Privacy policy
This page is available in English and in Lithuanian (lietuvių kalba). Both versions are equally binding.
Version 1.2 · in force from 7 October 2026 (version 1.0 applied from 4 October 2026; 1.1 from 5 October 2026 added the legal basis of each purpose, the right to object and the new steps of the step log; 1.2 adds the card you enter for the free trial, which goes to Paddle only, and the subscription reference of a running trial). Controller: Ignas Dauksa, individuali veikla (a sole trader registered in Lithuania), Kaunas, Lithuania. Contact: support@projektai777.eu. Payments are handled by Paddle.com Market Limited (UK), which is a separate controller for that data (§1). If the English and Lithuanian versions differ, the version more favourable to you applies.
The short version
- Your Moodle password never reaches us.
- Your course files stay in your browser.
- Synced pages are encrypted on your device; we cannot read them.
- No ads, no selling, no tracking across sites. We keep a short log of key steps under a code, not your name, for 90 days, to find and fix problems, stop abuse and count how many people reach each step. You can object: write to support@projektai777.eu.
- You can download everything or delete your account in Settings.
Jump to: 1. Who is responsible · 2. What we process and where · 3. Cloud preparation · 3A. Class sharing · 4. Children · 5. Transfers · 6. Your rights · 7. Security · 8. Changes
Details
- Your Moodle password never reaches us. Your course files are read only by the Tinystudy button, a bookmark you press inside your own signed-in Moodle tab on your own computer; it reads only what that tab shows you, on your instruction, and your Moodle session never leaves that tab. The imported course files and transcripts stay in that browser on your computer.
- When you are signed in, these are uploaded after being encrypted on your device, so that we cannot read them: your settings, your list of tests and deadlines, your progress (ticked tasks and grade goals) and your finished study pages. They are uploaded so that your phone can show them after you press "Connect your phone". The phone gets the key only through the QR link fragment (the part after the # sign), which is never sent to our server. Deleting your account deletes them.
- Five things go to Cloudflare, only when you press the button and only to be processed; each is held only as long as §2 and §3 say (study-content material until the job ends, and up to 24 hours while it waits for its turn; the finished content up to seven days; the text of a transcribed piece 24 hours, never the audio; essay, question and maths text not at all): the text of the material for one test (study content), short audio pieces of a video lesson (transcription), an essay you type for writing feedback, a question with the best-matching passages of your material (Ask my material), and the text of a maths task you photographed (never the photo), described below (§3).
- We keep the minimum for an account: your e-mail, your plan and trial dates, your consent choices, your birth month and year (only to apply the 18+ rule), and the encrypted copy described above.
- No advertising, no selling of data and no tracking across sites. We do keep a short step log to find and fix problems, prevent abuse and count how many people reach each step (section 2): which key steps happened (a sign-in e-mail, a robot check, a notification, a payment, a Moodle import, an error in the app) and whether each worked, under a code that is not your name or e-mail, for 90 days. Only if you tick "Help test Tinystudy" in Settings do we also keep your device and browser type, the screens you open and a few timings, until you switch it off and 90 days at most.
- Why we may process each kind of data (the legal basis) is in the table in section 2; how to object, restrict or withdraw consent is in section 6.
- Processors working for us: Cloudflare (hosting), Resend (e-mail delivery), Paddle.com Market Limited (payment, as an independent controller for that data), and Cloudflare Workers AI for the optional cloud preparation of study content (§1, §3).
- You can delete your account and its data with one button; a running subscription is cancelled first (the records that §2 lists as kept stay, for example the one-way free-trial and age record, payment and withdrawal records and an objection record; see §2 and §6).
1. Who is responsible
The controller is Ignas Dauksa, individuali veikla (a sole trader registered in Lithuania), Kaunas, Lithuania, the provider named in the Terms. For any question about your data or to use your rights, write to support@projektai777.eu. Your school remains the controller of the data on its Moodle site; we process what you, the student, choose to read from it through your own access, on your instruction (GDPR Article 6(1)(b), performance of the contract with you). We do not act for or on behalf of your school. Some processing is done for us by others, each acting under contract as our processor unless stated otherwise: Cloudflare (hosting our API, §5), Resend (sending sign-in links, receipts and reminder e-mails), and, for the optional cloud preparation of study content, Cloudflare Workers AI, named in the app next to the button (§3). Paddle.com Market Limited, a company registered in the United Kingdom, is our merchant of record: for payment, invoicing and VAT, it acts as an independent controller, not our processor (§2, §6; see also Terms §6).
