Information we collect
We collect the information needed to build private semester plans, run shared study features, and keep the experience safe. This includes:
- Account basics. Nickname, avatar selection, and any profile details you choose to share when building your Study Spaces identity. If you provide an email to link your profile, request support, or ask for a specific follow-up, we store it with the details needed to respond and keep your account in sync. We also record which rooms, circles, and tracks you join so we can show membership lists, schedules, and progress.
- Session metadata. Room identifiers, timer settings, streak counts, and the device-bound
userId/sessionIdpair that helps recognize this browser on return visits. Those browser identifiers are not a password and do not authenticate a paid plan; planner billing uses a separate opaque, HttpOnly browser session. - Planner records. Confirmed course work, availability, schedules, completion and reschedule history, and plan versions are stored privately in our D1 database so you can return across visits. Your browser identifiers and planner cookie link you to that private record; they do not make the plan public.
- Room activity records. Task names, completion timestamps, chat messages, whiteboard drawings, poll questions and votes, Assist questions and responses, and other content you share in rooms, which we store in our D1 database so rooms can replay announcements and conversations.
- Support interactions. Details you provide when contacting our team for help, along with operational logs generated when issues occur.
- Usage analytics. Event-level information about how Study Spaces is used (for example, which rooms are joined, which buttons are clicked, or whether prompts are dismissed) so we can understand feature performance and improve the product. PostHog and Cloudflare Zaraz are the analytics services configured in production.
- Syllabus AI analysis. If you use the free syllabus-to-calendar tool and give explicit consent, one complete source, its label, and an optional calendar year are sent in one analysis request to native Cloudflare Workers AI through the
studyspaces-syllabusAI Gateway. Supported sources are selectable-text PDF, TXT, Markdown, CSV, and pasted text. PDF text is extracted in the browser. The first-run limits are a 5 MB file, 100 PDF pages, 128 KiB of decoded UTF-8 text or 131,072 Unicode code points per source, and 100 date-like candidates; input over a limit is rejected and never silently truncated. There is no provider-initiated web search, URL discovery, or nested link fetching. The browser hashes its anonymous persistent ID into a fixed-length analysis header; Cloudflare invocation metadata may retain that pseudonymous header and edge metadata. Study Spaces stores no raw ID with source material, source text, raw files, provider prompts, provider bodies, or full provider responses. To recover a lost planner response without another provider call, the planner may temporarily retain a bounded, content-safe review DTO, its integrity hash, and an opaque reservation fence for up to 24 hours; this replay receipt is deleted by the existing hourly maintenance. The free syllabus utility remains ephemeral and has no result-replay receipt. Gateway cache and log collection are disabled for this route. Free analysis capacity is bounded and resets at 00:00 UTC; an attempt is reserved before provider work, and provider or validation failures are refunded exactly once. Results are provisional and require human review.
How we use information
We use your information to run and improve Study Spaces:
- Power timers, rooms, streaks, celebrations, and other core features you expect when joining a focus session.
- Personalize the experience, including saving your preferences and profile details on the devices you use.
- Maintain lightweight transcripts of room activity so participants can follow announcements and chat context.
- Monitor service reliability, debug issues, respond to support requests, and keep Study Spaces secure.
- Show your nickname, avatar, and focus stats to other participants where it makes sense—for example in shared rooms, circles, and leaderboards—without exposing your email address.
- Generate helpful responses in the Assist panel by sending your question and recent room conversation to our AI provider when you choose to use that feature.
- Measure usage and run lightweight experiments with PostHog and Cloudflare Zaraz so we can understand which features are working, fix issues, and improve Study Spaces over time. Automatic interaction capture masks visible text and form values; console-log capture is off, and exception signals are reduced to non-content operational metadata. Session replay and heatmaps stay off unless an explicit replay-consent record exists.
Cookies and local storage
Browser storage holds the anonymous userId and sessionId used by legacy rooms, along with timer preferences and other browser-only settings. Clearing it can reset those settings or make recovery necessary; it does not mean that a saved planner is only in this browser.
Some features also rely on small cookies and local flags—for example to remember autolaunch preferences, onboarding walkthrough state, or install prompts. PostHog may use a browser identifier and Cloudflare Zaraz may use its own analytics identifiers, depending on the active configuration. These tools measure product usage and reliability; they are not used to sell your information.
