Last updated: January 2025
1. Introduction
StudentHub ("we", "our", or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and protect your information when you access or use the StudentHub service (the "Service").
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
2. Information We Collect
We collect only the information necessary to provide and improve the Service.
a. Account Information
- Email address (used for authentication and communication)
b. Learning Management System (LMS) Data
When you connect an LMS (such as Canvas), we may collect:
- Course names
- Assignment titles
- Due dates
- Related academic metadata
We do not modify LMS data and do not access grades unless explicitly required for functionality.
c. Usage Data
- Pages visited
- Features used
- Interaction patterns within the Service
This data helps us improve performance, usability, and reliability.
d. Device & Technical Information
- Browser type
- Device type
- IP address (used for security, fraud prevention, and analytics)
3. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the Service
- Sync and display academic information from connected LMS platforms
- Authenticate users and send magic-link login emails
- Respond to support requests and user inquiries
- Improve functionality, performance, and user experience
- Monitor and protect against unauthorized or fraudulent activity
- Comply with legal obligations
We do not use your data for advertising or sell personal information.
4. FERPA Compliance (U.S. Education Records)
StudentHub is committed to compliance with the Family Educational Rights and Privacy Act (FERPA) for users in the United States.
- For Individual Students: You authorize StudentHub to access your educational records when you connect your LMS account. You may revoke this access at any time by disconnecting your LMS in Settings.
- For Institutional Use: When a school partners with StudentHub, we may act as a "school official" under FERPA, accessing student education records solely for the purpose of providing educational services on behalf of the institution.
- Read-Only Access: StudentHub only reads data from your LMS. We do not modify, submit, or delete any data in your LMS.
- Data Minimization: We collect only the data necessary to provide the Service (courses, assignments, due dates).
- No Re-disclosure: We do not share your educational records with third parties except as described in Section 7.
5. GDPR Compliance (European Users)
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, StudentHub complies with the General Data Protection Regulation (GDPR).
Legal Basis for Processing
- Contract Performance: Processing necessary to provide the Service
- Consent: LMS connections and optional communications
- Legitimate Interests: Security, fraud prevention, service improvement
- Legal Compliance: When required by law
Your GDPR Rights
- Right of Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Data Portability: Export your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time (e.g., disconnect LMS)
To exercise these rights, use the Data Export and Delete Account options in Settings, or contact us at contact@student-hub.net.
6. Data Storage & Security
We implement industry-standard security measures to protect your data, including:
- Encrypted storage for sensitive data (including LMS access tokens)
- Secure HTTPS connections for all data transmission
- Restricted internal access to user data
We retain personal data only as long as necessary to provide the Service or as required by law. You may request deletion at any time (see Section 9).
7. Data Sharing
We do not sell your personal information.
We may share limited data only in the following cases:
- Service Providers: Trusted third parties that help operate the Service (e.g., hosting, email delivery, analytics), under strict confidentiality obligations
- Legal Requirements: When required by law, regulation, or legal process
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to users
All third parties are required to protect your information.
8. Cookies & Tracking
We use only essential cookies required for:
- Authentication
- Session management
- Remembering user preferences
We do not use third-party advertising cookies or cross-site tracking technologies.
9. Children's Privacy
StudentHub is intended for students of various ages.
- If you are under 13, you must have parental or guardian consent to use the Service.
- We do not knowingly collect personal information from children under 13 without appropriate consent.
- If we become aware of unauthorized data collection from a child, we will promptly delete the information.
10. Your Rights & Choices
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your account and associated data
- Disconnect LMS integrations at any time
- Opt out of non-essential communications
Requests can be made by contacting us at the email below.
11. International Data Transfers
StudentHub may process and store data on servers located outside your country of residence. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your own.
We take reasonable measures to ensure appropriate safeguards are in place.
12. Data Retention
We retain your data only as long as necessary to provide the Service:
- Account Data: Retained while your account is active. Deleted within 30 days of account deletion request.
- LMS Data: Synced data (courses, assignments) is retained while your LMS is connected. When you disconnect your LMS, synced data is retained to maintain your dashboard. You may request deletion at any time.
- Session Data: Authentication sessions expire after 30 days of inactivity.
- OAuth Tokens: LMS access tokens are encrypted and retained only while your integration is active. Tokens are revoked and deleted when you disconnect.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date.
Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: contact@student-hub.net