Privacy Policy
Last updated: 2026-09-17 · This privacy policy describes the processing currently implemented in the web interface.
At a glance
- We process account data, learning material and progress when you use the corresponding learning feature.
- AI features send requested content to an AI provider through our backend. A local guest example in Flutter v2 requires no upload for this purpose.
- Usage analytics runs without a prior prompt during the current internal test phase. You can object at any time (analytics settings in section 8 or Do Not Track); your learning features remain available.
- You can delete your account in your profile. Without the app, you can reach us through Delete account or Support.
1. Controller
Benneth Müller, Borgfelder Straße 16, 20537 Hamburg, Deutschland. Contact: ben@creaiter.com.
2. Providing the application
The frontend is publicly available at studyventure.app and is hosted by Netlify. Technically necessary connection and device information, such as IP address, time, requested URL, browser and operating system details, may be processed for delivery, stability and abuse prevention. Netlify describes possible international transfers and the transfer mechanisms used for them. Details: Netlify privacy information. Further provider information is at the end of this section.
The StudyVenture backend API called by the interface is hosted on Render. When the API is called, including for public guest uploads, the connection data needed for the request and the submitted content are processed through Render's infrastructure. Details: Render privacy information. Further provider information is at the end of this section.
The technically necessary provision of requested features is based on Article 6(1)(b) GDPR. For stability, error handling and abuse prevention, we process necessary technical data on the basis of our legitimate interest in a secure, functioning service (Article 6(1)(f) GDPR).
Further provider information and unresolved details
We name the services involved alongside each feature. Some details of the provider accounts actually used have not yet been conclusively verified: the respective contracting entity, data processing agreements, subprocessors, processing regions, specific logging and retention periods, and safeguards used for possible transfers to third countries. We therefore cannot guarantee processing exclusively in Europe, a particular provider-side deletion period or a general exclusion of logging and model training. The linked provider information explains general terms; it does not replace confirmation of our specific account configuration. You can send questions about this to ben@creaiter.com.
3. Learning account, sign-in and contact
For registration, sign-in and session management, the web interface sends your email address and the credentials needed for your chosen sign-in method to Supabase Auth, such as a password or confirmation code. The interface does not store the password in plain text. Supabase keeps the session in the browser and refreshes the access token; the StudyVenture server receives the token to associate protected learning actions with the account. The legal basis is Article 6(1)(b) GDPR for providing the learning account.
Provider: Supabase, Inc./Supabase Pte. Ltd. Details: Supabase privacy information. Further information on providers and transfers is in section 2.
3.1 Other sign-in providers
Sign-in with Google or Apple is currently paused. The web interface does not offer the corresponding provider buttons. Existing return routes remain technically available for sign-in processes already started; they do not enable the paused entry route.
3.2 Account messages and support
Supabase generates requested messages for account confirmation, sign-in, password resets and account security. Hostinger sends these messages. This involves processing the recipient address, message content including necessary confirmation or sign-in links, and delivery information. Such links may contain short-lived sign-in credentials; do not share them. The legal basis for requested account messages is Article 6(1)(b) GDPR.
When you contact us by email, we process your address, message text, any attachments you choose to include, and the metadata required to deliver and answer the message. The support mailbox is also hosted by Hostinger. We handle contractual matters under Article 6(1)(b) GDPR and general enquiries under Article 6(1)(f) GDPR based on our legitimate interest in responding and communicating securely. We use the information to handle your enquiry. Further information: Privacy at Hostinger.
4. Learning material, AI processing and progress
Users can send text, video URLs and files up to 8 MB to the configured StudyVenture backend API. PDFs may be up to 24 MB. PDFs up to 8 MB may be sent in full to a configured document AI provider in the signed-in creation flow; large PDFs and selected PDF pages are instead converted to text on the server. JPEG, PNG and WebP source images up to 24 MB are resized locally in the browser before upload, so only the optimized image is transmitted. Materials may contain personal or confidential content; such content should only be uploaded if you are authorized to do so.
In the public Quickstart, exactly one PDF, DOCX, TXT or MD file up to 5 MB can be processed before sign-in. PDF and DOCX files in this guest route are always converted to text on the server; the complete file is not forwarded to the AI provider and is stored in Supabase neither as a file nor as a regular study set. For resumption and later transfer to an account, the backend keeps only a short-lived trial set of five flashcards derived from the material, together with random, hashed transfer keys. It is no longer usable after two hours and is removed during ongoing technical cleanup.
