Trust & Safety

How we protect student privacy, handle data, and keep AI-generated content safe.

Studyfin is a K–10 learning app used by families, teachers, and schools. This page explains, plainly, how we protect children's privacy, how we handle student data for schools, how we keep our AI-generated content safe, and the security practices behind the product. Where something is aspirational or on our roadmap, we say so.

🔒 COPPA-aligned 🏫 Built to FERPA principles 🤖 AI content, machine-checked 🛡️ Encrypted & access-controlled 🚫 We never sell children's data

1. Our safety commitment

Studyfin is built for children first. Our commitment to families and schools is simple: collect only the data we need to run the service, protect it, keep parents and schools in control, and be honest about how our content is made. We never sell children's personal data and we run no behavioral advertising to children. Because much of our learning content is generated by AI, we are careful not to overstate it — we explain below exactly what our automated checks do and where their limits are.

2. Children's privacy (COPPA)

Studyfin is designed for learners including children under 13, and we follow the principles of the U.S. Children's Online Privacy Protection Act (COPPA) and comparable laws.

3. Student records (FERPA)

When a school or district uses Studyfin, the school remains the owner and controller of student education records. Studyfin acts as a school official / service provider under the Family Educational Rights and Privacy Act (FERPA), performing an institutional service the school would otherwise perform itself, under the school's direction and control.

4. How our AI content is made safe

Being direct: most Studyfin lessons and quizzes are generated by AI and then automatically checked by software. We do not claim this content is official, expert-written, guaranteed, or 100% accurate. Here is what actually happens and where the limits are.

5. Security

Studyfin runs on trusted cloud infrastructure (Google Cloud / Firebase). Our security practices are designed to protect student and account data:

No method of transmission or storage is completely secure. We describe practices we follow and are designed to protect your data, and we work to respond promptly to any incident. Formal certifications such as SOC 2 are on our roadmap — ask us where each stands for your timeline.

6. Data handling & retention

What we collect and why

Retention, export & deletion (DSAR)

We keep personal information only as long as needed to provide the service or meet legal obligations, then delete or anonymize it. Some financial and transaction records may be retained after account erasure where the law requires it.

To make a data subject access request (export or deletion), parents and schools can use the dashboard (Download data / Delete data), open a support ticket, or email us (see Contact). Schools can define a full retention schedule in their Data Processing Agreement. For the full detail, see our Privacy Policy.

7. For schools & districts

Request our DPA (Data Processing Agreement)

We provide a Data Processing Agreement that covers roles, sub-processors, security, retention, and data return/deletion. A DPA template is available on request, and we're happy to review your district's own agreement.

Request our DPA Talk to us

School accounts include role-based access, an audit log, AI-moderated messaging, CSV data export, and Google & Microsoft SSO, built to FERPA / COPPA principles. On our roadmap: SOC 2, a formal accessibility (VPAT / WCAG) audit, and Clever / ClassLink roster sync — see for-schools or ask us where each stands.

8. Contact

Questions about privacy, security, or a data request? Email privacy@studyfin.app, use the in-app assistant, or open a support ticket. See also our Privacy Policy, Terms, and Safety & Compliance pages.

Studyfin is committed to earning the trust of the families and schools we serve. If something isn't right, tell us — we'll look into it and fix it.