Privacy notice
This notice explains what Study Sheet does with your information, and what it does not do. Your information runs your account, your revision workspace, the AI tools when you ask for them, and Friends. There are no advertising trackers. Nothing is sold, and your study data is never used to target ads at you.
- Guest study data stays in this browser unless you export it or choose to import it into an account.
- Signed-in study data is privately synced through Supabase and cached on your device.
- AI runs only when requested and uses the learning data or source material you deliberately choose. Linked exam-paper PDFs are not sent automatically.
- Social profiles can be discovered by other signed-in users. Progress sharing is off by default.
- Messages are limited to accepted friends, but they are not end-to-end encrypted.
- Nothing is stored on your device to measure visits, so guest reporting is only ever a total. Usage reporting for a signed-in account can be linked to that account.
- Two approved operators can view account details, selected subjects, numeric study totals, broad areas used, and last-active times, but not private writing or authentication secrets.
Who is responsible
Study Sheet is an independent project run by Mohi and Franckie from the United Arab Emirates. We operate studysheet.org and we are responsible for the information described here. Email appspire.2@gmail.com about anything in this notice, including support, security, and takedown requests.
This notice covers the official site at studysheet.org. Anyone running a separate copy of Study Sheet is responsible for it themselves, and must publish their own privacy information.
Information processed
The information processed depends on the features you choose to use.
- Account and authentication: email address, Supabase account identifier, authentication provider, session information, confirmation and recovery events, and profile details returned by Google or Discord when you choose that provider.
- Revision workspace: selected qualifications, subjects and papers; topic progress and notes; attempts, marks, targets, timing and reflections; mistakes, corrections and review dates; exam dates; weekly availability; planner entries; study activity; focus sessions; streaks; timer preferences; themes; and an active paper session or marking draft.
- AI study features: the selected qualification, subjects, boards and papers; topic progress and notes; attempt marks, dates and reflections; mistakes and corrections; targets and recent planner items; your prompt; pasted study text; text extracted in your browser from a PDF you choose; an audio or video file you deliberately upload for transcription; public YouTube captions, or the public title and description when no transcript is exposed; readable text fetched from a public HTTPS page you submit; limited source type, title and URL metadata; the type, status, time, model, token or audio duration, and estimated compute usage of each request; generated notes, explanations, quizzes, debriefs, flashcards, plans, suggestions, and Study Coach messages; and the usage count needed to apply the daily allowance and abuse-prevention limits. The service sends a bounded subset relevant to the requested feature, not the entire saved workspace. Do not enter sensitive personal information, confidential or unreleased exam material, another person's information, or material you do not have the right to process.
- Social profile: tagged username, display name, character design, bio, school, year group, study goal, presence choice, last-active time, and social privacy choices. Avoid entering contact details, a precise location, or anything sensitive in profile fields.
- Owner operations: the two approved Study Sheet operator accounts can receive account ID, email address, authentication provider, signup, confirmation, sign-in and last-active times, display name, tagged username, selected subjects, overall subject percentages, setup status, enabled-feature list, and numeric totals for focus sessions, study completions, paper attempts and mistakes. They can also see broad app areas and limited feature signals used by a signed-in account during the selected reporting period. The routine owner directory does not include passwords, tokens, private messages, AI prompt or output text, topic notes, mistake or correction text, planner content, paper answers, reflections, or individual marks.
- Study Sheet Pro purchase: if you buy a Pro pass, Study Sheet stores the payment provider's reference ID, the plan and price, currency, payment status, and the time it completed, so it can confirm the payment and apply Pro access to your account. It does not store your card number or other full card details -- those go directly to Ziina.
- Study Sheet Pro interest survey: a signed-in account is shown this one-time prompt once, asking which possible paid features would be used and whether a monthly price feels reasonable. If answered, the account, its display name or tagged username, and the specific answer are stored and can be viewed individually by the two approved operators -- this one survey is not anonymous. It can be reopened and changed at any time from Settings. It does not appear for guests.
- Daily leaderboard: for a signed-in account with a social profile that uses social features, one number a day: the minutes of timed study (focus sessions and timed papers) on your own calendar day, with that date. Nothing else about your study is sent for it. Whether you appear is covered below.
- Photo notes: a photo you add is read on your own device and is never uploaded. The text it produces stays in the page until you choose to create something from it, when it is sent like pasted text.
- Parent report and Study Wrapped: built on your device from your own study record. They leave only through the share option you choose, such as a message app. Study Sheet does not store or send them.