2. What we process and where
The Legal basis column uses the GDPR, Article 6(1): (a) your consent, (b) performance of the contract with you, (c) a legal obligation, (f) our legitimate interest. Our legitimate interest is preventing fraud and abuse, finding and fixing faults, and counting how many people reach each step to improve the service; we keep only what that needs, under codes, for the times shown, and you can object (§6).
| Data | Where it is processed | Purpose | Legal basis | Kept |
|---|---|---|---|---|
| Moodle password | Never typed into Tinystudy. You sign in on your school's own page; the Tinystudy button runs in that signed-in tab. | — | Not processed by us | — |
| What your Moodle shows you (courses, pages, files), read by the Tinystudy button | Read inside your own Moodle tab and handed to the Tinystudy tab in your browser; it does not pass through our servers. Your Moodle session, cookies and tokens never leave the Moodle tab. | Reading your courses and files for your own study | Contract, 6(1)(b) | Not held by us |
| Course materials, transcripts, the study content built from them | Your own browser (its IndexedDB storage) | Your private study | Not processed by us (stays in your browser) | Until you press "Delete everything Tinystudy keeps in this browser" in Settings (it clears the IndexedDB storage "tinystudy", the device-key store of the "planas" database, and the planas.* and tinystudy entries in this site's local storage, on this browser only) or clear the site's data in your browser |
| Text of the material for one test, when you press the button for study content | Our processing service on Cloudflare and Cloudflare Workers AI (§3) | Producing your study content | Contract, 6(1)(b) (you press the button) | Deleted when the job ends (within one day if it cannot run); a job that is still waiting for its turn holds the material for up to 24 hours at most; the finished content within seven days |
| Essay text, when you press the button for writing feedback (at most 6,000 characters, with the task you set) | Our processing service on Cloudflare and Cloudflare Workers AI (§3) | Giving you scores and advice on your own writing | Contract, 6(1)(b) (you press the button) | Not stored and not logged: the text goes to the model once and only counts are kept. Your daily limit counts the number of feedbacks, not the text |
| Audio pieces (60 seconds each) of a video lesson, when you press the button to transcribe it and the lesson has no captions | Our processing service on Cloudflare and Cloudflare Workers AI (§3) | Turning the lesson into text | Contract, 6(1)(b) (you press the button) | The audio is never stored and never logged; a piece exists only while it is processed. The TEXT of a transcribed piece (never the audio) is kept for up to 24 hours so that a retry of the same piece is free, then deleted. Only the number of seconds used is counted for your daily limit (lesson audio is part of Plus and the free trial: 600 minutes a day), per day |
| Account e-mail, plan, trial dates, consent choices, your birth month and year (no day), and, only while regional prices are switched on, two country codes: the country you opened your first sign-in link from and your school's country (from its Moodle web address, two letters only); while regional prices are off, neither is stored | Our hosted API (Cloudflare, EU/US edge; contract-based safeguards for transfers, see §5) | Sign-in by e-mail link, subscription, trial limits, and the price for your country (prices differ by country; the higher of these countries and the one you pay from decides it) | Contract, 6(1)(b): account, quotas and the price for your country | Until you delete the account; then removed within 30 days including backups |
| Hashed school account (a one-way fingerprint of your Moodle site + Moodle user number, made in your browser at your first import; we store only a second, peppered fingerprint of it, never the number) | Our hosted API | One free trial per school account: a second free trial for the same school account is refused | Legitimate interest, 6(1)(f): preventing abuse of the free trial | 12 months after the trial started; it is kept when you delete your account (see §6) |
| Free Plus gift list: a one-way, peppered fingerprint of an e-mail address that the operator gave Tinystudy Plus for free, its end date (or none) and a short label; never the address itself | Our hosted API | Giving that account Plus without payment | Legitimate interest, 6(1)(f): keeping a gift the operator decided to give | Until the operator takes the gift back; it is not removed when the account is deleted, so a new account with the same address gets the gift again |
| Free-trial and age record (a one-way, peppered fingerprint of your e-mail address, the date a free trial was used, the date of an instant in-app refund (one a year) and a mark if a payment was taken back through your bank (a chargeback), and, only if the account was blocked because you declared an age under 18, the birth month and year you declared) | Our hosted API | So that a deleted account cannot start a second free trial, and a blocked sign-up made again with the same e-mail address cannot give a different age (a different address starts without this record). It holds no readable e-mail address, and it is never reversed back to one. | Legitimate interest, 6(1)(f): trial and age-rule abuse prevention | At most 12 months after it last changed; it is kept when you delete your account (see §6) |
