Privacy Policy
Last updated: 22 July 2026
Stublish ("we", "us", or "our") operates the Stublish creative learning platform (the "Service"), which enables educators to create, assign, and review digital projects such as podcasts, slideshows, and publishing documents with their students. This Privacy Policy explains how we access, use, store, and share data — including Google user data — when you use the Service.
By creating an account or using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, you should not use the Service.
1. Who We Are
Stublish is operated by the Stublish team. For any privacy-related questions, you can contact us through the Contact Us page available in the app footer. We are the data controller responsible for your personal information processed through the Service.
2. Information We Collect
We collect the following categories of information:
- Account information: Your name and email address when you register or sign in using Google. Educators provide their email to receive account notifications, assignments, and billing receipts.
- Google account data: When you sign in with Google or connect a Google integration, we access your basic Google profile information (such as your name and email address) and, for specific integrations you authorise, data from connected Google services (for example, Google Classroom class rosters when you choose to sync them). We only request the scopes necessary for the feature you are using.
- Content you create: Lesson content, project files, student submissions, recordings, images, and text entered into the platform by educators or students.
- Classroom and student data: Class names, student first and last names, and assignment records created by educators to manage their classrooms.
- Billing information: When you purchase a subscription, we process your payment through Stripe. We do not store full card numbers — Stripe handles payment data securely. We retain your plan, invoices, and billing history.
- Usage data: Information about how you interact with the Service, such as device type, browser, pages visited, and timestamps, used to maintain and improve the platform.
- Support communications: If you submit a support ticket, we store your name, email, and the details you provide to resolve your enquiry.
3. How We Access and Use Google User Data
When you authorise a Google integration, Stublish accesses Google user data strictly to provide the feature you requested. Specifically:
- Google sign-in: We use your Google profile name and email address to create and authenticate your Stublish account. This information is used to log you in and display your name in the app.
- Google Classroom sync: If you choose to sync Google Classroom, we access your class names and student rosters solely to import them into Stublish so you can manage assignments. We do not modify your Google Classroom data without your explicit action.
- Scope limitation: We request only the OAuth scopes required for the specific feature you are using and do not access data beyond that scope.
We do not sell Google user data to any third party. We do not use Google user data for advertising. Google user data accessed through integrations is used solely to provide the requested functionality within Stublish.
4. How We Use Your Information
We use the information we collect to:
- Create and manage your account and authenticate your sign-in.
- Provide, maintain, and improve the Service's features.
- Process subscription payments and manage billing.
- Send you service-related notifications, such as assignment updates and billing receipts.
- Respond to support requests and enquiries.
- Monitor for misuse, inappropriate content, and security threats.
- Comply with our legal and educational obligations.
5. How We Store Your Data
Your data is stored on secure cloud infrastructure provided by our hosting and database providers. Account data, content, and classroom information are stored for as long as your account is active or as needed to provide the Service. Billing records are retained for the period required by tax and accounting law.
Student content and classroom data belonging to an educator are logically separated by educator account so that one educator cannot access another educator's students or classes.
6. How We Share Your Data
We do not sell your personal data. We share data only in the following limited circumstances:
- Service providers: We use trusted third-party providers to operate the Service, including hosting, authentication, email delivery, and payment processing (Stripe). These providers process data on our behalf under appropriate data protection terms.
- Google API services: When you authorise a Google integration, data is exchanged with Google's APIs to provide the feature. Google's use of data transferred to its APIs is governed by Google's own policies.
- Within classrooms: Educator-created content and student work is visible to the educator and the students within that classroom, as part of the Service's classroom workflow.
- Legal compliance: We may disclose information where required by law or to protect the rights, property, or safety of our users or others.
7. Data Security
We use industry-standard safeguards to protect your data, including encrypted transmission (HTTPS), access controls, and logical separation between educator accounts. No method of transmission or storage is completely secure, but we work to protect your information using reasonable technical and organisational measures.
8. Student Privacy
Stublish is designed for use in educational settings. Student accounts are created and managed by their educator. We collect the minimum student information needed to operate the classroom workflow — typically first and last name, and a login code or PIN. We do not use student data for advertising or sell it to third parties. Student content is visible only to the student's educator and, where applicable, classmates within an assigned group.
9. Your Rights and Choices
- Access and update: You can view and update your account information from the Settings page within the app.
- Google permissions: You can review and revoke Stublish's access to your Google account at any time through your Google Account security settings. Revoking access may disable features that rely on that integration.
- Account deletion: You can request deletion of your account and associated data by contacting us. Some records may be retained where required by law or for legitimate business purposes such as billing.
- Marketing: You may opt out of non-essential communications by following the unsubscribe link in any email or contacting us.
10. Cookies and Local Storage
The Service uses browser local storage and session storage to keep you signed in and to remember preferences. We do not use cookies for third-party advertising tracking.
11. Children's Data
Stublish is intended for use by educators and their students, including students under 13, within a supervised classroom context. Student accounts are created by educators, and we only collect the minimal information needed to operate the Service. We do not knowingly collect more information than necessary from students, and we do not use student data for behavioural advertising.
12. International Data Transfers
Your information may be processed and stored on servers located outside your country of residence. By using the Service, you consent to such transfers in accordance with this Privacy Policy.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes — especially to how we use Google user data — we will notify users through the app and update the "Last updated" date above. We encourage you to review this page periodically.
14. Payment Information
Stublish offers subscription plans billed through Stripe, our third-party payment processor. The following details explain how we handle payment information:
- Payment processor: All payments are processed securely by Stripe. We do not collect, store, or transmit your full card number, CVC, or other sensitive cardholder data on our servers. Stripe is PCI-DSS compliant and handles payment data in accordance with industry security standards.
- What we retain: We store your subscription plan, billing cycle (monthly, quarterly, 6-month, or yearly), billing status, invoices, and payment history. This information is used to manage your account and provide billing support.
- Subscription billing: Your subscription automatically renews at the end of each billing cycle unless cancelled. You can manage, upgrade, downgrade, or cancel your subscription at any time from the Billing page within the app or via the Stripe customer portal.
- AI credit top-ups: One-off purchases of additional AI credits are also processed through Stripe. These purchases are non-refundable once the credits have been used, except where required by law.
- Promo codes: Promotional discount codes may be applied at checkout. Discounts apply for the number of months specified by the promotion before reverting to the standard price.
- Refunds: Refund requests are considered on a case-by-case basis. If you believe you have been charged in error, please contact us through the Contact Us page. Refunds, where applicable, are issued back to the original payment method via Stripe.
- Stripe's privacy policy: Stripe's handling of your payment data is governed by Stripe's own privacy policy and terms of service, available on the Stripe website.
15. Contact Us
If you have questions about this Privacy Policy or how your data is handled, please contact us through the Contact Us page linked in the app footer or submit a support ticket from within the Service.