- Days the app was opened: the dates of the last ten days you opened Study Sheet, kept in your study data, so the one-time Pro survey waits until your third day instead of your first.
- Friends: profile searches, friend requests, accepted connections, declined-request cooldowns, removed connections, blocks, mutual-friend counts, and the progress categories you choose to share.
- Messaging: message sender and recipient, message text, sent time, read time, unread counts, and short-lived typing status. Messages are limited to 1,200 characters and can be exchanged only between accepted friends who are not blocked.
- Device, analytics, and service information: local browser identifiers used to separate guest and signed-in data, a key generated for a single page load that is never stored on the device, broad app areas opened, limited feature signals such as starting a focus session or sending a message, cached app files, and operational information such as IP address, browser type, request time, security events, and delivery records processed by the service providers listed below. Analytics events do not contain message text, task text, notes, marks, corrections, planner content, or paper answers. When an account is signed in, its limited events can be associated with that account for private operational reporting.
- Support: information you include when contacting the operator. Do not send passwords, authentication tokens, backup files, or private messages unless specifically and securely requested.
What other users can see
A social profile exists to be found. Other signed-in users can search for a discoverable profile by username, display name, or school. What they then see is your handle, display name, character, bio, school, year group, study goal, and mutual-friend count, plus your presence if you have allowed activity sharing. So treat every profile field as public to signed-in users, and keep private details out of them.
Accepted friends may exchange messages and see only the progress categories you enable. Subject percentages, seven-day study minutes, streak, and focus-timer status are separate switches and are off by default. Friends do not receive your notes, marks, corrections, planner entries, exam dates, task names, full activity history, email address, or complete private study state through the Friends interface.
Messages are not public, and the database only lets the two participants read them. They are still stored by Supabase, and they are not end-to-end encrypted. Removing a friend closes the conversation in the app for both people, but it does not immediately erase the stored history. Blocking goes further: it removes the connection, stops new contact, and hides the two accounts from each other in search.
Two approved operators can open a private account directory, used to see how the app is being adopted, whether it is reliable, and who needs support. It shows the account email and sign-in provider, the subjects selected, overall percentages, numeric study totals, the broad areas used, and the times of signup, sign-in, sync, and last activity.
What it deliberately withholds is everything you actually wrote. No passwords or tokens. No private messages. No AI prompts or outputs, topic notes, mistakes, corrections, planner content, paper answers, reflections, or individual marks. No other student can open this directory at all.
The daily leaderboard is shown to signed-in users. It lists a username without its number tag, the study character, that day's timed study minutes, and a Pro badge for Pro accounts. It never shows a display name, school, email, or account identifier. You appear on it if your profile is findable, or if you choose to join; you can hide yourself from it at any time from the leaderboard, and people who have blocked each other never see each other there. While few students are on it, the list also shows sample entries that are not real people or accounts; the leaderboard says so, and they fade out as more students join.
How AI processing works
AI runs only when you ask it to. When you do, Study Sheet sends Cloudflare Workers AI a bounded selection of what that particular request needs — never your whole workspace. Depending on the tool, that can be selected subjects, boards and papers; topic progress and notes; attempt marks, dates and reflections; mistakes and corrections; targets and recent planner items; your prompt; pasted text; text your browser extracted from a PDF you chose; or a recording you uploaded for transcription.
Several things deliberately do not happen. The original PDF is never uploaded, and Study Sheet does not OCR it. A photo for photo notes is read on your device and never sent to Cloudflare or anyone else. An uploaded recording goes to Cloudflare only to produce the transcript you asked for, and is not added to your library. Study Sheet does not download YouTube videos. It does not upload, OCR, or send a linked exam-paper or mark-scheme PDF — opening an external paper is a direct connection between your browser and the source, with Study Sheet out of the loop.
Submitting a public YouTube or webpage URL is different: the Study Sheet server fetches the available public captions or readable page text for that one request. If a video exposes no transcript, only its public title and description are used, and the result is clearly labelled as a topic guide.
What comes back is automatically generated study material. For a signed-in account, Study Sheet saves that output in Supabase along with the source type, title, URL, and a usage record, so you can reopen it and so it can be counted against your allowance. What it does not deliberately keep is the source itself: the raw recording, your pasted text, the extracted PDF text, the webpage text, and the transcripts are not stored in the saved item. Cloudflare and the external source may still process request and operational information under their own retention practices.
