StudyRoom - AI learning coach for every student

StudyRoom Privacy Policy

A clear view of how StudyRoom protects student, parent, teacher, and school data.

StudyRoom Privacy Policy

Version: 2026-07-16.1 Applies to: studyroom.cc and the StudyRoom application (web app, all subjects and features)

StudyRoom is operated by PIAZR Pty Ltd (ABN 69 660 867 390), 21A Eungai Pl, North Narrabeen NSW 2101. "StudyRoom Academy" is a registered business name of PIAZR Pty Ltd; "StudyRoom" is the product name used throughout this site and application.


For students: the short version

StudyRoom keeps track of what you've studied and how you're doing so it can give you better help — things like which topics you've mastered, your practice answers, and what you talk about with the AI tutor. A teacher or parent linked to your account can see a summary of your progress, and sometimes StudyRoom's AI notices you might need a hand and lets them know. Some of what you type or say is sent to outside AI companies (like Google, Anthropic, OpenAI, or DeepSeek) so they can generate a response — that's how the tutor works. If you're under 15, your parent or guardian has to say yes before you can upload photos of your work or use voice practice. You can ask a parent, teacher, or admin what StudyRoom knows about you at any time.


1. Who we are and what this document covers

StudyRoom ("we", "us", "the platform") is an AI-assisted tutoring product for school students in Australia, used directly by students and by their parents/guardians and teachers. This policy explains what personal information we collect, why, how it's used (including by AI systems), who it's shared with, how long we keep it, and what rights you have over it.

Quick summary: this policy applies to everyone with a StudyRoom account — students, parents, teachers, and admins.

2. What we collect, and why

CategoryExamplesWhy we collect it
Account/profilename, email, password (hashed), role, year level, state, home language, timezoneTo create and run your account, and to tailor content to your year level and curriculum (AU state)
Date of birthdate of birthRequired at registration so we can apply the right privacy protections if you're under 15 (see §6). Currently only collected at credentials registration — accounts created via Google sign-in do not yet have a DOB on file, which is a known gap we're closing (see §9)
Learning activitychat messages with the AI tutor, practice/exam answers, writing submissions, mastery/progress data, misconceptions, study plans, streaksThis is the core of how the tutor and planner work — without it we can't personalise anything
Photos of handwritten workphotos submitted for AI marking/feedbackLets the AI read and mark handwritten maths/exam work. Gated by parental consent for under-15 students (§6). Raw photos are not stored after marking
Voice / debating practicelive spoken conversation with an AI debate partner, saved as a text transcriptPowers the live voice debate-practice feature. Gated by parental consent for under-15 students (§6). Audio itself is never stored — only the transcript, and only until the retention window closes (§8)
AI usage metadatawhich AI model handled a request, token counts, cost, timestamps — not the message content itselfLets us monitor and cap AI spend, and audit which model produced a response
Guardian/teacher linksguardianship requests and approvals, class rostersSo parents can see their own child's progress and teachers can see their own class, and nobody else's
Consent recordsphoto-upload consent, voice-practice consent, terms/privacy acceptanceTo keep an accurate, auditable record of what was agreed to and by whom

Quick summary: we collect what's needed to run a tutoring product and keep it safe for kids — not more.

3. How the AI works with your data

When you chat with the AI tutor, submit writing, ask for a photo to be marked, or use voice debate practice, the relevant content is sent to a third-party AI provider to generate a response. We route text requests through OpenRouter (a US-based AI infrastructure company), which in turn sends the request to whichever model is active — this may be DeepSeek (a Chinese AI company), Google (Gemini), Anthropic (Claude), or OpenAI (GPT), depending on what an admin has configured.

  • Vision (photo marking) always uses a Google Gemini model.
  • Live voice debate practice uses Google's Gemini Live API directly (not via OpenRouter).
  • Text-to-speech (read-aloud) is generated on our own server (not sent to a third party) and cached.
  • Automated progress summaries and nudges (see §4) use Anthropic's Claude Haiku model.

Quick summary: your messages may leave Australia and be processed by AI companies based in the US or China, because that's how the tutor generates its responses. We don't sell this data or use it for advertising.

We keep a record of which model handled each request and its cost, but we do not store the actual prompt/response content in that usage log — it's metadata only. Separately, if we ever turn on optional debugging/tracing infrastructure (Langfuse) with content-tracing enabled, full prompt/response text could be logged for troubleshooting — as of this document's version, we have not confirmed whether this is active in production; this is flagged in the review checklist at the end of this document.

4. Automated decisions the AI makes about your progress

For mathematics (currently the only subject this covers), StudyRoom runs an automated process every few hours that looks at a student's recent activity — things like how many practice reviews are overdue, unresolved misconceptions, and days since last activity — and decides whether to:

  1. do nothing,
  2. send the student a gentle, encouraging nudge, or
  3. escalate: post a note to the student's teacher and linked parent(s), flagging that the student may need attention.

This is genuinely automated — no person reviews it before it's sent. The message itself is usually written by an AI model (Claude Haiku), grounded only in the real signals described above; if that AI call fails, a plain template message is used instead.

How to see and contest this: every automated nudge or escalation is recorded and visible to parents and teachers on the student's "AI Report" page, where a parent or teacher can reply, ask the AI a grounded follow-up question, or mark an escalation resolved. Students do not see this feed directly. A teacher can also mute the automated process for an individual student at any time.

Quick summary: an automated system — not a person — decides when to flag a student's progress to their teacher/parent. It's not a clinical or professional judgement, just a pattern in the platform's own data, and a teacher or parent can always follow up, question it, or turn it off for that student.

