Skip to main content
Back to home

Privacy Policy

Last updated: October 2026

1. Data controller

The data controller is Valerio Ferri – VAT number IT18640391001, Via Monte Bianco 181b, 00012 Guidonia Montecelio (RM), Italy, who provides the STUDIA service (website stud-ia.app and app app.stud-ia.app).No data protection officer (DPO) has been appointed: under Article 37 of Regulation (EU) 2016/679 (GDPR) the appointment is not mandatory, because our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data.

2. What data we process

  • Account: email address and name; if you register with email and password, the password is stored only in encrypted (hashed) form. If you sign in with Google, Google provides us with your name, email address and profile picture.
  • Profile and preferences: confirmation of legal age, age range, occupation (student, teacher, professional or other), university, course and year of study, level, region and city, goals, favourite subjects, bio, study style and hours, motivations, how you found us, language, avatar, theme and notification and marketing preferences. Name, age range, at least one study goal and how you found us are required to complete your registration (see the section “Purposes and legal bases”); the rest of the profile is optional, except for the data required by the features that need it (for example university and course to share).
  • Study profile: exams, grades, calendar and reminders you enter.
  • Content: the files you upload as study materials (kept only for the time needed to extract their text), the extracted text, outputs and their PDFs, conversations with Senior with the photos and files you attach, the images and files generated by Senior, voice dictations (transcribed into text), Senior’s “memory” (facts and preferences about your studies, which you can view and delete in the “What it remembers about you” section) and the semantic indexes of your materials (embeddings).
  • Sharing, showcase and reviews: the links you create, prices, unlocks and credits exchanged; the public card (name, university, course, year, avatar) shown to whoever opens your links; the reviews you choose to publish (first name, initial of the surname, university).
  • Credits and payments: credit balance and transactions, packages purchased, payment amounts and identifiers, your request for immediate performance (date, language and text version) and any withdrawal statements. Card details and billing address are collected directly by Stripe: we do not store card numbers.
  • Technical and security data: IP address, user agent, access and activity logs, consent log (version of the documents accepted, date, IP and user agent, confirmations given during registration), push notification data if you enable them (the technical address provided by your browser).
  • Diagnostics: error reports with a pseudonymous user identifier; in the app, only with your consent, the masked recording of some sessions (text and images hidden).
  • Communications: the emails you send us and the data submitted through the website forms (contact, blog newsletter with the confirmation of your consent, ambassador or job applications).
  • Referrals: referral code, referral count and, if you arrived through an invitation, the code you arrived with (stored for 30 days in a technical cookie).

3. Purposes and legal bases

  • Providing the service (account, uploading and processing materials, Senior, credits, sharing, support, service emails such as confirmations and receipts): performance of the contract, Art. 6(1)(b) GDPR.
  • Payments, accounting, tax obligations and handling withdrawals: contract and legal obligation, Art. 6(1)(b) and 6(1)(c).
  • Security, prevention of abuse and fraud, rate limiting and the consent log as evidence: legitimate interest in protecting the service and its users and the obligation to demonstrate consent, Art. 6(1)(f) and 6(1)(c).
  • Server-side error diagnostics: legitimate interest in the proper functioning of the service, Art. 6(1)(f). In-browser diagnostics and masked session recording are enabled, in the app only, with your consent (cookie banner), Art. 6(1)(a).
  • Quality control of AI answers: for some complex outputs (Genius) we keep the request sent to the model and its answer for 30 days, to compare the quality of different models, including those of other providers listed below: legitimate interest in improving the service, Art. 6(1)(f). You can object by writing to privacy@stud-ia.app.
  • Internal statistics in aggregate form (for example the number of users per age range or per channel through which they found us): legitimate interest, Art. 6(1)(f).
  • Promotional emails and newsletter: only with your consent, which you can withdraw at any time — for promotional emails in Preferences or through the link in every email, for the blog newsletter by writing to privacy@stud-ia.app; newsletter subscriptions are sent by email to the controller, who handles them. Art. 6(1)(a).
  • Answering your requests sent by email or through the website forms: pre-contractual measures and legitimate interest, Art. 6(1)(b) and 6(1)(f).
  • Obligations towards authorities (for example on reports of illegal content) and protection of our rights: legal obligation and legitimate interest, Art. 6(1)(c) and 6(1)(f).
To create an account you must provide your email address and confirm that you are at least 18 years old. To complete your registration we also ask for your name, age range, at least one study goal and how you found us: these answers are required, and without them you cannot complete your registration or use the service. We use your name, age range and goals to personalise your experience in the app, and the channel through which you found us for aggregate internal statistics. We do not take decisions based solely on automated processing that produce legal effects or similarly significant effects concerning you (Art. 22 GDPR).

