Privacy policy
Draft v0.3 · 2026-09-28 · Not yet in force. The final text will name the controller (a sole trader / individuali veikla registered in Lithuania), the contact e-mail and the effective date. Payments are handled by Paddle.com Market Limited (UK), which is a separate controller for that data (§1).
The short version
- Your Moodle password never reaches us. Your deadlines come from the calendar export link you give us, fetched once when you press the button and never stored on our servers; your course files are read by the Tinystudy button, a bookmark you press inside your own signed-in Moodle tab; it reads only what that tab shows you, on your instruction, and your Moodle session never leaves that tab.
- Your course files, transcripts and study content are kept in your own browser. Two things go to Cloudflare, only when you press the button, only to be processed and not kept: the text of the material for one test (study content), and short audio pieces of a video lesson (transcription), described below (§3).
- We keep the minimum for an account: your e-mail, your plan and trial dates, and, if you sign in, an encrypted copy of your settings and your list of tests and exams that we cannot read. Your plan and progress stay on your device.
- No advertising, no selling of data, no tracking across sites. Usage statistics are shared only if you switch them on.
- Processors working for us: Cloudflare (hosting), Resend (e-mail delivery), Paddle.com Market Limited (payment, as an independent controller for that data), and Cloudflare Workers AI for the optional cloud preparation of study content (§1, §3).
- You can delete your account and its data with one button (only a one-way record that a free trial was used stays, kept 12 months, plus your birth month and year only if the account was blocked because you declared an age under 18, see §2).
1. Who is responsible
The controller is the provider named in the Terms (a sole trader / individuali veikla registered in Lithuania). Your school remains the controller of the data on its Moodle site; we process what you, the student, choose to read from it through your own access, on your instruction (GDPR Article 6(1)(b), performance of the contract with you). We do not act for or on behalf of your school. Some processing is done for us by others, each acting under contract as our processor unless stated otherwise: Cloudflare (hosting our API, §5), Resend (sending sign-in links, receipts and reminder e-mails), and, for the optional cloud preparation of study content, Cloudflare Workers AI, named in the app next to the button (§3). Paddle.com Market Limited, a company registered in the United Kingdom, is our merchant of record: for payment, invoicing and VAT, it acts as an independent controller, not our processor (§2, §6; see also Terms §6).
2. What we process and where
| Data | Where it is processed | Purpose | Kept |
|---|---|---|---|
| Moodle password | Never with us. The password route sends it to your school's own login endpoint from your device and keeps only the token it returns. | — | — |
| Moodle calendar export link (deadlines) | Fetched server-side, once, when you press the button; not stored or logged | Showing your deadlines and notifications | Not stored |
| What your Moodle shows you (courses, pages, files), read by the Tinystudy button | Read inside your own Moodle tab and handed to the Tinystudy tab in your browser; it does not pass through our servers. Your Moodle session, cookies and tokens never leave the Moodle tab. | Reading your courses and files for your own study | Not held by us |
| Course materials, transcripts, the study content built from them | Your own browser (its IndexedDB storage) | Your private study | Until you press "Delete everything Tinystudy keeps in this browser" in Settings (it clears the IndexedDB storage "tinystudy", the device-key store of the "planas" database, and the planas.* and tinystudy entries in this site's local storage, on this browser only) or clear the site's data in your browser |
| Text of the material for one test, when you press the button for study content | Our processing service on Cloudflare and Cloudflare Workers AI (§3) | Producing your study content | Deleted when the job ends (within one day if it cannot run); the finished content within seven days |
| Audio pieces (60 seconds each) of a video lesson, when you press the button to transcribe it and the lesson has no captions | Our processing service on Cloudflare and Cloudflare Workers AI (§3) | Turning the lesson into text | Not stored and not logged; the piece exists only while it is processed. Only the number of seconds used is counted for your daily limit (30 minutes a day free, 120 on trial, 600 paid), per day |
