§StudySec
Privacy & data

Privacy Policy

Last updated: 9 June 2026
Effective from: 30 May 2026

There is also a shorter, plain-English version at studysec.app/privacy-for-students. They say the same things — that one is just easier to read.

StudySec is a study assistant for university and upper-secondary students. To work, it needs to handle some of your personal information — your account details, the lecture material you upload, the notes you make, the research you do, and the deadlines and study sessions you plan. This policy explains exactly what we collect, why, who else sees it, how long we keep it, and the rights you have over it. It is written to be read. If anything in it is unclear, tell us and we will fix it.

Your work is yours. We do not train AI models on it. We do not sell it. We do not share it beyond the providers we strictly need to deliver the service to you. When you leave, we delete it.

Waitlist

If you submit your email address via the waitlist form on this site, we collect and store your email address for the sole purpose of notifying you when StudySec launches. This is a pre-release waitlist — you have not signed up for the StudySec service itself.

What you will receive. Two emails only: a confirmation when you join, and one email when StudySec launches. Nothing else.

Legal basis. Consent — Article 6(1)(a) UK GDPR / EU GDPR. You gave consent when you submitted the waitlist form. This is separate from the performance-of-contract basis that applies to users of the StudySec service.

Processors. Your email address is stored in Supabase (EU Frankfurt) and delivered via Resend. Both are listed as sub-processors in the Sub-processors section below.

Retention. Your email is kept until the launch email has been sent, or until you unsubscribe — whichever comes first. After the launch email is sent, waitlist data will be deleted.

How to withdraw. Click the unsubscribe link in any email we send you, or contact support@studysec.app.

1.Who we are

StudySec is operated by Microflow Enablement Ltd, a company registered in England and Wales (company number 17197302), with its registered office at 20-22 Venture West Greenham Business Park, Newbury, England, RG19 6HX. In this policy, "StudySec", "we", "us", and "our" all refer to Microflow Enablement Ltd.

Microflow Enablement Ltd is the data controller for the personal information described in this policy. That means we are the company legally responsible for how it is handled.

You can contact us about anything in this policy by emailing privacy@studysec.app. We aim to respond to all privacy enquiries within five working days.

2.Who this policy applies to

This policy applies to everyone who uses StudySec, including:

  • Visitors to studysec.app who have not signed up for an account.
  • People who have signed up for an account, whether on a free trial, the Essentials tier, or the Pro tier.
  • People who have linked their Google Calendar or Google Drive to StudySec.
  • People who have contacted us by email.

Where you live

StudySec is built for students in the United Kingdom and the European Union, and accepts sign-ups from Australia, New Zealand, and other countries. This policy is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025; the EU General Data Protection Regulation (EU GDPR); the Australian Privacy Act 1988 and Australian Privacy Principles (APPs); and the New Zealand Privacy Act 2020 and the Information Privacy Principles.

Where any of these laws give you specific rights, we describe them in section 11. The substantive protections of this policy apply equally to everyone.

Your age

You must be at least 18 years old to sign up for a StudySec account. We do not knowingly accept sign-ups from anyone under 18. If we discover that someone under 18 has signed up, we will close the account and delete any data we have collected.

3.What we collect, and why

We only collect information that we need to deliver the service to you. We have grouped what we collect into the categories below. For each category, we explain what is collected, why, and what would happen if you chose not to provide it.

3.1 Account information

What we collect: your email address, a password (which we store as a one-way hash, never as readable text), and, if you sign in with Google, the OAuth tokens needed to maintain your session.

Why: to create your account, authenticate you when you log in, and contact you about your account.

If you do not provide it: you cannot use StudySec, because we cannot identify you as the holder of a specific account.

3.2 Your course information

What we collect: the name of your institution, your degree programme or course, your year of study, the academic terms you are studying in, the modules you are taking, and any subjects and topics within those modules.

Why: so that StudySec can organise your material by subject, recognise what your notes are about, and tailor research, planning, and practice to your actual course.

If you do not provide it: the product still works but works less well.

3.3 Documents and material you upload

What we collect: the files you upload — lecture slides, PDFs, notes, scanned pages, and similar academic material — along with the text we extract from them, the page count, the file type, and metadata such as the filename and which subject or topic the file relates to. Files are stored in encrypted storage in the European Union.

Why: so we can read your material, organise it into your notes, make it searchable, and let the AI agents work on it.

If you do not provide it: you can use StudySec without uploading anything, but most of its value depends on the material you bring to it.

