1. Safety summary
- Data is encrypted in transit using HTTPS.
- Original imported documents are processed on the Android device and are not uploaded.
- Extracted text and instructions are sent only when you request AI generation.
- Saved lessons, quizzes and exported PDFs are stored locally on your device.
- You can request deletion of your account and associated server data.
- StudyKitab does not sell personal information.
2. Data handled by the app
| Category | Examples | Purpose |
|---|---|---|
| Personal information | Email, name, university, department, registration number | Account management, profile features and assignment cover details |
| User IDs and authentication | Account ID, session and refresh tokens | Sign-in, security and keeping your session active |
| User content | Topics, questions, notes, extracted text, instructions and generated output | Creating assignments, lessons and quizzes |
| App activity | Generation attempts, completion status, daily usage and rewarded-ad credits | Service limits, recovery, reliability and abuse prevention |
| Device or other IDs | Advertising identifier and related ad signals when ads are enabled | Showing, measuring and securing ads through Google AdMob |
| Diagnostics and network data | Request timestamps, error codes, IP-derived security signals and aggregate model usage | Service delivery, debugging, capacity planning and security |
Data StudyKitab does not request
StudyKitab does not request precise location, contacts, call logs, SMS, health information or financial payment information for its current features.
3. On-device processing and storage
PDF, image, TXT, DOCX and PPTX extraction occurs locally. Text-to-speech and PDF generation also occur on the device. Saved study items stay on that device until you remove them, clear app storage or uninstall the app. Exported files in Downloads must be removed separately.
5. Security practices
StudyKitab uses encrypted connections, authenticated API requests, restricted database permissions and server-side authorization. You should still avoid including unnecessary sensitive personal information in prompts or documents.
6. Data retention and deletion
Temporary assignment request data is scheduled for deletion after approximately 48 hours. Operational metrics use limited retention periods described in the Privacy Policy. Account and profile data remain while the account is active.
You can request full account deletion from our public Delete Account page. Deletion removes the account and associated server-held user data, subject to limited lawful retention. Local files remain under your control on the device.