| Account e-mail, plan, trial dates, consent choices, your birth month and year (no day) | Our hosted API (Cloudflare, EU/US edge; contract-based safeguards for transfers, see §5) | Sign-in by e-mail link, subscription, trial limits | Until you delete the account; then removed within 30 days including backups |
| Hashed Moodle identity (a one-way fingerprint of your site + user id, only if you connected a school site) | Our hosted API | A counted signal against trial abuse; it is never used to refuse you a trial | The count is kept 365 days; deleting your account lowers it, and it is removed when it reaches zero |
| Free-trial and age record (a one-way, peppered fingerprint of your e-mail address, the date a free trial was used, and, only if the account was blocked because you declared an age under 18, the birth month and year you declared) | Our hosted API | So that a deleted account cannot start a second free trial, and a blocked sign-up made again with the same e-mail address cannot give a different age (a different address starts without this record). It holds no readable e-mail address, and it is never reversed back to one. | At most 12 months after it last changed; it is kept when you delete your account (see §6) |
| Settings and your list of tests and exams (cloud sync, for signed-in users) | Our hosted API, encrypted on your device before upload so that we hold ciphertext only; the key stays on your device and moves to another device only with your recovery code | Using the app on more than one device | Until you delete them or the account |
| Class-sharing pack and file fingerprint (only if you switched class sharing on) | Our hosted API | Reusing a study pack among classmates who opted in (§3A) | At most 30 days after its last use. The record holds the fingerprint of the material chunk and the pack only: nothing about who shared or who claimed it is stored, so a pack cannot be traced back to you |
| Bug and feature reports | Our hosted API | Fixing and improving the app | 24 months |
| Usage statistics (only if you switch "Help improve the app" on) | Our hosted API | Improving the app; event names, counts and error classes only — never your name, school, course content, grades or Moodle identity | 24 months, aggregated |
| Checkout and payment-hold records (a one-way hash of the checkout reference, and the subscription id; for a payment event we could not apply, its id, type and reason; when an account with a stored Paddle subscription reference is deleted, a record holding only that subscription id and the time - a free trial has no such reference and leaves no record; no e-mail, no card data) | Our hosted API | Linking a payment to the right account, and handling refunds for payments we could not apply | Checkout records are deleted with your account; payment-hold records are pseudonymised when your account is deleted: the link to your account is removed, but they still carry the subscription and event ids, which Paddle can trace back to a payment. They are kept for refund handling until the payment case is closed (the subscription cancelled and any refund made), at most 24 months |
| Payment data (card details, billing address) | Paddle.com Market Limited (UK), our merchant of record, as an independent controller | Billing, VAT, invoicing, your payment and withdrawal receipts | Per Paddle's own policy and tax law |
| Country code from your connection | Computed by our API on each request to pick a default language; not stored | Default language | Not stored |
3. Optional cloud preparation of study content
Cloud processing is optional and runs only when you press the button for it. (a) Study content (free plan: your nearest test; trial and paid plan: any test): the text of the course material for that test (at most about 60,000 characters) is sent to our processing service on Cloudflare and processed by Cloudflare Workers AI (an open-weight model that Cloudflare runs as our processor, chosen per language from the models Cloudflare offers, currently Meta Llama 3.3 70B), solely to produce your study content. The material is deleted from our systems as soon as the job ends; if a job cannot run, within one day. The finished study content is kept for you to collect and deleted after at most seven days. (b) Transcription of a video lesson: if the lesson has captions, the app uses them and sends nothing. If not, your browser extracts the audio and sends it in pieces of 60 seconds to our processing service, which has Cloudflare Workers AI (the Whisper large-v3-turbo speech model) turn it into text and sends the text back. The audio is not stored and not logged. Cloudflare does not use either for training models. The app names the provider next to each button before you use it. If you do not want this, use the baseline (no AI) and the captions your school provides. Picture, scan and formula reading happens in your browser and is not sent to us.
