Privacy Policy

Effective September 30, 2026 · Version 2026-09-30

This Privacy Policy explains how StudyOutlaws handles information when you use the StudyOutlaws website, account and dashboard, browser extensions, subscriptions, automation tools, support, and related services (the “Service”).

The information involved depends on the features you choose. A public answer lookup can use a code or link, while account automation, billing, Google Classroom, support, or an AI fallback can involve additional information described below.

1. Account and Identity Information

  • Account information such as email address, username, password, optional referral code, verification state, and security settings.
  • If you use Google sign-in, Google account identifier, email address, email-verification state, and optional profile name returned for the openid, email, and profile permissions.
  • Referral data, including referral codes, referrer and referred-account relationships, conversion state and time, qualifying invoice or payment identifiers, and reward-credit status.
  • For an account migrated from a legacy Wembean service, legacy source identifiers and mapping state used to associate the prior record with its StudyOutlaws account.
  • Session and account-security information, including session identifiers, IP address, user agent, expiry and last-seen time, and—for extension sessions—browser type, extension version, device fingerprint, and activity state.
  • Password-reset, email-verification, API, and challenge-token records, including applicable expiry, consumption, and revocation state.
  • Two-factor recovery codes are stored as one-way hashes and removed from the active set when used or when account security is reset.

2. Billing and Subscription Information

Stripe processes subscription payments. Initial purchases use Stripe Checkout, while renewals, plan changes, invoices, cancellations, and customer-portal actions use Stripe billing services. Payment details are entered with Stripe; StudyOutlaws receives billing identifiers and subscription information needed to provide the selected plan.

  • Stripe customer, checkout-session, subscription, invoice, plan, billing-cycle, status, seat, discount, period, and cancellation information.
  • Checkout and policy-acceptance records, which can include the StudyOutlaws user, checkout mode, policy version, terms state, IP address, and user agent.
  • Optional cancellation reason and feedback supplied when a subscription is ended.

3. Linked Platforms and Google Classroom

If you connect a school-platform account, StudyOutlaws processes the provider, username, connection status, verification or error information, and the credential or token needed to authenticate and perform the actions you request. Saved credential and token envelopes are encrypted at rest.

  • For supported account-connected platforms, credentials or provider tokens are sent to that platform to verify the account and perform the configured workflow.
  • A Google Classroom connection can store encrypted access and refresh tokens, token expiry, Google account identifier, granted permissions, and email or username.
  • The Google Classroom integration can read user-authorized course, coursework, form, and related information and can create an answer text file in the user’s Google Drive when that feature is requested.
  • Disconnecting a linked platform account removes its saved connection. A Google Classroom disconnect first asks Google to revoke the refresh token before the local connection is removed.

4. Tool Activity, Assignment Content, and Results

The Service processes the sources, settings, and results required for the tool you select. Depending on the workflow, this can include game or activity IDs, assignment and question text, answer choices, result data, linked-account selection, accuracy and timing settings, schedules, status, errors, and run history.

  • Automation jobs can retain platform, tool, status, input or configuration, result or error, and timing information.
  • Schedules can retain the selected account, time, timezone, configuration, and latest run or error state.
  • Solver caches can retain a source and its result so a recognized answer set can be reused and labeled.
  • Task and extension usage can retain the feature, tool, limit, date or duration, last activity, session, and IP information used to operate limits and investigate problems.

5. Support, Feedback, and Technical Information

  • Support tickets and feedback, including category, subject, status, messages, sender name, source page, read state, IP address, and user agent.
  • Security and audit events, including action, bounded metadata, request identifier, IP address, and user agent.
  • Application telemetry such as method, normalized route, response status, duration, authentication state, request identifier, query-key names, and bounded error context. Sensitive fields such as passwords, tokens, provider secrets, and webhooks are filtered from telemetry summaries, but relevant error, action, path, and identifier fields can remain.
  • Information needed to send account-verification and password-reset email through the configured mail-delivery provider.

