Privacy Policy
- Home
- Privacy Policy
Version 2.0 | Effective date: [February 25th, 2026]
Chapter 1 – Introduction and Purpose
This privacy policy (“Policy”) aims to clearly, completely, and accessibly inform the users of the eStudent AI mobile application (“Application”) regarding the processing of personal data, in accordance with Regulation (EU) 2016/679 on data protection (GDPR), Law no. 190/2018, and other applicable regulations.
This Policy reflects the commitment of 8BYTES DIGITAL VENTURES SRL, as data controller, to respect the principles of legality, fairness, transparency, and accountability in the processing of personal data.
The eStudent AI Application is a digital educational tool that provides academic assistance services through AI, document upload and organization, content generation, and administrative functionalities. For optimal operation, the platform collects and processes various types of personal data, detailed in the following sections.
This Policy applies to:
- all individual Users who use the application for personal, educational purposes;
- users who access the application through an account provided by a partner educational institution;
- institutions and contractual partners that interact with the Application as joint controllers, within the limits of the legal relationship established with 8BYTES DIGITAL VENTURES SRL.
If you do not agree with this Policy, please do not use the Application. The legal bases for data processing are those expressly indicated in Chapter 3 of this Policy. The mere use of the Application does not, in itself, constitute valid consent within the meaning of Art. 6(1)(a) GDPR.
Chapter 2 – Data Collected
In order to provide the services available within the eStudent AI application and to ensure optimal operation, 8BYTES DIGITAL VENTURES SRL, as controller, collects and processes the following categories of personal data:
2.1 User identification data
These are necessary for account registration, interface personalization, and the issuance of tax documents:
- Last name and first name – used for identifying the user within the application;
- Email address – used for authentication, official communications, notifications, password reset, and sending invoices;
- Mobile phone number (optional) – used for registration and authentication, at the User’s preference;
- Postal address (optional) – requested in the case of invoice issuance, in accordance with tax requirements;
- CNP / CUI (optional) – processed exclusively for tax purposes, in the case of invoice requests by natural or legal persons.
2.2 Authentication and security data
- Account password – stored in encrypted format, through Firebase Authentication, without direct access by eStudent;
- Session tokens and unique identifiers – used for active session management, fraud prevention, and access security.
2.3 Technical device data
These are collected automatically, for diagnostics, security, and optimization:
- device type and operating system;
- installed application version;
- unique device identifiers;
- network and connection information (e.g., IP, country, language).
2.4 Usage and error data
- Error logs – collected through Firebase Crashlytics, for the identification and remediation of technical errors;
- Anonymized usage statistics – used for performance analysis and improvement of application functionalities.
2.5 Data actively uploaded by the user
- Files and documents – any files voluntarily uploaded to the application by the user (e.g., notes, PDF documents, .docx, .pptx, etc.);
- Chat messages and AI interactions – saved to allow subsequent review and algorithm improvement;
- Notes (“iNotes”) and personalized labels – stored for the exclusive use of the user and organization of their content.
2.6 Financial and billing data
- Payment information – processed through Stripe (for direct payments within the app on Android and web) and through Apple App Store (for In-App Purchases on iOS), managed in accordance with applicable security standards (PCI DSS and Apple’s policies, respectively); eStudent does not store or access bank card data;
- Billing data – stored in Enlivy, in encrypted format, for the purpose of invoice issuance and reporting to ANAF SPV (Tax Authority’s Virtual Private Space), where applicable.
- Bank account IBAN (optional) – used strictly in the context of transferring income earned through the referral mechanism, whereby users are remunerated for paying customers brought through their own referral link.
2.7 Other data associated with the profile
- Academic and behavioral profiles – generated based on application usage, for personalizing the displayed content;
- Labels and thematic structures created by the user – internally associated with the profile.
2.8 Data concerning minor users
The eStudent AI Application may also be addressed to pupils and students under the age of 18. In accordance with Art. 8 GDPR in conjunction with Law no. 190/2018, in the case of users under the age of 16, the processing of personal data based on consent is lawful only if and to the extent that consent is given or authorized by the holder of parental responsibility. The Operator implements reasonable technical and organizational measures to verify the age of users and, where necessary, to obtain parental consent. Users aged between 16 and 18 may use the Application directly, under the conditions of this Policy. The Operator does not deliberately collect personal data from persons under 14 without verifiable parental consent.
Chapter 3 – Purpose of Data Processing and Legal Bases
The data collected through the eStudent Application is processed exclusively for legitimate, proportionate purposes necessary for the provision of the services offered. Each processing operation is based on at least one of the legal bases provided for in Art. 6 of Regulation (EU) 2016/679 (“GDPR”), depending on the nature of the relationship with the user and the operational context.
