Privacy Policy

Last updated: July 2026

1. Introduction

sHub ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our study management platform ("the Platform").

We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). For users in the European Economic Area (EEA), we also comply with the General Data Protection Regulation (GDPR). For users in the United Kingdom, we comply with the UK GDPR and the Data Protection Act 2018.

By using the Platform, you acknowledge the practices described in this policy. If you do not agree, please do not use the Platform.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Full name, email address, password (hashed), school name, year level, and subjects
  • Profile Information: Avatar, bio, study preferences, and time zone
  • Academic Data: Self-reported or LMS-synced grades, assessment scores, assignments, deadlines, and course enrolments
  • User Content: Notes, flashcards, study plans, calendar events, reminders, and any other content you create or upload
  • Communications: Information you provide when contacting support or participating in surveys

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent on the Platform, interaction patterns, and referral sources
  • Device Information: Browser type, operating system, device type, screen resolution, and unique device identifiers
  • Log Data: IP address, access times, request timestamps, and error logs
  • Cookies & Similar Technologies: Session cookies, persistent cookies, and local storage for authentication, preferences, and analytics

2.3 Information from Third Parties

  • LMS Platforms (Canvas, Daymap): Course listings, assignments, submissions, grades, calendar events, announcements, and user profile data, as authorised by you
  • Google Calendar (if connected): Calendar events and metadata for unified calendar display
  • Authentication Providers: If you use social sign-in, we receive basic profile information from the provider

3. How We Collect Information

We collect information through:

  • Direct Input: Forms, account setup, profile editing, and content creation features
  • Automated Technologies: Cookies, web beacons, analytics scripts, and server logs
  • API Integrations: Synchronisation with third-party services you authorise (LMS platforms, Google Calendar)
  • Third-Party Analytics: Services such as Sentry for error monitoring and performance tracking

4. Legal Basis for Processing (GDPR/UK GDPR)

For users in the EEA or UK, we process personal data on the following legal bases:

  • Consent: Where you have given consent for specific processing activities (e.g., cookies, marketing emails)
  • Contractual Necessity: Processing necessary to provide the Service under our Terms of Service
  • Legitimate Interests: For analytics, security, fraud prevention, and service improvement, where our interests do not override your privacy rights
  • Legal Obligation: Where we are required to process data by applicable law

5. How We Use Your Information

We use collected information for the following purposes:

  • Service Delivery: To operate, maintain, and provide the Platform's features, including LMS sync, calendar unification, AI study planning, and reminders
  • Personalisation: To tailor study plans, recommendations, and content to your subjects, goals, and preferences
  • AI Features: To generate study plans, flashcards, quizzes, and knowledge graphs based on your academic data
  • ATAR Estimation: To calculate indicative ATAR estimates using self-reported or synced grades against historical scaling data
  • Communication: To send reminders, notifications, service updates, and (with consent) marketing communications
  • Analytics & Improvement: To analyse usage patterns, diagnose technical issues, and improve the Platform
  • Security: To detect and prevent fraud, abuse, and unauthorised access
  • Legal Compliance: To comply with applicable legal obligations and enforce our Terms of Service

We never sell your personal information to third parties.

6. Data Sharing & Disclosure

We may share your information with the following categories of recipients:

6.1 Service Providers

We engage trusted third-party service providers to help deliver the Platform. These providers process data solely on our instructions and are contractually bound to protect your data:

  • Supabase Inc. — PostgreSQL database (hosted in United States / multi-region). Data at rest encrypted using AES-256.
  • Cloudflare, Inc. — R2 object storage (file uploads, user content). Zero-egress policy applies.
  • Upstash Inc. — Redis caching and QStash job queue.
  • Vercel Inc. — Web application hosting and edge functions.
  • Resend Inc. — Transactional and reminder email delivery.
  • Functional Software, Inc. (Sentry) — Error monitoring and performance tracking.
  • Google LLC — Gemini AI API (content may be processed on Google Cloud infrastructure).
  • Groq Inc. — AI inference API.
  • OpenRouter — AI model routing and inference.

6.2 LMS Platforms

When you connect an LMS account, data is synchronised between our Platform and the LMS provider (Canvas by Instructure, Daymap). Data shared with each LMS is limited to data necessary for synchronisation and is governed by that provider's privacy policy.

6.3 Legal & Regulatory Disclosures

We may disclose your information if required to do so by law, regulation, legal process, or governmental request, including but not limited to:

  • Compliance with Australian, South Australian, or federal law enforcement agencies
  • Enforcement of our Terms of Service
  • Protection of our rights, property, or safety, or those of our users or the public
  • In connection with a merger, acquisition, or sale of all or substantially all of our assets (with notice to you)

6.4 With Your Consent

We may share your information with third parties when you have given explicit consent to do so.

