Privacy
Privacy Policy
This Policy explains who processes your personal information in iStudyCloud, and how.
v1 · Effective October 2, 2026
1. Overview & scope
This Privacy Policy (the "Policy") explains how your personal information is handled in iStudyCloud, an AI-powered learning and creative workspace offered through istudycloud.com, our desktop and mobile applications, and related services (together, the "Service"). The Service has one brand but two companies that process personal information; Section 2 explains which company is responsible for which purposes.
The Service is at a stage where features are still being added and changed. This Policy describes the processing we perform today, and when the Service changes we will give notice and amend it under Section 12.
In this Policy, "we" or "the company" means the company responsible for your personal information (the controller), which is determined by the country you live in under Section 2.
2. Controller (responsible company) and roles
For members who live in Korea, the controller of personal information is 아이스터디클라우드 주식회사 (a Republic of Korea corporation, business registration no. 379-81-02863, the "Korean company"). For members who live in any other country, the controller is ISTUDYCLOUD INC. (a British Columbia, Canada corporation, registration no. BC1383084, the "Canadian company"). This applies to both free and paid use. The country you live in is determined by the billing country you provide when you pay. If there is no billing country, a member who uses the Service in Korean with the Republic of Korea time zone is treated as living in Korea, and for every other member the Canadian company is the controller. Your IP address and location information are not used for this determination.
The Canadian company develops the Service, holds the rights in the software and operates the platform (accounts, authentication, security, content storage and delivery, AI feature connections and infrastructure). To provide the Service to members in Korea, the Korean company entrusts platform operation to the Canadian company (outsourcing of processing, Section 5) and itself handles contract performance, payments, refunds, customer support and notices in Korea for members in Korea.
The seller of a paid product is shown before payment and on the receipt. The Korean company is the seller for Korean won payments, and the Canadian company is the seller for US dollar payments.
Agent subscriptions and content on the marketplace are sold by the seller (creator) shown on the product, and payment is processed through the seller's own Stripe account. The seller receives the order information needed to fulfil the transaction. We process it only as needed for intermediation and platform fee processing. Sellers can currently register only in Canada, the United States and Japan.
Each company uses only the information needed for its own purposes. Sections 5 and 6 describe when information moves between the two companies.
3. Information we collect
3.1 Account information
When you sign up we collect your email address, name, profile photo (if provided by your sign-in provider) and a unique authentication identifier. We do not store your password; authentication is handled by Firebase Authentication, and sign-in codes are sent by email.
If you sign in with a social account such as Google or Kakao, we receive from that provider the items you agreed to share with it: your email address (including whether it is valid and verified), profile, nickname and profile image. We only «receive» this information from the provider; we do not send your personal information to the provider.
Your account stores the interface language fixed at sign-up and, where your browser provides one, the two-letter country code described in Section 3.8. That code is derived from your browser's language setting and is not based on your IP address or any location measurement — it reflects the locale configured on your device and may differ from where you actually are. You can change the language in the product at any time. This country code is not used to choose the selling company. The controller is determined by your billing country under Section 2; the interface language and device time zone are used only when there is no billing country.
3.2 Organization, school and center information
When you create or join an organization we process the organization's name and type (personal, sole proprietorship, educational institution or enterprise), each member's email address or an identifier assigned by the organization (for example an employee or student number), display name, role, and billing contact details.
Organization owners and administrators can see the member list and roles, and each member's AI and Energy usage records, in order to run the organization. When a school, center or other institution invites members to use the Service, that institution is itself responsible for using member information for its own purposes (such as classes, assignments or work management), and we process that information as needed to provide the Service.
3.3 Content you create
Content you create or upload — studios, documents, drawings, files — is stored on infrastructure operated by the Canadian company so that we can provide it to you and to collaborators you choose. We treat this content as confidential and do not use it to train our own AI models.
3.4 AI prompts and responses
When you use AI features, your prompts and the context you choose to share with the assistant (selected text, files, workspace content) are sent to the model provider you select. We keep AI conversation history so that you can return to your chats.
If you use the customer support chat, your question, text extracted from any attachments, and the information about your organization needed to answer (organization name, plan, Energy summary, recent receipt summary and diagnostic records) are sent to the support AI (Google Gemini). The support AI only looks up information about the organization that asked.
