StudyBro
Privacy Policy
Effective Date: 16 March 2026
Governed by Swiss law (nFADP) and GDPR-compliant
1. Introduction and Data Controller
This Privacy Policy explains how StudyBro (the “App”) collects, uses, stores, and protects your personal data, and what rights you have in relation to it.
StudyBro is developed and operated by:
Léonard Dinichert
Individual developer — Geneva, Switzerland
Email: studybro.ch@gmail.com
Léonard Dinichert is the data controller for all personal data processed in connection with StudyBro.
This policy applies to all users of the StudyBro iOS application and any associated services. By using StudyBro, you acknowledge that you have read and understood this Privacy Policy.
2. Applicable Law
StudyBro is committed to protecting your privacy in accordance with:
- The Swiss Federal Act on Data Protection (nFADP / nLPD), applicable to all users;
- The EU General Data Protection Regulation (GDPR / Regulation (EU) 2016/679), applicable to users located in the European Economic Area (EEA);
- The UK GDPR, applicable to users located in the United Kingdom.
Where both Swiss law and GDPR apply, we apply the stricter standard. If you are in the EU, all references to legal obligations include GDPR obligations.
3. Data We Collect
3.1 Account and Profile Data
When you create an account, we collect:
- First and last name
- Username / display name
- Email address
- Password (hashed; we do not store plaintext passwords)
- Profile picture (optional)
- Education level and subjects of study (optional, used to personalise your experience)
3.2 Study Content
We store the content you create and upload, including:
- Study notes, flashcard sets, and Q&A cards
- AI chat conversations and prompts
- Scanned or imported documents (PDFs, images)
- Attachments and files you upload
3.3 Camera Access
If you use the built-in document scanner, we request access to your device camera to capture documents and handwritten notes. We do not record continuous video, access the camera in the background, or use the camera for any purpose other than scanning content you explicitly choose to scan. Scanned content is stored in your account.
3.4 Contacts Access
With your permission, the App may access your device’s contact list to help you find friends who are also using StudyBro. We do not upload or store your full contacts list on our servers. Contact data is used only at the time of the lookup and is not retained.
3.5 Usage and Technical Data
We automatically collect technical and usage data, including:
- Device type, operating system, and app version
- Features used, screens viewed, and interaction timestamps
- Session duration and study statistics (Pomodoro sessions, streaks, etc.)
- Error logs and crash reports
We do not collect precise GPS location data.
3.6 Subscription and Purchase Data
All in-app purchases and subscriptions are processed through Apple’s in-app purchase system. We do not receive your payment card details. We may receive from Apple a subscription status indicator (active, expired, cancelled) and a transaction identifier, which we use solely to manage your access to premium features.
4. How We Use Your Data
We use the personal data we collect for the following purposes:
- Providing the service: creating and managing your account, enabling all app features, storing your study content, and delivering AI-powered responses.
- Personalisation: adapting the app experience to your subjects, education level, and study preferences.
- Service improvement: analysing usage patterns, debugging errors, and improving features and performance.
- Security and integrity: detecting fraud, preventing abuse, and protecting our users and infrastructure.
- Communications: sending password reset emails, important service notices, and (where you have opted in) notifications about your study activity.
- Legal compliance: meeting our obligations under applicable law, including responding to lawful requests from authorities.
5. Legal Basis for Processing (GDPR)
For users in the EEA, the UK, or Switzerland, the legal bases on which we process your personal data are:
- Performance of a contract (Art. 6(1)(b) GDPR): processing necessary to provide the App and its features to you.
- Legitimate interests (Art. 6(1)(f) GDPR): analytics, security, service improvement, and fraud prevention, where these do not override your rights.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR): where we are required by law to process your data.
- Consent (Art. 6(1)(a) GDPR): for optional features (e.g., contact access, optional notifications). You may withdraw consent at any time without affecting the lawfulness of prior processing.
6. Third-Party Services and Data Processors
We share your data with the following third-party service providers solely to operate the App. These providers act as data processors under our instructions.
Google Firebase (Alphabet Inc.)
We use Firebase for authentication, database storage, file storage, and hosting. Your data may be stored in Firebase data centres located in the EU or the United States. Google’s processing is governed by a Data Processing Agreement under the EU Standard Contractual Clauses (SCCs).
Firebase Privacy information: https://firebase.google.com/support/privacy
OpenRouter
AI features in StudyBro are powered by OpenRouter, which routes your prompts to one or more AI model providers. When you use an AI feature, the content of your prompt (and any context you include) is transmitted to OpenRouter and to the relevant model provider. We do not intentionally include account identifiers (such as your email) with prompts. OpenRouter and model providers may log requests for security and monitoring purposes, subject to their own policies.