| Cloud copy for your phone (for signed-in users): settings, your list of tests and deadlines, your progress (ticked tasks and grade goals), and your finished study pages | Our hosted API, encrypted on your device before upload (AES-256-GCM) so that we hold ciphertext only and cannot read it. The key stays on your device. The phone gets it only through the fragment of the QR link (the part after the # sign), which browsers never send to a server, or through your recovery code. | Showing them on your phone after you press "Connect your phone" in Settings. Imported course files and transcripts are not uploaded; only what you import with the Tinystudy button on your own computer and what Tinystudy built from it as finished study pages. | Contract, 6(1)(b) | Until you delete them or the account; deleting your account deletes them at once (and from backups within 30 days, §6) |
| Reminder e-mail setting and the day a reminder is due (only if you switched reminders on; the reminder names no test and is only for a confirmed deadline; the study streak is never mailed) | Our hosted API and our e-mail provider (Resend) | Sending the one reminder you asked for | Contract, 6(1)(b): the reminder you asked for | Until you switch reminders off or delete the account |
| Class-sharing pack and file fingerprint (only if you switched class sharing on) | Our hosted API | Reusing a study pack among classmates who opted in (§3A) | Consent, 6(1)(a): only if you switched class sharing on | Deleted at most 30 days after it was made; using it does not extend that. The pack record holds the fingerprint of the material chunk and the pack only: nothing about who shared or who claimed it is stored in it. While sharing is on, the short-lived preparation record (kept up to seven days) holds your account number beside the material fingerprint; it is deleted with the job. When you switch sharing off, we delete the stored packs whose material fingerprint and language match one of your own jobs from those seven days (§3A) |
| Sales records for budgeting: a hashed payment reference (a one-way, peppered fingerprint of the payment or refund id from Paddle), the day, the net amount and the currency. No name, e-mail address or card data, and no link to your account number. These are pseudonymised personal data, not anonymous: we keep the secret behind the fingerprint and can see Paddle's payment references, so a known payment can be matched to its record | Our hosted API | Setting the daily AI allowance from recent sales | Legitimate interest, 6(1)(f): keeping AI costs within sales (the records are pseudonymised personal data) | 35 days, then deleted automatically (a yearly payment: 370 days, because it is counted over the year it pays for). You can ask for earlier deletion or object (§6; give the Paddle transaction reference so that we can find the record) |
| Network address in rate limits (sign-in, bug reports, trial requests) | Our hosted API | Stopping abuse: counting requests from one network address in a one-day window | Legitimate interest, 6(1)(f): abuse prevention | The network address is processed in our API and stored with the counter as a one-way code of the address (a peppered fingerprint, not the readable address); it is kept for at most one day (the longest counting window), then deleted automatically within the hour. It is not linked to your account |
| Daily usage counters (AI jobs, audio seconds, class-sharing requests) | Our hosted API | Applying the daily limits of your plan | Contract, 6(1)(b): the limits of your plan; legitimate interest, 6(1)(f): cost and abuse control | One counter per day. The AI-job counter is kept under a one-way code, not your account number, and is deleted automatically after seven days, also after you delete your account. The audio-seconds and class-sharing counters are tied to your account number and are removed at once when you delete your account |
| Daily preparation counter (which study-content preparation you started today and how many parts of it ran) | Our hosted API | Applying the daily limit of your plan once per preparation, not once per part | Contract, 6(1)(b): the limits of your plan | Kept under a one-way code, not your account number, and deleted automatically after two days; it holds no material text |
| "Ask my material" counter (only the number of questions asked that day, never a question or an answer) | Our hosted API | Applying the daily limit of your plan | Contract, 6(1)(b): the limits of your plan | Kept under a one-way code, not your account number; one number per day, deleted automatically after seven days |
| Maths-steps counter (only the number of maths tasks solved that day, never a task or its steps) | Our hosted API | Applying the daily limit of your plan | Contract, 6(1)(b): the limits of your plan | Kept under a one-way code, not your account number; one number per day, deleted automatically after seven days |
| Audio-seconds counter (only the number of seconds sent for transcription that day, never the audio) | Our hosted API | Applying the daily audio limit of your plan | Contract, 6(1)(b): the limits of your plan | One number per day, deleted automatically after seven days |