3.1 Main purposes of processing
a) Provision of Application services
- Creation and management of the user account;
- Access to application functionalities (iNotes, file upload, AI analysis, etc.);
- Processing of requests and interactions within the application.
Legal basis: Art. 6(1)(b) GDPR – performance of a contract to which the data subject is a party.
b) Ensuring account and infrastructure security
- Secure authentication;
- Prevention of unauthorized access;
- Protection against fraud and abuse attempts.
Legal basis: Art. 6(1)(f) GDPR – the legitimate interest of the controller to ensure system security.
c) Invoice issuance and compliance with legal obligations
- Collection of tax data (CNP, CUI, address);
- Automatic invoice generation through Enlivy;
- Reporting to ANAF through SPV, where applicable.
Legal basis: Art. 6(1)(c) GDPR – compliance with a legal obligation.
d) Assistance and technical support
- Management of requests submitted by users;
- Provision of prompt solutions through official contact channels;
- Diagnosis of technical problems based on error logs.
Legal basis: Art. 6(1)(b) and (f) GDPR – contract performance / legitimate interest.
e) Internal analysis and Application improvement
- Analysis of application usage patterns;
- Optimization of performance, design, and functionalities;
- Internal reporting and testing of new versions.
Legal basis: Art. 6(1)(f) GDPR – the legitimate interest of the controller to improve the product.
f) Personalization of the user experience (profiling)
- Adaptation of the interface, suggestions, and notifications based on usage history;
- Manual and/or automatic assignment of labels and thematic structure based on uploaded documents.
Legal basis: Art. 6(1)(a) GDPR – the explicit consent of the user.
Note: The profiling carried out within the Application does not produce legal effects and does not significantly affect the rights of users. You have the right at any time to object to this form of processing.
Chapter 4 – User Consent
In certain situations, the Operator processes the personal data of users on the basis of freely given, specific, informed, and unambiguous consent, in accordance with Art. 6(1)(a) GDPR.
Consent is explicitly requested when processing cannot be based on the performance of a contract, legal obligations, or the legitimate interest of the controller. Examples of such situations include:
- use of data for advanced profiling (adaptation of notifications, display of content based on behavior);
- activation of certain optional application functionalities that require access to additional data (e.g., integration with institutional accounts, generation of reports for educational institutions);
- initiation of individualized feedback campaigns or communications beyond those strictly necessary.
4.1 Manner of expressing consent
Consent is collected:
- by checking a dedicated checkbox at the time of account creation;
- through clear and affirmative actions (e.g., continuing to use a functionality after express notification);
- through explicit agreement, expressed in the context of a specific request (e.g., activation of an external integration or submission of qualified feedback).
eStudent will not pre-fill acceptance checkboxes and will not condition access to basic services on the provision of consent for processing that is not strictly necessary.
4.2 Right to withdraw consent
The User has the right to withdraw their consent at any time, without affecting the lawfulness of processing carried out prior to the withdrawal. Withdrawal may be carried out by:
- accessing the privacy section in the application (if available);
- sending a written request to [email protected].
The Operator undertakes to resolve withdrawal requests without undue delay and, in any event, within a maximum of 5 business days of receiving the request, in accordance with the principle of effectiveness of the exercise of rights provided for by GDPR.
4.3 Effects of consent withdrawal
Depending on the type of processing concerned, the withdrawal of consent may lead to:
- deactivation of certain application functionalities that were based on profiling or access to additional data;
- deletion of certain data that can no longer be retained in the absence of an alternative legal basis;
- inability to use advanced options, without affecting basic functionalities.
Users are informed of these consequences before withdrawal, and the Operator will make every effort to maintain the essential functionality of the application.
Chapter 5 – User Rights
As a data subject within the meaning of Regulation (EU) 2016/679 (GDPR), each user of the eStudent application benefits from a series of rights regarding their personal data. 8BYTES DIGITAL VENTURES SRL respects these rights and makes accessible channels available to users for their exercise.
A request regarding the exercise of any right may be sent to the email address [email protected]. 8BYTES DIGITAL VENTURES SRL undertakes to respond to the request within a maximum of 30 calendar days of receipt, pursuant to Art. 12(3) GDPR.
Depending on the complexity of the request, this period may be extended once, by a maximum of 30 additional days, with prior notification to the user.
5.1 Right of access (Art. 15 GDPR)
Users have the right to obtain confirmation as to whether or not their personal data is being processed and, if so, to request:
- access to the data in question;
- a copy of the processed data;
- information about the purposes of processing, the categories of data, the recipients, the storage duration, and the source of the data (if not provided directly by the user).