AI output can be wrong. It is there to help you revise. It is never used to make a legal, employment, admissions, grading, credit, or similarly significant decision about anyone.
How information is used
- To create and secure accounts, complete authentication, and send confirmation or recovery email.
- To provide, personalise, save, restore, and sync the revision workspace.
- To calculate progress, study suggestions, streaks, and timer status from the information you enter.
- To generate requested notes, flashcards, quizzes, explanations, debriefs, revision plans, and Study Coach answers; retain them in your account; apply plan allowances; and prevent unsafe or abusive AI use.
- To provide profile discovery, friend requests, selected progress sharing, presence, messaging, read status, and typing indicators.
- To prevent abuse using access controls, CAPTCHA, blocks, request limits, message limits, and diagnostic records.
- To understand adoption, active use, subject coverage, feature use, and which broad product areas need improvement.
- To monitor signed-in account activity, investigate faults, and respond to account support requests using the limited owner directory described above.
- To investigate faults, respond to requests, enforce the Terms, protect rights, and comply with legal obligations.
Study suggestions, generated answers, performance insights, and progress summaries are planning aids. Study Sheet does not use personal information to make legal, employment, admissions, grading, credit, or other similarly significant decisions.
Legal grounds
Where applicable law requires a legal basis, information is processed to provide the service and AI features you request; with your consent for optional choices such as progress sharing; for the legitimate interests of operating, measuring, and securing the service; and where necessary to comply with legal obligations or protect legal rights. You can choose whether to request an AI feature and can change social sharing choices at any time. Withdrawing a choice does not affect processing that was lawful before it was changed.
Cookies and device storage
Study Sheet sets no cookies. The site sends no Set-Cookie header, and there is nothing to accept or reject, which is why you are not asked.
Two kinds of storage are used on your own device, and neither is used to track you:
- Browser local storage, for your work: your study data, settings, and the guest-session choice. This is what lets the planner work without an account and keeps your work when you close the tab. It is strictly necessary to provide what you asked for, it stays on that browser profile, and clearing site data removes it.
- Browser database storage, for photo notes: the first time you read a photo, the text reader and its English language data are downloaded from Study Sheet and kept in the browser so they do not download again. They contain no personal information.
- Nothing for analytics: no identifier is stored on your device for measurement. Product events use a key generated for a single page load and discarded when the page closes, so a returning browser is not recognised.
Page-view measurement uses Cloudflare Web Analytics, which is cookieless, stores nothing on your device, and does not follow visitors between sites. Signing in stores a session so you stay signed in; signing out removes it.
Local storage, cloud sync, and backups
Guest study data and results from public checklists and free tools are stored in browser local storage, while the guest-session choice and temporary course or paper preselection are stored for the browser session. Public tool inputs and results are not synced to an account unless you deliberately continue in Study Sheet and enter or import them there. Nothing is stored on the device for analytics. Local data remains on that browser profile until you reset it, clear site data, or remove the browser profile.
For a signed-in account, the app keeps a local cache for resilience and syncs a versioned copy of the study state to that user's study_profiles record in Supabase. Row-level security restricts the full record to the authenticated user. A separate owner-only database function derives the limited account and numeric study summary described above without returning the full study-state document. Conflict checks help avoid silently replacing a newer copy from another device.
The installable app caches same-origin interface files for performance and limited offline reopening. It does not place third-party paper PDFs in the Study Sheet service-worker cache.
JSON backups and Excel exports are created in your browser and downloaded where you choose. They may contain names, notes, marks, corrections, dates, and study history. Study Sheet does not separately upload the exported file, but restoring while signed in places the restored study state into normal cloud sync. Store exports carefully.
Service providers
- Cloudflare hosts and protects the website, provides Workers AI for user-requested AI study features, and runs Cloudflare Web Analytics, which measures page views without cookies and without tracking visitors across sites. Cloudflare may process the submitted learning fields plus network, request, security, output, and diagnostic information needed to provide those services.
- Supabase provides authentication, account storage, private study sync, Friends data, messages, presence, realtime updates, AI outputs and usage records, database security, and aggregate product analytics storage.
- Brevo sends transactional account email and processes sender, recipient, delivery, bounce, and related email records.
- hCaptcha processes browser, device, network, interaction, and challenge information needed to detect automated or abusive authentication attempts.
- Ziina processes payment when you choose to buy a Study Sheet Pro pass. It handles your card details directly on its own checkout page; Study Sheet never sees or stores full card details, and only receives back a payment reference, amount, currency, and status.