| Withdrawal record (subscription id, transaction id and the steps of a 14-day withdrawal; no e-mail address, no card data) | Our hosted API | Finishing your withdrawal and refund even if a step has to be retried | Legal obligation, 6(1)(c), and contract, 6(1)(b): your withdrawal right | Kept when you delete your account, so that a refund can still be tracked, for as long as refund and tax records need it. It is pseudonymised, not anonymous: see the payment and withdrawal row below |
| Free welcome-page mark (a one-way fingerprint of your sign-in, and the id of the preparation that used it) | Our hosted API | Giving the free welcome study page once | Legitimate interest, 6(1)(f): abuse prevention | At most 12 months, then deleted automatically; it is kept when you delete your account so that the welcome page cannot be taken twice. It holds no readable e-mail address |
| Bonus study-page counter (a number of extra pages earned, under a one-way fingerprint) | Our hosted API | Counting extra study pages you have earned, for example from an invitation | Contract, 6(1)(b) | Kept under a one-way code, not your account number; deleted automatically 90 days after its last change, also after you delete your account |
| Payment and withdrawal records (transaction id, subscription id, amount, currency, time of the first payment, and the steps of a withdrawal) | Our hosted API | The 14-day withdrawal right and refunds | Legal obligation, 6(1)(c): payment, refund and tax records | When you delete your account, your account number in these records is replaced by the word "deleted", which pseudonymises them: they are no longer linked to your account here, but they still carry the transaction and subscription ids, which Paddle (our merchant of record) can trace back to you and your payment, so they remain personal data and we keep protecting them and handle your rights over them as for any other record. They are kept as long as the law requires for refund and tax records, then deleted |
| Objection record for the log of key steps (a one-way code of your mailbox and the day we recorded your objection; no e-mail address, no name, no reason) | Our hosted API | Keeping your objection, so that nothing is logged for your account again | Legal obligation, 6(1)(c): honouring your objection | Kept until you ask us to lift it, also when you delete your account, so that the objection still holds if you sign in again with the same e-mail address |
| Invite code and invite record (a code that is yours, and a one-way record that a classmate used it; no names, no e-mail addresses, nothing about your school) | Our hosted API | Giving you and a classmate the extra study pages of an invitation, once, and counting the invitations for the monthly limit | Contract, 6(1)(b) | 12 months, then deleted automatically; the invite record holds one-way codes, not your account number |
| Bug and feature reports | Our hosted API | Fixing and improving the app | Legitimate interest, 6(1)(f): fixing faults | 24 months |
| Step log, for everyone who asks for a sign-in e-mail: which key step happened (a sign-in e-mail sent or failed, a sign-in link used or expired, a robot check passed or failed, a notification saved or sent, a payment event handled, a study-page job done, waiting or failed, the result of a Moodle import, an error in the app with only its error name and script file name, and four steps of the plan journey: trial (code started, ended or claimed_fail, for the free trial), wall (a daily limit reached; code page_limit, ask_limit, math_limit, essay_limit or audio_limit), checkout (code opened, or refused with a short reason) and plan_view (code card or chooser: which plan view the app asked for; the invite row on the Today screen is counted in the same way), and, once for each mailbox at sign-up, source (a short code for the channel that brought the sign-up, taken from the link you opened, for example an advert, a classmate's invite or a school; only codes from a fixed list are kept and nothing else from the link)), whether it worked, the day and time, and a short machine code. It is stored under a coded id (the first 16 characters of a one-way, peppered code of your mailbox), never under your e-mail, name or account number, and never with a message, a question, a photo, your material or any text you wrote | Our hosted API | Finding and fixing problems for the first users, preventing fraud and abuse, and counting how many people reach each step, including which channel brought a sign-up, to improve the app (no row holds text or amounts). A daily summary of counts (per step: how many worked, how many failed and the most frequent failure codes, and how many accounts reached each step for the first time that day) goes to the person who runs Tinystudy; it holds no coded id. These codes are fixed words: no amount, price, text or e-mail address is ever in a row | Legitimate interest, 6(1)(f): fraud and abuse prevention, fixing faults and improving the service. You can object (§6): then no step is logged for your account any more | 90 days, then deleted automatically. It is removed at once when you delete your account |
