Privacy Policy
Last updated: August 11, 2026
This policy explains how Study Smart Serve(“we” or “the Service”), operated by Plus 44 Pty Ltd, handles your information.
1. Information we collect
- Account information. We collect your email and a securely hashed password when you create an account.
- Newsletter information. We store the email address that you submit to a newsletter form until you unsubscribe or ask us to delete it.
- Study progress. We store question attempts, scores, and completed lessons so you can see and sync your progress.
- Purchases and payment status. RevenueCat and the applicable Apple, Google, or web payment provider process purchases. RevenueCat receives your account ID when you sign in so access can work across devices. We keep a first-party transaction ledger for purchase integrity, refunds, fraud control, and financial records. We do not store your full card number.
- Optional product analytics. With your consent, PostHog receives screen, lifecycle, and typed feature events linked to a random product-scoped identifier, with device and app details. We do not send your account ID or email to PostHog. If an app build enables session replay, it starts only with analytics consent and masks text inputs and images.
- Optional web analytics. With your consent, Google Analytics receives web measurement events through Google Tag Manager.
- Optional diagnostics. With analytics consent, Firebase Crashlytics and its Firebase Sessions dependency receive crash reports, app performance metrics, diagnostics, and device and app details so we can find and fix faults.
- Optional attribution and advertising measurement.With your consent, we store first-touch campaign fields, Google click IDs, and a random journey ID in product-scoped first-party storage. AppsFlyer can receive campaign details, device identifiers, app activity, and conversion events for attribution. We do not send your account ID or email to AppsFlyer. The app does not show third-party ads.
- First-party measurement links. When optional measurement is on, we can link the random journey ID, pseudonymous PostHog ID, AppsFlyer ID, and campaign fields in our own database. We use this link to reconcile campaigns and purchases. We do not send your account ID through this endpoint as an analytics identifier.
2. How we use information
- Authenticate your account and keep your session secure
- Sync study progress across your devices
- Manage purchases and subscription access
- Improve features and fix faults
- Measure campaigns when you allow advertising measurement
- Send essential account messages, such as password resets
We do not sell personal data. We do not use your study data to show third-party advertising.
3. Consent and privacy controls
Optional analytics, diagnostics, and advertising measurement start in a denied state. On the website, Google Consent Mode v2 communicates your choice to Google tags. Use the Privacy choicescontrol on the website to accept, reject, or change a website choice. The mobile app asks for its optional measurement choices during first setup. On iOS, the system tracking prompt appears only after you allow advertising measurement. Turning both optional choices off clears product-scoped journey and first-touch records from your device or browser and removes optional RevenueCat measurement attributes. When you turn analytics off, the app also asks Firebase to delete unsent crash reports. Firebase applies its native diagnostics opt-out no later than the next app start.
Essential storage remains active because it supports sign-in, security, purchases, and saved study progress.
4. Cookies and local storage
The Service uses first-party cookies and local storage for your session, settings, progress, consent choice, and optional measurement. The optional journey and first-touch records use the current product's storage prefix and enforce a 90-day expiry. You can also clear website records with your browser controls.
5. Service providers
We share only the data each provider needs to run its service:
- Supabase, for authentication and data sync
- RevenueCat, Apple, Google, and Stripe, for applicable payments
- PostHog, for consented pseudonymous product analytics
- Google Analytics and Google Tag Manager, for consented web analytics
- AppsFlyer, for consented app-store campaign attribution
- Firebase Crashlytics, for consented crash reports and diagnostics
- Our email provider, for essential account email
6. Data retention
We keep account and progress data while your account remains active. Newsletter data stays until you unsubscribe or ask us to delete it. First-touch and journey records on your device or browser expire after 90 days. Pseudonymous analytics, attribution, and crash reports already sent to a provider can remain for that provider's configured retention period.
The Delete Account feature removes your Supabase sign-in account and synced progress. It does not cancel a subscription or automatically delete newsletter, purchase, analytics, attribution, or diagnostic records. Contact us to request deletion of other data where applicable. Service providers can retain records under their own legal and service rules.
7. Security
We use reasonable technical and organisational controls to protect your data. No internet or storage system can guarantee absolute security.
8. Children
The Service is intended for adults and is not directed to people under 18. Contact us if you believe a child has provided personal information.
9. Your rights
Your location may give you rights to access, correct, delete, or object to processing of your personal data. Email [email protected] to make a request.
10. Provider privacy policies
11. Policy changes
We may update this policy. We will change the date above when we do. We will provide an in-app notice or email for material changes.
12. Contact
Contact Plus 44 Pty Ltd at [email protected].