3.5 Payment and transaction information
US dollar payments are processed by Stripe, and Korean won payments by Toss Payments (including Toss BrandPay). Payment method details such as card numbers are held by the payment provider; we never see or store your full card number. For monthly recurring payments (subscriptions), a payment method is registered for the next payment. For US dollar payments, the payment method is held by Stripe and we keep only the Stripe customer identifier; payment method labels (for example the card brand and last four digits) are fetched from Stripe when needed. For Korean won payments, we keep the automatic payment key (billing key) issued by Toss Payments in encrypted form, together with the card issuer, the masked card number and whether the card is personal or corporate, to display the payment method.
To manage purchases we keep receipt records: purchasing organization, product, quantity, amount, currency, tax amount, payment rail, the payment provider's transaction reference, service period, next payment date, payment, failure and refund times, the selling company and its registration details, and the versions of the Terms and this Policy that applied at the time of purchase. For US dollar payments, Stripe collects your billing address to calculate tax; that address is held by Stripe.
3.6 Marketplace seller information
Identity verification, tax registration and payout information of marketplace sellers is collected and held directly by Stripe Connect. We keep only the connected account identifier, its verification status and the selling country.
3.7 Usage, diagnostic information and cookies
To operate and secure the Service we automatically collect IP address, browser or app version, operating system, language setting, time zone, and essential event and diagnostic records. We use cookies only to remember display settings (theme, sidebar and language), and we do not use advertising tracking or third-party analytics tools.
3.8 Pre-authentication context
When you submit a sign-in or email form before an authenticated session exists, we record the language your request indicates and, where your browser provides one, a two-letter country code taken from its language setting, in order to complete sign-in, send verification messages in the right language and diagnose delivery failures. We do not store your IP address for this purpose. This record is not linked to your account until sign-in succeeds, and it carries an explicit expiry time after which it is deleted automatically — see Section 7.
3.9 Alpha access requests
While the Service is in closed alpha, you can ask for access from the web, desktop or mobile app. When you do, the Canadian company records the email address and account identifier of the signed-in account, the use-case message you write (required, 10 to 280 characters), the app the request came from (web, desktop or mobile), how many times you have asked, the times of your first and latest request, and the review status together with any note our staff record when reviewing it.
We use this information only to review access requests, decide who may use the Service during the alpha, and apply that decision to your account. Your message is shown only to you and to the administrators who review alpha access.
If you withdraw a request while it is still under review, the request record, including your message, is deleted immediately. Otherwise it is kept with your account's alpha access status for as long as your account exists — see Section 7.
4. How we use information
The Canadian company uses personal information to: (a) provide and maintain the Service; (b) authenticate members and protect accounts; (c) store, sync and share workspace content; (d) route AI requests to the model provider you select and return results; (e) send service notices and payment and renewal notices; (f) detect abuse and keep the Service secure; (g) perform contracts, charge and refund US dollar payments and process marketplace fees; and (h) comply with applicable law. For members in Korea, it processes (a) to (f) on behalf of the Korean company under the outsourcing arrangement.
The Korean company uses the personal information of members in Korea to: (a) perform contracts, process Korean won payments and recurring payments, give refunds and issue receipts; (b) consult with and support customers; (c) inform people in Korea about the Service and market it (advertising messages are sent only with separate consent); and (d) comply with the laws of the Republic of Korea.
Customer enquiries are answered by the company responsible for the account or transaction concerned. We do not sell personal information, and we do not use customer content or AI prompts to train our own AI models. The Service does not currently send advertising emails.
5. Outsourcing of processing and sub-processors
The Korean company entrusts the processing of personal information to the Canadian company as follows. Processor: ISTUDYCLOUD INC. Entrusted work: overall platform operation (accounts, authentication, content storage and delivery, AI feature connections, storage of payment records, security and infrastructure). The Canadian company does not use the information of members in Korea for any purpose beyond the entrusted work.
We use sub-processors to operate the Service. Each receives only the data needed for its function and is bound by data-protection commitments. The list is split into «those that process data for every user» and «those involved only when you use a particular feature».
Sub-processors involved for every user:
Google LLC (Firebase and Google Cloud) — user authentication, the primary application database and real-time sync (Cloud Firestore), server functions, regional file storage, and mobile app notification delivery (Firebase Cloud Messaging).