| Help test Tinystudy (only if you tick it in Settings; off by default): your device and browser type (system, browser and its version, phone or computer, window size, screen density, language), which screen of the app you open, and a few timings (for example how long the first screen takes). Stored under the same coded id as the step log, never with any text you wrote, your courses or your files | Our hosted API | Finding and fixing problems that only show on some devices, and seeing which screens are slow | Consent, 6(1)(a): withdraw it any time by switching the box off | Until you switch the box off in Settings, when it is deleted at once; at the latest 90 days after it was made. It is also removed when you delete your account |
| Checkout and payment-hold records (a one-way hash of the checkout reference, and the subscription id; for a payment event we could not apply, its id, type and reason; when an account with a stored Paddle subscription reference is deleted, a record holding only that subscription id and the time - this includes the subscription of a running trial, which is cancelled first; no e-mail, no card data) | Our hosted API | Linking a payment to the right account, and handling refunds for payments we could not apply | Legitimate interest, 6(1)(f): billing holds, linking a payment to the right account and refunding payments we could not apply | Checkout records are deleted with your account; payment-hold records are pseudonymised when your account is deleted: the link to your account is removed, but they still carry the subscription and event ids, which Paddle can trace back to a payment. They are kept for refund handling until the payment case is closed (the subscription cancelled and any refund made), at most 24 months |
| Payment data (card details, billing address; this includes the card you enter to start a free trial: it goes to Paddle only and we never see it) | Paddle.com Market Limited (UK), our merchant of record, as an independent controller | Billing, VAT, invoicing, your payment and withdrawal receipts | Paddle's own basis as independent controller (contract and legal obligation) | Per Paddle's own policy and tax law |
| Country code from your connection | Computed by our API on each request to pick a default language; not stored | Default language | Not stored | Not stored |
3. Optional cloud preparation of study content
Cloud processing is optional and runs only when you press the button for it. (a) Study content (free plan: your nearest test; trial and paid plan: any test): the text of the course material for that test (in parts of at most 40,000 characters each; one test is usually one to three parts) is sent to our processing service on Cloudflare and processed by Cloudflare Workers AI (an open-weight model that Cloudflare runs as our processor, chosen per language from the models Cloudflare offers, currently Google Gemma 4 26B for Lithuanian, Latvian, Spanish and Thai, Mistral Small 3.1 24B for Greek and Meta Llama 3.3 70B for the other languages), solely to produce your study content. The material is deleted from our systems as soon as the job ends; a job that is still waiting for its turn holds it for up to 24 hours at most, and if a job cannot run it is deleted within one day. The finished study content is kept for you to collect and deleted after at most seven days. (b) Transcription of a video lesson: if the lesson has captions, the app uses them and sends nothing. If not, your browser extracts the audio and sends it in pieces of 60 seconds to our processing service, which has Cloudflare Workers AI (the Whisper large-v3-turbo speech model) turn it into text and sends the text back. The audio is not stored and not logged; the text of each transcribed piece (never the audio) is cached for up to 24 hours so that a retry of the same piece is free, then deleted (§2). (c) Writing feedback: if you press the button for feedback on an essay, the text you typed (at most 6,000 characters) and the task you set are sent to our processing service and processed by Cloudflare Workers AI, solely to give you scores and advice; the text is not stored and not logged, and only counts are kept. (d) Ask my material: if you ask a question about your material, your browser picks the passages of your own material that best match it (at most eight, at most 12,000 characters) and sends them with the question to our processing service, which has Cloudflare Workers AI write a short answer from those passages only. The question, the passages and the answer are not stored and not logged; only a daily count of questions is kept (§2). (e) Worked steps for a maths task: if you photograph a maths task, the photo is read in your browser and never sent; only the text of the task, as you confirmed or corrected it, is sent to our processing service, which has Cloudflare Workers AI solve it step by step and solve it a second time to check the answer. The task and the steps are not stored and not logged; only a daily count is kept (§2). Cloudflare does not use any of these for training models. The app names the provider next to each button before you use it. If you do not want this, use the baseline (no AI) and the captions your school provides. Picture, scan and formula reading happens in your browser and is not sent to us.