7. Data Storage & Security

We implement reasonable technical and organisational measures to protect your personal data, including:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3
  • Encryption at Rest: Database storage uses AES-256 encryption at rest
  • Access Controls: Strict role-based access controls; only authorised personnel have access to production data
  • Authentication: Passwords are hashed and salted using bcrypt; we support multi-factor authentication
  • Regular Audits: We conduct periodic security reviews and dependency scans

While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:

  • Account Data: Retained until account deletion
  • LMS-Synced Data: Updated with each sync cycle; retained until account deletion or integration disconnection
  • Usage Data: Retained in anonymised or aggregated form for analytics; identifiable logs retained for a maximum of 12 months
  • Backup Data: Retained for up to 90 days and then securely deleted

When you delete your account, we will delete or anonymise your personal data within 30 days, subject to legal retention obligations (e.g., tax or anti-fraud requirements).

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

9.1 Australian Users (Privacy Act)

  • Access: Request access to personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Complaint: Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)

9.2 EEA/UK Users (GDPR/UK GDPR)

  • Right to Access: Obtain confirmation of whether we process your data and request a copy
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data
  • Right to Restrict Processing: Request restriction of processing in certain circumstances
  • Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format
  • Right to Object: Object to processing based on legitimate interests or direct marketing
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Right to Lodge a Complaint: Lodge a complaint with your local data protection supervisory authority

9.3 California Users (CCPA)

  • Right to Know: Request disclosure of categories and specific pieces of personal data collected
  • Right to Delete: Request deletion of personal data
  • Right to Opt-Out: Opt out of the sale of personal data (we do not sell data)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

To exercise any of these rights, contact us at privacy@shub.com. We will respond within the timeframe required by applicable law (typically 30 days). We may need to verify your identity before processing your request.

10. Children's Privacy

The Platform is intended for students aged 13 and above. We do not knowingly collect personal information from children under 13 without verifiable parental consent. If you believe a child under 13 has provided us with personal data, please contact us immediately at privacy@shub.com and we will take steps to delete that information.

For students under 18, we encourage parents and guardians to monitor their child's use of the Platform and to review this Privacy Policy.

11. International Data Transfers

Your personal data may be transferred to and processed in countries other than your own, including Australia and the United States, where our infrastructure providers are located. When transferring data from the EEA or UK, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreement (IDTA) for transfers from the UK
  • Adequacy decisions where applicable

By using the Platform, you consent to the transfer of your data to Australia and the United States in accordance with this policy.

12. Cookies & Tracking Technologies

We use the following categories of cookies and similar technologies:

  • Essential Cookies: Required for authentication, session management, and security. These cannot be disabled.
  • Functional Cookies: Remember your preferences and settings (e.g., theme, time zone).
  • Analytics Cookies: Help us understand how users interact with the Platform (aggregated, anonymised data).

You can control cookie preferences through your browser settings. Disabling essential cookies may affect Platform functionality. We are not currently using third-party advertising cookies.

13. AI & Automated Decision-Making

The Platform uses AI features to generate study plans, flashcards, quizzes, and knowledge graphs. These features involve automated processing of your academic data. You should be aware that:

  • AI-generated content may contain errors; you should independently verify it
  • You can choose not to use AI features; this will not affect your ability to use other parts of the Platform
  • Data sent to AI providers (Google Gemini, Groq, OpenRouter) is subject to their privacy policies
  • We do not use your data to train third-party AI models unless explicitly authorised
  • The ATAR estimator is an automated calculation based on historical scaling data and is not a form of AI; it provides indicative estimates only

14. Marketing Communications

We may send you service-related communications (e.g., password resets, feature updates, security alerts) that are necessary for the operation of the Platform. With your consent, we may send marketing communications about new features or offers. You may opt out of marketing communications at any time by:

  • Clicking the "unsubscribe" link in marketing emails
  • Updating your notification preferences in account settings
  • Contacting us at privacy@shub.com

We will never sell your contact information to third parties for their marketing purposes.

15. Data Breach Notification

In the event of a data breach involving personal information that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). For EEA/UK users, we will comply with applicable breach notification requirements under the GDPR.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be effective immediately upon posting to this page. We will notify registered users of material changes via email or in-app notification. The "Last updated" date at the top of this page will reflect the most recent revision. We encourage you to review this policy periodically.

17. Contact & Complaints

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

  • Email: privacy@shub.com
  • Support: support@shub.com

Complaints (Australia)

If you are dissatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

Complaints (EEA/UK)

You have the right to lodge a complaint with your local data protection supervisory authority. Contact details are available at: edpb.europa.eu


© 2026 sHub. All rights reserved.