3.4 Notes and your work in StudySec

What we collect: the notes you create or that StudySec creates for you, including their content, the subject and topic each note belongs to, when it was made and last edited, whether the change was made by you or by an AI agent, and the full version history. We also store a numerical embedding for each note — a list of numbers derived from the note's content that lets us find related notes when you ask a question. These embeddings cannot be turned back into the original note.

Why: notes are the heart of StudySec. Version history lets you see how a note has changed and what was edited by an AI agent. Embeddings power the research feature's ability to find your most relevant notes in response to a question.

3.5 Research chats

What we collect: every research conversation you have inside StudySec — your questions, the answers, the web sources that informed each answer, and which of your own notes were used to inform the answer. We retain the chat title and the linked subject.

Why: so you can come back to a research conversation later, see where each claim came from, and send any part of it to your notes.

3.6 Your planner

What we collect: deadlines, exams, study sessions, lectures, and other events; their start and end times; whether they are complete; whether they were created by you, by StudySec, or imported from Google Calendar; and, for AI-suggested sessions, whether you accepted, edited, or rejected them. We retain rejected suggestions so the AI does not suggest the same session again.

3.6A Google Calendar

What we collect: When you connect Google Calendar, we import your calendar events into StudySec. For each imported event, we store the title, start time, end time, all-day status, and a Google identifier. We do not import attendees, location data, or descriptions. Imported events are refreshed periodically while Google Calendar is connected. We also receive the email address and display name of the Google account you connect, so we can show you which account is in use and manage the connection.

Why: So your study commitments and your personal commitments appear together in the StudySec planner, giving you a unified view of your week. The Google identifier lets us keep your StudySec view consistent with your actual Google Calendar – for example, if you delete an event in Google Calendar, we know which event to remove from StudySec.

3.7 Quizzes and practice

What we collect: the quizzes generated for you, the questions in each quiz, your attempts, your answers, your scores, and which notes the questions were drawn from.

3.8 Your onboarding interview

What we collect: the conversation you have with StudySec's onboarding agent when you first sign up, the information it extracts (your institution, modules, term dates, key assessments), and any documents you upload during the interview.

3.9 Subscription and billing

What we collect: an identifier from Stripe linking your account to a Stripe customer record, the plan you are on, your subscription status, your free trial status and end date, and the current period end date. Your card details are handled entirely by Stripe — they pass through Stripe's payment form and we never see, store, or process them.

When you sign up for a free trial, your card is collected by Stripe at sign-up but not charged until the trial ends. You can cancel before the trial ends, in which case no charge is made.

3.10 Usage metrics

What we collect: the number of pages we have processed for you in the current calendar month, the number of research chats you have created, and similar counters needed to apply the limits described in your plan. These reset each calendar month.

3.11 Communications with us

What we collect: any emails you send us, support tickets, and any feedback you submit through the product.

3.12 What we do not collect

  • Advertising identifiers, advertising cookies, or tracking pixels. We do not run ads.
  • Geolocation. We do not collect or store your location.
  • Behavioural profiles for the purposes of marketing, personalisation of advertising, or sale to third parties.
  • Special category data (such as health, religion, political views, sexuality) unless you voluntarily include it in your own notes or uploads.
  • Information about anyone other than you.

4.Why we are allowed to process your information

Performance of a contract (Article 6(1)(b))

This is the basis for almost everything in section 3. When you sign up for StudySec, you enter into an agreement with us under which we deliver the service to you. Processing your account, your course information, your uploads, your notes, your research chats, your planner, your quizzes, and your onboarding interview is necessary to deliver that service.

Legitimate interests (Article 6(1)(f))

We rely on legitimate interests for:

  • The background web search during onboarding that looks for publicly available information about your course (such as a module handbook on your university's website).
  • Detecting and preventing misuse of the service, abuse of our systems, and fraud.
  • Understanding, in aggregate, how the product is being used, so we can improve it. We use only privacy-respecting, cookieless analytics.

You have the right to object to any of this processing under section 11.

Consent (Article 6(1)(a))

We rely on your specific consent for:

  • Marketing emails (optional checkbox at sign-up). You can withdraw consent at any time via the unsubscribe link.
  • Connecting Google Drive or Google Calendar (a post-beta feature). Your consent is given through Google's own OAuth screen.

Legal obligation (Article 6(1)(c))

We rely on legal obligation when we have to keep certain records (for example, billing and tax records required under UK law) or when we have to respond to a valid legal request from a court or regulator.