3A. Optional class sharing
This is off unless you switch it on in Settings. If you switch it on, then when you and a classmate have both collected the same file from your school's course, Tinystudy can give you the study pack that was already prepared from that file, instead of preparing it again. Your browser makes a one-way fingerprint (a hash) of a chunk of the material; our server uses only that fingerprint to find a matching stored pack, and hands the pack only to a student who proves they hold the same material (by answering a salted check the server chooses) and has also switched sharing on. What is stored is the study pack our service made from your teacher's material (never content typed or uploaded by a student), kept by fingerprint only, with only the study fields (questions, answers, cards, quizzes, tables and exercises). Before it is stored we remove e-mail addresses and phone numbers; the study content is written by the AI from the material and can still contain names that appear in it, such as an author or a historical figure. We do not share your name, e-mail, notes, answers, progress or which school or course you are in. We keep no class lists, and nothing about who shared a pack or who claimed it is stored: the stored record has no link to any account. Requests are rate limited and the pack is not public, listed or searchable. The legal basis is your consent (GDPR Art 6(1)(a)). You can withdraw your consent at any time in Settings: from then on you neither receive nor add packs. Because we deliberately keep no record of who added a pack, we cannot pick out and delete the packs made from your material; every pack is deleted automatically at most 30 days after its last use. If a teacher or school asks us to remove material, use the bug-and-feedback button in the app and we will remove it.
4. Children
Tinystudy is for adults only. We do not knowingly offer accounts to anyone under 18, and you confirm that you are 18 or older when you sign up. We ask for your month and year of birth only to apply this rule. If a person declares an age under 18, the account is blocked; if we find that an account belongs to someone under 18, we close it and delete its data. What was already uploaded to a blocked account (encrypted settings, notification subscriptions, bug reports) stays only until the account is deleted; the app offers the delete button on the blocked notice. To stop a blocked person from signing up again with another age, the declared month and year of birth are kept in the one-way record described in §2, and cannot be changed afterwards. We show no advertising to anyone.
5. Where data is stored and transfers
Our hosted API runs on Cloudflare's network; account data is stored in their EU-eligible data locations where available, and transfers outside the EU are covered by the EU standard contractual clauses and, for US providers, the EU–US Data Privacy Framework where the provider is certified. Course materials stay in your browser, except the material text of a test and the audio pieces of a lesson you send to cloud processing (§3), which Cloudflare processes on its network and we do not keep.
6. Your rights
You can access, correct, export and delete your data. Deleting your account (Settings → "Delete my account and all its data") removes everything else immediately — the account, the encrypted blobs, push subscriptions, checkout records, your birth month and year, and your signed-in sessions on every device — and from backups within 30 days. Bug reports you sent are kept without any link to you. Records of payments we could not apply are pseudonymised: the link to your account is removed, but they still carry the subscription and event ids, which Paddle can trace back to a payment; they are kept until the payment case is closed, at most 24 months (see §2). Deleting your account does not cancel a paid subscription; use the in-app "Cancel subscription" or "Withdraw and get a refund" button first (Terms §6). If a subscription reference from Paddle was stored for your account, we keep only that subscription id (see §2) so that we can stop it and refund anything charged after the deletion. Only the free-trial and age record in §2 stays (a one-way fingerprint with no readable address, at most 12 months; the birth month and year are kept in it only if the account was blocked because of a declared age under 18). Data in your browser (materials, transcripts, study content, tests, settings and the device key) can be deleted by you with the Settings button "Delete everything Tinystudy keeps in this browser", which also runs after you delete your account; it works on that browser only, so repeat it on any other browser or device where you used Tinystudy, or clear the site's data. You may withdraw the usage-statistics consent at any time with the same switch. You can complain to the Lithuanian State Data Protection Inspectorate (VDAI) or your local authority.
7. Security
HTTPS everywhere; sign-in by single-use e-mail links; a strict content-security policy on every page; no third-party scripts; the Tinystudy button only loads a script whose hash is checked, only reads from your own Moodle site and passes data to the Tinystudy tab by an origin-checked, nonce-protected message; hosted data is encrypted on your device before upload. Details: the security page of our source repository.
8. Changes
We will announce material changes in the app and by e-mail at least 30 days before they take effect.
Related: Terms · How AI is used