Cloudflare, Inc. — content delivery, web application firewall, R2 object storage for user files and media, Workers compute, and transactional email such as sign-in codes, invitations and pass-expiry reminders.
Sub-processors involved only when you use the related feature — if you do not use that feature, no information about you is shared with them:
AI model providers (OpenAI, Anthropic, Google) — when you use AI features, your prompts and the context you choose to share are sent to the model provider you select for inference. We do not send content to a provider you have not selected. If you connect your own ChatGPT subscription account, those requests are sent to OpenAI through the connected account. The customer support chat uses the support AI (Google Gemini) described in Section 3.4.
Soniox, Inc. — processes your voice and the related text when you use voice input (speech recognition) or read-aloud (speech synthesis).
Apple Inc. — notification delivery (APNs) if you allow notifications in the iOS app.
Stripe, Inc. — US dollar payments and recurring payments, and identity verification and payouts for marketplace sellers (Stripe Connect Express). Each payment is processed through the payment account of the company that sells the product.
Toss Payments Co., Ltd. — Korean won payments and recurring payments (including Toss BrandPay and automatic payments), processed through the Korean company's merchant account.
Sub-processors in the second group are involved only when the feature is actually offered and you use it.
We will update this list when sub-processors change and give notice of material changes under Section 12.
For organizations pinned to a specific region under Section 6, the database and file-storage sub-processors serve that organization through infrastructure in the pinned region.
6. International transfers and data residency
By default, workspace data is stored in our primary region in the United States (Google Cloud us-west2, Los Angeles). An organization can ask to pin its workspace data to a specific region we operate — northamerica-northeast2 (Toronto, Canada) or asia-northeast3 (Seoul, Republic of Korea). Database records and uploaded files of a pinned organization are stored in the pinned region; organizations that are not pinned use the default region. A region assignment cannot be changed after creation.
Personal information of members in Korea is transferred abroad as follows (notice under the Korean Personal Information Protection Act). Recipients: ISTUDYCLOUD INC. (Canada, support@istudycloud.com) and the sub-processors in Section 5. Destination countries: the United States and Canada (for an organization pinned to the Seoul region, that organization's database and files stay in the Republic of Korea). Items: the account, organization, content, AI, payment and usage records described in Section 3. Timing and method: transmitted over the network whenever you use the Service. Purpose: the entrusted work in Section 5. Retention: Section 7.
Information of members who live outside Korea is processed by the Canadian company and may be stored on the infrastructure of the sub-processors in Section 5 (in the United States, Canada and elsewhere). We apply industry-standard safeguards to these transfers, including standard contractual clauses where applicable.
You may refuse the international transfer of your personal information by notifying us at the contact in Section 12. Where a transfer is essential to providing the Service, refusing it may limit some or all of the Service.
7. Data retention and deletion
We keep personal information while your account is active or as long as needed to provide the Service. Workspace content and AI history remain until you delete them or close your account. Content, groups and AI conversations moved to the trash are permanently deleted one year after they were moved there. A deleted organization can be restored for 90 days and is cleaned up afterwards. Identity details of members removed from an organization or content are masked 30 days after removal.
Transaction records (receipts, payments, recurring payments and refunds) are kept separately from Service data by the company that sold the transaction, under its statutory record-keeping obligations: 10 years for Korean won transactions and 7 years for other transactions. The period for Korean won transactions includes the periods required by Korea's Act on the Consumer Protection in Electronic Commerce (5 years for payment and supply records, 3 years for consumer complaint and dispute records). If the first payment right after card registration is declined on the spot, the Toss Payments automatic payment key (billing key) is deleted immediately, and when you switch to another card we ask Toss Payments to delete the previous key. When a recurring payment ends (cancellation at the end of the billing period, termination after failed payments, or a full refund), we delete the organization's billing key right away and ask Toss Payments to delete it as well. While a cancellation is scheduled but paid time remains, or while a failed payment is being retried, the key stays stored in encrypted form. If you cancel the automatic payment with Toss Payments or your card company, the key is no longer used for payments. You can request deletion of the billing key at any time at support@istudycloud.com. Transaction records remain for the applicable period even if you delete your account and are not used for any other purpose.