4. Artificial intelligence

To provide STUDIA’s features we send to the artificial intelligence providers, only when you use a feature that requires it and to the extent necessary: the text of your materials, the images and audio to be processed, chat messages and attachments and, for Senior, some profile context (name, language, calendar, study notes and memory, credit balance). The providers process this content in the United States (see the section on transfers).
  • Anthropic (Claude): generation of study materials, advanced modes, Senior’s answers, text recognition in the most difficult cases.
  • OpenAI (GPT, Whisper, embeddings): Senior’s answers in some modes and as a fallback, transcription of audio, video and dictations, semantic indexing of materials.
  • Google (Gemini): text recognition from photos and scanned PDFs, Senior’s answers in some modes, preparation of context for searching your materials, image generation and, in some cases, generation of study materials and titles.
Under the providers’ terms for paid API use, the content sent is not used to train their models; providers may retain it for a limited period for security and abuse-prevention purposes. AI output may contain errors: always check it. If you do not want content to be processed by AI systems, do not upload it: without this processing the features cannot be provided. You can delete materials, outputs, conversations and Senior’s memory at any time.

Bibliographic searches. For the Research feature and for some of Senior’s answers we send to public academic databases (Semantic Scholar, OpenAlex, PubMed, arXiv, Crossref, CORE, DOAJ, dblp) only the text of the search: never your name, your email or your files.

5. Who we share data with

Data is processed by providers acting as our processors (Art. 28 GDPR), under a data processing agreement (DPA):
  • Supabase — database, authentication, storage of files up to 20 MB and of generated PDFs — servers in the EU (Ireland). DPA
  • Cloudflare (R2) — storage of larger files, of photos and files attached in the chat and of content generated by Senior — storage bound to EU jurisdiction. DPA
  • Vercel — hosting of the website and the app — server functions in the EU (Dublin), global delivery network. DPA
  • Railway — background processing (text extraction, OCR, transcriptions, PDF generation, calls to AI models) — servers in an EU region; company based in the United States. DPA
  • Upstash — processing queue and rate limiting, with pseudonymised identifiers — servers in the EU (Ireland). DPA
  • Anthropic — artificial intelligence models (previous section) — United States. DPA
  • OpenAI — artificial intelligence models, transcription, semantic indexing — United States. DPA
  • Google (Gemini API) — artificial intelligence models, OCR, image generation — United States and other countries. DPA
  • Resend — sending emails — sent from the EU (Ireland). DPA
  • Sentry (Functional Software) — error diagnostics — data stored in the EU. DPA
  • Google Workspace — the email system we use to handle your requests — EU and other countries. DPA
  • Internal technical alerting and uptime-monitoring tools, which receive at most pseudonymous identifiers.
The following act as independent controllers: Stripe, for payments (it processes payment data partly as our processor and partly as a controller, for example to prevent fraud and comply with its own legal obligations: Stripe privacy policy); Google, if you sign in with your Google account; browser notification services, if you enable push notifications; the academic databases listed in the previous section, which receive only the search text. Some data is visible to other users by your choice (public card, shared content, published reviews). We disclose data to authorities only when required by law. We do not sell your personal data.

