Privacy Policy

Your Privacy Matters

AvaStudy is a personal study app designed for students. We take privacy seriously — especially for younger users — and we are committed to being transparent about how your information is used.

No Ads. No Data Sales. Ever.

We do not run ads, sell your data to third parties, or share your information for marketing purposes. Your data is used only to make the app work for you.

Who This App Is For

AvaStudyis designed for students of all ages, including children. We recommend that parents or guardians be aware of and involved in their child's use of the app, particularly for children under 13.

We do not knowingly collect personal information from children under 13 without parental awareness. If you are a parent or guardian and believe your child has created an account without your knowledge, please and we will promptly delete the account and all associated data.

Parents may also request deletion of a child's account at any time by contacting us or by using the in-app deletion option at Settings → Parents & Safety → Delete Account.

What We Collect

  • Your Google account name and email (used only to identify your account)
  • Study content you upload — photos of notes, PDF files, or pasted text — used to generate your games. Uploaded files are stored in Firebase Storage and sent to the Claude AI API for processing.
  • Your in-app progress: coins, XP, streaks, badges, and game history
  • Subscription status — whether you are on the free or paid plan. Payment information is handled entirely by Stripe and is never stored by AvaStudy.
  • Push notification preferences and device token — only if you choose to enable push notifications. This is entirely optional and can be turned off at any time in your device settings or in-app Settings.
  • Game scores saved to shared-set leaderboards (only when you join a shared set)
  • Weak-area tracking: which questions you miss most, stored per study set to personalize practice and daily challenges
  • An optional test grade you type in for a study guide — kept private to your own account. It is stored with that guide and is never shown to anyone else, including a teacher who shared the guide with you. Its only use is to show you how your practice related to the result, and a summary in the weekly parent email if one is set up.
  • Usage analytics: which features you use, pages you visit, and in-app interactions — collected to help us improve the app
  • How you found us: the page you signed up from, the site you arrived from, and any campaign tags on the link you clicked (including a Google Ads click id, if you came from an ad). This tells us which of our own pages and posts bring people in. It is never used to build a profile of you, is never shared, and no ads are shown to you in the app.
  • If you are a teacher who signed up through a link on a flyer or email we sent your school, or a student who joined a guide shared by such a teacher, your account is tagged with that school's code. We use it only to see, in aggregate, whether outreach to a school is working. You can view or clear it in Settings. The domain of your sign-in email is also recorded for the same aggregate purpose.

How We Use It

Your data is used only to make the app work for you — to save your progress, generate your study content, and personalize your experience. The only third-party service that receives any of your content is Anthropic's Claude AI API, which processes your uploaded study material to generate games. No personal identifying information is ever included in those requests.

When you are part of a shared study set, your best scores per game type are visible to other members of that set on the leaderboard. Your display name and pet are shown alongside your score — no email address or any other account information is visible to other members. Leaving a shared set removes you from its leaderboard.

Study set creators can see the display names of users who have joined their shared set. Members of a shared set can see each other's display names and scores on the leaderboard. Shared sets are accessible only via a private 5-letter code — they are not publicly searchable or discoverable.

Once someone joins a set you shared, the person who created it can also see how the set is going overall: who has joined, who has started playing, and how many members are still finding each concept difficult. These concept figures are totals only.The creator is never shown which individual member missed which question, and never sees another member's personal progress, confidence scores, or practice history. Scores shown to the creator are the same best-per-game scores already visible to every member on the leaderboard.

What a Teacher Sees in a Class

A teacher can create a class — a roster joined by a code — and assign study guides to it, optionally with a due date. When a student joins a class or plays an assigned guide, the teacher who owns that class can see, for that class only:

  • the student's display name;
  • which assigned guides the student has completed, started, or not opened;
  • the student's best score and time spent on assigned guides;
  • which concepts within the assigned guides the student is still finding hard;
  • results of any live class game the student played.

That is the whole list.A teacher never sees a student's pet, coins, streak, level, badges, other study guides, personal practice history, self-logged test grades, or anything the student does outside that class. Question-by-question answers are never shown for an individual student — concept figures are the student's own mastery on the assigned material, not a transcript. This boundary is built into the product and cannot be turned off by a teacher or an admin.

A teacher can post a text message to the whole class — a reminder or a note — which students see on their dashboard and in their class list. This is one-directional: students cannot reply, message the teacher, or message each other, and no student contact information is collected or shown. A student can turn off the push notification for these in Settings.

A student can leave a class at any time from their Classroom or Stats page, which removes the teacher's access to their progress in it. Assigning students to a class is the teacher's responsibility: by doing so they confirm they have the authority to enroll those students and have obtained any parental consent their school or local law requires.

