1.Who we are#Link to section: Who we are
FluxStudy is built and operated by Sansavision, a division of Sansa Group AB, Gothenburg, Sweden (org. nr 559111-9507). Sansa Group AB is the data controller for the personal data described in this policy. That means we decide why and how it is processed.
For all data protection questions and requests — including from the EU/EEA and the UK — contact our data protection contact at support@fluxstudy.com. Our lead supervisory authority in the EU is the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY).
2.At a glance#Link to section: At a glance
- We collect what we need to run your study plan, practice and coaching, and nothing for advertising.
- We don’t sell your data, and we don’t use your private notes, answers or conversations to train AI models.
- When you use an AI feature, the text needed for that request is sent to an AI model to produce your answer. Section 5 explains exactly which providers are involved.
- You can export your cards, notes and plans and delete your account yourself in Settings, at any time.
- Strictly necessary cookies keep FluxStudy working. Optional preference and analytics cookies are only used if you allow them, and you can withdraw at any time in Cookie settings.
- Your EU/EEA and UK data-protection rights are summarised on our GDPR page.
3.What we collect, why, and on what legal basis#Link to section: What we collect, why, and on what legal basis
The table below lists each category of personal data, what it is used for, the legal basis under Article 6 of the GDPR, how long it is kept and who processes it for us. The legal bases we rely on are:
- Contract (Art. 6(1)(b)): processing needed to give you the service you signed up for.
- Legitimate interests (Art. 6(1)(f)): for example keeping FluxStudy secure and reliable. We have balanced these interests against your rights, and you can object (see section 8).
- Legal obligation (Art. 6(1)(c)): for example keeping accounting records.
- Consent (Art. 6(1)(a)): optional preference and analytics cookies, which under the ePrivacy rules (in Sweden, the Electronic Communications Act, LEK) need your consent before anything is stored on or read from your device. You can withdraw it at any time.
| Data category | Examples | Purpose | Legal basis (Art. 6 GDPR) | Retention | Recipients / processors |
|---|---|---|---|---|---|
| Account | Email address, optional name, account ID, interface, explanation and exam languages, time zone, sign-up date. | Creating and running your account; showing the app in your language and scheduling in your time zone. | Contract — 6(1)(b) | While your account is active; deleted when you delete your account. | Cloudflare (database) |
| Sign-in and security | One-time sign-in links and 6-digit codes (stored only in hashed form), session records including IP address and browser user agent, a Turnstile human-check result, a security log of account changes (email change, devices signed out, new-device sign-ins; masked email address and device type only). | Passwordless sign-in, keeping you signed in, preventing abuse such as automated sign-in attempts, rate limiting, letting you and us review security-relevant account changes. | Contract — 6(1)(b); legitimate interests in security — 6(1)(f) | Links and codes expire after 5 minutes and work once. Sessions expire 30 days after they were last renewed, end when you sign out, and are deleted with your account. Security log entries are deleted after 13 months, or earlier when you delete your account. | Cloudflare (database, email delivery, Turnstile) |
| Study materials | Files you upload (PDF, Word, PowerPoint, photos and scans) and pasted text; file name, type, size and a content fingerprint; extracted text split into passages with page or section anchors; search embeddings (numeric representations of passages). | Your library, search, practice and coaching grounded in your own materials. | Contract — 6(1)(b) | Until you delete the material or your account. Deleting a material removes the file, its extracted text and its embeddings. | Cloudflare (file storage, database, AI processing for text extraction, photo transcription and embeddings, vector search); relevant passages go to AI providers when you use an AI feature (see section 5). |
| Goals, courses and plans | Courses, exams and deadlines, study goals, availability and rest days, study preferences, calendar events you import, plan versions. | Building a study plan around your real week and adjusting it when things change. | Contract — 6(1)(b) | While your account is active; deleted when you delete your account. | Cloudflare (database) |
| Practice and progress | Flashcards and questions, your answers and self-ratings, confidence, hints used, review schedule, mock exams and answers, focus sessions and minutes, XP and streaks, progress state per topic. | Spaced review, mock exams, showing your progress and rewards. Progress states are calculated only from your own practice results. | Contract — 6(1)(b) | While your account is active; deleted when you delete your account. | Cloudflare (database) |
