Privacy Policy

Last updated: October 1, 2026

1. Privacy principles

We try to collect the least personal information we need to run RD Study Lab, secure the product, support users, and process purchases. We also try to avoid keeping identifying information longer than needed.

2. Information we collect

We group the information we collect into three categories. The first is always active because it is needed to run and protect the service. The second and third are described in their own sections below.

a. Account and study information

  • Account information such as your email address and account status.
  • Study data you create or generate, such as decks, flashcards, study plans, bookmarks, and results.
  • Usage summaries such as daily counts of questions answered, cards reviewed, and study time.
  • Purchase metadata such as plan tier, amount, currency, Stripe customer, checkout, payment, charge, product, price, receipt, refund, and dispute reference IDs; the offer and policy versions accepted at checkout; entitlement timing; and non-sensitive authorization outcomes such as AVS, CVC, 3-D Secure, and Stripe risk results. We do not store the card number or CVC itself.
  • Support or feedback information that you submit to us.

b. Essential first-party service and security logs (always active)

To operate the service, keep accounts secure, and prevent abuse and account sharing, our servers record limited first-party logs whenever you use the app. This logging is necessary to provide the service. It is not browser analytics, it does not depend on the PostHog analytics choice described below, and it cannot be switched off while you continue to use RD Study Lab.

These essential logs can include:

  • Your internal account identifier.
  • The action or event performed, the time it happened, and the page path where it occurred.
  • The IP address and browser user-agent associated with the request.
  • A stable device identifier and related device and browser characteristics, stored to recognize the devices signed in to your account.
  • Limited access and security records used for authentication, rate limiting, and abuse monitoring.

We use these essential logs to operate the service, authenticate you, protect account security, detect and prevent abuse and account sharing, troubleshoot problems, and administer the product. This identifying data is deleted automatically on the schedule set out under Retention below.

c. Optional and server-side reporting

  • For all visitors, limited cookieless PostHog events such as pages visited, referrers, campaign tags, and device and browser characteristics. This mode uses no cookies or browser storage and creates no PostHog person profile, but its network requests can still involve an IP address and browser information.
  • If you accept browser analytics, additional product usage data such as interactions, feature events, errors, journeys across visits, and privacy-masked session replay. After sign-in, if you have not declined analytics, PostHog events are associated with your internal account identifier and email address.
  • Limited purchase lifecycle events that our servers send to PostHog using your internal account identifier and Stripe reference IDs, as described under Payments below.

3. Browser storage, cookies, and local storage

We use authentication cookies through Supabase and local storage for product features such as theme preference and in-progress review session state. PostHog runs without cookies or browser storage while you are signed out and have not accepted analytics, or after you decline. If you sign in without declining, PostHog uses local storage to maintain account-linked analytics. Expressly accepting analytics also enables privacy-masked session replay. We do not use advertising or remarketing cookies on the site.

See our Cookie Notice for more detail.

4. Payments

Payments are handled by Stripe. We do not store full card numbers, card security codes, or full payment credentials on our servers. We do keep limited billing-related records we need to confirm access, support purchases, prevent fraud, and maintain basic business records.

If you participate in referrals, we record the referral code and linked account identifiers, qualifying purchase references, reward amounts and status, and completed e-transfer references. Administrators can use your account email to arrange manual payouts. Referrers see reward balances, not their friends’ email addresses or payment details.

We also send limited purchase lifecycle events, such as activation, cancellation, and payment failure, to PostHog from our servers using your internal account identifier and Stripe reference IDs. This operational reporting does not use browser cookies or local storage and is separate from optional browser analytics consent.

When you ask us to start a purchase, we record the time, your internal account and device identifiers, IP address, browser user-agent, the exact offer and policy disclosure, and their version and integrity hash. Stripe separately records whether you accepted its required Terms checkbox. If payment succeeds, we retain a minimized transaction and delivery record to confirm authorization, access, refunds, and disputes. We do not retain full Stripe webhook payloads.