For AI imports, the backend may use OpenAI, Google Gemini or Anthropic depending on its server configuration. The specific active provider is not hard-coded in the interface. The purpose and legal basis are performance of the requested contract under Article 6(1)(b) GDPR. Before the first AI import the app obtains permission for this feature; it can be revoked at any time under Profile → Privacy. Providers used in production depend on server configuration; unresolved details are in section 2.
In the character studio, signed-in users can request a profile character or a purely cosmetic helper pet from fixed role, mood, colour and supporter options. Optionally, in the web interface users can select their own JPG, PNG or WebP image up to 8 MB as a loose style reference. They must confirm their rights to the image and explicitly confirm that it does not depict a real person. The reference is transmitted transiently to OpenAI Images Edit, normalized on the server and stored in StudyVenture neither as a source file nor as a reference. Instead of the raw account ID, OpenAI receives only a hashed provider user identifier derived from it. Without a reference, the backend creates a technical image prompt solely from the closed set of options. The normalized result is converted to 384 × 384 pixels in WebP format and stored in private Supabase storage associated with the account. It can only be retrieved through the authenticated StudyVenture API and is removed, together with the selection and generation log, during self-service account deletion. Deleting a StudyVenture account does not automatically delete possible technical logs at the AI provider; their scope and retention periods depend on the applicable provider contract. The production reference-image feature also remains subject to server-side enablement. The information in section 2 applies to possible provider logs and transfers.
With the AI tutor, the explicitly submitted question is sent to the AI provider configured on the server together with at most six entries from the previous conversation and at most six cards from the selected study set, selected on the server for their relevance to the question. In addition to questions and answers, card excerpts may include existing answer options, explanations, hints, examples and keywords. StudyVenture does not persist the tutor chat in its database; the interface keeps it only in its current runtime state. Before the first question to the AI tutor the app obtains permission for this feature; it can be revoked at any time under Profile → Privacy. The history is reset when the page reloads or the user identity changes.
The card, study set, file or URL references displayed by the tutor identify the study set used for the answer. They do not independently confirm that an AI statement has been checked against the original document, a specific PDF page or an external source. Further information on possible provider logs and transfers is in section 2.
During the current test phase, Cloudflare Turnstile is temporarily disabled for the public Quickstart. In this mode, the web interface loads no Cloudflare widget, and the backend sends neither a Turnstile token nor the derived IP address to Cloudflare for guest generation. Our own strict abuse limits remain active: StudyVenture processes the derived IP address to limit requests and stores only a domain-specific HMAC hash for the 24-hour allowance. The raw IP address is not stored in the preview table.
Users under 16 should only enable the AI features with the agreement of a parent or guardian. The AI permission dialog shows a corresponding notice; nothing is blocked. The sole basis for this is the age band stored during setup (under 14, 14–17, 18–24, 25 and older) — no date of birth is collected. The age band determines the example sets suggested, the length of the daily learning path and whether this notice appears.
Video sources and quality checks
For a supported video source, the backend sends the normalized video URL to Supadata (Dumpling Software UG) to retrieve a transcript. The transcript is then passed to the configured AI provider for the requested card creation. The source reference and processing job are stored in association with the account. Further information: Privacy at Supadata.
The backend supports OpenAI, Google Gemini and Anthropic; server configuration determines which services process a particular generation request. A quality check may send the original material or medium and proposed cards to the same AI provider again. It serves to check the requested cards; no additional permanent review log of this AI assessment is created. The exact provider assignment currently used in production has not yet been conclusively verified. Information on processing through the APIs: OpenAI: API data controls, Google: Gemini API terms and Anthropic: commercial terms. This information must be distinguished from the terms for personal chat accounts. The contractual version and account settings applicable to the specific service still require separate verification.
For AI card and tutor requests from signed-in users, we store the account ID, UTC date and number of reserved AI provider attempts in Supabase. Failed attempts also count. These technical counters limit daily AI usage, prevent abuse and control costs; they are separate from optional usage analytics. There is one counter row per account. When another attempt is reserved on a new UTC day, the date and count in that row are replaced. Otherwise, the row is retained until account deletion and is deleted with the account. A separate global daily counter row contains no account ID; deleting an individual account does not reset that counter.
Stored study sets, cards and confirmed learning actions are associated with your account so you can learn, resume and view your progress. Depending on the feature, this includes answers, correctness, learning timestamps and game or learning progress. The purpose is to provide the requested learning service (Article 6(1)(b) GDPR); separate optional usage analytics is explained in the analytics section.
The memory-image tool processes entered notes locally in the browser and uses fixed design rules to create a graphic. It does not call an AI provider for this purpose. An explicitly triggered download creates the PNG file locally and saves it through your browser's download function; notes and graphics are not uploaded for generation.