| AI coaching and generated content | Messages you send Nova (up to 4,000 characters), image descriptions you submit, generated images, preferences you ask Nova to remember, which model produced an item, usage counts. | Answering your questions, creating practice and study images you ask for, applying your plan’s allowances. | Contract — 6(1)(b) | Nova messages are processed to produce a reply and are not stored as a chat history in our database. Saved preferences, generated items and images are kept until you delete them or your account. Provider-side handling: see section 5. | Cloudflare (AI inference, storage); OpenRouter, DeepInfra and xAI (see section 6) |
| Content reports | The item you reported, the reason (for example “wrong answer key”) and any note you add (up to 1,000 characters). | Fixing wrong content, pausing a disputed item so it doesn’t affect your progress, and keeping a record of reports. | Legitimate interests in content quality and integrity — 6(1)(f) | Kept after account deletion, but disconnected from your account. | Cloudflare (database) |
| Reminders and emails | Whether study reminders and the weekly recap are on, quiet hours, a log of which reminder was sent when (to avoid duplicates). | Sending sign-in emails you request, and study reminders or a weekly recap if they’re switched on. | Contract — 6(1)(b) for sign-in emails; legitimate interests in helping you keep to your plan — 6(1)(f) for reminders (you can switch them off in Settings) | While your account is active; deleted when you delete your account. | Cloudflare (email delivery, database) |
| Push notifications (iOS app) | If you use the FluxStudy app and allow notifications: a push token for your phone, platform, app version and language; whether reminders come by push, email or both; short-lived delivery receipts (status and error code). A reminder push holds only a short line such as “Your study plan is ready” and a link into the app, never your notes or study content. | Delivering the reminders and weekly recap you switched on to your phone, and removing phones that no longer accept notifications. | Legitimate interests in helping you keep to your plan — 6(1)(f); you control notifications in iOS Settings and in FluxStudy Settings | The token is deleted when you sign out of the app, when Apple reports the app was uninstalled, or when you delete your account. Delivery receipts are deleted after 2 days. | Expo (push delivery service, 650 Industries, Inc.) and Apple Push Notification service; Cloudflare (database) |
| Subscription and billing | Your plan, Stripe customer and subscription IDs, price version, renewal date and status; a receipt of each billing event Stripe sends us (event ID and type). Payment card details go directly to Stripe and never reach our servers. | Providing paid plans and their allowances, handling renewals and cancellations, bookkeeping. | Contract — 6(1)(b); legal obligation — 6(1)(c) | The subscription record is deleted with your account. Billing event receipts are kept for as long as accounting and tax law requires. Stripe keeps its own records under its own policy. | Stripe; Cloudflare (database) |
| Product events | First-party events such as “material uploaded”, “session started” or “upgrade started”, with a time, coarse references (course or topic ID, model name) and a version tag. Never your documents, answers, codes or conversations. | Understanding whether key features work (for example, whether plans get created and sessions completed) and fixing problems. | Legitimate interests in improving and maintaining the service — 6(1)(f) | Deleted automatically after 13 months, or earlier when you delete your account. | Cloudflare (database) — stored by us in our own database |
| Product analytics (optional) | Only if you allow Analytics: how pages and features are used (for example pages viewed, buttons clicked, device and browser type), linked to a pseudonymous identifier. Never your documents, answers or conversations. Exact data points: to be confirmed when enabled. | Understanding how FluxStudy is used and where people get stuck, so we can improve it. Never for advertising. | Consent — 6(1)(a), with ePrivacy/LEK consent for cookies | Collection stops as soon as you withdraw consent. AppHelm’s published policy keeps analytics data for up to 13 months; the exact setting for FluxStudy: to be confirmed when enabled. | AppHelm, a product analytics service operated by our own group (Sansavision, Sansa Group AB), running on Cloudflare — not yet enabled |
| Support messages | Your email address and whatever you write to us. | Answering your questions and handling privacy requests. | Contract — 6(1)(b); legal obligation — 6(1)(c) for rights requests | As long as needed to resolve your request and document it. | Our email provider |
| Connection data | IP address, browser type and request details handled when you visit the site. | Delivering pages, protecting FluxStudy against attacks and abuse. | Legitimate interests in security and availability — 6(1)(f) | Short-lived operational records, kept according to Cloudflare’s own retention. | Cloudflare (network, security) |
Some data is kept only on your device, such as offline flashcards, unsaved mock-exam answers and your sound setting. See our Cookie & Storage Policy for the full list.
