Privacy Policy
Version 1.0 - Effective July 15, 2026
This policy explains how Study Anything processes your account, PDFs and study activity when it creates interactive exam preparation from your material.
Controller and contact
The controller is STRICS IT GmbH, Florian-Gmainer-Strasse 4, 4240 Freistadt, Austria. For privacy, support or safety requests, contact hello@strics.at.
This policy covers the Study Anything iOS app, its Firebase backend and these legal pages.
Account and profile data
You can sign in with Apple or Google. We receive a Firebase user identifier and, depending on your provider choices, your name, email address and profile information. Study Anything never receives your Apple or Google password.
You can choose a display name, username, profile photo and bio. Signed-in users can search by username and may see your display name, username, profile photo, bio, study streak and XP so that friends can identify each other. You can edit this information in Profile.
PDFs and generated study packs
When you choose a PDF, the app sends the file name, page count and PDF to Firebase Storage and Cloud Functions. The backend extracts text and useful diagrams and creates concepts, explanations, flashcards, matching tasks, practice questions and exam questions. Do not upload material that you are not entitled to process or unnecessary personal, confidential or sensitive information.
The completed study pack, question bank and study progress are stored in Firestore. Useful diagram crops can remain in Firebase Storage while the pack exists. Source PDFs and temporary extraction or generation files are removed after generation completes, fails or is cancelled. If an automated deletion fails, the file remains protected from public access and is removed during operational cleanup or account deletion.
AI processing
Study Anything sends the PDF content and necessary generation instructions from our authenticated backend to OpenRouter, which routes the request to the configured AI model provider, including Google models. Providers process the submitted content to return extraction and study-material results; they do not receive your Study Anything password or full billing details.
AI output can be incomplete or wrong. Review generated content against the source before relying on it for an exam, professional decision or safety-critical purpose.
Study activity, friends and safety
We store answers, mastery by concept, XP, daily-goal and streak information so the app can choose useful review questions and restore progress across devices. This data is not used for advertising.
You can add another signed-in user to your study circle and share a pack with specific selected friends. Study Anything does not make packs publicly discoverable. A recipient can report a shared pack or block its owner. We store the reporter identifier, target identifiers, reason, status and timestamps needed to review the report, prevent abuse and take proportionate action.
Subscriptions and purchases
Apple processes payment details. StoreKit supplies product, transaction, renewal, expiration, refund and revocation information so we can verify Plus or MAX access and enforce upload and page limits. We store the verified entitlement, an account-linked StoreKit identifier and limited notification or restore records needed for access, fraud prevention and support.
We do not receive your full payment-card details. Studying an existing pack or a pack shared by a friend does not require a paid upload entitlement.
Security and operational data
Firebase App Check and Apple App Attest process device-attestation assertions to reduce automated abuse. Backend infrastructure also receives technical data such as IP address, timestamp, requested function, app and operating-system version, result, duration and error type.
We use this data to secure accounts, enforce subscriptions and cost limits, investigate failures and prevent abuse. Study Anything does not use the advertising identifier, sell personal data or include third-party advertising, Firebase Analytics or Firebase Crashlytics.
Purposes, legal bases and providers
We process account, document, generated-content, study, sharing and subscription data to perform our contract and provide the features you request. We process proportionate security, moderation and diagnostic data for our legitimate interests in protecting users, preventing fraud, controlling service cost and maintaining reliability. Where consent is required, you may withdraw it, although the affected feature may stop working.
We use Apple for sign-in and StoreKit; Google for Google Sign-In, Firebase Authentication, App Check, Firestore, Storage, Cloud Functions and operational logs; OpenRouter and its routed model providers for requested AI processing; and Vercel for these public legal pages. Processing can occur outside the European Economic Area under applicable safeguards such as adequacy decisions or standard contractual clauses.
Retention and deletion
Your profile, generated packs, derived images, progress, friend relationships and sharing records remain while needed to provide your account. Moderation and security records remain while a report is investigated or as needed to prevent repeated abuse, resolve disputes or meet legal obligations.
You can delete your account in Profile. Account deletion removes your profile, owned packs, progress, friend and sharing records, uploaded files, moderation links, billing mapping and Firebase Authentication account, and revokes the Study Anything Sign in with Apple credential when applicable. Deleting the account does not cancel an Apple subscription; manage that separately in your Apple Account subscription settings.
Your rights and updates
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection and may withdraw consent. Contact hello@strics.at. You may complain to the Austrian Data Protection Authority or your local supervisory authority.
Study Anything is not directed to children under 13. If local law requires parental consent at a higher age, a parent or guardian must provide it. We may update this policy when the app, providers or law changes; the current version and effective date remain available here.