This right may be limited in situations expressly provided by law (e.g., protection of the rights of other persons).
5.2 Right to rectification (Art. 16 GDPR)
Users may request the correction or completion of personal data that is inaccurate or incomplete, including by providing a supplementary statement.
Rectification shall be carried out without undue delay, and the user shall be notified in writing.
5.3 Right to erasure (“right to be forgotten,” Art. 17 GDPR)
Users may request the erasure of personal data in the following situations:
- the data is no longer necessary in relation to the purposes for which it was collected;
- the user withdraws their consent and there is no other legal basis;
- the data has been unlawfully processed;
- the data must be erased to comply with a legal obligation.
The exercise of this right is subject to the legal provisions regarding the retention of certain categories of data (e.g., accounting or tax data), in accordance with Chapter 5 of the Application’s Terms and Conditions.
5.4 Right to object (Art. 21 GDPR)
The User has the right to object, on grounds relating to their particular situation, to the processing of data when it is based on:
- the legitimate interest of the controller;
- the performance of a task carried out in the public interest;
- processing for profiling purposes.
In the case of a justified objection, the Controller shall no longer process the data in question, unless it demonstrates that it has compelling legitimate grounds that override the interests of the user.
5.5 Right to restriction of processing (Art. 18 GDPR)
Users may request the temporary restriction of data processing in the following situations:
- the accuracy of the data is contested – for the period of verification;
- the processing is unlawful, but the user opposes erasure and requests only restriction;
- the data is no longer needed, but is requested by the user for the establishment, exercise, or defense of legal claims in court;
- the user has objected to processing and is awaiting verification of whether the legitimate interests prevail.
During the restriction period, the data shall not be subject to any operations other than storage, except with the express consent of the user or for legal reasons.
5.6 Right to data portability (Art. 20 GDPR)
The User has the right:
- to receive their personal data in a structured, commonly used, and machine-readable format (e.g., .CSV, .JSON);
- to request the direct transmission of data to another controller, where technically feasible.
This right applies only to data provided by the user, which is processed automatically, on the basis of consent or the performance of a contract.
5.7 Right to lodge a complaint with the supervisory authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedies, each user has the right to lodge a complaint with the national supervisory authority for the processing of personal data, if they consider that the processing of their personal data infringes the provisions of the GDPR or of Law no. 190/2018. In Romania, the competent authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP), with its headquarters at Bd. G-ral Gheorghe Magheru no. 28–30, Sector 1, Bucharest, anspdcp.eu, email: [email protected], phone: +40.318.059.211.
Chapter 6 – Data Storage and Retention Period
The Operator uses modern technical infrastructures and specialized services to store and protect the personal data of users, in accordance with applicable regulations, in particular Regulation (EU) 2016/679 (GDPR) and tax legislation in Romania.
6.1 Retention principles
Data is retained only for the duration necessary to fulfill the purposes for which it was collected, in compliance with the following principles:
- minimization of the retention period;
- purpose limitation;
- ensuring deletion or anonymization of data after the expiration of the retention period;
- compliance with legal and contractual retention obligations.
In the event that data is used for multiple purposes, the longest retention period shall apply only if strictly necessary and justified.
6.2 Data retention periods
| Type of data | Retention period | Notes |
| Identification data (name, email, address, CNP/CUI) | For the duration of account existence + 30 days from deletion | For issuance of supporting documents, account recovery, internal audit |
| Authentication data (encrypted password, tokens) | For the active duration of the account | Immediate deletion upon account deactivation |
| Files uploaded by the user | For the active duration of the account | Immediate deletion at user’s request or account closure |
| Chat messages and notes | For the duration of the account or until express deletion request | Available only to the Operator and the user for personalizing the Application user experience |
| Billing data (in Stripe, Apple App Store, and Enlivy) | 10 years | In accordance with Accounting Law no. 82/1991 |
| Error logs and anonymous statistics | 12 months | Retained for application diagnostics and optimization |
| Tags and personalized profiles | For the active duration of the account | Part of the user’s structure |
6.3 Deletion procedure
After the expiration of the retention periods, data will be:
- permanently deleted from operational and backup databases;
- or, if immediate deletion is not possible (e.g., logs integrated into security systems), they will be irreversibly anonymized.
Data deletion is carried out through automated or manual procedures, documented and periodically audited. The user may at any time request information about the status of the deletion process by sending a request to [email protected].
