Privacy Policy
Last Updated: 24 April 2026
1. Introduction
Foci AI Study Platform ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our AI-powered study platform at fociai.co.uk.
We are the data controller for the personal data we process. Our contact details are provided at the end of this policy.
2. Information We Collect
2.1 Personal Information
- Account Information: Email address, display name, password (encrypted)
- Profile Information: Bio, avatar, study preferences, subscription tier
- Contact Information: Phone number (if provided for verification)
- Payment Information: Processed securely through Stripe (we don't store card details)
2.2 Study Content
- Uploaded Documents: PDFs, Word documents, PowerPoint presentations
- Google Drive Files: Google Docs and Slides (with your explicit consent)
- Generated Content: AI-created notes, flashcards, quizzes, summaries
- Study Sessions: Progress data, quiz results, study analytics
2.3 Technical Information
- Usage Data: How you interact with our platform, features used, time spent
- Device Information: Browser type, operating system, IP address
- Cookies: Essential cookies for functionality and analytics
3. How We Use Your Information
3.1 Legal Basis (GDPR Article 6)
- Contract Performance: Providing our study platform services
- Legitimate Interest: Improving our services, analytics, security
- Consent: Google Drive integration, marketing communications
- Legal Obligation: Compliance with UK data protection laws
3.2 Purposes
- Deliver AI-powered study tools and features
- Process and analyze your study materials
- Generate personalized learning content
- Provide customer support and account management
- Process payments and manage subscriptions
- Improve our platform and develop new features
- Ensure platform security and prevent fraud
- Comply with legal obligations
4. Data Sharing and Third Parties
4.1 Service Providers
- OpenAI: AI processing for content generation
- Google: Drive integration (with your consent)
- Stripe: Payment processing
- Firebase/Google Cloud: Data storage and hosting
- AssemblyAI: Voice transcription services
4.2 Data Protection
All third-party providers are bound by strict data protection agreements and only process your data as necessary to provide their services.
5. Data Security
- Encryption: All data encrypted in transit and at rest
- Access Controls: Strict access controls and authentication
- Regular Audits: Security assessments and monitoring
- Data Minimization: We only collect data necessary for our services
6. Your Rights (GDPR)
6.1 Your Data Protection Rights
- Right of Access: Request copies of your personal data
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
6.2 How to Exercise Your Rights
Contact us at raihanpetkar123@gmail.com to exercise any of these rights. We will respond within 30 days.
7. Data Retention
- Account Data: Retained while your account is active
- Study Content: Retained until you delete it or close your account
- Usage Analytics: Anonymized after 2 years
- Payment Records: Retained for 7 years (legal requirement)
8. International Data Transfers
Some of our service providers may be located outside the UK/EEA. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions by the UK government
- Other appropriate safeguards
9. Children's Privacy
Our service is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe we have collected data from a child under 13, please contact us immediately.
10. Cookies
We use essential cookies for platform functionality and optional analytics cookies. You can manage cookie preferences in your browser settings.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes via email or platform notification.
12. Contact Information
13. Complaints
If you have concerns about how we handle your personal data, you can:
- Contact us directly at raihanpetkar123@gmail.com
- Lodge a complaint with the Information Commissioner's Office (ICO)
- Visit: ico.org.uk/make-a-complaint