Trust & Safety
Studyfin is a K–10 learning app used by families, teachers, and schools. This page explains, plainly, how we protect children's privacy, how we handle student data for schools, how we keep our AI-generated content safe, and the security practices behind the product. Where something is aspirational or on our roadmap, we say so.
1. Our safety commitment
Studyfin is built for children first. Our commitment to families and schools is simple: collect only the data we need to run the service, protect it, keep parents and schools in control, and be honest about how our content is made. We never sell children's personal data and we run no behavioral advertising to children. Because much of our learning content is generated by AI, we are careful not to overstate it — we explain below exactly what our automated checks do and where their limits are.
2. Children's privacy (COPPA)
Studyfin is designed for learners including children under 13, and we follow the principles of the U.S. Children's Online Privacy Protection Act (COPPA) and comparable laws.
- Consent gate for under-13: a neutral age screen runs before a learner starts. A child under 13 must be added by a parent, guardian, or school, who provides consent — until then the child cannot access lessons. We record who consented and when.
- Parent controls: from the parent dashboard, a parent or guardian can block any subject or topic per child, review progress, and manage the account. Schools may provide consent for school-managed accounts.
- Deletion on request: parents and schools can review, export, or permanently delete a child's information and revoke consent — directly from the dashboard (Download data / Delete data) or by contacting us. We delete the account and associated personal data unless we are required to retain specific records by law.
- Data minimization: we collect only what the educational service needs, and we do not condition a child's participation on disclosing more than is reasonably necessary.
3. Student records (FERPA)
When a school or district uses Studyfin, the school remains the owner and controller of student education records. Studyfin acts as a school official / service provider under the Family Educational Rights and Privacy Act (FERPA), performing an institutional service the school would otherwise perform itself, under the school's direction and control.
- Used only to provide the service: student data is used solely to deliver Studyfin to that school and its students — not for advertising and not for our own unrelated purposes.
- School stays in control: access is role-based, and the school directs how records are used and who may access them.
- Export & delete on request: schools can export student data (e.g. CSV) and request deletion. On termination, we return or delete student data per the agreement.
- No re-disclosure: we do not re-disclose student records except to sub-processors needed to run the service, or as the school directs or the law requires.
4. How our AI content is made safe
Being direct: most Studyfin lessons and quizzes are generated by AI and then automatically checked by software. We do not claim this content is official, expert-written, guaranteed, or 100% accurate. Here is what actually happens and where the limits are.
- Generated, then machine-checked: content is produced by AI and passed through automated checks — including a second automated pass that re-checks lessons and quiz answers for correctness and age-appropriateness before a student sees them.
- Safety filters on every prompt: strict content rules are applied to exclude violent, sexual, hateful, scary, or profane material, tuned for a school setting.
- Moderated, delivered-first chat: student-facing chat is screened by automated moderation before a reply is delivered, so unsafe content is filtered rather than shown.
- Human-reportable: families and teachers can report any item that looks wrong or inappropriate. Reported content is re-checked and corrected or removed.
- No personal data trains third-party models: we do not send students' personal information to third-party AI providers to train their models. Prompts used to generate content are not used to identify students.
- Honest about limitations: automated checks reduce errors but do not eliminate them. AI can still be wrong. Please treat generated content as a study aid, verify anything important, and report issues so we can fix them.
5. Security
Studyfin runs on trusted cloud infrastructure (Google Cloud / Firebase). Our security practices are designed to protect student and account data:
- Encryption: data is encrypted in transit (HTTPS/TLS) and at rest.
- Least-privilege access: access to systems and data is limited to what a role needs; sensitive operations are enforced server-side rather than trusted to the browser.
- Tested security rules: database access rules are enforced on our servers and are covered by tests to help prevent unauthorized reads and writes.
- Audit logging: sensitive actions are recorded in an audit log for accountability and review.
- Staff sign-in: we use trusted identity providers, and single sign-on (SSO) is available for staff and school accounts where supported (Google and Microsoft).
No method of transmission or storage is completely secure. We describe practices we follow and are designed to protect your data, and we work to respond promptly to any incident. Formal certifications such as SOC 2 are on our roadmap — ask us where each stands for your timeline.
6. Data handling & retention
What we collect and why
- Account info (name, email, role) — to create and secure accounts.
- Learning activity (lessons, quizzes, progress, mastery) — to deliver and adapt the learning experience and show progress to parents and teachers.
- Payment info — processed by Stripe; we do not receive full card numbers.
- Technical logs — standard logs needed to operate and secure the service.
Retention, export & deletion (DSAR)
We keep personal information only as long as needed to provide the service or meet legal obligations, then delete or anonymize it. Some financial and transaction records may be retained after account erasure where the law requires it.
To make a data subject access request (export or deletion), parents and schools can use the dashboard (Download data / Delete data), open a support ticket, or email us (see Contact). Schools can define a full retention schedule in their Data Processing Agreement. For the full detail, see our Privacy Policy.
7. For schools & districts
Request our DPA (Data Processing Agreement)
We provide a Data Processing Agreement that covers roles, sub-processors, security, retention, and data return/deletion. A DPA template is available on request, and we're happy to review your district's own agreement.
School accounts include role-based access, an audit log, AI-moderated messaging, CSV data export, and Google & Microsoft SSO, built to FERPA / COPPA principles. On our roadmap: SOC 2, a formal accessibility (VPAT / WCAG) audit, and Clever / ClassLink roster sync — see for-schools or ask us where each stands.
8. Contact
Questions about privacy, security, or a data request? Email privacy@studyfin.app, use the in-app assistant, or open a support ticket. See also our Privacy Policy, Terms, and Safety & Compliance pages.