How you're told about a nudge or escalation: these are shown in-app on the "AI Report" page and can also be delivered by email. In addition, once WhatsApp is enabled for production, a parent or teacher (never a student) who has opted in may receive these notifications over WhatsApp — see §7 for how that works, who provides it, and how to opt out. (As of this version, WhatsApp delivery is not yet live to real users — it is in sandbox/testing pending WhatsApp Business verification.) What this does not do (yet): it does not currently look at English/writing activity, and does not detect real-time distress during a live voice session — see §5's live-voice section for that specific gap.

5. Live voice practice — extra detail

If a student uses live voice debate practice: their microphone audio is streamed to Google's Gemini Live API in real time to hold a spoken conversation; the audio itself is never saved — only a text transcript of the session. Sessions are capped (currently 15 minutes each, 30 minutes/day per student) and time-boxed. The AI is instructed to stop and suggest talking to a trusted adult if a student expresses distress, but this is a prompt-level instruction, not an independently verified real-time safety check — after the session ends, the transcript is automatically scanned for safety concerns, and if anything is flagged, the student's teacher(s) are notified.

Quick summary: voice practice conversations aren't recorded as audio, only as text, and there's an automatic after-the-fact safety check on top of the AI's own in-conversation instructions.

6. Children's data and consent

We treat any student whose date of birth is unknown, or who is under 15, as needing parental/guardian consent for two specific capabilities:

  • Photo uploads (for AI marking of handwritten work), and
  • Voice practice (live spoken debate sessions).

A parent/guardian must be linked to the student's account (via our guardianship-verification process) before consent can be granted for an under-15 student; a student aged 15 or over can consent for themselves. If we don't know a student's date of birth, we treat them as under 15 by default (fail-closed) rather than assuming they're old enough.

For general use of the tutor (chat, practice, exams, writing) below the age of 15, we rely on the account having been set up and approved by a parent, teacher, or admin in the first place — every new account requires admin approval before it can be used at all.

Guardian identity verification today is an admin's own judgement call (e.g. "known family," confirmed by the student), not an independent identity check — we're flagging this honestly rather than overstating how rigorous it is.

Quick summary: photo uploads and voice practice need a parent's yes for under-15 students. If we don't know a student's birthday, we treat them as needing that yes.

7. Who we share information with

  • AI providers described in §3, to generate tutoring responses.
  • Linked parents/guardians and teachers, who can see a student's progress summary, writing feedback, and the AI Report feed described in §4 — never a student's raw private chat conversation with the tutor.
  • Email delivery via Resend, for notifications you've opted into.
  • Opt-in WhatsApp notifications to parents and teachers only — never students. If a parent or teacher chooses to — and once the production WhatsApp sender is approved and enabled — they may receive supported alerts (such as progress digests and status alerts) over WhatsApp, sent and delivered directly via WhatsApp (Meta Platforms) — Meta's Cloud API, with no third-party messaging intermediary. Recipients verify their phone number and explicitly enable WhatsApp (with a separate cross-border consent, see §9) before any WhatsApp message is sent, and can reply STOP at any time to turn all WhatsApp messages off (email and in-app notifications continue). As of this version, WhatsApp delivery to real users is not yet live — it is dormant pending WhatsApp Business verification and production configuration. Only approved, factual message templates are used — never free-form or AI-composed text.
  • WhatsApp (not SMS) is used to deliver a one-time code when verifying a phone number for the WhatsApp feature above, via a Meta authentication-message template.
  • We do not sell personal information, and we do not use student data for advertising.

8. How long we keep information

Honestly: most data categories do not yet have a formal retention/deletion schedule — this is a known gap we're actively working on (see §9), not something we're hiding.

The one exception today is debate transcripts: these are automatically deleted after 30 days by default (an admin-configurable setting), via a daily automated job.

Everything else — chat history, practice/exam records, writing submissions, notifications, AI usage logs — is currently retained indefinitely while your account is active. We will update this section with a full schedule once one exists.

Quick summary: voice-practice transcripts auto-delete after 30 days. Everything else is kept indefinitely for now — we're working on a proper retention schedule.

9. Cross-border data

Some of the providers we use are based outside Australia, so personal information may be processed on servers outside Australia:

  • AI providers — the United States for OpenRouter, Google, Anthropic, and OpenAI; China for DeepSeek — process the content you share with the tutor (§3).
  • Meta/WhatsApp delivers the opt-in WhatsApp notifications described in §7; processing may occur outside Australia.

Accountability (Australian Privacy Principle 8.2). PIAZR Pty Ltd remains accountable for personal information disclosed to these overseas providers. We take reasonable steps to ensure they handle it in a way consistent with the Australian Privacy Principles. Before any WhatsApp notifications are enabled for a parent or teacher, we capture a separate, one-time cross-border consent covering this overseas disclosure.

10. Your rights

  • Access & export: you (or your guardian, if you're a student) can export your own writing data (submissions, feedback, growth history, goals) at any time.
  • Deletion: you can request deletion of your writing data specifically, the same way. This does not currently delete your whole account or other data types (chat history, practice records, exam attempts) — for a full account deletion, contact an admin directly; there is no self-service option for that yet.
  • Correction: most profile fields can be edited directly in Settings/Profile. Date of birth cannot be self-edited (to prevent a student ageing themselves past the under-15 protections above) — ask an admin to correct it if it's wrong.
  • Questions or complaints: email our privacy contact at privacy@studyroom.cc, or contact your school/platform admin.

11. Changes to this policy

We'll update the version number and date at the top of this document whenever we make a material change, and you'll be asked to re-accept it the next time you sign in if the version has changed since you last agreed.