For users in Australia

Under the Australian Privacy Act, we collect and use your personal information for the primary purposes described in section 3. Where we use information for a related secondary purpose that you would reasonably expect (for example, contacting you about a security issue affecting your account), we do so under APP 6.2.

For users in New Zealand

Under the New Zealand Privacy Act 2020 and the Information Privacy Principles, we collect and use your personal information for the purposes set out in section 3. We observe Information Privacy Principle 12 (disclosure of personal information outside New Zealand) by relying on the same transfer safeguards described in section 6.

5.Who else sees your information

To deliver StudySec, we use a small number of carefully chosen third-party providers ("sub-processors") who handle information on our behalf. Every sub-processor is bound by a written agreement that requires them to handle information only on our instructions, to protect it with appropriate security, and to comply with UK and EU data protection law.

Our full, current sub-processor list is published at studysec.app/sub-processors. We commit to giving you at least 30 days' notice — by email and on that page — before adding any new sub-processor that handles your personal information.

StudySec’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Sub-processors at launch

Supabase — hosts our database, file storage, authentication, and realtime services. EU (Frankfurt). Covered by Supabase's Data Processing Addendum.

Vercel — hosts the StudySec web application and runs the server functions that power it. Globally distributed with EU primary regions for personal data. Covered by Vercel's Data Processing Addendum.

Trigger.dev — runs background jobs for document processing. EU-proximate execution. Covered by Trigger.dev's Data Processing Addendum.

AWS Textract — extracts text from scanned PDFs and image files. EU (Ireland — eu-west-1). Covered by the AWS GDPR Data Processing Addendum.

Anthropic (Claude) — powers StudySec's AI agents. United States (see section 6 for transfer safeguards). They see prompts and context we send, including excerpts of your documents and notes — not your raw stored files. Under our commercial terms, user content is not used to train AI models. Anthropic retains API inputs and outputs for a standard period (currently 30 days) for operational purposes, after which they are deleted. Anthropic may retain content for up to two years if their safety systems flag a possible policy violation or if legally required.

Perplexity — powers the web search component of the research feature. United States. They see your research query only — not your notes. Zero Data Retention is in place for the Sonar API.

Voyage AI — converts your notes into numerical embeddings for semantic search. United States. They return a vector and do not retain the original text.

Stripe — processes subscription payments. Your card details go directly to Stripe; we never see them. Covered by Stripe's Data Processing Agreement.

Resend — sends transactional and marketing emails. Globally distributed, primarily United States. Covered by Resend's Data Processing Addendum.

Plausible — provides cookieless website analytics for studysec.app. European Union (Germany). They receive anonymous, aggregate metrics only — page visited, referrer, approximate country, and device type — with no cookies set, no fingerprinting, and no data that can identify an individual. Covered by Plausible’s Data Processing Agreement.

Prighter (iuro Rechtsanwälte GmbH) — our EU GDPR Article 27 representative. Processes personal data submitted by EU data subjects when they exercise their data subject rights via Prighter’s request portal — specifically name, contact details, and the content of the request. Austria (European Union). Covered by a Data Processing Agreement with Prighter.

Post-beta sub-processors (Google)

After our beta period, StudySec offers optional integrations with Google Calendar and Google Drive. These are off by default and only activate if you connect them yourself.

If you connect Google Calendar: StudySec uses the calendar.events scope, which permits both reading and writing of calendar events. We also use the userinfo.email, userinfo.profile, and openid scopes to identify which Google account is connected.

Reading your calendar (all tiers with the integration enabled, including Essentials and Pro): We import your Google Calendar events into StudySec so they appear in your planner alongside your study commitments. Imported events include the title, start time, end time, and a Google identifier. They are stored in StudySec’s database (in the European Union) and refreshed periodically using Google’s incremental sync. Imported events are read-only inside StudySec — to change or remove them, you do so in Google Calendar.

Writing to your calendar (Pro tier only): On the Pro tier, you can optionally have StudySec write study sessions to your Google Calendar. This is controlled by you and is off by default. You can switch it on per-event (you click “Send to Google Calendar” for individual sessions you accept) or in automatic mode (every study session you accept is also added to your Google Calendar). We never write to your calendar without your prior opt-in. On the Essentials tier, write-back is not available — your StudySec study sessions remain inside StudySec only.

When you delete a study session in StudySec that had previously been written to your Google Calendar, we delete the corresponding event from your Google Calendar.

If you connect Google Drive: you can import files from your Drive using the narrow drive.file OAuth scope. StudySec can only access files you specifically choose to import. The original files remain in Google Drive; we process the imported content through the same pipeline as direct uploads.

