1. About this policy
This Privacy Policy describes how Plue AB ("we", "us", "our") collects, uses, stores, and protects your personal data. We comply with the EU General Data Protection Regulation (GDPR), Swedish data-protection law, and Apple App Store guidelines.
2. Data controller
Company: Plue AB
Contact: contact form
Website: joinplue.com
3. Data we collect
Data you give us directly
- Email, name, and optionally phone number on signup
- Grade level, track, courses, and study goals
- Messages you send to the AI assistant
- Direct messages you send to other users
- Notes, documents, and images you upload
- Flashcards, quiz results, and study material you create
- Homework, assignments, and their deadlines
- Exam dates and scheduling preferences
- Lecture recordings and transcripts (may include voices of teachers or classmates you captured during class)
- Audio and transcripts from speaking practice. Speaking-practice audio is streamed to OpenAI in real time for assessment but is not stored by us, only the transcript is kept.
- Friend connections and referral codes
Data we collect automatically
- Login frequency and session data
- Which features you use and how often. This is logged in our own database as events, for example that a quiz was completed or that a pricing view was shown. We store the time, the event name, and simple values such as plan or count, never text you wrote yourself.
- If you consent, selected product-analytics events are sent from the app to PostHog in the EU. They may include a temporary random session identifier, your subscription plan, and the event name, time, and limited technical values such as a count or duration. The session identifier exists only in memory during the page visit, is not persisted on the device by the PostHog SDK, and is never linked to your account. We never send your content, page paths, or free text. IP addresses are discarded, and neither automatic interaction capture nor session recording is used. No account events are sent to PostHog from our server.
- Study progress (streak, XP, quiz scores)
- Device type and browser version (anonymised)
- Push-notification tokens (device identifiers for sending notifications)
- Error reports and performance data
Data we do not collect
- We never store card or bank data (handled by Stripe)
- We do not track your location or GPS
- We never sell your personal data to third parties
- We do not use your data to train AI models
4. How we use your data
Necessary to deliver the service
- Deliver AI-generated answers, flashcards, quizzes, and summaries
- Personalise content to your courses and level
- Save your progress, study material, and settings
- Power spaced repetition and study planning
- Handle homework and exams with AI scheduling
- Listen mode for read-aloud of study content
- Manage your account and subscription
Improving the service (legitimate interest)
- Understand how the app is used to improve features
- See where students get stuck, for example if a step in onboarding makes many drop off
- Identify and fix technical issues
- Send important service notifications
Sharing with PostHog (with consent)
- Limited usage statistics are sent to our analytics provider PostHog only if you consent. If you decline, the app keeps working exactly the same and we still log limited usage statistics in our own database.
- You can change your choice at any time under Settings and Privacy. When consent is withdrawn, the app stops sending new events to PostHog.
5. Legal basis
Contract: Processing required to deliver the service (GDPR Art. 6(1)(b))
Consent: Product analytics and sharing limited usage statistics with PostHog, plus marketing (GDPR Art. 6(1)(a))
Legitimate interest: Security, fraud prevention, and technical operations (GDPR Art. 6(1)(f))
Legitimate interest: our own usage statistics: We log how the service is used in our own database so we can improve it (GDPR Art. 6(1)(f)). We do this because otherwise we cannot see where students get stuck. The data never leaves our systems, is not shared onward, is not used for advertising or profiling, and never contains text you wrote. You can object to this processing at any time through our contact form.
6. Third parties and sub-processors
We share data with these service providers, all under data-processing agreements:
Supabase (database and authentication): Stores your data within the EU (Frankfurt, Germany). GDPR-compliant with DPA.
OpenAI (AI features): Processes your queries, chat messages, flashcards, lecture recordings (including voices captured during class), and speaking-practice audio to generate AI responses, transcriptions, and assessment. Data sent to OpenAI is not used to train their models. US-based, under EU Standard Contractual Clauses (SCCs).
Anthropic (AI features): Used for certain AI generations (for example study guides and summaries from lecture recordings). Data is not used to train their models. US-based, under EU Standard Contractual Clauses (SCCs).
Google (login and integrations): Used for Google sign-in and optional integrations with Google Calendar, Google Classroom, and Google Drive.
Stripe (payments): Handles payments. We never store card or bank details. Stripe is PCI DSS-certified.
