1. Introduction
StudentHub is a study organiser for iPhone, iPad and Mac. This Privacy Policy explains what information the app handles, who processes it, and what rights you have.
StudentHub is designed to keep your data on your own devices. There is no user account, no login, and no StudentHub server that stores your notes, recordings, files or study material. Most of what this policy describes therefore concerns data that never reaches us at all.
The data controller for the limited processing described below is:
Kjølberg Productions, Leksvikgata 9, 7066, Norway. Organisation number: 933 342 050.
Contact: hello@contact.getstudenthub.app
2. Information We Collect
Content you create in the app. Subjects, notes, tasks, calendar entries, boards, flashcards, grades, work shifts, audio recordings, imported files and photos. This content is stored locally on your device using Apple's SwiftData framework. If you have iCloud sync enabled, it is also synchronised through your own private iCloud account. We have no access to it, and it is never transmitted to us.
Audio recordings and imported files. Recordings and files are stored on your device. You can optionally enable syncing, which stores them in your own private iCloud Drive folder so they are available on your other devices. This is off by default because of the storage involved. Whether stored locally or in iCloud, we have no access to them, and they are never transmitted to us. Transcription runs entirely on-device using Apple's speech recognition; audio is never uploaded for transcription, and the app never enables server-based recognition.
AI-generated study material. Summaries, flashcards and quiz questions are generated by Apple Foundation Models running on your device. The source text is not sent to us or to any external service.
Purchase information. If you subscribe to StudentHub Pro, your purchase is processed by Apple. We use RevenueCat to verify subscription status. RevenueCat receives an anonymous, randomly generated app user identifier, your subscription status, and standard purchase metadata from Apple's receipt. It does not receive your name, email address or payment card details, and we never see your payment details.
Calendar feed addresses. If you add a timetable feed (ICS), the app fetches that address directly from the server you specify. The address and the calendar data are stored on your device. We do not operate or see these requests.
Apple Calendar. If you grant calendar access, the app reads events from Apple Calendar to display them alongside your study blocks. This data stays on your device.
What we do not collect. StudentHub contains no analytics, no advertising, no tracking technologies, no cookies, and no third-party software development kits other than RevenueCat. We do not collect your IP address, device identifiers for advertising, location data, or usage statistics. We do not build profiles, and we do not carry out automated decision-making or profiling within the meaning of Article 22 GDPR.
3. How We Use Your Information
We use the limited information described above only for the following purposes:
To verify and restore your subscription entitlement, so that paid features work on all your devices.
To respond to you if you contact our support address.
To comply with legal obligations, including accounting and tax requirements relating to purchases.
Content you create in the app is processed solely on your device and in your own iCloud account, for the purpose of providing the app's functionality to you.
4. Legal Bases for Processing
Under the General Data Protection Regulation (GDPR), we rely on the following legal bases:
Performance of a contract (Article 6(1)(b)) — verifying subscription status so we can provide the paid features you purchased, and responding to support requests about your use of the app.
Legitimate interests (Article 6(1)(f)) — maintaining the security and integrity of the app, and preventing fraudulent or abusive use of subscriptions. We have assessed that these interests do not override your rights and freedoms, particularly as the data involved is anonymous or pseudonymous.
Legal obligation (Article 6(1)(c)) — retaining transaction records where required by law.
We do not process special categories of personal data. We do not rely on consent for any processing described in this policy, because the app does not carry out any optional processing that would require it.
5. Sharing Your Information
We do not sell your personal information, and we do not share it for advertising or cross-context behavioural advertising purposes.
We share data only with the following recipients, acting as processors or independent controllers as indicated:
Recipient | Role | What they receive | Where |
|---|---|---|---|
Apple Inc. | Independent controller | Payment processing, App Store transactions, and — if you enable it — iCloud storage of your app content in your own private account | Global, incl. EU |
RevenueCat, Inc. | Processor | Anonymous app user identifier and subscription status | United States |
RevenueCat processes data on our behalf under a data processing agreement. Apple's handling of your Apple Account, payments and iCloud is governed by Apple's own privacy policy, over which we have no control.
We will also disclose information if required to do so by law, court order, or a valid request from a public authority, or where necessary to establish, exercise or defend legal claims.
6. International Transfers
RevenueCat is located in the United States. Transfers of personal data outside the European Economic Area are made on the basis of the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate. Given that the data transferred is limited to an anonymous identifier and subscription status, the risk to your rights is low.
You may request a copy of the relevant transfer safeguards by contacting us.
7. Data Security
We apply appropriate technical and organisational measures to protect personal data. Content created in the app is stored using the operating system's file protection and, where iCloud sync is enabled, is transmitted and stored under Apple's encryption. Communication with RevenueCat is encrypted in transit using TLS.
