Privacy Policy

Last updated: 3 May 2026

What we collect

To run StudySync we ask for, and process, the following from your Google account(s):

  • Profile — your email, name, and avatar URL.
  • Calendar events — read access to your primary calendar so the scheduler can see when you're busy and write study blocks back to it.
  • Drive files (Student account only) — read-only access to course folders you point us at, so we can attach the right case PDFs to upcoming study blocks.
  • Gmail messages (Student / Personal accounts only) — read access for classification and label-write access for the StudySync/* labels we apply to your inbox.
  • Razorpay payment metadata — order IDs and capture status. We never see card numbers — those go directly to Razorpay.

How we use it

  • Run the AI scheduler that generates your weekly study plan.
  • Surface upcoming class info on your dashboard.
  • Categorize and label inbox messages, when you ask us to.
  • Process payments for paid plans.
  • Send essential service emails (billing receipts, security notices). We do not send marketing email without your opt-in.

What we don't do

  • We never sell, share, or rent your data to third parties.
  • We never train models on your private content.
  • We never read or analyse your Work email — Work accounts are granted Calendar scope only.
  • We never post, send, or modify anything in your Google account that you didn't explicitly trigger.

Storage and security

Your OAuth refresh tokens are encrypted at rest with AES-256-GCM before being written to our database. The encryption key lives in a managed secret store, separate from the database. Sessions use opaque random tokens and expire after 30 days of inactivity. All traffic is TLS 1.2+.

Cached data — calendar events, classified emails, scheduled study blocks — is retained only as long as your account is active.

Your rights

  • Access: email support@studyinsync.com for an export of everything we hold on you.
  • Deletion: click Delete account in your dashboard or email us. Hard-delete propagates to all backups within 30 days.
  • Disconnect a Google account: click the × on the account tile on your dashboard. We immediately delete all cached data tied to that account.
  • Revoke at Google: you can also revoke our access at myaccount.google.com/permissions. We'll detect that on the next API call and stop syncing.

Children

StudySync is not intended for users under 18. We don't knowingly collect data from minors.

Changes to this policy

If we make a material change, we'll notify the email address on your account at least 14 days before it takes effect. Otherwise, the "last updated" date above reflects the most recent revision.

Contact

Questions, requests, complaints — email support@studyinsync.com. We aim to reply within 2 business days.