Privacy policy
Last updated: July 23, 2026
The canonical version of this policy is published at scmstudyapp.io/privacy. SCM Study also makes the policy available in the app. If a bundled copy is older, the published web version controls.
Short version: we collect the data needed to operate, secure, support, and improve our services. We do not sell personal information, share it for cross-context behavioral advertising, or use third-party advertising trackers.
Scope and who we are
SCM Education Solutions ("SCM", "we", "us") operates SCM Study on mobile and the web, scmstudyapp.io, scmeducation.com, our newsletters, and related support and inquiry services (together, the "Services"). Where applicable, SCM is the controller or business responsible for the personal information described in this policy.
Privacy questions and rights requests can be sent to privacy@scmeducation.com.
Information we collect
- Account and profile information: email address, an internal user ID, optional display name, email-verification state, authentication provider, and account preferences. Supabase processes password hashes or OAuth/session credentials for authentication; SCM does not receive or store plaintext passwords.
- Study activity: practice answers and results, mock-exam scores, flash-card review history and schedules, reading progress, streaks, goals, and study plans. Guest activity can remain only on the device. We collect study activity from our servers when a signed-in user enables cross-device sync or otherwise submits it to the Services.
- Subscription and purchase information: product and plan identifiers, purchase and entitlement status, billing platform, price and currency, purchase, renewal, expiration, cancellation, refund, and billing-status dates, and provider transaction or customer identifiers. Google, Apple, or Stripe processes payment credentials; SCM does not receive or store full payment-card numbers.
- Diagnostics and app performance: crash reports, stack traces, app version, operating-system and device information, breadcrumbs, and performance measurements needed to diagnose reliability problems. The app disables Sentry's default collection of personally identifiable information and applies additional event and breadcrumb scrubbing before transmission.
- Website and security logs: IP address, user agent, request time, requested resource, and similar network metadata processed by our hosting, authentication, database, and security systems for delivery, debugging, fraud prevention, and abuse prevention.
- Communications, newsletter, and inquiry information: email address, marketing preference and consent record, and, if you contact us, your name, company, inquiry topic, message, source page, and our correspondence with you.
We receive information directly from you, automatically from your device when you use the Services, and from the billing and service providers involved in your purchase or account.
How we use information
We use information to:
- create and secure accounts and authenticate users;
- provide study features, personalize practice, and sync progress;
- process purchases, maintain entitlements, and provide billing support;
- operate, troubleshoot, secure, and improve the Services;
- respond to support, privacy, and business inquiries;
- send account, security, billing, and material policy communications; and
- send marketing email only where you have opted in or another lawful basis permits it. Every marketing email includes an unsubscribe method.
We do not use personal information for automated decisions that produce legal or similarly significant effects.
Legal bases for EEA and UK users
Depending on the processing, we rely on:
- Contract: providing accounts, sync, subscriptions, and requested support;
- Legitimate interests: service security, fraud and abuse prevention, diagnostics, product improvement, and responding to business inquiries;
- Consent: marketing communications where consent is required; and
- Legal obligation: tax, accounting, compliance, and valid legal requests.
You may withdraw consent at any time. Withdrawal does not affect processing already carried out lawfully.
When we disclose information
We disclose only the information reasonably necessary to providers and platforms that help deliver the Services:
- Supabase: authentication, database, storage, and server functions;
- Vercel: website and web-application hosting;
- Sentry: crash, error, and performance diagnostics;
- RevenueCat: subscription purchase history, entitlement management, and customer billing-portal access;
- Google Play and Apple App Store: mobile-app distribution and in-app subscription billing;
- Stripe: payment processing for eligible web purchases; and
- Resend: transactional and opt-in marketing email delivery.
These providers may process information in multiple countries and may also have independent obligations as payment or platform providers. We may also disclose information if required by law, to protect rights and safety, in a corporate transaction subject to appropriate safeguards, or with your direction or consent.
We do not sell or rent personal information. We do not disclose personal information for cross-context behavioral advertising.
International processing
SCM and its providers primarily process information in the United States and may process it in other countries where they operate. Where data-protection law requires a transfer mechanism, we and our providers use an applicable lawful safeguard, such as an adequacy decision or approved contractual protections.
Retention
We keep information only as long as reasonably necessary for the purposes described above, including legal, accounting, security, and dispute-resolution needs:
- account and server-synced study data are kept while the account is active and are deleted when account deletion is completed, subject to the exceptions below;
- crash, diagnostic, security-log, and backup data are retained for the limited periods configured with the relevant provider and then deleted or overwritten;
- newsletter information is kept until you unsubscribe or ask us to delete it, except for a minimal suppression record needed to honor the opt-out;
- support and inquiry records are kept while needed to handle the request and maintain appropriate business records; and
- transaction, tax, fraud-prevention, and accounting records may be retained for the period required or permitted by law after account deletion.
Deletion from active systems may not immediately remove information from encrypted, access-restricted backups. Backup copies are isolated from ordinary use and are removed as the backup cycle rolls forward.
Account deletion and subscriptions
You can delete your account in SCM Study under Profile → Delete Account or request/schedule deletion at scmeducation.com/account/delete. You can also email privacy@scmeducation.com from the address on your account.
Account deletion removes the account and associated server-synced study data, subject to required transaction and legal records. Deleting an SCM account does not cancel a subscription. To stop future charges, cancel first through Profile → Manage subscription or through the store or billing portal where you subscribed.
Cookies and local storage
The web Services use first-party cookies or browser storage for sign-in, security, preferences, and required functionality. The mobile app uses device storage for sessions, preferences, offline study data, and sync state. We do not use third-party advertising cookies, cross-site ad trackers, or advertising fingerprinting.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal information; restrict or object to certain processing; withdraw consent; and appeal or complain to a regulator. You may also have the right not to be discriminated against for exercising a privacy right.
Send requests to privacy@scmeducation.com. We may verify the request using the email or authentication method associated with the account. Authorized agents may submit a request where local law permits. We will respond within the period required by applicable law.
California notice
In the preceding 12 months, the categories collected may have included: identifiers (such as email, account ID, and IP address); customer and commercial information (such as name, subscription, and purchase history); internet or electronic activity (such as app interactions and diagnostics); professional information voluntarily provided in an inquiry; and inferences used to personalize study activity (such as weak-area or scheduler state). Sources, purposes, and recipient categories are described above.
We have not sold personal information or shared it for cross-context behavioral advertising. We do not use sensitive personal information for purposes that trigger a right to limit under the California Consumer Privacy Act.
Children
The Services are not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal information, contact us so we can investigate and delete it where required.
Security
We use administrative, technical, and organizational safeguards designed to protect information. These include TLS in transit, provider security controls, restricted administrative access, authentication controls, and data-minimizing diagnostic configuration. No system is completely secure, so we cannot guarantee absolute security.
Changes
We may update this policy as the Services or legal requirements change. We will update the date above and, when required, provide additional notice before a material change takes effect.
Contact
Privacy questions or rights requests: privacy@scmeducation.com.
General support and billing questions: support@scmeducation.com.