Privacy
Privacy Policy
How Studevia handles student documents, profile data, messages, interview preparation, and AI-assisted processing.
Updated July 19, 2026 · Version 1.1
Privacy at a glance
This summary is a reading aid. The complete policy below remains the authoritative notice.
What Studevia uses your data for
To secure your account, organize your study-visa preparation, review the documents you choose to upload, provide assistant support, and run interview practice. Studevia does not sell your personal data or use it to train AI models.
Who can see it
You can see your workspace. An assigned assistant receives only the access needed for your support. Restricted administrators and approved service providers access data only when needed for support, security, or delivery. Studevia does not send your file to an embassy or school for you.
What the interview AI receives
Only minimized text needed for the practice interview, such as your destination, study-plan context, broad funding category, and answers. Passport images, bank statements, account numbers, names, email addresses, and Studevia user identifiers are not intentionally sent to the interview provider.
Your choices and rights
After signing in, the Privacy dashboard lets you review consent choices, request a data export, and request account deletion. Some transaction, consent, security, or audit records may have to be retained for a limited lawful purpose.
On this page
1. Who is responsible and how to contact us
The legal person operating Studevia determines why and how personal data is processed and acts as the data controller. Its registered legal name, address, registration details, privacy email, and Data Protection Officer details, if applicable, must be published here before Studevia is opened to the public.
Until a dedicated privacy address is published, privacy questions and rights requests can be submitted through the Studevia contact page. We may ask for reasonable account verification before acting on a request.
This policy applies to the Studevia website, student and assistant workspaces, account services, document review, communications, payments, and AI interview preparation.
2. Data we collect
Account details such as name, email, phone number, role, language, acceptance records, login security information, MFA status, sessions, device/IP security signals, and account-lifecycle requests.
Student profile information such as nationality, destination country, study goals, academic background, study gaps, and previous visa refusal details.
Documents uploaded for review, including passports, transcripts, admission letters, financial proof, accommodation proof, insurance, CVs, and related visa files.
Messages, assistant notes, interview answers and feedback, checklist progress, school and application information, subscriptions, payment references, and support activity.
Security and audit records such as authentication events, MFA recovery use, administrator actions, sensitive-document access, suspicious activity, and technical error metadata. Payment-card data is handled by the payment provider and should not be stored by Studevia.
3. Purposes and legal bases
Contract and requested pre-contract steps: create and secure the account, provide purchased or requested preparation services, manage documents, assistant support, messages, checklists, interviews, subscriptions, and payments.
Legitimate interests: protect students and the platform, prevent fraud and abuse, investigate incidents, maintain audit trails, improve reliability, and defend legal claims. We balance those interests against user rights and expectations.
Legal obligations: retain records or respond to competent authorities where accounting, tax, consumer, security, or other applicable law requires it.
Consent, where required: optional data sharing, future non-essential cookies, or another clearly described optional use. Consent can be withdrawn without affecting earlier lawful processing.
Studevia does not sell student personal data and does not use passports, bank documents, diplomas, interview answers, or messages to train Studevia or third-party AI models.
4. Who can receive or access data
The student can access their own workspace. An assigned assistant receives only the access needed for the included support workflow. Authorized administrators may access data for support, security, assignment, legal, or incident-response needs.
Service providers may process limited data on Studevia instructions: hosting and database providers, private object storage/CDN, email delivery, payment processing, bot protection, AI inference, monitoring, backup, and security providers.
Data may also be disclosed when required by applicable law, a valid order, or to establish, exercise, or defend legal claims. Studevia does not disclose a student file to an embassy or school merely because it is stored on Studevia.
Assistant access is assignment- and purpose-limited, logged, and removed when no longer required. Assistants must not copy passport numbers, bank details, or documents into personal devices, external messaging services, or unrelated notes.
5. AI interview processing
AI is used to generate practice questions, evaluate answers, identify missing explanations or inconsistencies, and prepare readiness feedback. It supports preparation; it does not make a visa, admission, eligibility, or other legally significant decision.
The interview provider receives minimized text context such as destination, study plan, academic coherence, coarse sponsor/funding categories, and the student answer. Studevia does not send passport files, bank statements, account numbers, document images, names, email addresses, or student identifiers through the interview feature.