Purchasing is currently disabled; the regular product route offers no purchase completion. Technically prepared purchase or plan interfaces alone do not trigger a payment. If you already hold entitlements from earlier use, they may remain associated with your account. The description of payment processing must be supplemented before purchasing is enabled.
5. Live matches and challenges
In live multiplayer, the StudyVenture backend processes participant associations through learning accounts, display names, the study set used, match and invitation codes, game configuration, connection and match status, and timestamps. During the game, questions, answers, HP and rankings are synchronized between participating clients and the match server. After the match, the score, number of correct answers and, for each round, card reference, submitted answer, correctness and response latency are stored in Supabase. This data supports running the requested game, reconnection, server-side evaluation and displaying results; the legal basis is Article 6(1)(b) GDPR.
For an asynchronous challenge, the backend stores the creator, study set, card order, game configuration, reference score, display name, sharing code, status and creation time. Anyone with the link or code receives the shared questions and answer options without solutions, together with the display name and reference score. The challenger's answer log is transmitted for server-side evaluation; the current backend route does not persist this attempt log. Challenge links should therefore only be shared with the intended people.
6. Applying to the creator programme
Anyone applying through the form on the Creator Programme page submits their name, email address, selected platform and the link or username of their profile. A free-text motivation and the person who referred the application may be added voluntarily. Confirmation of adulthood, consent to this processing, the receipt timestamp and the application's processing status are also stored.
Processing is solely for reviewing and responding to the application and contacting the applicant about it. The legal bases are Article 6(1)(b) GDPR (steps before a possible contractual relationship) and Article 6(1)(a) GDPR (consent given in the form). The information is not used for advertising, usage analytics or profiling. The technical service providers described here are used for storage and communication; the application is held in the same Supabase database as the other application data and is accessible there only to the backend.
Consent can be withdrawn at any time with effect for the future. Application data is needed only for as long as required for the decision, requested further contact or statutory retention duties. We currently cannot guarantee automatic deletion after a fixed number of months. If no further contact is desired, an informal message to the address stated in the legal notice is sufficient.
7. Storage in the browser
StudyVenture uses the following storage only for the respective purposes stated:
- Supabase session and access token for the learning account and sign-in.
- Local Storage for user-specific learning/demo states, active sets and UI settings.
- The technically necessary `studyventure.locale` cookie stores the selected interface language (German or English) for at most one year and applies to the entire website. It contains no user identifier.
- Session Storage for short-term game, result and navigation handovers and a versioned, unsaved study set editor draft in the current tab. The draft may contain a set title, description, card content and AI instructions, and is deleted after successful saving or confirmed discarding.
- Quickstart temporarily stores the preview ID, random resumption key, expiry time, five derived trial cards and the previous answer log in the current tab. The raw file, extracted source text, file name, IP address and access token are not stored there. The entry is removed after confirmed transfer to an account and is no longer usable after expiry.
- An account-specific active match snapshot in Session Storage contains the match ID, invitation code and, where applicable, the invitation link. It enables reconnection after a reload and is removed on leaving, signing out or an actual account change.
- For enabled browser reminders, `studyventure.reminder-device.v1` stores an account-specific device identifier. The `studyventure-reminder-state-v1` cache keeps the local activation state for the service worker. These entries are used exclusively for the requested reminders.
- `studyventure.analytics-consent.v7` stores the voluntary analytics decision. `studyventure.analytics-home-prompt.v7` only remembers whether the optional offer was displayed on the home page. This technically necessary display marker prevents repetition and does not permit analytics.
- After consent for previously activated analytics is withdrawn, PostHog also stores a non-identifying opt-out marker with the prefix `__ph_opt_in_out_`, so the already loaded SDK sends no further events. Declining before the first activation does not load the SDK and therefore creates no PostHog marker.
- From the first visit and only without Do Not Track: `studyventure.analytics-id.v1` contains a random pseudonymous browser ID and its expiry time. It is valid for at most 90 days, is then replaced and is deleted when you object. While you are signed in, it is linked to your account identifier; on sign-out it is replaced with a new one, so subsequent use without sign-in is no longer attributed to your account.
- During the current internal test phase, PostHog creates its own entries (`ph_…`) in Local Storage and cookies without asking beforehand, so that sessions and recordings are connected across page changes. If you object using the analytics settings further down this page, these entries are deleted.
Technically necessary storage accesses are based on section 25(2), no. 2 TDDDG; subsequent processing is necessary for performance of a contract under Article 6(1)(b) GDPR. Analytics processing takes place only with consent under section 25(1) TDDDG and Article 6(1)(a) GDPR; the opt-out marker is technically necessary to reliably respect withdrawal (section 25(2), no. 2 TDDDG).