Specific commitments for Google user data

Where you connect a Google account to StudySec, the following apply:

  • We request only the Google API scopes we need.
  • We do not transfer Google user data to any third party except as needed to provide the service, as disclosed in this policy, or where legally required.
  • We do not use Google user data for advertising. We do not run advertising.
  • We do not use Google user data to train AI models, ours or anyone else's.
  • You can revoke StudySec’s access at any time via myaccount.google.com/permissions or from within your StudySec account settings. When you disconnect, we stop syncing immediately, remove any imported Google Calendar events from your StudySec planner immediately, and delete any cached Google user data and access tokens within 30 days.

Other recipients

Beyond the sub-processors above, your personal information is shared:

  • With professional advisers (lawyers, accountants, auditors) where strictly necessary, under their professional duties of confidentiality.
  • With courts, regulators, or law enforcement if we are legally required to disclose it — and only to the extent required.
  • With a successor in interest if Microflow Enablement Ltd is acquired or merges. We will give you advance notice and the opportunity to delete your account before any transfer.

We never sell your personal information. We never share it with advertisers.

6.Where your information is processed

StudySec's primary storage — your database records and your uploaded files — is hosted in the European Union (Frankfurt, Germany). For the day-to-day work of the application, your information stays in the EU.

Some of our sub-processors are based outside the UK and EU, primarily in the United States. When we use them, your personal information is transferred to those countries. We only make these transfers where we have a legal mechanism in place to protect your information to the same standard as in the UK or EU.

UK to United States

For transfers from the United Kingdom to the United States, we rely on the UK-US Data Bridge (an extension of the EU-US Data Privacy Framework) for any sub-processor that has self-certified under it. For sub-processors that are not certified, we use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, with appropriate supplementary measures.

EU to United States

For transfers from the European Union to the United States, we rely on the EU-US Data Privacy Framework for any sub-processor that has self-certified under it. For others, we use the European Commission's Standard Contractual Clauses (2021 modules), supported by a Transfer Impact Assessment. As an additional safeguard, we maintain Standard Contractual Clauses with our US-based sub-processors regardless of their DPF certification status.

Australia and New Zealand

For users in Australia, the Australian Privacy Act and APP 8 (Cross-border disclosure of personal information) apply. For users in New Zealand, the Privacy Act 2020 and Information Privacy Principle 12 apply. We take reasonable steps to ensure that overseas recipients handle your personal information to the same standard as required by your country's law.

7.How long we keep your information

We keep your information for as long as you have a StudySec account, and for a short period after you delete it.

While your account is active

  • Account details (email, hashed password): retained for the lifetime of your account.
  • Course information, subjects, modules, terms: retained for the lifetime of your account.
  • Uploaded documents and their extracted text: retained until you delete the document or your account.
  • Notes and their full version history: retained until you delete a note or your account.
  • Research chats (active and archived): retained for the lifetime of your account unless you delete them.
  • Planner events, including AI suggestions you have rejected: retained so that the AI does not suggest the same thing twice.
  • Quizzes and attempts: retained for the lifetime of your account.
  • Subscription and billing records: retained for six years after account closure to meet UK tax and accounting obligations.

When you delete your account

When you ask us to delete your account, you have two options:

  • Standard deletion (default): your account is immediately suspended. After a 14-day grace period, all your data is permanently deleted. Within the 14 days you can recover the account by logging back in.
  • Immediate deletion: all your data is permanently deleted right away, with no grace period.

In both cases, deletion is technical and complete. Every database row associated with your account is removed via a cascade delete and every file in our storage is deleted in parallel. Backups are overwritten on our standard backup rotation, which completes within 30 days of deletion. We keep only what we are legally required to keep — primarily billing and tax records for six years.

Information retained by sub-processors

When you delete your account, we instruct our sub-processors to delete your information in accordance with their data processing agreements. Anthropic retains inputs and outputs for a standard period (currently 30 days). Perplexity and Voyage AI do not retain query content after the response is returned. Stripe retains billing records as required by financial regulations.

Google Calendar events (if you have connected the integration): imported events are retained while Google Calendar is connected. They are removed from StudySec immediately when you disconnect the integration, or when Google Calendar reports the event as deleted (whichever comes first). A background sweep runs after disconnection as a redundant safeguard.