6. How StudyOutlaws Uses Information

  • Create and authenticate accounts, verify email, reset passwords, manage two-factor authentication, and maintain sessions.
  • Provide plans, checkout, subscriptions, invoices, cancellations, referrals, limits, and account features.
  • Connect and verify user-selected third-party accounts, load relevant course, assignment, game, or question information, and perform the tools, submissions, schedules, and notifications the user configures.
  • Display, cache, label, and troubleshoot results; measure service performance; prevent abuse; apply rate limits; and investigate security or operational failures.
  • Respond to support tickets and feedback and deliver account, security, and billing communications.

7. AI Features

Some tools can use an AI fallback when a supported provider lookup does not produce a result. For those requests, StudyOutlaws may send the selected platform, bounded contextual text, question or assignment text, answer options, and relevant images or image URLs to the configured OpenAI-compatible AI endpoint to generate an answer. The default configuration uses Groq, but the configured provider can change.

  • AI fallback is used only in workflows that are configured to request it.
  • AI output can be incomplete or incorrect and should be reviewed before use.
  • The configured AI provider’s handling of information is also governed by its own service terms and privacy practices.

8. When Information Is Disclosed

StudyOutlaws discloses information when needed to provide a feature, secure the Service, process a transaction, comply with law, or carry out an action you request. The categories of recipients can include:

  • Stripe for checkout, billing, customer-portal, invoice, and subscription functions.
  • Google for Google sign-in and, when separately authorized, Google Classroom, Forms, and Drive functions.
  • hCaptcha for anti-abuse verification; the verification token and request IP address are sent for validation.
  • The configured AI provider when an AI fallback described above is used; the default endpoint is Groq.
  • The configured email-delivery provider for verification, reset, and account messages.
  • Discord if support notifications are configured or if you choose to send dashboard run notifications to a Discord webhook.
  • The educational platforms you select, to authenticate, read relevant information, and perform the actions you configure.
  • Infrastructure, database, cache, security, and hosting providers used to operate the Service, and authorities or other parties when legally required or reasonably necessary to protect users, the Service, or third parties.

9. Cookies and Local Storage

StudyOutlaws uses cookies and similar browser storage to keep sessions working, protect sign-in and connection flows, and remember limited interface state.

  • The main web session cookie can last up to 30 days and is HttpOnly, SameSite=Lax, and Secure in production. A readable session-hint cookie can use the same maximum age.
  • Short-lived security cookies include Google sign-in and Google Classroom state and two-factor challenge state.
  • A limited account-profile cache can be written to sessionStorage and localStorage so the interface can render while a fresh session is checked. Invalid and stale entries are removed.
  • Selected Membean interface settings can use localStorage, while active or resumable assessment snapshots can use sessionStorage.
  • hCaptcha and connected third-party services may use their own browser technologies under their respective policies.

10. Security

StudyOutlaws uses technical safeguards designed for the information it processes. New and changed passwords are one-way hashed using Argon2id. An older account can retain a legacy bcrypt, scrypt, or PBKDF2 hash until a successful password login upgrades it to Argon2id. Authentication and recovery tokens are stored as hashes. Linked-provider credential and token envelopes and two-factor secrets are encrypted at rest using AES-256-GCM. Production session cookies use Secure and HttpOnly protections where applicable.

  • Encryption at rest is not end-to-end encryption: the server decrypts linked credentials or tokens when needed to call the selected provider.
  • No online service can guarantee perfect security. Protect your password, review active sessions, and contact support if you believe an account or connection has been used without permission.

11. Retention and Account Deletion

Information is retained for as long as needed for the functions described in this policy, security, billing and disputes, and legal obligations. The period varies by category. Automated maintenance may remove expired authentication records, completed or failed jobs, and older support, feedback, audit, or request records, and may redact IP-address and user-agent fields. Billing-dispute evidence packets marked with a legal hold can be kept past their ordinary cleanup period.

  • The in-product account-deletion flow replaces the account email, username, and password hash; marks the email unverified and the account deleted; clears two-factor secrets and recovery codes; and revokes web, API, and extension sessions. It does not automatically erase every field or associated record.
  • Associated records can remain, including encrypted linked-platform credentials or tokens, schedules, OAuth identity data such as a Google account identifier or email, and billing, job, support, audit, or dispute records. Contact [email protected] for a privacy request concerning retained records.
  • A user can disconnect linked platform accounts and can delete their own support tickets. The deletion flow checks the stored subscription state and blocks deletion when it is active, trialing, past due, or incomplete; manage the Stripe subscription first and confirm the updated status before trying again.

