities can obtain your data only in the cases provided for by law.

7. Retention periods

  • Account, profile, content: kept for as long as your account is active.
  • Inactive accounts: automatic deletion after 12 months without a login, with a warning email at 11 months. Accounts with an active subscription are excluded from this deletion.
  • Deletion of the account (by you or through inactivity): data erased within 30 days.
  • Invoices and accounting records: 10 years (Article L. 123-22 of the French Commercial Code).
  • Technical logs (errors, performance): 90 days.
  • Security and login log: 12 months.
  • Expired login tokens and codes: purged within 7 days.
  • Proof of consent: 5 years after the withdrawal of consent or the deletion of the account (limitation period).
  • Addresses signed up to the newsletter without an account: kept until unsubscription, and for no more than 3 years after the last contact (CNIL recommendation on direct marketing).

8. Your rights

You have at any time the rights of access, rectification, erasure, objection, restriction and portability of your data, as well as the right to give directives on what happens to your data after your death (Article 85 of the French Data Protection Act).

You can export all of your data (including the history of your consents) or delete your account directly from your settings, or by writing to [email protected]. Marketing consent can be withdrawn at any time from your settings or through the unsubscribe link at the bottom of each marketing email.

We reply within one month at most (Article 12 of the GDPR), a period that may be extended by two months for complex requests. In the event of a persistent disagreement, you may lodge a complaint with the CNIL, the French data protection authority: www.cnil.fr.

9. Minors

StudiAI is aimed at secondary school and university students. Registration is open without parental agreement from the age of 15, an age set by Article 45 of the French Data Protection Act in application of Article 8 of the GDPR. The year of birth is requested at sign-up for that sole purpose.

Below the age of 15, the joint consent of the holder of parental authority is required: we collect the parent’s email address and send them a validation link. Until that validation has been completed, the account remains limited. The parent may at any time withdraw their consent and request the deletion of the account at [email protected].

No marketing email is sent to underage users.

10. Security

Passwords hashed with Argon2, TLS encryption in transit, sessions of limited duration with rotation of refresh tokens, optional two-factor authentication, per-user data isolation, control of internal access, rate limiting and anti-bot protection on the authentication forms, encrypted backups.

As no system is infallible, any data breach presenting a risk is notified to the CNIL within 72 hours and, where the risk is high, to the individuals concerned as soon as possible (Articles 33 and 34 of the GDPR).

11. Cookies

StudiAI uses only strictly necessary cookies (session, security, preferences, abuse prevention) and cookie-free audience measurement. The details are set out in our Cookie Policy (https://studi-ai.com/cookies).

12. Changes

This policy may be updated to reflect changes in the service, in our processors or in the legal framework. Any substantial change will be brought to your attention by email or in the app. The date of the last update appears at the top of the page.