To prevent fraud or respond to a refund, payment inquiry, or chargeback, we may combine these purchase records with limited account, login, access, device, support, and product-usage records. We disclose only the evidence reasonably needed for the matter to Stripe and, through Stripe or when otherwise necessary, to payment networks, acquiring or issuing banks, professional advisers, regulators, law enforcement, or courts.

5. AI features

The OpenRouter-powered AI tutor is currently disabled, and RD Study Lab does not currently send study prompts, questions, answers, or related study context to OpenRouter. Before enabling this feature for users, we will update this Policy and provide an appropriate in-product notice explaining what will be sent, why, and where it will be processed. Do not submit sensitive personal health information or other highly sensitive personal information if an AI feature is later enabled.

6. How we use information

We use personal information to provide the service, authenticate users, personalize study tools, process purchases, provide support, investigate abuse, prevent account sharing, improve reliability, understand product use, and comply with legal obligations. Essential first-party service and security logging and limited cookieless measurement happen automatically. Additional PostHog analytics storage and session replay are used only if you accept them. Signed-in PostHog analytics uses your internal account identifier and email address unless you decline analytics.

7. Service providers and processing outside Canada

We share information only with providers needed to operate the service. We do not sell personal information or share it for targeted advertising, marketing, or cross-site behavioural advertising.

  • Supabase, for the database and authentication. The primary database is hosted in the selected Canadian region, while Supabase and its subprocessors may process limited information from the United States or other countries to provide support, security, and infrastructure services.
  • Railway, for application hosting and related operational logs. This information is processed primarily in the United States.
  • Stripe, for checkout, payment processing, receipts, fraud prevention, refunds, and payment disputes. Stripe and payment-system participants may process information in Canada, the United States, and other countries where they operate.
  • PostHog, for cookieless usage measurement, account-linked product analytics, error reporting, and consented session replay. We use PostHog’s United States cloud region.
  • Resend, for account and service emails and optional marketing emails. Recipient addresses, message content, and delivery logs are processed and stored in the United States.
  • OpenRouter is configured for the disabled AI tutor but is not currently receiving user study prompts or responses. If the feature is enabled, its processing locations and data uses will be disclosed before use.

Stripe and participants in the payment system, such as payment networks and acquiring or issuing banks, may receive minimized purchase, authorization, delivery, account-access, support, and product-usage evidence when needed to prevent fraud, investigate a payment, or respond to a refund or dispute. We do not send individual study answers as routine dispute evidence.

Because some of these providers operate outside Canada, your personal information may be processed in the United States and other countries. While information is in another country, it may be accessible to the courts, law enforcement, and national security authorities of that country under their laws.

You can ask us for written information about our policies and practices regarding service providers outside Canada, and you can direct questions about how those providers collect, use, disclose, or store personal information to our Privacy Contact, listed in the Contact section below.

8. Retention

We keep personal information only as long as we need it, and we delete identifying operational data automatically on the schedule below.

  • Access and security logs, including IP address and browser user-agent: deleted after 90 days.
  • First-party product events, including IP address and browser user-agent: deleted after 12 months.
  • Live activity signals contain account and tab identifiers, activity categories, and contact times, not answers or draft text. Signals older than 24 hours are removed on the next daily retention run. Account labels remain until changed or the account is deleted.
  • Device records used to enforce the device limit: kept while the device remains in use. The IP address and user-agent attached to a device are cleared after 90 days of inactivity.
  • Limited email consent and withdrawal records are retained to document permission and prevent unwanted marketing, including after account deletion. These records are separate from ordinary study data.
  • Account, study, and progress data: kept while your account is open, and deleted when you delete your account.
  • Checkout acceptance records, including purchase IP address, device identifier, and browser user-agent: normally deleted after 2 years unless an active legal hold requires them longer.
  • Minimized billing, purchase, entitlement, refund, and dispute records: normally deleted after 7 years unless an unresolved dispute, bookkeeping or tax requirement, or documented legal hold requires them longer.
  • Referral reward and payout records survive account deletion. Settled records are normally deleted 7 years after the latest associated reward, payout, or reversal; unpaid rewards, unresolved adjustments, active disputes, and legal holds are retained until resolved. Abandoned referral checkout records are removed after 90 days.

