Privacy policy

What we collect, why, and who else sees it. Short version: the minimum needed to run the site, and we do not sell or share it for advertising.

Last updated 5 Sep 2026 · StudySnacks, Route de Praz-Véguey, 1022, Chavannes-près-Renens, Suisse

What we actually store

Your email address and password. The password is never stored as text — our authentication provider stores a hash of it, and we could not read it if we wanted to.

Your name, if you choose to enter one. It is optional and you can change or clear it whenever you like.

What you have access to and until when: whether you hold a term pass, and its end date.

A record of each purchase: amount, date, which term or session it was for, and the payment reference from Stripe. We keep these because accounting law requires it.

Feedback you leave on a video, including the rating and any comment.

For live sessions: which groups you are in, whether your seat is held or paid, your votes on proposed times, and any invite link you used.

A device record: a short fingerprint derived from your browser and screen, a rough label like "Chrome on Windows", and when it was last seen.

What we do not do

We do not sell your data. Not to anyone, at any price.

We do not share it with advertisers, data brokers or analytics networks, and there are no advertising or tracking pixels on this site.

There is no third-party analytics: no Google Analytics, no Meta pixel, no session recording, no heatmaps. We do not know which videos you watched, how far you got, or when you were online.

We do not build a profile of you, and we do not use your data to train anything.

We do not email you marketing. The only emails we send are about something you did: a receipt, your group filling up, a time being confirmed, joining details, or a cancellation.

Cookies

A session cookie that keeps you logged in. Without it you would have to sign in on every page.

A signed device cookie, so returning on the same laptop is recognised as the same laptop.

A language cookie remembering whether you chose English or French.

That is the whole list. All three are necessary for the site to work, none of them tracks you across other websites, and there is nothing here to advertise with.

Who else processes your data

Supabase — accounts, passwords and the database. Hosted in the region chosen when the project was created.

Stripe — payments. Your card number goes to Stripe directly and never touches our servers; we never see or store it. We hold only Stripe's reference to the payment and your customer id.

Bunny.net — video delivery. It sees the requests that stream a video, including your IP address, as any video host must.

Resend — sending the notification emails described above. It processes your email address and the message.

Vercel — hosting. Standard server logs, including IP addresses, kept for a short period.

Each of these is a processor acting on our instructions, not a party we sell to.

All of them operate outside Switzerland, in the EU or the United States, so your data leaves the country in the course of running the site. That is lawful and ordinary: the EU is recognised by Switzerland as offering adequate protection, and the American services operate under the Swiss-US Data Privacy Framework and standard contractual clauses. We mention it because you are entitled to know where your data actually is, not only who holds it.

How long we keep it

Account data: while your account exists, and deleted when you close it.

Purchase records: kept after account deletion for as long as tax and accounting law requires, because we are not allowed to delete them sooner. They are reduced to the transaction itself.

Device records: deleted when you unbind the device or close your account.

Feedback: kept, but detached from your account on deletion, so it stays useful for improving a video without still pointing at you.

Your rights

You can ask for a copy of everything we hold about you, ask us to correct it, or ask us to delete it. Write to us and we will do it — there is no form to fill in and no charge.

You can change your name and password yourself from your account page, and unbind a device there too.

If you think we have mishandled your data you can complain to your national data protection authority. We would rather you told us first, so we can fix it.

Security

Passwords are hashed by our authentication provider, not stored. Payment card details never reach our servers.

The database enforces access rules at the row and column level, so one account cannot read another's data even if a page were to ask for it by mistake.

If a breach ever affects your data, we will tell you what happened and what to do about it, rather than hoping you do not notice.