We only use technically necessary browser storage (localStorage) to keep you logged in and remember your settings. No cookies, no tracking, no analytics. More in our Privacy Policy.
Last updated: August 5, 2026
The data controller responsible for data processing on this website is: Savio Lauro Schreiner An den Weiden 6 50999 Köln, Germany Email: support@studipace.com Contact for data protection: Savio Lauro Schreiner, support@studipace.com. You can direct any privacy-related request to this address. Data Protection Officer (DPO): We have not appointed a Data Protection Officer. StudiPace is not legally required to designate one — the thresholds of Art. 37 GDPR and § 38 BDSG (e.g. at least 20 people constantly engaged in automated processing, or large-scale processing of special categories of data) are not met. As the data controller, the operator may not act as his own independent DPO. We will reassess this obligation as StudiPace grows.
This section explains which data we process depending on how you use StudiPace. We distinguish between simply visiting the website (without an account) and registering for and using the platform. A) When you only visit the website (informational use, no account) When you access studipace.com without logging in, our hosting provider (AWS) automatically processes standard server log data that your browser transmits: your IP address, the date and time of the request, the requested page/URL, the referrer URL, and your browser type and user agent. This data is technically necessary to deliver the website and to keep it secure and stable. It is stored only for a short period (server logs, as a rule up to 30 days) and is not combined with other data to identify you. We do not use tracking cookies, third-party analytics (e.g. Google Analytics), or fingerprinting. We do collect anonymous, aggregate page-view statistics — for example, to see how many visitors reach the signup page. Each page view sends only the page path, the referring domain (not the full referrer URL), and a coarse screen-width bucket (rounded to the nearest 100px) to our own server. No cookie, browser storage, or visitor identifier is used, no IP address is stored with this data, and individual page views cannot be linked to each other, to a person, or to an account. This applies whether or not you are logged in. B) When you register for and use the platform Account data: Name, email address, grade level, and password (stored as a bcrypt hash — we never store your password in plain text). We also store your email verification status and subscription plan. Subscription data: If you subscribe to a paid plan (Pro or Max), your payment is processed by Stripe. We store your Stripe customer ID and subscription ID to manage your plan. We do not store your credit card number, CVV, or full payment details — these are handled entirely by Stripe. See: https://stripe.com/privacy Study data: Subjects, exams, exam dates, topics, study sessions, homework, availability preferences, weekly activities, timetable entries, and generated schedules. Timetable photos: If you use the "Scan photo" feature, you may upload a photo of your class timetable. The image is sent to our AI provider (Anthropic) for text extraction, then immediately discarded — we do not store the photo on our servers or in your account. Only the extracted timetable entries (subject names, days, and times) are saved. AI study data (Max plan): If you use Daily Chat, we store your text conversations and an AI-generated study profile (communication style, recurring study habits, a rolling 14-day personal context, and per-subject notes). See section 11 "AI-powered features" for details. Daily Chat is text-only — we do not record or transcribe your voice. Usage data: Login timestamps, session activity, and in-app actions (e.g. which schedule suggestions you accept or modify, when you complete sessions). We use this internally to operate and improve the Service. Email communications: We send transactional emails (email verification, password resets, login notifications, subscription confirmations) via our email provider Resend. Your email address and name are shared with Resend solely for the purpose of delivering these emails. Marketing emails (optional): If you opt in — at signup or anytime in Settings → Privacy & data — we share your email address and first name with Resend so it can add you to a marketing mailing list ("Audience") and send you occasional product updates and study tips. You can withdraw consent anytime in Settings, or via the unsubscribe link in any marketing email; either way, you are removed from the list. Technical data: For login notification emails and account security, we process your IP address and user agent when you sign in. Your IP address is also written to the security-relevant server logs described in section A. C) When you submit a right-of-withdrawal declaration (Widerruf) If you use our public withdrawal form (Widerrufsbutton, required for paid subscriptions), we store the data you enter — your name, email address, an optional contract reference, and an optional reason — together with your IP address and a timestamp. We are legally obliged to keep this as evidence that the declaration was received and acknowledged.
