How your data works.
Your account and content
StudySoda stores your name, email address, password hash, sessions, study materials, subjects, topics, saved items, learning progress, and exam attempts in the site operator’s PostgreSQL database. Passwords are hashed by the authentication library. API keys are stored as hashes, with a visible prefix and usage metadata.
Public learning, with a private option
New materials are public by default. On the Free plan, reviewers, flashcards, and exams are public. They show your display name and may appear in search engines. Subject and topic details become public when they contain public materials. Pro lets you create and edit private materials. Your email address and personal study progress are not published. Making a public material private prevents new access through this site, but cannot remove independent copies, previously submitted exam records, or search-engine caches.
Administrative access
Authorized site administrators can view and edit public and private materials to operate and support this service. Private visibility prevents access by other learners and search engines; it is not end-to-end encryption. Administrative material access, edits, plan changes, and policy changes are recorded in an audit log. Administrators do not receive your password or API-key secret.
If your plan changes
Existing private materials stay private when Pro ends. You can still read, export, and delete them. To create or edit private materials, renew Pro. Publishing an existing private material is always an explicit choice; a plan change never publishes it automatically.
Cookies and storage
The app uses session cookies to keep you signed in. Study answers and progress are stored in the database, not solely in your browser. There are no advertising trackers or analytics integrations included in this app. Fonts and interface assets are hosted with the application.
Connected tools
An API key gives its holder the permissions you selected for your account’s materials. You can revoke a key at any time. When you choose to send content to an external AI assistant, that service handles it under its own policies. Ordinary studying and editing do not send your materials to a generation service.
AI sources and drafts
When you choose Generate draft, the selected source text and your instructions are sent through the site operator’s configured Codex gateway to its AI provider. Public links are fetched to extract text. Raw uploads are processed temporarily; extracted text and generated drafts are stored privately in this site’s database for up to seven days. You can delete unused sources and completed drafts in AI assistant. Drafts are not public materials and are never published automatically. Once you save a draft as a material, that material follows the visibility and retention rules above.
The gateway and AI provider have their own processing and retention settings, which the site operator must review. Deleting a source here cannot retroactively erase provider records. Avoid sending credentials or content you do not have permission to share.
Export and deletion
Export your original materials in account settings. Deleting a material also deletes its associated bookmarks, progress, and exam attempts. Deleting an account removes its original content, progress, sessions, and API keys. Copies made by other users remain independent. The operator’s database backups may retain data until their configured retention period ends.
Who operates this installation?
StudySoda is self-hosted software. The person or organization running this domain controls database access, backups, email delivery, security logs, and retention. Before opening a public service, its operator should publish their identity, contact details, and applicable privacy and service terms.