Global Legal & Trust Center

Draft โ€“ under legal review

StudyBench AI Privacy Policy, Terms of Service & Country-Specific Notices

Jurisdiction:

Global Student Privacy Commitment: Zero Commercial Data Selling

StudyBench AI strictly does not sell student personal records, handwritten working, exam papers, or study notes to third parties or advertising data brokers. All information is processed solely to provide secure, individualized educational tutoring and academic curriculum support.

Privacy in simple words

  • We keep your name, email, class and what you ask the tutor so the app can help you learn.
  • You chat with an AI tutor. It is a computer program, not a person, and it can make mistakes.
  • We do not send your name or email to the AI companies. What you type, upload or say does go to them, so please do not put private details such as your address or phone number in a question.
  • Safety filters check chats. If something worrying shows up, we send your parent or guardian a short note. We do not show them what you wrote.
  • We do not show adverts and we do not sell your information.
  • If you are under 18, tracking your progress for teachers starts switched off. You or your parent can switch it on in your account settings.
  • StudyBench AI is only available in some countries for now. The sign-up screen shows which.
  • You or your parent can ask us to show you your information or delete it. Write to the support address below.
  • If something online made you uncomfortable, tell a parent, a teacher or another adult you trust.

Corporate Identity & Data Controller

StudyBench AI is designed, owned, and operated globally by AARUDHRA NEXTGEN AI LIMITED (Company Registered in England & Wales, Company No. 17189093). Registered Office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

General Inquiries: support@studybench.org
Privacy & Grievance Officer: grievance@studybench.org

11. Information We Collect

  • Account & Identity Data: Name, email address, school or educational institution, class/grade, role (student/teacher/parent), and preferred study medium (Tamil, English, Sinhala, Hindi, etc.). Profile image if Google OAuth is chosen.
  • Parental / Guardian Consent Data: For students under 18 (aged 13 and over), a parent or guardian creates their own account and adds the student. We keep the link between the two accounts, the student's name and email address as the parent entered them, the dates the invitation was sent and accepted, the parent's confirmation that the student is 13 or older, the country, and consent records (policy version and time). Students cannot create an under-18 account on their own.
  • Academic Materials & Student Queries: Mathematical problem statements, textbook camera photos, uploaded PDF study materials, voice doubt recordings, quiz responses, whiteboard diagrams, flashcards, and personalized revision schedules.
  • Learning Progress & Mastery Signals: Lesson start/completion checkpoints, quiz scores, conceptual mastery confidence levels, and difficulty signals utilized to customize Socratic tutoring and teacher classroom analytics.
  • Billing & Transaction Tokens: Subscription plan selection and payment transaction identifiers handled by third-party payment providers. We do not store full card numbers on our own servers.
  • Technical & Security Telemetry: IP address (utilized strictly for coarse country/region curriculum alignment and rate-limiting DDoS protection), device user-agent, and encrypted session authentication tokens.
  • Safety Monitoring (student accounts): Messages a student sends to the AI tutor, and the tutor's answers, are checked by automatic safety filters. If a filter flags a serious concern about the student's wellbeing or safety (for example self-harm or threats), we email the verified parent or guardian a short notice that names the kind of concern. We do not include what the student wrote. We keep a record of the kind of concern and the time for 365 days. Filters can be wrong. We send at most one notice per student per day.

22. Purpose of Processing & Strict Data Retention Schedule

Personal and academic data is processed strictly to provide step-by-step Socratic teaching, LaTeX mathematical formulas, interactive board animations, and authorized school classroom insights under the following automated retention schedule:

๐Ÿ“š Study Questions & Uploaded PDFsRetained for 12 months from creation or deleted immediately upon student/parent deletion request.
๐Ÿ“Š Learning Activity & Mastery EventsAutomatically pruned 365 days after creation. Opting out instantly disables future telemetry collection.
๐Ÿ›ก๏ธ Privacy Requests & Erasure LogsFormal erasure and GDPR/DPDP request records are purged 90 days after verified closure.
๐Ÿ’ณ Invoices & Statutory Financial LogsRetained for the mandatory statutory period prescribed by applicable corporate taxation laws (typically 6-7 years).

33. AI Model Processing & Third-Party Sub-processors

When processing academic doubts or drawing mathematical graphs, questions and uploaded media are transmitted via encrypted TLS/HTTPS directly to enterprise AI inference endpoints (Google Gemini, Groq, or OpenRouter/OpenAI/Anthropic).

Zero Training on Minor / Student Prompts: Commercial enterprise API agreements ensure that student questions and submissions are not utilized to train public foundation models or shared with unauthorized commercial entities.

44. Student & Parental Statutory Rights

Every student and guardian is equipped with self-service data management tools directly inside Account โ†’ Privacy & Data:

๐Ÿ“ฅ Right to Data Portability (JSON Export)

Download a complete machine-readable copy of all cloud study records, quizzes, and saved notes with a single click.

๐Ÿ—‘๏ธ Right to Erasure / Right to be Forgotten

Submit an instant account erasure request. All personal data, study history, and uploaded files are deleted.

Country-Specific Privacy Notes

The notes below summarise how we aim to handle data under rules that may apply in our key territories. They are being reviewed by a qualified adviser and are not a statement of legal compliance.

๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ‡ช๐Ÿ‡บ United Kingdom & European Union / EEA

UK GDPR โ€ข DPA 2018 โ€ข ICO Children's Code โ€ข EU GDPR
  • Lawful basis (Article 6): We are documenting a lawful basis for each purpose; the bases we expect to rely on are (a) Performance of Contract to provide requested educational tutoring; (b) Legitimate Interests for platform cybersecurity and cheat-prevention; (c) Compliance with Legal Obligations for tax/billing; and (d) Consent for optional progress insights and under-age services.
  • ICO Age-Appropriate Design Code (Children's Code): We enforce all 15 standards: (1) Best interests of the child as primary consideration; (2) Data Protection Impact Assessments (DPIAs); (3) Age-appropriate transparent explanations; (4) Detrimental use prevention; (5) Default high-privacy settings with opt-out progress telemetry; (6) Data minimization; (7) Zero commercial profiling; (8) Strict geolocational limits; (9) Parental notification transparency; and (10) Accessible complaint mechanisms.
  • Cross-Border International Transfers (Articles 44โ€“49): Transfers outside the UK/EEA rely on UK International Data Transfer Agreements (IDTA), EU Standard Contractual Clauses (SCCs), or the EU-US Data Privacy Framework.
  • Supervisory Authority & Complaints: UK users have the right to lodge complaints with the Information Commissioner's Office (ICO) at ico.org.uk. EU/EEA users may contact their national Data Protection Authority.

๐Ÿ‡บ๐Ÿ‡ธ United States of America (US Federal & State Laws)

COPPA โ€ข FERPA โ€ข CCPA/CPRA โ€ข SOPIPA
  • COPPA (15 U.S.C. 6501โ€“6508 / 16 CFR Part 312): Our parent-first sign-up shows that the holder of an adult account invited the child; it is not verifiable parental consent under COPPA. We do not accept children under 13, and use by children in the US needs further work first. Parents can ask us to review or delete their child's personal information.
  • FERPA & School Official Exemption (34 CFR Part 99): When deployed by US educational institutions, whether StudyBench AI can act as a "School Official" depends on the agreement with each school. This has not yet been confirmed.
  • California Consumer Privacy Act & CPRA (Cal. Civ. Code ยง 1798.100+): California residents possess the Right to Know, Right to Delete, Right to Correct, and Right to Non-Discrimination. We do NOT sell or share personal information or sensitive student data as defined by the CCPA/CPRA.
  • Student Online Personal Information Protection Act (SOPIPA): We strictly prohibit targeted advertising, amassing student profiles for non-educational purposes, or selling K-12 student data.

๐Ÿ‡ฎ๐Ÿ‡ณ India โ€” DPDP Act 2023 & DPDP Rules 2025

Digital Personal Data Protection Act 2023
  • Data Fiduciary Obligations: AARUDHRA NEXTGEN AI LIMITED processes digital personal data strictly for specified educational purposes with clear itemized notices in English and regional languages (including Tamil and Hindi).
  • Section 9 (Processing of Children's Personal Data): StudyBench AI is not open to students in India yet. Under the Act a person under 18 is a child, verifiable parental consent is needed, and tracking or behavioural monitoring of children is restricted. Before we open India to students we will take advice on how this applies to our progress insights and safety monitoring. We do not show advertising.
  • Data Principal Rights under DPDP Act: Users enjoy: (1) Right to Access summary of personal data and processing activities; (2) Right to Correction and Erasure; (3) Right to Grievance Redressal; and (4) Right to Nominate another individual in event of death or incapacity.
  • Grievance Redressal Mechanism: Indian residents may contact our Designated Grievance Officer at grievance@studybench.org (Acknowledgment within 24 hours, resolution within statutory timelines). If unresolved, appeals may be submitted to the Data Protection Board of India.

๐Ÿ‡ฑ๐Ÿ‡ฐ Sri Lanka โ€” Personal Data Protection Act No. 9 of 2022

PDPA 2022 โ€ข 2025 Amendments โ€ข Gazette No. 2498/16
  • Part I & Part III Principles: We aim to process personal data of Sri Lankan students (including G.C.E. O/L, A/L, and university learners) lawfully and transparently, with purpose limitation and data minimisation. Readiness work is in progress ahead of the 1 January 2027 commencement date.
  • Section 26 Cross-Border Transfer Mechanisms: Some cloud and AI processing happens outside Sri Lanka. We are documenting vendor locations and transfer safeguards for this, and that work is not yet complete.
  • Data Subject Rights: Sri Lankan citizens have the right to access, rectify, erase, or object to processing of personal data. Requests are addressed promptly via support@studybench.org.
  • Regulatory Authority: Complaints may be directed to the Data Protection Authority of Sri Lanka (DPA) at dpa.gov.lk.

๐ŸŒ International, Commonwealth & Rest of World

Australia APPs โ€ข Canada PIPEDA โ€ข Singapore PDPA
  • Australia & New Zealand: Compliance with the Australian Privacy Principles (Privacy Act 1988) and the New Zealand Privacy Act 2020 has not yet been assessed.
  • Canada: Compliance with PIPEDA and provincial education rules has not yet been assessed.
  • Singapore & Middle East (UAE / Saudi Arabia): Compliance with the Singapore PDPA, UAE PDPL and Saudi PDPL has not yet been assessed.
Last Updated: October 2026 โ€ข Draft pending legal review
Open StudyBench