We process your data on the following legal bases under the GDPR (DSGVO). For each category of data we state the purpose and the corresponding legal basis. Account data (name, email, grade, password hash, verification status, plan) • Purpose: creating and securing your account, email verification, authentication, password reset. • Legal basis: Art. 6(1)(b) GDPR (performance of the contract / provision of the Service). Subscription data (Stripe customer and subscription ID, plan status) • Purpose: providing and managing your paid subscription, processing payments, preventing misuse. • Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR (our legitimate interest in reliable billing and fraud prevention). Study data (subjects, exams, topics, sessions, homework, availability, schedules) • Purpose: generating and displaying your personalised study schedule and progress. • Legal basis: Art. 6(1)(b) GDPR (performance of the contract). Timetable photos • Purpose: extracting your class times via AI text recognition. Photos are not stored. • Legal basis: Art. 6(1)(b) GDPR (performance of the contract). Usage and technical data (login timestamps, in-app actions, IP address, user agent) • Purpose: operating the Service, login notifications for account security, rate limiting, preventing abuse and unauthorised access, ensuring stability and security. • Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in a secure, stable, and abuse-resistant Service). AI study data (Daily Chat conversations and AI-generated study profile, Max plan) • Purpose: providing the conversational Daily Chat feature and personalising its guidance. • Legal basis: Art. 6(1)(b) GDPR (performance of the contract for the Max plan). See section 11. ML-based personalisation (opt-in) • Purpose: learning scheduling preference weights from your own session and day ratings to bias your future session placement. This is a server-side, per-user weighting model. It does not train the underlying AI model, and no data is sent to Anthropic for this purpose. • Legal basis: Art. 6(1)(a) GDPR (your consent). It is opt-in and disabled by default; you can enable or withdraw it anytime in Settings → Profile. Right-of-withdrawal declarations (name, email, contract reference, reason, IP, timestamp) • Purpose: evidencing receipt and acknowledgment of a withdrawal declaration. • Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation, § 312k BGB / Directive (EU) 2023/2673). Anonymous page-view analytics (page path, referring domain, screen-width bucket) • Purpose: understanding aggregate website and signup-funnel usage so we can improve the site. • Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in understanding and improving the Service). No cookie, IP address, or persistent identifier is stored with this data. Marketing emails (opt-in) • Purpose: sending you occasional product updates and study tips by email. • Legal basis: Art. 6(1)(a) GDPR (your consent). Off by default; withdraw anytime in Settings → Privacy & data or via the unsubscribe link in any marketing email. Cookie / local-storage preference • Purpose: remembering that you have seen the storage notice. • Legal basis: § 25(2) no. 2 TDDDG (storage strictly necessary to provide the service you requested); no separate consent is required. You can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Your data is hosted on Amazon Web Services (AWS) infrastructure. The legal basis for hosting your data with AWS is Art. 6(1)(b) GDPR (hosting is necessary to provide the Service), in conjunction with a Data Processing Agreement (Auftragsverarbeitungsvertrag) with AWS under Art. 28 GDPR. We use the AWS EU (Frankfurt, eu-central-1) region. Your data is stored within the European Union. AWS complies with GDPR and has implemented appropriate technical and organizational measures to protect your data. Details: https://aws.amazon.com/compliance/gdpr-center/ We do not sell, rent, or share your personal data with third parties for marketing purposes. Your data is shared only with the following processors: • AWS (hosting infrastructure) — stores your account and study data within the EU (Frankfurt region). Acts as data processor under Art. 28 DSGVO. • Anthropic (AI processing) — processes text prompts for study time estimation, timetable photo extraction, and AI study chat. Receives only the specific content needed for each request (e.g., topic names, timetable photos, or chat messages). Does not receive your name, email, or password. Does not use your data for model training. See: https://www.anthropic.com/privacy • Stripe (payment processing) — processes Pro and Max subscription payments. Receives your email address and payment details. We do not store your credit card information. Stripe is PCI-DSS compliant. See: https://stripe.com/privacy • Resend (email delivery) — delivers transactional emails (verification, password reset, login notifications, subscription confirmations) and, if you opt in, marketing emails via a Resend Audience (mailing list). Receives your email address and name. See: https://resend.com/legal/privacy-policy No other third parties receive your data. If we add or replace sub-processors in the future, we will update this Privacy Policy and notify you by email at least 14 days before the new sub-processor receives any of your data.
We store your data for as long as your account is active and you use the Service. Upon account deletion (available in Settings): • Your personal data (name, email, account details) is permanently deleted immediately. • Your study data (subjects, exams, sessions, schedules) is deleted immediately. • Your Stripe subscription is cancelled automatically. Stripe may retain transaction records per their own retention policy. • Password reset tokens and email verification tokens are deleted immediately. • Anonymized, aggregated data that cannot be linked back to you may be retained for algorithm improvement. Inactive accounts: In line with the principle of data minimisation, if you do not log in for 24 months, we will warn you by email and then delete your account and associated data, unless an active subscription or a statutory retention obligation requires otherwise. We may retain data longer if required by law (e.g., tax or commercial law retention obligations under German law, typically 6-10 years for business records — this applies particularly to payment and invoice data).