Core study activity is also stored in aggregated daily totals. If you accept browser analytics, PostHog retains product events and privacy-masked replay according to the retention settings we configure there. We avoid storing unnecessary identifying metadata in routine feedback capture.

9. Security

We use reasonable technical and organizational safeguards designed to protect account access and stored data. No service can promise absolute security, and you should also protect your own device, password, and account credentials.

10. Your choices and requests

Email preferences

Marketing emails are optional. Where email signup is available, you can choose study tips, product news, and occasional offers, and withdraw your choice in Settings or through an unsubscribe link. Essential account, purchase, security, and requested support messages are handled separately.

We record your email preference, the time and source of your choice, and the consent wording and sender details shown to you. Limited consent and withdrawal records may remain after account deletion to document your choices and prevent unwanted marketing. We do not record your IP address or browser information in these consent records.

Deleting your account

You can delete your account yourself at any time from Settings, under Delete account. This permanently removes your profile, study history, results, flashcards, study plans, saved bookmarks, feedback you submitted, device records, and the access and security logs tied to your account. It cannot be undone.

If you would rather we did it for you, email us and we will delete your account and ordinary study data. Before deletion, we preserve only aggregate counts and timestamps showing delivery and use for purchases linked to the account; we do not preserve individual study answers. Minimized billing and dispute records remain with us for the retention period above, and records of past payments also remain with Stripe under its legal and tax obligations. We do not store your card details.

Access and correction

You can ask us what personal information we hold about you, ask for a copy of it, and ask us to correct anything that is inaccurate. Email our Privacy Contact and we will respond within 30 days. You can also update your account details directly in Settings.

Analytics choices

You can accept, decline, or withdraw browser analytics consent at any time from our Cookie Notice.

11. If something goes wrong

If a security breach involving your personal information creates a real risk of significant harm to you, we will notify you and the appropriate privacy regulator as soon as feasible. We keep a record of security incidents.

If you have a privacy concern, contact us first and we will work to resolve it. If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada, or to your provincial privacy regulator if you live in Alberta, British Columbia, or Quebec.

12. Contact

RD Study Lab is operated from Alberta, Canada. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.

Privacy Contact: the owner and operator of RD Study Lab is the person accountable for privacy compliance and can be reached at [email protected]. This is also the contact for questions about service providers outside Canada.

Mailing address: PO Box 68091 RPO Bonnie Doon Shopping Centre, Edmonton AB T6C 4N6

13. Age eligibility

RD Study Lab is intended for people aged 18 and older. You must be at least 18 to create an account or purchase access. If you believe someone under 18 has provided personal information through an RD Study Lab account, contact [email protected] so we can review the account and take appropriate action.

14. Updates

We may update this Privacy Policy as the product changes. We will post updates with a new effective date. If a material change affects how we handle existing users’ personal information, we will also provide reasonable notice by email or in the product before the change takes effect and will obtain consent where applicable law requires it. Continued use alone does not replace any consent required by law.

Revision history

  • October 1, 2026: Added optional marketing email preferences, consent records, and our mailing address.
  • September 24, 2026: Added referral attribution, reward accounting, and manual e-transfer records and retention.
  • September 8, 2026: Clarified age eligibility, PostHog identifiers and email disclosure, cross-border provider details, and the status of disabled AI features.
  • September 5, 2026: Added live activity signals and their short retention period.
  • September 3, 2026: Clarified the recipients and safeguards involved when purchase and usage evidence is used to prevent fraud or respond to a payment dispute.
  • August 29, 2026: Clarified the limited purchase, checkout-acceptance, delivery, refund, and dispute records retained for fraud prevention, bookkeeping, and dispute handling.
  • July 25, 2026: Published specific retention periods, added self-serve account deletion, named a privacy contact, and added detail on processing outside Canada.
  • July 19, 2026: Clarified that anonymous, cookieless analytics run for all visitors, while cookie-based analytics and session replay require consent.
  • July 11, 2026: Current version published.