4.Where your data comes from#Link to section: Where your data comes from
- From you: your email address, what you upload, type, answer and choose.
- From your use of FluxStudy: session records, product events, progress calculated from your practice.
- From Stripe: subscription status and renewal details if you buy a paid plan.
5.How AI features use your data#Link to section: How AI features use your data
Nova, practice generation, mock exams and study images are AI features. When you use one, we send the content needed for that request to an AI model and return the result to you. That content can be your message, relevant passages from your own materials and notes, and preferences you asked Nova to remember. Specifically:
- Reading your materials: text extraction from files, transcription of photos and scans, and search embeddings run on Cloudflare Workers AI.
- Searching your library: Nova can search your own notes and materials (one note, one course or your whole library, as you choose) and notes other learners explicitly shared with you, which are labelled as shared. Search embeddings of your notes and of your question are made on Cloudflare Workers AI and stored in Cloudflare Vectorize; only the few most relevant passages are sent with your message, and Nova shows which ones it used. Nova never searches other people’s content that wasn’t shared with you. Deleting or trashing a note removes its passages and embeddings from search.
- Standard coaching runs on Cloudflare Workers AI (currently the GLM-5.3-Flash model).
- Deep tutoring, practice questions and mock exams are sent through OpenRouter to DeepInfra, which runs the model (currently StepFun Step 3.7 Flash). Requests are set to use only DeepInfra for this route. If that route is unavailable, some requests fall back to the standard Workers AI model.
- Study images are created from the description you write, sent through OpenRouter to xAI’s image model. Your uploaded photos are not sent to this route. The resulting image is stored privately in your account.
Uploaded content is treated as data, not instructions: text inside a document can’t make Nova save preferences or act for you. We don’t use your content to train AI models. The providers’ own handling of requests is governed by their terms and our agreements with them. Content sent through OpenRouter may be processed outside the EU (see section 6).
Camera and photos
Nova, Notes and the Library can read a photographed problem, classroom board or handout. The camera only turns on after you tap “Open camera” in one of these tools, and it turns off when you close it; you can always pick an existing photo instead. Your browser asks for permission first, and no embedded third party can use the camera.
- Photos are resized and re-encoded on your device before upload, which removes location and camera details (EXIF).
- They are sent to Cloudflare Workers AI (currently the GLM-5.3-Flash model, with Meta’s Llama 3.2 Vision as a backup) only to read the text, maths or layout on them. Reading photos counts toward your standard Nova allowance.
- A photo you solve with Nova isn’t stored unless you choose “Save to notes”, which keeps it privately as a note image.
- A scanned handout keeps its page photos privately with the material you save, next to the text you reviewed, so you can look at the actual pages later. You can delete one photo or all of them at any time in the Library (the text stays); deleting the material or your account deletes them too.
- A board or paper scan keeps the photos in the note by default (“Keep the photos in the note”); you can switch that off before saving or remove the images from the note later.
- Stored photos count toward your storage, are only shown to you, and are included in your data export.
- Photos are never used to recognise or identify people; faces in them are ignored. We don’t use your photos to train AI models.
AI can be wrong
AI output can contain mistakes. Practice scores and progress states are study aids, not grades or predictions of exam results. You can report any item you think is wrong.
No automated decisions with legal effects
FluxStudy does not make decisions based solely on automated processing that have legal or similarly significant effects on you (Art. 22 GDPR). Review schedules and progress states only organise your own study, and you stay in control of your plan.
