Skip to main content

Privacy Policy

Effective 2026-07-30

StudySite is operated by Martlet Solutions, LLC. We process student education records on behalf of educational institutions and process other account data to provide StudySite. This policy describes the information collected, how it is collected, who controls it, why it is used, how long it is retained, and the choices available.

What we collect

  • Identity and account data: name, email, profile image, role, institution/section membership, invitations, sign-in events, authentication factors and session identifiers. This is provided by you, your institution, or Clerk.
  • Instructor and authoring data: courses, sections, modules, objectives, assignments, files, sources, prompts, rubrics, configurations, approvals, and publication/version history. This is entered, uploaded, imported, or generated at an instructor's request.
  • Learner and education-record data: enrollments, learning sessions, chats, transcripts, code and assessment submissions, assignment repositories, grader status, attempts, completions, instructor feedback, and AI Experience evidence. This is created when learners and instructors use assigned workflows.
  • AI and media data: prompts, responses, citations, provider/model/run metadata, instructor-approved source corpora, learner research files, speech transcripts, generated audio, and usage totals. StudySite does not retain microphone audio captured for browser speech recognition.
  • Connected-account data: OAuth identity, encrypted access/refresh tokens, and content deliberately selected from GitHub, Google Docs/Drive, or Microsoft OneNote.
  • Billing and entitlement data: product, price, transaction/customer identifiers, access-code and entitlement history, refunds, and billing contact information. Stripe—not StudySite—processes full payment-card details.
  • Support and feedback data: issue reports, ratings, feedback, support messages, page context, and attachments deliberately submitted by a user.
  • Security and service data: IP address, user agent, request paths, timestamps, audit events, webhook/job status, errors, performance measurements, and abuse/security signals.
  • Optional product analytics: a pseudonymous account identifier, page views, and bounded feature events only after opt-in. Name/email, student code, terminal output, uploads, source text, and free-text responses are excluded.

How and why we use it

  • Provide authentication, courses, learning activities, tutoring, authoring, code execution, connected accounts, billing, support, and instructor reporting.
  • Maintain security, audit sensitive actions, prevent abuse, diagnose failures, and satisfy legal or institutional obligations.
  • Run optional analytics only after affirmative consent.
  • We do not sell personal data, display advertising, target users for advertising, or use student data to train a general-purpose model.

Ownership and control

StudySite does not claim ownership of user content, personal data, or education records. Users and contracting institutions retain their respective rights. Martlet receives only the limited right to process data as needed to provide, secure, and support StudySite. Institutions control education records processed on their behalf.

Retention

  • Optional analytics and transient activity events: 30–60 days according to the user's setting.
  • Tutor/chat session content: 30–60 days according to the user's setting.
  • Education records and published course evidence: for the institution's configured term, contractual period, or documented instruction, then deleted or de-identified, subject to legal obligations.
  • Account and connected-account data: while the account or integration is active, then removed through the deletion process.
  • Billing, security, and audit evidence: only as long as needed for tax, fraud prevention, dispute, security, or other legal obligations.
  • Provider copies and backups: removed under the applicable provider deletion cycle after StudySite deletes or expires the controlling record.

Your choices and rights

  • Access and portability: download the available self-service JSON export from Settings and contact us for institution-controlled or provider-held records not included there.
  • Correction: update profile and preferences in Settings or request correction through the institution or StudySite.
  • Deletion: schedule account deletion in Settings with a 30-day cancellation period. StudySite deletes account-linked private data and authentication access; shared instructional content may be transferred to an institution-controlled anonymous owner rather than destroying other users' course access. Records under a documented legal or institutional hold are handled with the institution.
  • Analytics: optional PostHog analytics are off by default and can be enabled or withdrawn in Settings.
  • Connected accounts: optional GitHub, Google, and Microsoft integrations can be disconnected in Settings.
  • Requests: admin@studysite.ai. Parents or eligible students seeking FERPA records should normally begin with the educational institution.

Third parties and cookies

The public Subprocessor Liststates each provider's purpose, data received, and whether its feature is optional. The Cookie Policy lists cookies and their purposes. We do not share data with advertisers.

Children and education institutions

StudySite accounts are generally for users age 13 or older. When an institution authorizes StudySite for a younger learner, the institution is responsible for providing the authorization or parental consent required by applicable law. StudySite uses that learner's data only to provide the institution-directed educational service.

Policy changes

Material changes will be announced to account holders and institutional contacts at least 30 days before taking effect. The effective date on this page identifies the current version. Changes required immediately for security or law will be announced as soon as reasonably possible.

Contact

Questions about this policy? Email admin@studysite.ai.