Privacy Policy

Effective 20 June 2025

1. Introduction

This Privacy Policy explains how CAHRAN TECHNOLOGIES LIMITED ("Studytok", "we", "us", "our") collects, uses, and shares information when you use the Studytok mobile and web applications, websites, and related services (collectively, the "Service"). By accessing or using the Service, you acknowledge that you have read and understood this Policy.

2. Data Controller

CAHRAN TECHNOLOGIES LIMITED
E-mail: support@studytok.com

3. Information We Collect

  • Account Information – e-mail address, self-chosen username, optional profile photo, country and region selected at sign-up, and your confirmation that you are at least 16 or have parental consent.
  • Usage & Learning Data – points, streaks, leaderboard rank, question-answer history, in-app events, device identifiers, crash logs, and performance metrics.
  • Uploaded Content – notes, documents, images, videos, links, and other materials you provide.
  • Feed Creation Content – text content used in the creation of educational feeds is collected and stored for analytics purposes to improve content generation and user experience.
  • Session Recording Data – we utilise PostHog's session replay technology to record user interactions, including mouse movements, clicks, page views, and form inputs (excluding sensitive information) for the purpose of improving user experience and troubleshooting issues.
  • Subscription & Transaction Records – plan tier, renewal dates, RevenueCat/Stripe transaction references. (We never store raw payment-card data.)
  • Cookies & Similar Technologies – Firebase and Amplitude analytics cookies, PostHog tracking identifiers, and AdMob identifiers for advertising, subject to consent.

4. Legal Bases

We process personal data only when we have a lawful basis, including performance of a contract (providing the Service), legitimate interests (security, analytics, product improvement), consent (personalised ads where applicable), and legal obligations (accounting, taxation, and regulatory reporting).

5. How We Use Information

  • Operate, maintain, and improve the Service.
  • Generate personalised study questions and Studytok Shorts (your content is sent transiently to Google Gemini for this purpose; no personal data is included in prompts).
  • Analyse user behaviour through session recordings to identify usability issues, optimise user journeys, and enhance the overall user experience.
  • Process and analyse text content from feed creation to improve content generation algorithms and understand user engagement patterns.
  • Provide customer support and transactional communications.
  • Display contextual or personalised advertisements (Google AdMob) after user consent via the Google UMP screen.
  • Monitor and enforce compliance with our Terms of Service.

6. Analytics and Advertising Partners

  • Amplitude (event analytics)
  • PostHog (session replay, user analytics, and behaviour tracking)
  • Firebase (crash reporting and performance monitoring)
  • Google AdMob (advertising)
  • OpenAI Moderation API (screening of publicly shared feeds)
  • Google Gemini API (content generation)

7. Sharing and Disclosure

We do not sell personal data. We share information only:

  • With the processors listed above under data-processing agreements.
  • With authorities when required by law or to protect our rights or users.
  • During a merger, acquisition, or sale of assets (you will be notified beforehand).

8. International Data Transfers

Some partners (e.g., Google Gemini) may process data outside the EEA. All such transfers rely on Standard Contractual Clauses or other lawful safeguards.

9. Data Retention

We keep account data until you delete your account. Deletion triggers immediate removal from production systems; no long-term backups are kept. Session recordings are retained for a maximum of 90 days for analysis purposes. Text content from feed creation is retained indefinitely for analytics and service improvement purposes unless account deletion is requested. Certain financial records must be kept for statutory periods (usually six years).

10. Security

All traffic is encrypted (TLS 1.2+) and data at rest is encrypted (AES-256). We monitor for vulnerabilities and restrict access to authorised staff only.

11. Your Rights (GDPR & Equivalent)

You may request access, rectification, erasure, restriction, portability, or object to processing. E-mail support@studytok.com. You also have the right to lodge a complaint with the Irish Data Protection Commission.

12. Children

Studytok is not directed to children under 13. Users under 16 may use the Service only with verifiable parental consent confirmed via the age-gate checkbox.

13. Breach Notification

If we become aware of a personal-data breach, we will notify the Irish Data Protection Commission and affected users within 72 hours via push notification and e-mail.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be announced in-app and via e-mail (or equivalent notice). Continued use of the Service after the effective date constitutes acceptance.

15. Contact

For privacy questions: support@studytok.com
For copyright notices: legal@studytok.com