8.How we protect your information

8.1 Database isolation

Every piece of personal data in StudySec is tagged with the user it belongs to. Our database enforces, at the database level, that one user can only ever access their own data. This protection (called Row Level Security) is applied to every table, with no exceptions. We do not rely on application code to filter your data — the database itself enforces it.

8.2 File access

Files you upload are not publicly accessible. To access a file, our application generates a short-lived, signed URL each time the file is requested. There are no public links to your files.

8.3 Encryption

Data is encrypted in transit using TLS 1.2 or higher. Data is encrypted at rest in our database and file storage. Google Calendar event titles are encrypted at the field level using AES-256-GCM before being written to the database. Start and end times are stored without field-level encryption as they are required for date-range queries.

8.4 Cookies and analytics

StudySec uses only essential cookies for authentication. We do not use cookies, pixels, or other tracking technologies for advertising, behavioural profiling, or cross-site tracking.

For analytics, we use Plausible.io, a privacy-respecting, cookieless analytics tool. It records anonymous metrics (page views, referrer, approximate country, device type) without setting cookies, without fingerprinting, and without retaining any data that can be tied back to an individual. It is exempt from cookie consent requirements under UK and EU law.

8.5 Operational security

API keys and other credentials are stored exclusively in encrypted environment variables, never in source code or browser code. Access to administrative tools is protected by multi-factor authentication.

8.6 If something goes wrong

If a personal data breach occurs and is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

9.Our commitments

These are the commitments we make to every StudySec user, regardless of where they live or what plan they are on. They reflect what we think a trustworthy study tool should do — not because the law requires it in every case, but because it is the right way to build a product students can rely on.

What this means in practice

  • Best interests first. Where there is a tension between our commercial interests and your best interests, your best interests win.
  • Strong privacy by default. Settings that protect your privacy are switched on by default.
  • No behavioural advertising. We do not run advertising and we never will.
  • No profiling for marketing. The product personalises your study experience, but it does not build a behavioural profile of you for any other purpose.
  • No geolocation. We do not collect or use your location.
  • No nudge techniques. We do not use streaks, guilt-trip notifications, or psychological pressure to push you into using the product more.
  • Easy controls. Deleting your account and exporting your data are easy to find and easy to use.
  • Plain-English transparency. We publish a shorter, plain-English version of this policy at studysec.app/privacy-for-students for anyone who prefers it.

10.AI and your data

StudySec is built on AI agents. Because AI is at the centre of how the product works, you deserve a clear account of what AI is doing with your data.

10.1 What AI does

Six AI agents power different parts of StudySec:

  • The Onboarding Agent helps you set up your course, modules, and key dates in conversation.
  • The Organisation Agent reads files you upload and files them into the right subject and topic.
  • The Notes Agent turns your raw material into structured notes.
  • The Research Agent answers your research questions by combining web search with your own notes.
  • The Planning Agent (Pro tier) proposes study sessions around your deadlines and your life.
  • The Quiz Agent generates practice questions from your notes.

10.2 What data each agent sees

Different agents see different things. Each agent gets only what it needs. The Organisation Agent sees a small excerpt of text from the beginning, middle and end of each document. The Research Agent sees your research question, the most relevant of your own notes, and web results. The Planning Agent sees your deadlines and (if connected) your Google Calendar availability — to find times to suggest, not to read your calendar in detail. When it generates study session recommendations, event titles from your Google Calendar are included in the prompt sent to Anthropic’s Claude API, solely to avoid scheduling conflicts. Anthropic does not use API inputs to train its models by default. No agent has access to your full account simultaneously.

10.3 Where AI processing happens

All AI processing happens at Anthropic (Claude models). Web search happens at Perplexity. Note embeddings are created at Voyage AI. See section 5 for what each provider does with the data we send them, and section 6 for transfer safeguards.

10.4 What AI does not do with your data

Your data is not used to train AI models. We have arranged with our AI providers that user content is excluded from model training. This applies to Anthropic, Perplexity, and Voyage AI under their commercial terms with us. The AI agents personalise the experience for you, based on your data, in your account — they do not learn from your account in any way that affects what other users see.

10.5 Showing the work

Wherever an AI agent has produced something — a note, a research finding, a quiz question, a study session — we show you where it came from. Notes show which lecture or document they were generated from. Research answers cite the web sources used. Quiz questions link back to the notes they were drawn from.

10.6 AI can make mistakes

AI models can be wrong, can misunderstand, and can occasionally produce content that is misleading even when it sounds confident. We recommend treating AI-generated content as a draft that you check, not as a final answer.