Browser reminders
If your browser supports the feature and the service is configured for it, you can enable learning reminders in your profile. A push subscription is created only after your selection and browser notification permission. The stored data includes the push address (endpoint), the keys needed for encrypted delivery, your account and device association, and the weekdays, time, time zone and language of the requested schedule.
Our backend sends encrypted notifications to your browser's push service: depending on the browser, Google (Firebase Cloud Messaging), Mozilla or Apple (Apple Push Notification service). The respective service processes technical delivery and connection data. An individual push delivery has a short validity period of five minutes; this is not a deletion period for your stored schedule. The purpose is the reminder you requested. This optional processing is based on consent (Article 6(1)(a) GDPR and section 25(1) TDDDG). You can turn the reminder off in your profile or withdraw notification permission in your browser. Changing browser permission alone does not automatically delete the settings stored in your account.
8. Usage analytics with PostHog (internal test phase, without a prior prompt)
During the current internal test phase, the frontend loads `posthog-js` without asking beforehand and sends data to the configured PostHog endpoint; the documented default is the EU endpoint. Your consent is therefore not requested in advance. You can object to this processing at any time — using the analytics settings further down this page and using your browser's Do Not Track setting. An objection is stored, stops the processing immediately and remains effective on later visits. Event content consists of pseudonymous page views of known, normalized routes and deliberately defined product actions. These include entry into study set creation, completed sign-in/registration, start and result of study set generation, collection actions, starting/resuming/cancelling/completing learning rounds, broadly bucketed answer correctness and response time, daily bonuses, interest in games and claimed achievements. Quantities, percentages, duration and latency are sent only as broad ranges. To measure time spent, the application also sends a heartbeat every 30 seconds with the broad area you are in (such as Learning or Collection), and the time spent in an area as a broad range when you leave it. The heartbeat pauses when the tab moves into the background or there has been no input for five minutes. Time spent also counts only active foreground time. Entry into and departure from an area are recorded with the platform (Web, iOS or Android), contract version and the reason: navigation or a background transition. This can reveal interruptions and usage patterns; a missing completion does not prove a crash. Short-lived random analytics session identifiers connect related events and, where applicable, the masked replay.
Technical error diagnostics: With the same voluntary consent, we record unexpected JavaScript and rendering errors as a broad error class, affected area and technical code position (delivered program bundle file, line and column). Free-form error messages, function names, source code, local file paths and request content are not transmitted. Rejected asynchronous operations can also be detected this way. Reports are limited to avoid error loops. Operating system crashes or closing the browser are not reliably captured. This expanded scope requires new consent (version v7); earlier refusals remain in effect.
Onboarding interruptions: We record the currently visible setup step, next, back and skip actions, direct start, save attempts, save success or failure, completion, and navigation or background transitions with broad active duration. A random attempt identifier created only after consent, a sequential event number and the first observed step connect this run. The identifier remains only in memory and changes on a new run, account change or renewed consent. Steps visited before consent are not added retrospectively. Goals, subjects, exam dates and time budgets are not transmitted. A final step without completion indicates a possible interruption, not its cause or proven permanent abandonment.
Learning progress, creation and return visits: Random, transient session and attempt identifiers connect learning start, the first visible question, the first confirmed answer, completion and interruption. For set creation, we record the method, broad source type, preview, saving step and result, plus waiting time and card count in ranges. An uncertain saving status is distinguished from a confirmed error. Sessions and identifiers change on restart, account or consent changes and after at least 30 minutes in the background. Earlier actions are not added retrospectively. For registered accounts, the account UUID is used to evaluate whether learning resumes on later days. No additional permanent device identifier is created; guests are not included in this account-based return measurement.
For the tutor and memory-image tool, we record explicitly triggered operations, success or failure and successful downloads. For the Pro offer, we record viewing, deliberately selected plan options and closing, as well as the actual availability of purchasing. An option automatically suggested from an exam date is not transmitted. Purchase completions or revenue are not claimed without an actual purchase.
Association with your account: If you are signed in and have not objected, analytics events are associated with your account identifier. Only three additional broad attributes are transmitted: whether the account is a guest or registered account, the calendar week of registration (not the day), and the selected language. If you previously used the app as a guest or without signing in, these earlier events are attributed to your account.
