Privacy

Privacy Policy

Last updated July 16, 2026

Study Gate is built to collect as little about you as possible. Your study material never touches our servers. The only thing we store is the minimum needed to run a leaderboard, a profile, and study clubs.

01What stays on your device (we never see it)

  • Your notes, uploaded files, and generated cards, held in your browser's local extension storage.
  • Your Gemini API key, stored locally and sent only to Google, never to us.
  • Which sites you block and your review history live entirely in the extension.

When you generate cards or get an answer graded, the relevant notes, files, or answer text are sent directly from your browser to Google's Gemini API using your own key. That request is governed by Google's terms and privacy policy. We are not a party to it and never receive that content.

02What we store (only if you create an account)

Creating an account is optional. If you do, our server stores:

  • Your username, display name, and optional one-line bio.
  • A salted, scrypt-hashed password, never the password itself, and it can't be reversed.
  • Aggregate study stats: questions answered, correct/incorrect counts, focused minutes, streak, cards mastered, and a per-day answered count for the weekly board.
  • Decks you choose to publish, and the club you join.

Accounts do not require an email address. We don't run ads, third-party trackers, or analytics SDKs. There is no advertising identity attached to you.

If you email us, your email address and message remain in our support inbox. They are not added to the Study Gate account database.

03What's public

A leaderboard and shareable profiles only work if some of this is visible. Your username, display name, bio, stats, and published decksappear on your public profile and the leaderboard. Club members can see each other's usernames and answered counts. Anything you publish as a shared deck is public to anyone with its code. Don't put private information in a display name, bio, deck, or club.

04Cookies

A single httpOnly session cookie keeps you signed in on the website. It carries an opaque random token, not your identity, and is used for nothing but authentication. We set no advertising or tracking cookies.

05Your control

  • Export everything the extension holds anytime via Settings > Export backup.
  • Sign out to stop syncing; clear the extension's storage to wipe local data.
  • Unpublish a deck to remove it from the library. Delete your account and all its server-side data anytime from your account page; it is removed right away, along with your sessions, published decks, and club membership.

06Security

Passwords are salted and hashed with scrypt. Sessions are opaque tokens that expire. The API is rate-limited against brute force and abuse, and the site sends standard hardening headers. No system is perfectly secure, but we've deliberately minimized what the application stores. The account database contains no email addresses, notes, or API keys. Messages you email to us remain in the support inbox.

07Changes

We may update this policy as Study Gate grows. Material changes will be reflected in the “last updated” date above. Continuing to use an account after a change means you accept the updated policy.