3A. Optional class sharing
This is off unless you switch it on in Settings. If you switch it on, then when you and a classmate have both collected the same file from your school's course, Tinystudy can give you the study pack that was already prepared from that file, instead of preparing it again. Your browser makes a one-way fingerprint (a hash) of a chunk of the material; our server uses only that fingerprint to find a matching stored pack, and hands the pack only to a student who proves they hold the same material (by answering a salted check the server chooses) and has also switched sharing on. What is stored is the study pack our service made from your teacher's material (never content typed or uploaded by a student), kept by fingerprint only, with only the study fields (questions, answers, cards, quizzes, tables and exercises). Before it is stored we try to remove e-mail addresses and phone numbers (international format or after a word like "tel"); this is best effort, so names can remain: the study content is written by the AI from the material and can contain names that appear in it, such as an author or a historical figure. We do not share your name, e-mail, notes, answers, progress or which school or course you are in. We keep no class lists, and nothing about who shared a pack or who claimed it is stored: the stored record has no link to any account. Requests are rate limited and the pack is not public, listed or searchable. The legal basis is your consent (GDPR Art 6(1)(a)). You can withdraw your consent at any time in Settings: from then on you neither receive nor add packs. Our job record keeps the fingerprint of the material beside your account number for up to seven days. When you switch sharing off, we delete the stored packs whose fingerprint and language match one of your own jobs from those seven days. A pack that matches none of them (made earlier, or never linked to a job of yours) cannot be traced to anyone, so it stays until its automatic deletion, at most 30 days after it was made, and we cannot pick it out. If a teacher or school asks us to remove material, use the bug-and-feedback button in the app and we will remove it.
4. Children
Tinystudy is for adults only. We do not knowingly offer accounts to anyone under 18, and you confirm that you are 18 or older when you sign up. We ask for your month and year of birth only to apply this rule. If a person declares an age under 18, the account is blocked; if we find that an account belongs to someone under 18, we close it and delete its data. What was already uploaded to a blocked account (encrypted settings, notification subscriptions, bug reports) stays only until the account is deleted; the app offers the delete button on the blocked notice. To stop a blocked person from signing up again with another age, the declared month and year of birth are kept in the one-way record described in §2, and cannot be changed afterwards. We show no advertising to anyone.
5. Where data is stored and transfers
Our hosted API runs on Cloudflare's network; account data is stored in their EU-eligible data locations where available, and transfers outside the EU are covered by the EU standard contractual clauses and, for US providers, the EU–US Data Privacy Framework where the provider is certified. When you open the landing page, it asks our API for the current prices (one request, sent without cookies), so your network address reaches our API and Cloudflare as with any request (see the rate-limit row in §2). Course materials stay in your browser, except the material text of a test, the audio pieces of a lesson and the essay text you send to cloud processing (§3), which Cloudflare processes on its network; we keep them only as §2 and §3 say for each feature (study-content material until the job ends and at most 24 hours while queued, the finished content up to seven days, the text of a transcribed piece 24 hours; never the audio, and not the essay text, questions or maths tasks).
