SStudle

Privacy Policy

Last updated: 27 September 2026

This policy explains how Studle collects, uses, stores and shares personal information when you use it. It is written to reflect what the application actually does today; where a decision has not yet been made, it is marked clearly.

Status: Studle is in active development. Several described features (server-side recording storage, transcription, AI study tools and Study Groups) are not yet live; this policy describes current behaviour and flags what must be confirmed before public launch.

1. Introduction

Studle is a student study application. It lets you create an account, record lectures or audio you choose to capture, take notes, organise study material and (in future) collaborate in Study Groups. This policy explains how your personal information is handled when you use Studle.

The data controller for Studle is [LEGAL ENTITY / CONTROLLER DETAILS REQUIRED].

2. Information you provide

Account information (handled through our authentication provider, Clerk): your email address, your first and last name, an optional profile picture, and — if you sign in with Google or Microsoft — the basic profile information those providers return. Passwords, where used, are managed and stored by Clerk, not by Studle.

Education / profile information you enter in Studle: your university, programme/degree, year of study, and the modules/subjects you add.

User content: recordings and audio you capture, notes and bookmarks you create during a recording, and study material you generate. See section 3 for where this is currently stored.

Currently not collected server-side: uploaded PDFs/images/files, transcripts, quizzes and shared Study Group resources are described in the product plan but are not yet processed or stored by Studle's servers. This section will be expanded when those features go live.

3. Recording and transcription

Studle processes audio only when you deliberately start a recording. It does not listen in the background and does not record without you starting a session.

Where recordings are stored today: when you record, the audio is captured in your browser and saved locally on your device (in your browser's storage) so you don't lose it. Recordings are not currently uploaded to or stored on Studle's servers, and are not sent to any third party. Clearing your browser data removes them.

Transcription: live transcription is not currently active. No audio or transcript is currently sent to any external transcription service.

[OWNER DECISION REQUIRED — recording storage & transcription] Before enabling server-side upload of recordings (Cloudflare R2) or transcription, this section must be updated to state exactly where audio/transcripts are stored, how long they are kept, and which processor (if any) performs transcription.

Your responsibility: you are responsible for ensuring you are permitted to record lectures, meetings, conversations or other people, including obtaining any consent required by law, and complying with your university's or institution's rules.

4. AI processing

Studle plans to offer AI features such as transcription, summaries, study notes, quizzes, flashcards, mind maps and material comparison.

Currently, no AI provider processes your content. The summary and study features shown in the app today are local, non-AI demonstrations, and no user content is sent to an AI service.

[OWNER DECISION REQUIRED — AI providers] When AI features are enabled, this section must name the actual provider(s), what content is sent, and whether that content may be used for model training — stated only after verifying the provider's terms/settings. Do not assume either way until confirmed.

5. Study Groups

Study Groups are a planned feature and are not yet active. When they launch, they will follow a strict private-by-default model:

  • Your private content — recordings, transcripts, notes, uploaded files and your study history — stays private.
  • Joining a Study Group will not automatically expose any private content. Only material you deliberately share into a group will be accessible to its permitted members.
  • Group members may see appropriate information such as your display name/profile and the resources you explicitly share.
[TO VERIFY AT LAUNCH] Study Group access controls and sharing must be enforced in code (with server-side ownership checks) before this section can be relied upon.

6. Device information

To support signing in on multiple devices and (in future) moving a recording between your own devices, Studle records information about the devices you use with your account:

  • a device identifier generated by Studle,
  • a device name and device type,
  • timestamps such as when the device was first seen and last active,
  • a trusted/revoked status.

Studle does not collect hardware serial numbers or similar permanent hardware identifiers.

7. Technical information

When you use Studle, standard technical information is processed to operate and secure the service, including your IP address and basic request/browser information handled by our hosting provider (Cloudflare), and authentication/session information handled by Clerk. Security-relevant events may be logged to protect the service.

8. Why we use information

  • to provide Studle and your account;
  • to authenticate you and keep you signed in;
  • to store your profile and the study material you create;
  • to carry out recording you request, and store it locally on your device;
  • to support signing in across your devices;
  • to keep the service secure and prevent abuse;
  • to fix problems and keep the service reliable;
  • to comply with legal obligations.

We do not sell your personal information, and we do not currently use it for advertising or third-party analytics.