PostHog (product analytics): Receives only limited, consented, session-level product-analytics events from the app. We use PostHog's EU environment. The temporary session identifier is never linked to your account. IP addresses are discarded, and automatic interaction capture and session recording are disabled. PostHog acts as a processor under a data-processing agreement; any transfers outside the EEA are protected by EU Standard Contractual Clauses.
Resend (email): Sends transactional emails like account confirmations, password resets, and reminders.
Firebase / Apple Push Notification Service: Delivers push notifications to your device.
7. Cookies
Necessary cookies: Required for login, session management, and security. Cannot be disabled.
Functional cookies: Save your preferences like theme and language choice.
Product analytics: Helps us understand how the app is used. Requires your consent. You can accept or decline in the consent banner and change your choice at any time under Settings and Privacy.
8. Data retention and deletion
Active accounts: Data is stored as long as you have an active account.
Inactive accounts: Accounts unused for 24 months may be deleted after email warning.
On account deletion: All personal data is permanently deleted within 30 days, including any lecture-recording audio files in storage.
Lecture-recording audio: Audio files from a recording are automatically deleted after 30 days. The transcript and your notes remain as long as you keep the recording.
Usage statistics: Identifiable events in our own database are retained for no more than 14 months. We retain them for that period so we can compare a term with the same term in the previous year. When you delete your account, they are detached from you immediately and become anonymous. PostHog receives only session-level events with a temporary identifier that is never linked to your account.
Anonymised data: Aggregated statistics may be retained in anonymised form.
Legal requirements: Accounting records may be retained per Swedish bookkeeping law (7 years).
9. Your rights
Under the GDPR you have the following rights:
Access: Request a copy of all data we hold about you.
Portability: Download your data in a machine-readable format (JSON).
Rectification: Correct inaccurate or incomplete information.
Erasure ("right to be forgotten"): Permanently delete your account and all associated data.
Restriction: Restrict certain processing.
Objection: Object to processing based on legitimate interest.
Withdraw consent: Withdraw consent for product analytics at any time under Settings and Privacy.
Exercise these rights directly in the app (Settings) or through our contact form. We respond within 30 days.
10. Children and minors
plue is intended for middle-school and high-school students.
Minimum age: You must be at least 13 years old to create an account.
Under 16: Parental or guardian consent is required for data processing per GDPR Art. 8.
Under 18: We recommend having parental or guardian approval to use the service.
Parent dashboard: Parents can track their child's study progress without seeing private content through our parent dashboard.
11. Lecture recording and third-party voices
When a student uses the recording feature for a class, other people's voices may be captured, such as the teacher or classmates. In that case we process third-party voice data without directly obtaining their consent. How we handle this:
The student's responsibility: Before every recording the student must actively confirm they have the teacher's (or equivalent person's) permission to record. Responsibility for holding that permission lies with the student, not with plue.
Our role: plue provides the tool but does not decide who is recorded or why. We log every attestation so we can show the question was asked.
Voice biometrics and special-category data: We never use lecture recordings to identify individual speakers via voiceprints, or to infer health, emotion, or other sensitive attributes. The audio is treated as ordinary personal data, not biometrics.
Deletion request from a third party: If you are a person whose voice was recorded, you can request deletion through our contact form. Include the school and approximate date of the class so we can locate the recording. We delete the affected audio and transcripts within 30 days of a confirmed request.
Automatic audio deletion: Audio files are automatically deleted after 30 days. The student's transcript and notes remain as long as the recording is kept in the account.
12. Study-material visibility
Flashcards and study sets are public by default. Other users can find and study them via the explore page or share links.
You can change visibility to private at any time by clicking the visibility icon next to your set.
AI chat messages and lecture recordings are always private and never shared with other users.
13. Security
- All data is transmitted encrypted via TLS/SSL
- Passwords are hashed with bcrypt (never in plain text)
- Database with Row Level Security (RLS) – you can only access your own data
- Servers within the EU via Supabase (Frankfurt, Germany)
- Regular security review by external CTO
- No card details are stored by us (handled entirely by Stripe)
14. International transfers
Your data is primarily stored within the EU. When data is transferred to the US (e.g. to OpenAI or Google for AI features), it is done under EU Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework.
15. Changes to this policy
We may update this policy as needed. We will notify you of material changes via email or in the app at least 30 days in advance.
16. Supervisory authority
If you believe we are processing your personal data in violation of the GDPR, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY, imy.se) or your local supervisory authority.
17. Contact
For questions about this privacy policy or your personal data, use our contact form.