A planner identity cookie is HttpOnly, Secure, SameSite-limited, and opaque. It is used only to recover a planner identity across requests and can be cleared by resetting the identity or browser cookies. A saved one-time recovery link from a signed-in planner device can restore access on another device; Study Spaces does not email it. If every signed-in device and saved link are gone, the planner cannot be recovered here.
Analytics and replay controls
Study Spaces currently uses two analytics services: PostHog for product events, performance, and redacted error signals, and Cloudflare Zaraz for event routing and analytics. We send bounded product telemetry rather than form values or free-form room content.
- Automatic capture. PostHog masks all visible text, element attributes, and form inputs before interaction data is sent. URLs are reduced to their path, without query strings or fragments.
- Error signals. Unhandled errors and rejections may produce a countable PostHog error event, but exception messages, stack traces, and console messages are not sent. Console-log autocapture is disabled.
- Replay and heatmaps. Session replay and heatmap collection are disabled unless an explicit analytics-replay consent record is already present in the browser. No record means these features remain off.
- Retention. We keep analytics events only as long as needed to understand product use, improve reliability, and make product decisions. Retention can vary with the PostHog and Cloudflare Zaraz workspace settings; session replay and heatmap data are not collected by default.
When we share information
We do not sell your personal information. We only share it when it is necessary to operate the platform or when the law requires it:
- With trusted infrastructure, analytics, and AI partners—including Cloudflare (which hosts our Worker and D1 database, provides Zaraz analytics, and processes the consented syllabus AI request) and PostHog (which processes product analytics, performance, and redacted error events)—under contractual and technical safeguards.
- To comply with legal requests, protect our rights, or prevent abuse.
- With your direction or consent, for example when you link Study Spaces to a third-party integration or ask us to follow up on a support request.
Data retention
We keep personal data only as long as needed for the purposes in this policy. Confirmed planner work, availability, schedules, completion and reschedule history, and plan versions remain in our private D1 database so you can return across visits; ending a trial or Semester Pass does not erase the plan, and you can request deletion. Room activity such as task announcements, chat, whiteboard drawings, polls, and Assist conversations is also stored in D1 unless or until it is cleared. Consent-based syllabus AI requests do not retain raw source text, raw files, provider prompts, provider bodies, or full provider responses. The planner may retain a bounded, content-safe review DTO, integrity hash, and opaque reservation fence for up to 24 hours to recover a lost response without another provider call; the existing hourly Worker cleanup removes that temporary receipt. The free syllabus utility remains ephemeral and does not store a replay result. Native Cloudflare Workers AI and the studyspaces-syllabus AI Gateway process one consented source; there is no provider-initiated web search, URL discovery, or nested link fetching. Gateway cache and log collection are disabled for this route, though Cloudflare invocation metadata may retain the pseudonymous request header and edge metadata. Free analysis capacity is bounded and resets at 00:00 UTC. The daily quota table keeps only a hashed identity and attempt count; deletion is scheduled after seven days through the existing hourly Worker cleanup and may lag. Operational caches used to coordinate timers, presence, and WebRTC participants expire within minutes. Product analytics events are retained only for product measurement and reliability work, subject to the active PostHog and Cloudflare Zaraz workspace settings; we do not collect session replay or heatmap data by default. If you request account deletion, we will delete or anonymize your personal information, unless we must retain certain records for legal, security, or reliability reasons.
Your choices
You are in control of your information:
- Update or delete profile details from within the app.
- Clear your saved identity and timer preferences by deleting Study Spaces data from your browser storage.
- Request a copy or deletion of your information by emailing privacy@studyspaces.org.
- Link or remove an email address from your profile at any time, or continue using Study Spaces anonymously if you prefer.
- Choose whether to use optional features like Assist, whiteboard, polls, or video; the core timer and rooms work even if you keep things text-only or anonymous.
- Session replay and heatmaps are off unless you have explicitly opted in. To ask about analytics access, deletion, or a privacy concern, email privacy@studyspaces.org.
Children's privacy
Study Spaces is designed for individuals who are at least 13 years old (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children without parental consent. If you believe a child has provided information to us, please contact us so we can delete it.
International users
By using Study Spaces, you understand that your information may be processed in the United States and other countries where we or our service providers operate. We take steps to ensure your data is handled securely and in line with this policy.
Changes to this policy
We may update this Privacy Policy to reflect product, legal, or regulatory changes. We will post the revised version here and update the date at the top of the page. Significant updates may be shared through additional notice in the app or by email.
Contact us
If you have questions about this Privacy Policy or our data practices, email us.
We are committed to helping you stay focused without compromising your privacy.