Do not include passwords, precise addresses, phone numbers, or other sensitive personal data in AI prompts.
OpenRouter Privacy Policy: https://openrouter.ai/privacy
Apple Inc.
If you sign in with Apple or make in-app purchases, Apple processes relevant data under its own privacy policy. Apple’s processing is governed by Apple’s standard terms and the EU SCCs where applicable.
Apple Privacy Policy: https://www.apple.com/legal/privacy/
Google Sign-In
If you choose to sign in with Google, Google processes your authentication data under its own privacy policy and our OAuth agreement.
Google Privacy Policy: https://policies.google.com/privacy
We do not sell, rent, or share your personal data with third parties for their own independent advertising or marketing purposes.
7. International Data Transfers
Your data may be transferred to and processed in countries outside Switzerland or the EEA (in particular the United States), through our use of Firebase and OpenRouter. We ensure that any such transfers are covered by appropriate safeguards, including:
- EU Standard Contractual Clauses (SCCs) with Google Firebase;
- Adequacy decisions or other transfer mechanisms as applicable.
By using StudyBro, you acknowledge that your data may be transferred internationally as described above.
8. Data Retention
We retain your personal data for as long as your account is active and for a reasonable period thereafter to fulfil legal, security, or operational obligations.
- Account data: retained while your account exists, plus up to 90 days after deletion for backup clearance.
- Study content (notes, flashcards, AI chats): retained while your account exists; deleted when you delete your account or the individual item.
- Usage logs and error data: retained for up to 12 months from collection.
- Subscription records: retained for up to 7 years as required by Swiss accounting and tax law.
When you delete your account, your personal data is deleted or anonymised from active systems. Residual copies in backups are removed according to our backup provider’s standard schedules (typically within 90 days).
9. Your Privacy Rights
Depending on your location, you have the following rights regarding your personal data:
- Right of access: you may request a copy of the personal data we hold about you.
- Right to rectification: you may ask us to correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”): you may request deletion of your personal data, subject to legal retention requirements.
- Right to restriction: you may ask us to restrict processing in certain circumstances.
- Right to object: you may object to processing based on legitimate interests.
- Right to data portability: you may request your data in a structured, machine-readable format.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting prior processing.
Swiss users also have equivalent rights under the nFADP, including the right to information, correction, and deletion.
To exercise any of these rights, please contact us at studybro.ch@gmail.com. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.
You also have the right to lodge a complaint with a supervisory authority:
- In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC) at https://www.edoeb.admin.ch
- In the EU: the data protection authority in your country of residence.
10. Children’s Privacy
StudyBro is not directed to children under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13 without verifiable parental consent, we will take steps to delete that data promptly.
Users aged 13 to 17 (or below the age of majority in their jurisdiction) may only use StudyBro with the consent and under the supervision of a parent or legal guardian. By allowing a minor to use the App, the parent or guardian accepts responsibility for the minor’s use and for compliance with these terms.
11. Security
We implement technical and organisational measures to protect your data against unauthorised access, loss, or alteration. These include:
- Firebase security rules restricting access to your data to your own account;
- Encrypted data transmission (TLS/HTTPS);
- Password hashing via Firebase Authentication;
- Access to backend systems limited to the developer for maintenance and support purposes only.
No system is perfectly secure. In the event of a personal data breach that is likely to result in a high risk to your rights, we will notify you and/or the relevant supervisory authority as required by applicable law.
12. Cookies and Tracking
StudyBro is a native iOS application and does not use browser cookies. We may use local device storage (e.g., app preferences) to remember your settings. We do not use third-party advertising trackers or cross-app tracking technologies.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the App, our practices, or applicable law. We will notify you of material changes via an in-app notice and/or email at least 14 days before the new policy takes effect. Continued use of the App after the effective date of a change constitutes your acceptance of the updated policy.
The current version of the Privacy Policy is always available in the App (Settings → Security and Privacy) and on our website.
14. Contact and Data Protection Requests
For any questions about this Privacy Policy, to exercise your rights, or to report a data protection concern, please contact:
Léonard Dinichert
StudyBro
Geneva, Switzerland
Email: studybro.ch@gmail.com
We aim to respond to all privacy-related enquiries within 30 days.
Last updated: 16 March 2026 — StudyBro Privacy Policy v1.0