Privacy Policy

Student Track keeps your academic life on your own device. There is no account to create, nothing is uploaded, and there is no way for us to read your data even if we wanted to.

Effective 4 August 2026 · App version 0.1.0

1. Who we are

Student Track is built and published by Xylora Studios, a studio based in the United Kingdom. You can reach us through the Support screen inside the app, or via https://student-track.xylorastudios.com.

Xylora Studios is the data controller for the small amount of information described below. Everything else stays with you.

2. What stays on your device

Subjects, teachers, coaching centres, timetables, holidays and cancellations, attendance records, tasks, exams, grades, study timer sessions, reminders, tuition and other costs, profiles, notes and preferences are stored in your device's own database. They are written locally and read locally.

We operate no server that receives this content. It is not backed up to us, it is not synchronised between your devices by us, and it is not visible to us in any form.

Uninstalling the app, or clearing site data in your browser for the web version, deletes that database. If the data matters to you, export a backup first.

3. What we never collect

No account, sign in, email address or phone number is required to use Student Track, including the paid tier.

There is no usage analytics, no behavioural tracking, no advertising identifier, no fingerprinting and no third party tracking library in the app.

We do not build a profile of you, and we do not sell, rent or share personal information, because we do not hold any.

4. Backup files

Exporting a backup writes a file into a location you choose. That file contains your own records in plain, readable form so that you can inspect it and other software can import it. It is not encrypted.

From the moment it leaves the app, the file is yours to look after. Anyone who can open the file can read what is in it, so store it somewhere you trust and be careful where you send it.

Importing a backup happens entirely on your device. Nothing is uploaded for processing.

5. Purchases

On the web, purchases are handled by Stripe. You are taken to a checkout page hosted by Stripe, you complete the purchase using whatever payment method you normally use, and Stripe tells our service only whether that purchase succeeded. We never see or store your payment details. Stripe processes your information under its own privacy policy as an independent controller.

On Android, purchases are handled by Google Play billing under Google's own terms and privacy policy. The same applies: we never see your payment details.

The only information our service records at the point of purchase is the reference identifier the payment provider gives us, which is what allows a licence key to be issued or reissued to you.

6. Licence keys

A paid purchase produces a licence key. The key is a short signed statement that says which tier was bought and, where relevant, when it runs until.

The app checks that signature with mathematics performed on your device, using a public key shipped inside the app. There is no call to a server, so the paid tier keeps working with no connection at all, permanently.

The key does not identify you, does not contain your name or email, and cannot be traced back to your records by us. If you lose it, we can reissue it from the payment reference.

7. Support and feedback

When you send a support request or feedback from inside the app, the message you typed is delivered to our private team channel, along with the app version, the platform you are on, and your tier, so that a report is actionable.

Nothing else is attached. Your records are never included. If you choose to type a name, an email address or details of your problem into the message, that is what we receive, and we use it only to reply to you and to fix the issue.

Support messages are kept only as long as they are useful, and are deleted once the matter is resolved.

8. Currency and exchange rates

Prices are set in pounds sterling and shown to you in your own currency. To do that, the website asks a public exchange rate service for current rates and reads the region your browser reports. No identifier of you is sent, and no record of the request is kept.

9. Permissions the app may ask for

Notifications, so that reminders and alarms can reach you. Refusing this only disables reminders.

Biometric unlock, so that a fingerprint or face check can protect the app. The check is performed by your operating system, and no biometric data is ever available to the app.

File access, so that you can save and open backup files in a location you choose.

10. Security on your device

If you set a PIN, it is stored only as a salted PBKDF2 SHA-256 hash with 100,000 iterations. The PIN itself is never written anywhere.

Because your records live on your device, the security of your device is the security of your data. A screen lock and full device encryption are strongly recommended.

11. Children and students

Student Track is a study tool used by school pupils as well as college, university and adult learners. Since we collect nothing, there is no personal data of a child for us to process, disclose or misuse.

Parents and guardians can review everything the app holds simply by opening the app or exporting a backup, and can delete all of it by uninstalling or clearing app data.

12. Your rights

Under UK GDPR you have rights of access, correction, deletion, portability and objection. For the records inside Student Track these rights are already in your hands: you can see, edit, export and delete everything directly, without asking us.

For the narrow items we do hold, being a payment reference and any support message you sent us, write to us and we will act on your request.

13. Changes to this policy

This policy may be updated as the app grows. The current version always lives at https://student-track.xylorastudios.com/privacy and is shown inside the app, with the effective date at the top.

If a change ever meaningfully affects how information is handled, it will be called out in the release notes rather than slipped in quietly.

14. Contact

Use the Support screen inside the app. Xylora Studios, https://xylorastudios.com.