Before an external AI request, Studevia removes or masks common contact, passport, banking, account-number, and secret patterns. Direct prompt-injection and tool-use instructions may be rejected. The interview model has no Studevia tools, document-store access, messaging authority, or ability to submit an application.
Interview responses may be inaccurate. Scores measure practice readiness, not approval probability. Users should verify important requirements with the competent embassy, consulate, school, or official government source.
When an external provider is enabled, Studevia requires approved retention/training controls and contractual review. Processing may involve providers outside the user country; the applicable transfer safeguard and provider list must be published before production activation.
6. International transfers
Some infrastructure, email, security, payment, storage, or AI providers may process data outside the European Economic Area. Before production, Studevia will identify those providers and locations and use an applicable transfer mechanism, such as an adequacy decision or contractual safeguards, where required.
Users may request information about the safeguards applicable to their data through the privacy contact route.
7. Security
Studevia uses access controls, resource-ownership checks, MFA for staff, encrypted transport, protected authentication cookies, CSRF protection, rate limiting, audit logging, restricted storage links, encrypted TOTP secrets, session revocation, and security monitoring.
No system can promise absolute security. Users should protect their credentials, enable available MFA, report suspicious access promptly, and avoid sending sensitive documents through ordinary email or external chat.
Security logs are protected from ordinary assistant access and may be preserved when reasonably necessary to investigate abuse, account compromise, unauthorized document access, or fraud.
8. Retention, deletion, and backups
AI interview sessions, answers, AI feedback, assistant interview reviews, and related review-access records are scheduled for deletion after 90 days by default. Studevia may configure a shorter period, but the production setting cannot exceed 365 days.
Documents, profile data, and messages are kept while needed for the active account and support workflow, then deleted or anonymized according to the production retention schedule. Users may delete eligible documents and request account deletion through the available account process.
Payment, accounting, fraud-prevention, consent, security, and audit records may be retained longer when required by law or reasonably necessary to demonstrate transactions, protect accounts, investigate incidents, or defend claims. Access remains restricted and the data is not reused for interview training.
Deletion from active systems may not immediately remove encrypted backup copies. Backups remain access-restricted and expire through the backup rotation schedule rather than being restored for ordinary use.
A deletion request may be delayed or limited when data must be retained by law, for unresolved payments or disputes, or for documented security and fraud investigations. Studevia will explain an applicable limitation when legally permitted.
9. Your privacy rights
Depending on applicable law, users may request access, correction, deletion, restriction, portability, or object to certain processing. Where processing relies on consent, consent may be withdrawn.
Studevia does not make solely automated decisions that grant or refuse a visa, admission, subscription, or legal right. Users may challenge AI feedback and request human assistance when included in their service.
Requests will be handled after appropriate identity verification and within the period required by applicable law. Users may also complain to the data-protection authority responsible for their place of residence, work, or the alleged infringement.
10. Children and policy changes
Studevia is intended for users legally able to create an account and purchase or receive the service. A separate verified parental or guardian process is required before knowingly serving younger users where applicable law requires it.
Material changes to data uses, AI processing, recipients, or retention will be dated and communicated appropriately. Where a new use requires consent, it will not begin before that consent is obtained.
11. Cookies and browser storage
Studevia uses strictly necessary secure cookies for authentication and refresh sessions. Authentication tokens are not exposed to browser scripts. A separate readable anti-CSRF cookie allows the application to protect state-changing requests. Local browser storage may retain the selected language, application update recovery state, and a private dashboard quick note on the user device.
Security and payment providers, such as Cloudflare Turnstile and the checkout provider, may use strictly necessary cookies or similar technologies to prevent abuse, verify requests, and complete a payment securely.
Studevia does not currently activate advertising cookies, behavioral profiling, retargeting pixels, or non-essential audience analytics. If these tools are introduced later, they will remain disabled until the visitor has received clear information and made an applicable consent choice.
Session cookies expire according to their configured lifetime and are cleared by the server on logout. Refresh sessions can also be revoked after password, account, or security changes. Saved device preferences remain until the user changes them or clears browser data.