6.Service providers and international transfers#Link to section: Service providers and international transfers
We use a small number of providers to run FluxStudy. Each may only process personal data for the purposes described here. We don’t sell personal data or share it with advertisers.
| Provider | What they do for us | Data involved | Where |
|---|---|---|---|
| Cloudflare, Inc. | Hosting (Workers), database (D1), file storage (R2), vector search (Vectorize), AI inference (Workers AI), outbound email (Email Service), bot protection (Turnstile), network security and delivery. | All categories in section 3. | Global network; US company. |
| OpenRouter, Inc. | Routes deep tutoring, practice and mock-exam generation, and image requests to the model providers below. | The text of those requests: your message, relevant passages from your materials, saved Nova preferences, image descriptions. | United States. |
| DeepInfra, Inc. (via OpenRouter) | Runs the deep tutoring and generation model. | The same request text as above. | United States. |
| xAI (via OpenRouter) | Generates study images. | The image description you write. | United States. |
| Stripe | Checkout, payments, subscriptions, receipts and the billing portal. Checkout is set up with Stripe Managed Payments, under which Stripe can act as the seller of record for your purchase and so as an independent controller for payment data. | Email address, payment details, billing country and address, purchase and subscription details. | Global; European entity for EEA customers. |
| AppHelm (Sansavision, Sansa Group AB) — not yet enabled | Product analytics, only for visitors who allow Analytics in Cookie settings. | Usage events and a pseudonymous identifier. | Runs on Cloudflare’s global network. |
AppHelm is a product of our own corporate group, so analytics data stays within Sansa Group AB rather than going to an unrelated company.
Data processed worldwide
Our vendors for hosting, payments, AI and email may store and process your data on servers around the world, including outside the EU/EEA and the UK. Where the law requires it, these vendors rely on recognised safeguards such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework. You accept this Privacy Policy and our Terms of Service when you sign in or use FluxStudy. If you don’t agree to your data being processed this way, please don’t use FluxStudy.
We may also disclose data where the law requires it, to protect people’s safety or our legal rights, or as part of a merger or sale of the business, with this policy continuing to apply.
7.How long we keep your data#Link to section: How long we keep your data
Your data is kept while your account is active and deleted when you delete your account. The retention column in section 3 gives the specifics. When you delete your account from Settings, this is what happens:
- All your sessions are ended immediately, on every device.
- Your uploaded files and generated images are deleted from storage, and your search embeddings are deleted.
- Your account and study data are deleted from our database: materials and extracted text, courses, goals, plans, practice items, answers, review schedule, mock exams, focus sessions, rewards, Nova preferences, reminder settings, product events and usage records.
- Content reports you filed are kept for quality and abuse-prevention records, but disconnected from you.
- Billing event receipts are kept as accounting law requires, and Stripe keeps its own transaction records. Deleting your FluxStudy account does not by itself cancel a paid subscription, so please cancel it first (Pricing → “Current plan · manage”).
- Copies in our database provider’s point-in-time recovery backups expire on a rolling basis and are not used to restore deleted accounts.
Deleting your account also removes some storage on the device you use at the time. To remove everything from a device, clear site data for fluxstudy.com (see the Cookie & Storage Policy).
8.Your rights and how to use them#Link to section: Your rights and how to use them
Under the GDPR you have the right to:
- Access the personal data we hold about you and get a copy.
- Rectification: correct inaccurate data. You can change most things yourself in the app.
- Erasure: have your data deleted. Use “Delete account” in Settings → Account, or ask us.
- Restriction: ask us to limit processing while an issue is resolved.
- Data portability: receive your data in a machine-readable format. In Settings you can export flashcards (CSV), notes (Markdown) and plans (CSV), and your committed plan as a calendar file (ICS). Ask us for anything else.
- Object to processing based on legitimate interests, such as product events or reminders. You can switch reminders off in Settings.
- Withdraw consent at any time where we rely on consent (optional preference and analytics cookies). Use “Cookie settings” in the site footer, the Cookie & Storage Policy or Settings → Privacy & data. Withdrawing is as easy as giving consent and doesn’t affect processing that happened before. FluxStudy’s core service never depends on consent to optional cookies.
- Complain to a supervisory authority: in Sweden, Integritetsskyddsmyndigheten (IMY), imy.se (opens in a new tab), or the authority where you live or work. We’d appreciate the chance to help first.
Making a request
Our GDPR page explains each right, the legal bases we use and how international transfers are protected in more detail.