Specific study set, card or game session IDs, titles, learning material, questions, answers, explanations, file names, video URLs, invitation codes, email addresses, names, scores, payment data and raw error messages are not transmitted. During the current internal test phase, without asking beforehand, session recordings (Session Replay) and automatically captured interactions (Autocapture: clicks, visited pages, time spent) are also transmitted, including the browser and device properties technically needed for them. All input fields are masked in recordings, as are flashcard questions, answer options and explanations, so a recording does not reveal which content a particular person studied. Surveys and feature flags remain excluded. You can object to this at any time using the analytics settings further down this page and using your browser's Do Not Track setting. The random browser ID helps understand usage and return visits by the same browser within at most 90 days; account association is described above. A stored objection remains in effect until you lift it again in the analytics settings.
During HTTPS transmission, PostHog technically also processes connection data such as IP address, time and user agent. The frontend does not pass this information as its own event properties. Whether and for how long the provider stores connection data depends on its processing and account settings; the unresolved details described in section 2 apply.
The recipient/processor is PostHog, Inc.; Frankfurt in the EU is the intended cloud location. PostHog may use subprocessors and, as a US company, have connections to third countries. Further provider information is in section 2. Details: Privacy at PostHog. We currently cannot state a specifically verified retention period for the PostHog account in use.
You can object to usage analytics at any time with effect for the future — using the analytics settings below or your browser's Do Not Track setting. An objection does not affect any learning feature. It stops new events, deletes the first-party browser ID and resets the PostHog identity in the browser so future activity is no longer associated with your account. Data already stored at PostHog and associations already made are not automatically deleted; contact support for deletion.
Analytics settings
Current status: Not decided yet
When allowed, we measure sanitized page paths and broad product and learning signals including active screen duration, interruptions and sanitized technical errors with code positions. Setup steps, navigation actions and save outcomes are connected by a temporary random attempt ID; setup answers remain excluded. Registered accounts are used to measure return learning visits. Learning attempts, import outcomes, waiting times, tutor, memory images and deliberate Pro interest help identify friction. Session IDs also change after 30 minutes in the background. A random browser ID is valid for 90 days, and short-lived analytics session IDs connect events. While signed in, your account identifier, account type, sign-up week and language are added. Learning content, specific answers, your email address, name, scores and purchases remain excluded; withdrawing consent deletes the ID and removes the link to your account.
AI features
StudyVenture asks for your permission per feature before its first use. You can grant or revoke it here. Without permission no content goes to an AI provider; the rest of the app stays usable.
Without an account your choice applies to this browser only. After you sign up StudyVenture asks again before the first call.
AI import
Loading the recipient details …
AI tutor
Loading the recipient details …
Character studio
Loading the recipient details …
For a signed-in account, previously stored local analytics consent is not sufficient on its own: the account's current consent status is also checked before activation. This prevents a previous withdrawal from being overwritten by an old device decision. You give new consent explicitly through the existing analytics setting. If verification fails, analytics remains disabled. Guests can continue to decide about optional local analytics without an account.
9. Retention and deletion
Account, learning material and progress data are stored only for as long as necessary for the learning service, legal duties or handling a deletion request. In the web interface, you can start two-step account deletion in your profile and explicitly confirm it. Alternatively, you can request deletion through Delete account or by sending a message to ben@creaiter.com. Local demo and UI data can be removed by deleting the website data.
Guest trial sets not transferred to an account have a functional lifetime of two hours. Failed and expired entries are cleaned up during Quickstart requests. This usability period does not guarantee that every record is physically deleted exactly after two hours.
10. Data subject rights
Under the GDPR, you have in particular the following rights, subject to its conditions:
- Access (Article 15), rectification (Article 16) and erasure (Article 17),
- Restriction of processing (Article 18),
- Data portability (Article 20),
- Objection to processing under Article 21,
- Withdrawal of consent with effect for the future (Article 7(3)),
- Complaint to a data protection supervisory authority (Article 77).
Your right to object
Where processing is based on legitimate interests (Article 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We stop this processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or grounds for pursuing or defending legal claims. If processing for direct marketing takes place, your objection ends that use without such a balancing of interests.
How we handle your request
We respond to your request without delay, at the latest within one month of receipt. Where an extension is necessary because of scope or complexity, we inform you within that month and give reasons; an extension of at most two further months is possible. Requests are generally handled free of charge. Where we have reasonable doubts about identity, we request only the additional information necessary for confirmation. We answer electronic requests electronically where possible. If we refuse a request, we explain why and inform you about complaint procedures and judicial remedies.
To exercise your rights, simply send a message to ben@creaiter.com.
11. Required information and automated decisions
Account and learning material data are required only when the relevant feature is used. Analytics is entirely optional. No decision based solely on automated processing with legal or similarly significant effects within the meaning of Article 22 GDPR takes place.