Back to courses

Privacy Policy

Last updated: March 16, 2026

1. Data Accessed

When you sign in with Google we access the following Google account information: (1) basic profile information (display name and profile photo), (2) the email address associated with your Google account, and (3) a Google account identifier used to link your PoliStudy account. We also request offline access (a refresh token via OAuth) so your session can be refreshed without repeated sign‑ins. Authentication and token handling are managed by our provider (Supabase).

2. Data Usage

We use Google account information to authenticate you and to create or populate your PoliStudy profile (display name, avatar). We associate your account with app data such as pinned courses, quiz attempts, streaks, and supporter/donation status. We also use profile data to personalize the UI and to permit access to authenticated features. We do not use your Google account for marketing unless you explicitly opt in.

3. Data Sharing

We do not sell your Google account data. We share information only with third-party services that are required to operate the Service: (a) Supabase — for authentication, user accounts, and data storage; (b) Groq (LLM provider) — used to generate tutor explanations (user-submitted question text may be sent to Groq); (c) Ko‑fi (donation provider) — webhook payloads may include donor email and name and are used to match donations to PoliStudy accounts. We do not send Google profile or email to Groq as part of normal operations. Each provider processes data according to their policies.

4. Data Storage & Protection

User data and application data are stored in our hosted database (Supabase). Access to production secrets and service-role keys is restricted to server-side code only. Key protections include session cookies issued over HTTPS, Row-Level Security (RLS) policies that limit users' access to their own rows, and administrative routines that run with a service role key on the server. If you need more technical details about backups or encryption-at-rest, contact support and we will provide infrastructure-level information.

5. Data Retention & Deletion

We retain personal data only as long as necessary to provide the Service and to meet legal obligations. You can permanently delete your account from the Settings page; this triggers an administrative removal of your authentication record and cascades deletion of associated application data (profile, pinned courses, recorded attempts, supporter rows). Some backups and logs maintained by our hosting provider may persist for a short period after deletion. To request deletion or ask about retained backups, please use our contact form and include your account email or user id.

6. Account Deletion (How it works)

To delete your account: open Settings → Delete Account and confirm. The site will call an admin routine that removes your auth record and cascades deletes on related data in our database. After deletion you will be signed out. If you cannot access the account, please use our contact form and include proof of ownership and we will guide you through the process.

7. Third-Party Processors & Purpose

Third-party services we rely on process data only for the purposes described: authentication and session management (Supabase), AI-driven content (Groq), and donation processing (Ko‑fi). We limit what we share to the minimum necessary for each service to perform its function and rely on contractual and technical protections with those providers.

8. Security

We apply reasonable administrative and technical safeguards to protect user data, including restricting service-role keys to server-side code and using HTTPS for all network traffic. No internet service can be guaranteed fully secure; please report suspected breaches using our contact form immediately.

9. Your Rights

Depending on your jurisdiction you may have rights to access, correct, or delete personal data. To exercise these rights, please use our contact form with your request and we will respond under applicable law. For account deletion see the Settings page (Delete Account) or use our contact form if you need assistance.

10. Contact

For privacy questions, data access requests, or deletion requests contact us at

Questions about privacy? Contact us at