12. Your Choices and Privacy Requests

You can update your username, review and revoke sessions, disconnect linked accounts, manage or cancel a subscription, delete your own support tickets, and start account deletion from the available account controls.

  • Depending on where you live, privacy law may give you additional rights concerning access, correction, deletion, restriction, objection, or portability.
  • Send a privacy request to [email protected]. StudyOutlaws may need to verify your identity and the account involved before acting on a request and will handle the request as required by applicable law.
  • Not every right applies in every location or to every record, and some information may need to be retained for security, billing, disputes, or legal compliance.

13. Children and Students

The Service is not intended for anyone under 18 years of age. You must be at least 18 years old to use the Service. Parents or guardians with a privacy question or request can contact [email protected].

14. Changes and Contact

This policy may be updated to reflect changes to the Service, providers, security practices, or legal requirements. The Last Updated date identifies the current version. Questions and privacy requests should be sent to [email protected].

15. Email Communications

StudyOutlaws may use the email address associated with your account to send communications related to your account and the Service. These communications may include account verification, password resets, security alerts, billing and subscription notices, support messages, service interruptions, important platform or service changes, new features, supported platforms, and updates to our Terms of Service or Privacy Policy. Certain account, security, billing, legal, or service-related communications may be necessary while your account remains active.

StudyOutlaws may also use your email address to send product announcements, feature updates, information about newly supported platforms, promotions, special offers, and other communications about StudyOutlaws and its services where permitted by applicable law. Marketing emails will include a way to unsubscribe where required. If you unsubscribe from marketing communications, we will stop sending those promotional emails, but you may still receive essential communications related to your account, security, billing, legal notices, support, or operation of the Service.

Promotional email is optional. Accepting our Terms of Service and Privacy Policy does not subscribe you to marketing. You can choose “Email me updates” separately and change that choice in account settings or through an unsubscribe link.

16. Policy Acceptance and Communication Preferences

We keep a history of your policy acceptance: account ID, acceptance time, Terms and Privacy Policy versions, document hashes, the statement presented, and whether you accepted during signup or in an update popup. We also keep marketing choices, their time, source, disclosure version, and the verified email identity to which they apply. These records document your choices; policy acceptance is not marketing consent.

Acceptance records are retained separately from routine session and operational-log cleanup, including through account soft deletion, for compliance, dispute handling, and legitimate recordkeeping. Contact us to exercise your privacy rights; requests are reviewed under applicable law and retention obligations. No device fingerprint or IP address is collected for these acceptance records.

Privacy questions and requests: [email protected]

17. Optional Product Measurement and Setup Progress

Optional first-party product measurement requires its own versioned choice. Marketing consent does not turn it on. If you decline or measurement is unavailable, the product remains usable. You can change this choice from the website footer. After consent we may store a bounded source category, an approved public landing path, an anonymous first-party visitor identifier, allowlisted views and clicks, and account-linked signup, task-outcome and verified billing facts. We do not send coursework, answers, credentials, full referring URLs or arbitrary URL parameters to this measurement system.

Raw growth events are retained for 90 days. Bounded cohort summaries are retained for 13 months. New account-linked growth records are removed on account deletion; withdrawing measurement removes account-linked optional growth records. Reports distinguish unknown sources, missing instrumentation and observation periods that are not yet complete. Client-reported extension milestones are distinct from server-confirmed useful results.

Functional setup records include your selected platform and task, checklist and prompt dismissals, saved desktop handoff, extension setup milestones, and first useful-use progress. These support the product independently of optional measurement. No question text or answer is stored in these records.

A verified account that opted into marketing may receive one setup reminder after 24 hours without a useful result. Activation, unsubscribe, deletion and a known relevant platform outage suppress that reminder. Explicit desktop handoff emails go only to your verified account address. Existing unsubscribe, suppression and delivery-deduplication records prevent repeated delivery.

Support