9.Study buddies (optional)#Link to section: Study buddies (optional)
Study buddies are off until you invite someone or accept an invite, and you can have at most 5. A buddy sees only your first name, whether you studied today (yes or no), how many days you studied this week inside a shared weekly goal you both joined, and your streak count if you turn that on. You choose this per buddy in Progress. Buddies never see your notes, cards, grades, mock scores, minutes, times of day, courses, exam dates or your “why”. There are no rankings, no public profiles and no notifications.
Invite links work once and expire after 7 days; we store only a scrambled (hashed) version of the link. If you invite someone by email, we send that one invite and keep only a hashed form of the address, to limit invites to 5 a day. Removing a buddy is instant and they aren’t told. Expired invites are deleted daily, cheers after 30 days and shared goals after 12 weeks. Buddy data is included in your export and deleted with your account (legal basis: contract — 6(1)(b)).
10.Classes and teachers (optional)#Link to section: Classes and teachers (optional)
Any learner can create a class and teach it, or join one with an invite. A teacher sees your first name and that you joined. Nothing about your studying is shared by default. In each class you can choose to share study days per week, practice on the class’s pack cards, progress on the pack’s objectives and mock scores on pack courses, and turn each off again at any time; we record each choice (consent, 6(1)(a)). Teachers never see your notes, Nova chats, your “why”, habits, results outside the class’s packs or times finer than a day. Class averages only appear when at least 5 students share the same thing, and there are no rankings.
Course packs a teacher publishes are copied into your own library when you add them, and stay yours if you leave. Files a teacher shares stay in the teacher’s storage and are viewable only by class members while the pack is live; teachers confirm they have the right to share them. Invite links expire and are stored only as a hash; email invites keep only a hashed address for rate limiting, and expired invites are deleted daily. Leaving a class is instant. Class data is in your export. If you delete your account, your memberships and sharing choices are deleted; a class you taught alone is closed (students keep their copies), and packs you created in a class with other teachers are removed (legal basis for running classes: contract, 6(1)(b)).
11.Emails we send#Link to section: Emails we send
- Sign-in emails from
auth@fluxstudy.com, only when you ask to sign in. They contain a link or code that expires after 5 minutes. - Study reminders and a weekly recap from
notifications@fluxstudy.com, sent outside your quiet hours. Turn them off any time in Settings. - We don’t send marketing emails, and we don’t track email opens or clicks.
12.How we protect your data#Link to section: How we protect your data
- All connections use HTTPS. Session cookies are HttpOnly, Secure and SameSite.
- Sign-in links and codes are stored hashed, expire after 5 minutes, work once, and are rate-limited.
- Sign-in emails are protected by a human check (Cloudflare Turnstile) against automated abuse.
- Every request is checked against your account: your files, passages and search results are only reachable by you. Stored files are private and not publicly listed.
- Payment card details are handled by Stripe and never touch our servers.
No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will notify the supervisory authority and, where required, you.
13.Age requirement#Link to section: Age requirement
FluxStudy is for adults aged 18 and over. We don’t knowingly collect personal data from anyone under 18. If you believe someone under 18 has an account, contact us and we will delete it.
14.Cookies and on-device storage#Link to section: Cookies and on-device storage
We use strictly necessary cookies and on-device storage to run FluxStudy and remember settings you change. Optional preference and analytics cookies are only used after you allow them in our cookie banner, and are off by default. We honour Global Privacy Control as a refusal of analytics. There are no advertising cookies.
Analytics will be provided by AppHelm (product analytics), which is not yet enabled. You can change or withdraw your choice at any time through “Cookie settings” in the footer or Settings → Privacy & data; when you withdraw, analytics stops and the analytics cookies we can identify are deleted. See the Cookie & Storage Policy for every item.
15.California residents#Link to section: California residents
If you live in California, our Notice for California Residents explains your rights under the CCPA/CPRA. We do not sell or share personal information.
16.Changes to this policy#Link to section: Changes to this policy
We’ll update this policy when our practices or providers change, and revise the “last updated” date. If a change materially affects how we use your data, we’ll tell you in the app or by email before it takes effect.
17.Contact#Link to section: Contact
Sansa Group AB (data controller)
Org. nr 559111-9507 · VAT no. SE559111950701
Email: support@fluxstudy.com