10.7 Academic integrity

StudySec is built as an assistant, not a ghostwriter. We do not write essays, exam answers, or coursework for you. Our Academic Integrity Statement sets out our position in detail.

11.Your rights

Under data protection law, you have a set of rights over your personal information. To exercise any right, email us at privacy@studysec.app. We will respond within one month.

11.1 Right of access

You can ask for a copy of the personal information we hold about you and confirmation of how we are using it. We will provide this free of charge in most cases.

11.2 Right to rectification

If any information we hold about you is wrong or incomplete, you can ask us to correct it. Most account-related information you can correct yourself in the product.

11.3 Right to erasure

You can ask us to delete the personal information we hold about you. The easiest way is to delete your account from within the product — see section 7. You can also ask us to delete specific items rather than your whole account.

11.4 Right to restriction of processing

In some circumstances you can ask us to stop processing your information without deleting it — for example, if you contest its accuracy and want us to verify it before continuing.

11.5 Right to data portability

You can ask for a copy of your personal information in a structured, machine-readable format. From launch, StudySec offers an export of your notes as Markdown files and your account data as a JSON file. We are working toward an expanded export that also includes your research chat history and note version history.

11.6 Right to object

You have an absolute right to object to your information being used for direct marketing. You can also object, on grounds specific to your situation, to processing we carry out under legitimate interests.

11.7 Right not to be subject to automated decisions

StudySec makes some automated decisions — for example, deciding which subject to file an uploaded document under, or which study session to suggest. These are not legal or similarly significant decisions about you, and you can override or change any of them.

11.8 Right to withdraw consent

Where we process your information based on your consent, you can withdraw that consent at any time. Doing so does not affect the lawfulness of anything we did before you withdrew.

11.9 Right to complain to us directly

The UK Data (Use and Access) Act 2025 introduced an explicit right for you to complain directly to us about how we are handling your personal information. We treat such complaints seriously, acknowledge them within 30 days, and respond without undue delay. Email privacy@studysec.app to raise a data protection complaint.

11.10 Rights for users in Australia

Under the Australian Privacy Act and the Australian Privacy Principles, users in Australia have the right to access and correct personal information we hold about them (APP 12 and APP 13), and the right to make a complaint about how we handle personal information.

11.11 Rights for users in New Zealand

Under the New Zealand Privacy Act 2020, users in New Zealand have the right to access and correct personal information we hold about them, and the right to make a complaint to the Office of the Privacy Commissioner.

11.12 If you are not happy with our response

If you are not satisfied with how we have handled a request or a complaint, you have the right to complain to a data protection authority:

  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk — 0303 123 1113
  • European Union: the data protection authority of your country of residence — edpb.europa.eu
  • Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au — 1300 363 992
  • New Zealand: Office of the Privacy Commissioner (OPC) — privacy.org.nz — 0800 803 909

We would always prefer the chance to put things right first. Please tell us at privacy@studysec.app before going to a regulator if you can.

12.Changes to this policy

We may update this policy from time to time. When we do:

  • Material changes (changes to what information we collect, what we do with it, who we share it with, or how long we keep it) will be notified to you by email at least 14 days before they take effect, and signposted on the product when you next log in.
  • Non-material changes (clarifications, formatting, minor corrections) will be reflected by updating the "Last updated" date at the top of this page.

We will never apply new uses of your information retroactively to data we already hold without your consent. Older versions of this policy are kept on request — email privacy@studysec.app if you would like to see a previous version.

13.How to contact us

For anything about this policy, your information, or your rights:

  • Email: privacy@studysec.app
  • Post: Microflow Enablement Ltd, 20-22 Venture West Greenham Business Park, Newbury, RG19 6HX, United Kingdom

We aim to respond within five working days, and to formal data protection requests within the legal one-month timeframe.

Data Protection Officer

StudySec is not required to appoint a Data Protection Officer under UK or EU GDPR. Data protection matters are handled directly by the founder, who can be reached at privacy@studysec.app.

EU representative

Because Microflow Enablement Ltd is established in the United Kingdom and offers services to data subjects in the European Union, we have appointed iuro Rechtsanwälte GmbH (trading as Prighter) as our EU representative under EU GDPR Article 27.

iuro Rechtsanwälte GmbH t/a Prighter
Schellinggasse 3, 1010 Vienna, Austria

EU data subjects can contact Prighter directly to exercise their data subject rights or to raise a data protection concern, via Prighter’s data subject request portal: app.prighter.com/portal/12978750567. You can also contact us directly at privacy@studysec.app.