Customer support conversation records are kept for 30 days after the conversation ends and then deleted.
You can request deletion of your account and personal information at any time at support@istudycloud.com. We complete eligible deletion requests within 30 days, subject to legal retention obligations.
Pre-authentication context (Section 3.8) expires 1 hour after the final verification message for that request is sent. If a code is resent, the expiry is renewed to 1 hour from the resend. Expiry and deletion are distinct: the record stops being valid the moment its expiry passes and is treated as expired from then on, while physical deletion is carried out by an automated process and is normally completed within 24 hours of expiry. Only the former is immediate, so we state both.
Alpha access requests (Section 3.9) are deleted immediately if you withdraw them while they are still under review; otherwise they are kept with your account's alpha access status for as long as your account exists, and you can ask for them to be deleted together with your account as described above.
8. Your rights and where to exercise them
Depending on applicable law, you may: request access to the personal information we hold about you, correct inaccurate information, request deletion, restrict or object to processing, withdraw consent, and request a copy in a portable format.
To exercise your rights, contact support@istudycloud.com. Your request is handled by the company responsible for the information, and if you are not sure which company that is, you can still use the same address and it will be passed to the responsible company.
Residents of Canada may complain to the Office of the Privacy Commissioner of Canada (OPC, priv.gc.ca), and residents of the EEA and UK may contact their local supervisory authority.
Users in the Republic of Korea may, in addition, file a complaint or apply for dispute mediation with the Personal Information Protection Commission (pipc.go.kr), the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972) or the KISA Privacy Infringement Report Center (privacy.kisa.or.kr, 118).
9. Children's privacy and educational institutions
iStudyCloud is not directed to children, and, except for the legal representative consent exception in the Republic of Korea stated below, we do not knowingly collect personal information from children below the age at which they can consent for themselves under applicable law. That age is 13 in Canada and the United States, 14 in the Republic of Korea and mainland China, and 16 in Vietnam and in EEA member states that have not set a lower age. These ages describe the thresholds for consenting to the processing of personal information for oneself. Registration and payment for paid products are subject to the legal guardian consent requirements in Section 3 of the Terms of Service, while the processing of personal information is subject to both the country-specific thresholds and the exception for the Republic of Korea in this section. In the Republic of Korea, we process personal information of children under 14 only with the consent of their legal representative.
Educational institutions planning to use the Service with minors should contact us in advance to put an appropriate data processing agreement in place. The institution is responsible for managing students' enrolment, grade and completion records, and we do not award credits or graduation qualifications.
10. Security
We protect personal information with industry-standard safeguards, including TLS encryption in transit, encryption at rest in managed databases and object storage, role-based access control, least-privilege access, audit logs and infrastructure security monitoring.
No system is perfectly secure. If we become aware of a personal information breach that poses a risk of significant harm, we will notify affected members without undue delay and report to the authorities required by law — the Office of the Privacy Commissioner of Canada under Canadian law and, for personal information of users in the Republic of Korea, the data subjects and the Personal Information Protection Commission within 72 hours under the Personal Information Protection Act.
11. Privacy officers
Under the Korean Personal Information Protection Act, the Korean company designates and publishes a privacy officer. Privacy officer of the Korean company: YOO JEEWON (유지원), Chief Executive Officer. Contact: 02-717-1161 / support@istudycloud.com. You may bring questions, complaints and requests for remedies regarding personal information to the privacy officer, and we will respond without delay.
Privacy Officer of the Canadian company: YOO JEEWON, Director · support@istudycloud.com.
12. Versions, languages and changes
This Policy is provided in Korean, English, Japanese, Chinese (Simplified and Traditional) and Vietnamese. Where the Korean company is the controller, the Korean version is the original; where the Canadian company is the controller, the English version is the original. Other language versions are translations, and if they differ from the original, the original prevails. The version that applied when you paid is recorded on your receipt.
We may amend this Policy as the Service changes. We will notify you of material changes by email and in-service notice at least 30 days before they take effect. Where an amendment requires your consent, we will ask for it separately.
Send privacy questions, access requests and complaints to support@istudycloud.com.
This Policy does not limit any rights you have under the mandatory personal information protection laws of the country where you live.
This Policy takes effect on October 2, 2026 (v1). The previous review draft never took effect.