6. Transfers outside the European Economic Area

Some providers are based in the United States (even when the servers we use are in the EU) or also process data outside the European Economic Area; in particular, the AI providers process content in the United States. In these cases the transfer is based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (Decision (EU) 2023/1795), for certified providers, or on the standard contractual clauses approved by the Commission (Decision (EU) 2021/914) included in our contracts with the providers. You can request a copy of the safeguards by writing to privacy@stud-ia.app.

7. How long we keep data

  • Account and profile: as long as the account is active. When you delete it, the data is immediately deleted from active systems, except for copies of content you shared that other users have already received, which stay in their library; backup copies are overwritten automatically according to their technical cycles, normally within 30 days for the database and within 180 days for files.
  • Files uploaded as study materials: only for the time needed to extract their text (normally a few minutes); incomplete uploads are deleted within 24 hours, web pages imported into the chat within 72 hours.
  • Photos and files attached in the chat, images and files generated by Senior, PDFs of outputs: until you delete the conversation or the output, or until the account is closed.
  • Extracted text, outputs, conversations, Senior’s memory and study profile: until you delete them or until the account is closed.
  • Activity logs: IP address and user agent are removed after 90 days; technical data on the use of AI services (operation, cost) after 180 days; processing job records after 30 days; read notifications after 90 days.
  • Requests kept for AI quality control: 30 days.
  • Error diagnostics (Sentry): up to 90 days.
  • Consent log: as long as the account is active; it is deleted together with the account.
  • Withdrawal statements sent from the app: as long as the account is active; the notification we receive by email is kept like other requests.
  • Payments: transaction data, including the request for immediate performance, is kept by Stripe and in the controller’s accounting records for 10 years, as required by law; the credit log in the app is deleted together with the account.
  • Emails and requests: for as long as necessary to handle them and to protect our rights in case of disputes.
  • Promotional emails and newsletter: until you withdraw your consent.

8. Your rights

You have the right to request access to your data, rectification, erasure, restriction of processing and portability, to object to processing based on legitimate interest and to withdraw your consent at any time, without affecting the lawfulness of prior processing (Articles 15-22 GDPR). In the app you can:
  • download all your data in JSON format from Preferences → Personal data;
  • correct your profile data and delete your account from the Profile page;
  • turn off promotional emails in Preferences or through the link in every email;
  • change your cookie choices with the “Cookie preferences” link;
  • view and delete Senior’s memory in the “What it remembers about you” section.
For anything else, write to privacy@stud-ia.app: we reply within one month. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (garanteprivacy.it) or with the supervisory authority of the country where you live or work.

9. Cookies and similar technologies

We use technical cookies and local storage tools that are necessary for the service to work (login session, security, language, theme, interface preferences, referral code, recording your cookie choice). With your consent we also enable, in the app only, error diagnostics (Sentry), which may record some sessions in masked form. We do not use profiling or marketing cookies or third-party analytics tools such as Google Analytics. You can change your choice at any time with the “Cookie preferences” link. Details are in the Cookie Policy.

10. Minors

The service is reserved for adults, i.e. people aged 18 or over; minors may not use it, even with the permission of a parent or guardian. We do not knowingly collect personal data from people under 18: if we find out that an account belongs to a minor, we delete it together with the related data, except for data we are required by law to keep (see the section on data retention). If you believe a minor has provided us with data, write to privacy@stud-ia.app.

11. Security

We protect data with appropriate technical and organisational measures: encrypted connections (HTTPS), passwords stored only in encrypted form, per-user data access controls, pseudonymous identifiers in technical logs and diagnostics, restricted administrative access. In the event of a personal data breach that poses a risk to your rights, we will inform you as required by Articles 33 and 34 GDPR.

12. Changes to this policy

We may update this policy to reflect changes in the law or in the service. In case of material changes we will inform you by email or in the app before they take effect. The date of the last update is shown at the top.

To exercise your rights or ask questions about the processing: privacy@stud-ia.app.

This site uses cookies

This website only uses technical tools that are necessary for it to work: your consent is not needed. Error diagnostics are active only in the app, if you accept them. Learn more in our cookie policy