Under the GDPR (DSGVO), you have the following rights: Right of access (Art. 15): You can request information about what personal data we store about you. Right to rectification (Art. 16): You can request correction of inaccurate data. You can also update most data directly in the app (Settings page). Right to deletion (Art. 17): The quickest way to delete your data is the "Delete account" button in Settings → Privacy & data — after email confirmation it erases your account and all associated data immediately. You can also request deletion by email; see "Identity verification" below. Right to restrict processing (Art. 18): You can request that we limit how we process your data. Right to data portability (Art. 20): You can request your data in a structured, commonly used, machine-readable format. Right to object (Art. 21): You can object to processing based on legitimate interests at any time. Right to withdraw consent (Art. 7(3)): Where processing is based on consent, you can withdraw it at any time. Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority. As StudiPace is based in Cologne, the primary competent authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LfDI NRW), Kavalleriestr. 2–4, 40213 Düsseldorf, poststelle@ldi.nrw.de. You may also lodge a complaint with the supervisory authority in your own EU member state. Identity verification: To protect your data, we act on access, correction, deletion, and portability requests only for the account holder. The self-service tools in Settings → Privacy & data (data export and account deletion) authenticate you automatically — they are the fastest and most reliable way to exercise these rights. If you contact us by email instead, we may first need to verify that you control the account, normally by confirming the request from the account's registered email address. Where we cannot reasonably establish that a requester is the account holder — for example, someone who has lost access to both the account password and its registered email — we may be unable to identify the relevant data or to comply with the request, as permitted by Art. 11(2) and Art. 12(6) GDPR. To exercise any of these rights, contact us at support@studipace.com. We will respond within 30 days.
StudiPace uses browser localStorage (not traditional cookies) only for technically necessary purposes: • Authentication token (JWT) — required to keep you logged in • User ID and display name — required for the app to function • Theme preference (light/dark/system) — user interface setting • Color scheme preference — user interface setting • Storage-notice acknowledgment — remembers that you have already seen the storage notice Legal basis: § 25(2) no. 2 TDDDG — this storage is strictly necessary to provide the service you explicitly requested, so no consent is required. We do not use any optional or consent-based storage. We do not use third-party tracking cookies, Google Analytics, or any external analytics scripts. We do not use advertising cookies or retargeting. The anonymous page-view analytics described in section 2 are sent directly to our own server on each page load and do not use cookies or browser storage of any kind. You can clear all stored data at any time by clearing your browser's site data for studipace.com.
We implement appropriate technical and organizational measures to protect your data: • All data is transmitted over HTTPS (TLS encryption in transit) • Passwords are hashed using bcrypt (never stored in plain text) • Authentication uses JWT tokens with expiration • Email verification is required for new accounts • Login notifications are sent to alert you of new sign-ins (including IP and device) • Password reset links expire after 1 hour • API rate limiting protects against brute force attacks on login and password reset • Payment processing is handled entirely by Stripe (PCI-DSS Level 1 certified) — we never see your card details • Database access is restricted and encrypted at rest (AWS encryption) • Security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options) are configured • We follow the principle of data minimization — we only collect data necessary for the Service
StudiPace is designed for students. If you are under 16 years of age, you need consent from a parent or legal guardian to create an account. We do not knowingly collect data from children under 16 without parental consent. If we become aware that we have collected data from a child under 16 without proper consent, we will delete that data promptly.
Your account and study data is stored in the AWS EU (Frankfurt) region within the European Economic Area (EEA). The following services may process data outside the EEA: • Anthropic (AI features) — topic names, timetable photos, and chat messages may be sent to servers in the United States. No personal account data (name, email, password) is included. Covered by SCCs. • Stripe (payments) — your email and payment details are processed by Stripe, which operates globally. Stripe is certified under the EU-U.S. Data Privacy Framework. See: https://stripe.com/privacy • Resend (email delivery) — your email address and name are transmitted for transactional and, if you opt in, marketing email delivery. Covered by SCCs. Timetable photos are processed in real-time and are not stored by Anthropic or by us after extraction is complete. For any other transfers outside the EEA that may become necessary in the future, we will ensure adequate safeguards are in place (SCCs or adequacy decisions).