Account Security

Access to your account is authenticated through Google Sign-In. We use Firebase security rules to ensure that only you can read or modify your own account data, study sets, and progress. No other user can access your information.

Data Storage

Your account data and study content are stored securely using Google Firebase. Uploaded photos and PDFs are stored in Firebase Storage; your progress, scores, and game data are stored in Firestore. Only you can see your account data and study sets unless you explicitly share them.

The app also uses your browser's local storage to remember small preferences — such as which challenge nudges you've dismissed and which "how to play" tips you've already seen. This data never leaves your device.

Data Retention

When you delete a study set, it is marked for deletion and removed from your active library immediately. When you delete your account, all associated data is erased immediately and cannot be recovered.

Firebase infrastructure may retain short-term system logs and backups for operational reliability, typically for a period of up to 30 days. These are not accessible toAvaStudy staff and are not tied to your personal account in any identifiable way.

Inactive accounts are not automatically deleted. Your account and data remain stored as long as your account exists. You may delete your account at any time as described in the Deleting Your Data section below.

What You Can Upload

AvaStudy supports the following file types for study guide creation:

  • Photos / images — JPG, PNG, or other common image formats
  • PDF files — typed or scanned documents
  • Pasted text — copy and paste directly from any source

Word documents, PowerPoint files, and other formats are not currently supported. Please do not upload files containing sensitive personal information — only your study material is needed.

Third-Party Services

AvaStudy uses the following third-party services to function. Each provider receives only the minimum data necessary to perform their specific function — none of them receive more information than what is described below.

  • Google Sign-In — for authentication. We receive your Google account name and email address.
  • Firebase (Google) — for secure data storage, authentication, and push notification delivery.
  • Stripe — processes subscription billing for paid accounts. Your payment information (card number, billing address) is sent directly to Stripe and never stored by AvaStudy. Stripe may store a customer ID to manage billing. See stripe.com/privacy.
  • Anthropic Claude AI API— converts your uploaded photos, PDFs, or pasted notes into flashcards and games. The content you upload is transmitted to Anthropic's servers for processing. No personal identifying information — such as your name or email — is included in these requests.

    Per Anthropic's API usage policies, content submitted via the API is not used to train Anthropic's models and is not retained beyond what is necessary to complete the request. Uploaded content is not permanently stored by Anthropic. For full details, see anthropic.com/privacy.
  • Amazon SES — delivers the emails AvaStudy sends you: a welcome message, a note when a study guide finishes processing, streak and come-back-and-study reminders, a note if a study guide could not be built or if we add free uploads to your account, and subscription notices such as renewals, payment problems, and cancellations. Your email address and first name are transmitted to Amazon to send these. We never send marketing email from third parties, and we never share your address with anyone else.

    Every one of these can be turned off in Settings → Notification Preferences, except messages required to run your account, such as billing notices.
  • Amplitude — collects anonymous usage analytics such as which features you use and how you navigate the app. Your account ID is used to connect events across sessions, but no name, email, or study content is shared.
  • Microsoft Clarity — records anonymized session replays, heatmaps, and interaction data (clicks, scrolls, mouse movement) to help us understand how the app is used and identify issues.

    The following are explicitly excluded from Clarity's capture: uploaded study content (photos, PDFs, and pasted text), text typed into upload fields, and any other sensitive input areas. Text inputs throughout the app are masked. Uploaded images and PDF content are never part of session replay recordings.

    You can opt out of Clarity at any time via clarity.microsoft.com/optout.

Amplitude and Microsoft Clarity may collect standard device and browser information as part of their operation. Neither service receives your name, email, study content, or game data.

Deleting Your Data

You can delete individual study sets at any time from within the app. You also have the right to permanently delete your entire account and all associated data at any time.

To delete your account, go to Settings → Parents & Safety → Delete Account. Confirming will immediately and permanently erase:

  • Your profile, name, and all account settings
  • All coins, XP, streaks, badges, and game history
  • Your pet and all owned accessories
  • All study sets you created — their content, their leaderboards, and the photos or PDFs you uploaded to make them
  • Your entries on any shared-set leaderboards you joined
  • Your daily challenges, missions, and board progress

This action cannot be undone. Deletion is processed immediately — there is no waiting period or recovery option. As noted in the Data Retention section, Firebase system infrastructure may retain short-term operational logs for up to 30 days, but your account and personal data are removed immediately.

Questions?

If you have any questions about how your data is handled — including requests related to a child's account — and we'll get back to you promptly.

Last updated: September 2026 — added what a teacher can see about a student in a class (and the boundary around it), one-directional class messages, and teacher enrollment responsibility; earlier updates: children's privacy, AI retention policy, leaderboard visibility, analytics masking, data retention, account security, shared-set disclosures, and how we record where a signup came from