- Google or Discord processes an authentication request under its own notice when you choose that provider.
- GitHub processes information you voluntarily submit to the public project issue tracker.
These providers may process information in countries outside the United Arab Emirates. Study Sheet sends each one only what its service needs, and relies on their service terms, security measures, and transfer safeguards. Data-protection rules still apply to those transfers.
External papers, learning resources, and communities
Study Sheet provides metadata and links to exam boards, paper archives, notes providers, educator channels, publishers, libraries, and lawful open-book services. It does not host the linked paper, note, video, or textbook files and does not bypass source access controls. Permissions held for specified exam material are used only within their documented scope; they do not mean that every linked paper is licensed for every use or that an exam board endorses Study Sheet.
When you open an external link, video destination, or paper inside the in-app viewer, your browser connects directly to the external provider. That provider can receive standard connection information such as your IP address, browser details, referrer, and request time and may use its own storage technologies. The provider's privacy notice and terms then apply.
The Partner Communities directory contains curated links to independently operated Discord servers. Study Sheet can receive aggregate link-use signals but does not receive or control activity inside those servers. Discord and each server operator are responsible for their own rules, moderation, membership, and information practices.
Retention
- Guest data remains until it is reset or browser data is cleared.
- Signed-in study state, social profile, connections, blocks, progress snapshots, and messages generally remain until the relevant item is changed or the account is deleted.
- A Study Sheet Pro survey answer remains, tied to that account, until it is changed from Settings or the account is deleted.
- Saved AI outputs remain in the signed-in account until the output is deleted using the feature's delete control or the account is deleted, subject to limited security, legal, and backup retention. Deleting an output does not restore the daily allowance used to generate it.
- AI usage-event records, including request identifier, feature, units, status, and timestamps, remain to apply allowances, investigate misuse, and operate the service, generally until the account is deleted.
- Removing a friend stops access through the app but does not by itself erase stored messages. Account deletion removes records linked to that account through database deletion rules.
- A typing indicator expires after a few seconds. Its expired database status may remain until it is updated or the account is deleted.
- Declined-request records can remain to enforce safety cooldowns. Rate-limit, authentication, email-delivery, security, and infrastructure logs remain according to operational needs, provider policies, and legal requirements.
- Deduplicated product analytics events can remain for up to 13 months. Nothing identifying a browser is stored with them, so guest reporting is only ever a total. Events recorded while signed in can appear in the private owner directory, as broad per-account totals and last-use times.
- Daily leaderboard totals are kept for 14 days and then deleted.
- Files you export remain wherever you save or share them.
Security
Study Sheet is protected by encrypted transport, authentication, row-level database security, narrowly scoped database functions, access restrictions, rate limits, CAPTCHA, blocking tools, and conflict-aware saves. None of that makes any internet service absolutely secure, and this one is no exception.
What helps most is on your side: use a unique password, protect your email account, sign out on shared devices, and tell us quickly if you think your account has been misused.
Your choices and rights
- Use guest mode without creating an account.
- Choose whether guest progress is imported into an account. It is not attached automatically.
- Edit your study information and social profile in the app.
- Keep progress categories private, accept or decline requests, remove friends, and block or unblock accounts.
- Download a JSON backup or Excel export and reset study data from Settings.
- Choose whether to use AI features and delete saved AI output using the controls provided for that feature.
- Delete a signed-in account from Settings. Keep any export you need before deletion.
- Request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where applicable by emailing the operator.
Requests may require reasonable identity verification. Some information may be retained where required for security, legal claims, or other lawful obligations. The UAE's official data-protection overview explains the federal framework and relevant individual rights.
Young users
Study Sheet is built for students, and some of them are under 18. If that is you, read this notice with a parent or guardian and get whatever permission is required where you live.
Some practical advice for any student using it: go by a first name or a nickname, and only add people you actually know. Keep contact details, your precise location, your school timetable, passwords, and anything sensitive out of your profile, your messages, your notes, and your AI requests. Parents and guardians are welcome to contact us about a young person's information.
Changes and contact
This notice may change when the service, providers, or legal requirements change. Material changes will be reflected by updating the date above and, where appropriate, by an in-app notice.
For privacy, support, security, or takedown requests, email appspire.2@gmail.com. Public project reports may also be opened at GitHub Issues, but issues are public. Never post an email address, account detail, backup, private message, or other personal information there.