9. UK GDPR lawful bases

Where UK data protection law applies, we rely on the following lawful bases, matched to each purpose:

  • Performance of a contract — to create and run your account and provide the core features you ask for.
  • Legitimate interests — to keep Studle secure, prevent abuse, and maintain and improve reliability, balanced against your rights.
  • Consent — where genuinely required, for example if optional features that share content or use AI/analytics are introduced. We do not currently rely on consent for any active processing because no such optional processing is live.
  • Legal obligation — where we must process information to comply with the law.
[LEGAL REVIEW REQUIRED] The mapping of lawful bases should be confirmed by a data-protection professional before public launch, especially once transcription, AI and Study Group sharing are enabled.

10. Service providers

We use the following providers to operate Studle:

  • Clerk — authentication and account management (email, name, password where used, profile image, Google/Microsoft sign-in, and sessions).
  • Cloudflare — hosting and infrastructure: the application runs on Cloudflare Workers, profile/account data is stored in Cloudflare D1, object storage (Cloudflare R2) is provisioned for future audio storage, and Durable Objects support session coordination.
  • Google / Microsoft — only if you choose to sign in with them, in which case they act as identity providers via Clerk.

We do not currently use any analytics, transcription or AI subprocessor. Any such provider will be added here only after it is actually integrated.

11. International transfers

Some providers may process information outside the UK. Clerk and Cloudflare are global providers and may process data in other countries.

[OWNER CONFIRMATION REQUIRED — international transfers] The specific regions used and the safeguards relied upon (for example UK/EU data-region settings and the providers' standard contractual clauses / data processing terms) must be confirmed from your Clerk and Cloudflare configuration before this section is finalised.

12. Retention

Account and profile information is kept while your account is active. Recordings and notes you create are kept on your own device until you delete them or clear your browser data.

[OWNER DECISION REQUIRED — retention] Retention periods for account data, and for any future server-stored recordings/transcripts, have not yet been decided. You need to decide how long each category is kept after account closure or inactivity before launch. We have not stated any specific period here to avoid inventing one.

13. Deletion

Today you can remove individual modules from your profile, delete recordings stored on your device (by deleting them or clearing your browser data), and sign out at any time.

[OWNER DECISION REQUIRED — account & data deletion] A full "delete my account and associated data" feature is not yet implemented. Deleting an account through the authentication provider would not currently remove associated records held in Studle's database. Full deletion (including cascade removal of profile, modules, device records and any future stored recordings) should be implemented before public launch so this section can honestly describe it.

14. Your rights

Subject to the conditions in UK data protection law, you may have the right to: access your personal data; have inaccurate data corrected; have data deleted; restrict or object to certain processing; data portability; and, where processing relies on consent, to withdraw that consent. Not every right applies to every situation.

You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. To exercise any right, contact us using the details in section 19.

15. Security

We use appropriate measures to protect your information, including encrypted connections (HTTPS), security headers, authenticated APIs with per-account access checks, and reliance on established providers (Clerk, Cloudflare) for authentication and infrastructure. No online service can be guaranteed to be completely secure, and we do not claim Studle is.

16. Children

Studle is intended for students.

[OWNER DECISION REQUIRED — minimum age / student eligibility] No minimum age or eligibility rule is currently set. You must decide the minimum age and any eligibility requirements (and how they are enforced at sign-up) before public launch.

17. Cookies and similar technologies

Studle uses only what is needed to sign you in and run the app:

  • Strictly necessary (authentication/security): cookies and browser storage set by our authentication provider, Clerk, to keep you securely signed in.
  • Local storage on your device: Studle stores your in-progress recordings and quick notes in your browser (IndexedDB) so they are not lost. This stays on your device.

Studle does not currently use analytics, advertising or other optional/tracking cookies.

[TO CONFIRM] Because only strictly necessary technologies are in use today, a consent banner is not required for optional tracking. If analytics or other optional technologies are added later, a compliant consent mechanism will be needed and this section must be updated.

18. Changes to this policy

We may update this policy as Studle develops. When we make material changes we will update the "Last updated" date above and, where appropriate, provide notice within the app.

19. Contact

For privacy questions or to exercise your rights, contact: [PRIVACY CONTACT REQUIRED].

Controller / legal entity details: [LEGAL ENTITY / CONTROLLER DETAILS REQUIRED].

Read the Terms of Use →