No method of electronic storage or transmission is completely secure. While we work to protect your data, we cannot guarantee absolute security.
Because there is no StudentHub account system and no server holding your content, the most significant protection for your data is the security of your own device and Apple Account. We recommend using a device passcode and two-factor authentication on your Apple Account.
8. Data Retention
Content in the app is retained until you delete it. Deleting an item in the app removes it from your device and, if sync is enabled, from your iCloud account. Deleting the app removes its local data; content synchronised to iCloud is removed when you delete the app's data from iCloud in your device settings. Backups you have exported to iCloud Drive remain until you delete them.
Subscription records are retained by RevenueCat for as long as your subscription is active and for a reasonable period afterwards to support restoration of purchases, and by us where required for accounting purposes — under Norwegian law, generally five years.
Support correspondence is retained for up to 24 months after the matter is resolved.
9. Your Rights
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:
Access the personal data we hold about you.
Rectify inaccurate or incomplete data.
Erase your data ("right to be forgotten").
Restrict processing in certain circumstances.
Data portability — receive your data in a structured, commonly used, machine-readable format.
Object to processing based on legitimate interests.
Withdraw consent at any time, where processing is based on consent.
Lodge a complaint with a supervisory authority. In Norway this is Datatilsynet (datatilsynet.no). If you are elsewhere in the EEA, you may complain to your local authority.
To exercise these rights, contact hello@contact.getstudenthub.app. We will respond within one month, and will not charge a fee unless your request is manifestly unfounded or excessive.
Please note that because we do not hold your app content, most of these rights are exercised directly in the app itself: Settings → Export data provides portability, and Settings → Delete all data provides erasure. For your iCloud data, you can also manage and delete it from your Apple Account settings.
10. Additional Regional Rights
StudentHub is available in 172 countries and regions. In addition to the rights described above:
United States (California — CCPA/CPRA) — you have the right to know what personal information is collected, to request deletion, to correct inaccurate information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use sensitive personal information to infer characteristics. You will not be discriminated against for exercising your rights. Residents of other US states with comparable privacy laws have equivalent rights.
Republic of Korea (PIPA) — you have the right to be informed of, access, correct, delete and suspend the processing of your personal information, and to be notified of any breach. You may also file a dispute with the Personal Information Dispute Mediation Committee.
Vietnam (Decree 13/2023/ND-CP) — you have the right to be informed, to consent and withdraw consent, to access, correct, delete and request restriction of your personal data, and to complain to the Ministry of Public Security.
Brazil (LGPD) — you have the right to confirmation of processing, access, correction, anonymisation or deletion, portability, information about data sharing, and to complain to the ANPD.
Japan (APPI), Australia (Privacy Act), Canada (PIPEDA), Switzerland (FADP), United Kingdom (UK GDPR) — you have equivalent rights of access, correction and deletion under your local law.
Because we hold no content and no identifying information about you, these rights are in practice exercised within the app itself, using Settings → Export data and Settings → Delete all data, and through your Apple Account for anything synchronised to iCloud.
11. Children's Privacy
StudentHub is rated 4+ and is available to users of all ages. It is designed so that this is safe by default: the app has no user account, no chat or messaging, no social features, no user-to-user contact, no advertising, no analytics, and no tracking. Nothing a user writes, records or imports is transmitted to us.
We do not knowingly collect personal information from children. The only identifier associated with a user is an anonymous, randomly generated subscription identifier used solely to verify entitlement to StudentHub Pro and to restore purchases. Under the United States Children's Online Privacy Protection Act (COPPA), this constitutes use of a persistent identifier for support for the internal operations of the service, for which parental consent is not required. It is not used to contact anyone, to build a profile, or for advertising.
Purchases are made through the Apple Account that owns the device. Parents and guardians can restrict or disable in-app purchases using Screen Time on the device.
The app contains links that open outside StudentHub — our social media profiles, our support email, and our legal pages. Parents and guardians who wish to prevent this can restrict outbound links and app installation through Screen Time.
In the Republic of Korea, where the user is under 14, processing requires the consent of a legal guardian. Because we do not collect personal information from users of the app, no such consent is required for ordinary use; where a subscription is purchased, that transaction is made through the Apple Account of the account holder.
If you are a parent or guardian and believe a child has provided us with personal information, contact hello@contact.getstudenthub.app and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Where changes are significant, we will notify you in the app or by another reasonable means before they take effect. The date at the top of this policy indicates when it was last revised, and the current version is always available at getstudenthub.app.
13. Contact Us
For any question about this policy or your data:
Email: hello@contact.getstudenthub.app
Postal: Kjølberg Productions, Leksvikgata 9, 7066, Norway