StudiPace uses AI to power several features. We use Anthropic's Claude models via Anthropic's commercial API. Anthropic acts as a processor and does not use data sent through this API to train its models. Below we describe each feature and the data involved. Timetable photo recognition: When you scan a timetable, the photo is transmitted to Anthropic solely to extract text (subject names, days, times). The photo is processed in real time and is not stored by us or by Anthropic afterwards. Only the extracted entries are saved. Legal basis: Art. 6(1)(b) GDPR. Study-time estimation: To suggest how long to study a topic, we send the topic name (and similar short study metadata) to Anthropic to obtain an estimate. No name, email, or password is included. Legal basis: Art. 6(1)(b) GDPR. Daily Chat (Max plan): Daily Chat is a text-based conversation in which you describe your homework, exams, or how your day went, and the AI proposes schedule edits. We store your chat messages and an AI-generated study profile ("memory"): your communication style, durable study habits and goals, a rolling personal context of roughly the last 14 days (which may include mood or life events you mention), and short per-subject notes. This profile and a limited recent context are sent to Anthropic to generate each reply. Legal basis: Art. 6(1)(b) GDPR. ML-based personalisation (opt-in): A server-side model learns scheduling weights from your own session and day ratings to bias future session placement. It runs entirely on our infrastructure, is isolated per user, does not train any AI model, and sends no data to Anthropic. Legal basis: Art. 6(1)(a) GDPR (consent — toggle in Settings → Profile). Voice and avatar: StudiPace does not record, store, or transcribe your voice, and does not offer an AI voice avatar or spoken study companion. All AI interaction is text-based. Should we introduce any voice feature in the future, we will update this Privacy Policy in advance and obtain a separate, valid legal basis before any voice data is processed. Where AI processing involves a transfer outside the EEA, see section 10 (international data transfers).
StudiPace uses automated processing to generate and personalise your study plan: • Schedule generation: An algorithm assigns study sessions to dates using a penalty-based scoring system that considers subject difficulty, available time, spacing requirements, and proximity to exam dates. • Readiness scoring: A formula combines four components — coverage (studied vs. planned minutes), spacing (session distribution), quality (your session ratings), and retention (forgetting-curve decay) — into a 0–100 score shown on each exam page. • ML-based personalisation (opt-in only): If you have enabled it in Settings, the system learns scheduling preference weights from your session and day ratings and uses them to bias future session placement. These processes produce study-plan suggestions only. In our assessment they are not "automated decisions" within the meaning of Art. 22 GDPR: the generated schedule has no legal or similarly significant effect on you, and you can freely review, edit, move, delete, or ignore every suggested session at any time. If you have questions about how a suggestion was produced, contact us at support@studipace.com; you can also disable ML personalisation anytime in Settings → Profile.
In the event of a personal data breach, we will act as follows: • Supervisory authority notification: We will notify the LfDI NRW within 72 hours of becoming aware of the breach, as required by Art. 33 GDPR, unless the breach is unlikely to result in a risk to your rights and freedoms. • User notification: If the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay (Art. 34 GDPR) via your registered email address and/or an in-app notice. Notifications will describe the nature of the breach, the categories of data affected, the likely consequences, and the measures taken or planned to address the breach.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notification at least 14 days before they take effect. The current version of this policy is always available at this page. We encourage you to review it periodically. Version history: v1.4 — 5 August 2026: Added optional marketing emails (opt-in at signup or in Settings, delivered via a Resend Audience) and disclosed the anonymous, cookie-free page-view analytics used to measure the signup funnel. v1.3 — 15 July 2026: Split processing by informational vs. registered use, added per-category legal bases, a dedicated AI-features section, right-of-withdrawal data, 24-month inactivity deletion, and the TDDDG basis for necessary storage; clarified that Art. 22 GDPR does not apply; noted that no Data Protection Officer is appointed; removed the discontinued analytics tool. v1.2 — 20 May 2026: Added automated decision-making disclosure, data breach notification procedure, ML profiling opt-in (opt-out by default), and specified LfDI NRW as competent supervisory authority. v1.1 — 9 April 2026: Added sub-processor list, ML profiling consent, and account deletion procedure. v1.0 — Initial release.
For questions about this Privacy Policy or to exercise your data protection rights: Savio Lauro Schreiner Email: support@studipace.com An den Weiden 6 50999 Köln, Germany
See also: Terms of Service · Impressum