6. Your rights
You can access, correct, export and delete your data. Where we process data on our legitimate interest (6(1)(f), see the Legal basis column in §2: the sales records for budgeting, the step log, rate limits, the trial and age record, the trial identity, billing holds and gifts), you have the right to object: write to support@projektai777.eu and we stop that processing for your account unless we can show a compelling reason that overrides your interests. If you object to the step log, we record your objection with an internal tool (it keeps only the one-way code of your mailbox and the day, never your e-mail address): from then on no row of the step log or the Help-test log is written for your account, for any step, including sign-in and background jobs, and we delete the rows we hold for it. You can also ask us to restrict processing while a complaint or a correction is checked, and where processing rests on your consent ("Help test Tinystudy" and class sharing, 6(1)(a)) you can withdraw it at any time, in Settings or by e-mail, without affecting what was done before. To export your data, press "Download my data" in Settings: you get one file, tinystudy-export-<YYYY-MM-DD>.json, with two parts. The part "account" holds what we keep about you: e-mail, plan and dates, consent state, birth month and year if stored, the country codes if stored (only while regional prices are on), the end day of a free Plus gift if you have one, the step-log and Help-test rows kept under your coded id, bug reports you sent, payment records, and your invite code with the number of classmates who used it and who is still pending (no names). The part "studyData" holds your study pages and your own marks made on this device. The file never contains your device key, sign-in tokens or your Moodle files. Deleting your account (Settings → "Delete my account and all its data") removes immediately: the account, the encrypted blobs, the push subscriptions, the checkout records, your birth month and year (apart from the copy in the free-trial and age record described below, kept only if the account was blocked because of a declared age under 18) and your signed-in sessions on every device; the same data leaves our backups within 30 days. What stays after deletion is only what §2 lists as kept, set out in the next paragraphs. Bug reports you sent are deleted too. Records of payments we could not apply are pseudonymised: the link to your account is removed, but they still carry the subscription and event ids, which Paddle can trace back to a payment; they are kept until the payment case is closed, at most 24 months (see §2). If you have a paid subscription, deleting your account first cancels it at Paddle right away (you confirm this in the app; inside the 14-day withdrawal period the app also offers the full refund first, Terms §6); if the cancellation cannot be done, nothing is deleted and you can try again. Payment and withdrawal records stay with the word "deleted" in place of your account number: they are pseudonymised, not anonymous, because the transaction and subscription ids can still be traced to you through Paddle (see §2). The sales records for budgeting in §2 are pseudonymised personal data, not anonymous: they carry no link to your account, but we keep the secret behind the fingerprint and can see Paddle's payment references, so a payment we know of can be matched to its record. Deleting the account therefore does not remove them by itself; each is deleted automatically 35 days after the day of the sale (370 days for a yearly payment). The same rights apply to them: if you send us the Paddle transaction reference of your payment, we find the record and give you a copy, correct it, restrict it or delete it, and you can object to it, as set out in this section. The records that §2 lists as kept after deletion stay: the free-trial and age record, the hashed school account, the welcome-page mark, a free Plus gift, an objection record, and payment, withdrawal and hold records. The fingerprints hold no readable address; the free-trial and age record is kept at most 12 months, and the birth month and year are kept in it only if the account was blocked because of a declared age under 18. Data in your browser (materials, transcripts, study content, tests, settings and the device key) can be deleted by you with the Settings button "Delete everything Tinystudy keeps in this browser", which also runs after you delete your account; it works on that browser only, so repeat it on any other browser or device where you used Tinystudy, or clear the site's data. You can complain to the Lithuanian State Data Protection Inspectorate (VDAI) or your local authority.
7. Security
HTTPS everywhere; sign-in by single-use e-mail links; a strict content-security policy on every page; the only scripts from other companies are the payment window of Paddle and the bot check of Cloudflare Turnstile, which runs in a sandboxed frame that cannot see your data, loaded only when you sign in or pay. Paddle's payment window opens inside the app page: once you open it, Paddle's script is loaded into that page and stays there until you close or reload the page, so it could in principle read what that page can read, including the key to your encrypted copy (Paddle is the seller of record and bound by its own privacy terms). What protects you today: the key is never sent to us, the payment window opens only when you press to pay, and closing or reloading the page removes Paddle's script from it; the Tinystudy button only loads a script whose hash is checked, only reads from your own Moodle site and passes data to the Tinystudy tab by an origin-checked, nonce-protected message; hosted data is encrypted on your device before upload. Details: the security page of our source repository.
8. Changes
We will announce material changes in the app and by e-mail at least 30 days before they take effect.
Related: Terms · How AI is used