Privacy Policy
Last updated: April 12, 2026
1. Introduction
Leonenko Group LLC ("Company," "we," "us," or "our") operates StudyStack( "study-stack.com"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We are committed to protecting the privacy of our users, including teachers, school administrators, parents, and students. Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not use the Service.
2. Information We Collect
2.1 Account Information
When you register for an account, we collect your name, email address, and authentication credentials (via Google OAuth or email sign-up). For teacher accounts, we may also collect your school name, grade level, and subject area.
2.2 Usage Data
We automatically collect information about how you interact with the Service, including pages viewed, features used, resources generated, timestamps, and device information (browser type, OS, screen resolution).
2.3 Generated Content
We store the educational content you generate through the Service (lesson plans, worksheets, study materials, etc.) to allow you to access, edit, and reuse your materials.
2.4 Uploaded Content
If you upload files (documents, images, PDFs), we store these files to process and generate educational materials. Uploaded files are associated with your account and are not shared with other users.
2.5 Payment Information
Payment processing is handled by Stripe. We do not store credit card numbers or full payment details on our servers. We retain only the information necessary to manage your subscription (plan type, billing period, transaction IDs).
3. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain the Service, including generating personalized educational content.
- Improve the Service by analyzing usage patterns and feature adoption (in aggregate, not individually).
- Personalize your experience, including remembering your teaching style, grade level, and subject preferences.
- Process transactions and manage your subscription.
- Send transactional emails (password resets, subscription confirmations, important service updates).
- Respond to support requests and communicate with you about the Service.
4. What We Do NOT Do
We want to be clear about what we will never do:
- We do not sell your personal data to third parties, advertisers, or data brokers. Ever.
- We do not share your data with advertisers or use it for targeted advertising.
- We do not sell student data. Student education records are never monetized, shared, or used for non-educational purposes.
- We do not use your content to train AI models without explicit, opt-in consent. Your generated content is yours.
- We do not display ads on StudyStack.
5. Data Retention and Deletion
- Active account data is retained for as long as your account is active and you continue to use the Service.
- Upon account deletion, we initiate a 30-day soft-delete period. During this window you may reactivate your account and recover your data.
- After the 30-day soft-delete period, all personal data and generated content is permanently and irreversibly purged from our systems, including backups.
- You may request deletion of your data at any time by contacting us at hello@study-stack.com.
6. COPPA Compliance (Children Under 13)
StudyStackcomplies with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13 without verified parental consent.
- Student accounts for children under 13 may only be created by a parent, legal guardian, or authorized school administrator acting in loco parentis.
- We collect only the minimum information necessary to provide the Service to child users.
- Parents and guardians may review, modify, or request deletion of their child's information at any time.
- We do not condition a child's participation on disclosing more personal information than is reasonably necessary.
If you believe we have inadvertently collected information from a child under 13 without proper consent, please contact us immediately and we will promptly delete it.
7. FERPA Compliance
When StudyStackis used by schools or teachers in an educational setting, we act as a "school official" under FERPA with a legitimate educational interest. For full details on our FERPA compliance practices, please visit our FERPA Compliance page.
8. Cookies and Tracking
8.1 Essential Cookies
We use essential cookies to maintain your session, remember your preferences, and keep you logged in. These cookies are strictly necessary for the Service to function.
8.2 Analytics
We use privacy-friendly analytics to understand how users interact with the Service in aggregate. We do not use invasive tracking pixels, fingerprinting, or third-party advertising cookies.
8.3 Your Choices
You can configure your browser to reject cookies, though some features of the Service may not function properly without essential cookies.
9. Third-Party Services
We use a limited number of third-party services to operate StudyStack:
- Vercel — hosting and infrastructure.
- Neon — database hosting (encrypted at rest).
- Stripe — payment processing (PCI DSS compliant).
- OpenAI — AI content generation (data processing agreement in place; your data is not used to train their models).
- Postmark — transactional email delivery.
- Google OAuth — authentication (we only receive your name and email).
Each third-party service processes only the minimum data necessary and is bound by their own privacy policies and our data processing agreements.
10. Data Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit using TLS 1.3.
- Database data is encrypted at rest.
- Access to production systems is restricted and audited.
- We conduct regular security reviews of our codebase and infrastructure.
11. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your data.
- Portability — request an export of your data in a portable format.
- Objection — object to processing of your data for certain purposes.
To exercise any of these rights, contact us at hello@study-stack.com. We will respond within 30 days.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.
13. Contact
If you have questions or concerns about this Privacy Policy, please contact us at hello@study-stack.com or visit our Contact page.