Chapter 7 – Services and Third Parties Involved in Data Processing
In order to provide the services of the eStudent AI application efficiently, performantly, and safely, 8BYTES DIGITAL VENTURES SRL collaborates with several digital service providers, which act either as processors (pursuant to Art. 28 GDPR) or as joint controllers, depending on the contractual relationship and the type of data managed.
All service providers are rigorously selected and are contractually obligated to comply with GDPR requirements and to implement appropriate technical and organizational measures for the protection of personal data.
7.1 Infrastructure and authentication services
Firebase (provided by Google LLC)
The eStudent application uses Firebase infrastructure, which provides several essential components for application operation:
- Firebase Authentication – secure authentication and user account management;
- Firestore Database – real-time storage of data generated in the application (AI chat, profiles);
- Firebase File Storage – storage of files and documents uploaded by the user;
- Firebase Crashlytics – error monitoring and automated reporting for diagnostic purposes;
- Firebase Functions – running serverless backend functions.
Data is stored in certified data centers (ISO 27001, SOC 2) located in the European Union. Google acts as a processor.
7.2 Payment processors
7.2.1 Stripe Payments Europe Ltd.
Used for processing payments made by card directly in the application or on the web platform. Stripe manages:
- bank card data;
- transaction data;
- payment history.
Stripe is PCI DSS Level 1 certified, and card data is not accessible to eStudent AI. Stripe acts as a processor.
7.2.2 Apple Inc. (App Store / In-App Purchase)
Used for processing payments made through the In-App Purchase mechanism on iOS devices. Apple manages:
- payment data associated with the user’s Apple ID account;
- transaction data (including subscription confirmation, renewal, and cancellation);
- purchase history made through the App Store.
Apple processes payments in accordance with its own security and privacy standards, and eStudent AI does not have access to the user’s bank card data or other payment instruments. Apple acts as an independent controller with respect to its direct relationship with the user for payment processing, and as a data processor to the extent of transaction data transmitted to the Operator.
7.3 Invoice issuance
Enlivy SRL
Enlivy, as a technical partner, also manages the integrated automated invoicing system, which enables:
- generation of invoices in legal format;
- transmission of invoices to ANAF SPV, where applicable;
- retention of tax data in encrypted format.
Enlivy acts as a processor for the invoicing service. Invoices are issued in the name of the Operator.
7.4 Push notifications
OneSignal, Inc.
Used for sending push notifications to users (e.g., reminders, feature updates, security alerts).
OneSignal acts as a processor, and the data collected is minimal (device ID, operating system).
7.5 AI processing services (model API providers)
For the provision of AI-based educational assistance functionalities (e.g., personalized explanations, summarization, content generation, document and image analysis), eStudent AI may transmit certain data to specialized AI service providers, which generally act as processors of the Operator (within the meaning of Art. 28 GDPR), exclusively on the basis of the Operator’s instructions and within the limits necessary for the provision of services.
Providers used (as applicable):
- OpenAI (via OpenAI API)
- Google Cloud Vertex AI (via API and Vertex AI Search)
- Microsoft Azure (AI services hosted/operated in Azure)
7.5.1 Types of data transmitted to AI providers
Depending on the functionality accessed by the user, the following categories of data may be transmitted to AI providers, to the extent necessary for generating responses and carrying out analysis:
- Messages from user conversations (content entered in chat and requests submitted to AI), as well as generated responses;
- User learning memories (e.g., strengths, weaknesses, learning objectives, progress, recurring difficulties), for the purpose of personalizing explanations and the educational pathway;
- Learning preferences chosen by the user (e.g., preferred style of explanations, level of detail, language/tone), for adapting responses;
- Documents and photos uploaded by the user (e.g., PDF, .docx, .pptx, images), in whole or in part (relevant fragments), for functions such as summarization, information extraction, structuring, generation of study sheets, or explanations based on uploaded materials.
Note: The Operator seeks to minimize data transmitted (e.g., sending relevant fragments when possible) and to avoid the inclusion of data that is not necessary for the requested purpose.
7.5.2 Purposes of processing through AI providers
The data transmitted may be processed by AI providers exclusively for:
- generating educational responses and personalized explanations;
- analysis, structuring, summarization, and transformation of content from uploaded documents and images;
- personalization of the learning experience (adaptation to preferences and “learning memories”);
- prevention of abuses and ensuring security (e.g., detection of fraudulent/abusive activities), where necessary for the protection of the service.
7.5.3 Legal bases
Depending on the functionality and user settings, processing is carried out on the basis of:
- Art. 6(1)(b) GDPR – performance of the contract (provision of AI functions requested by the user within the Application);
- Art. 6(1)(a) GDPR – consent (where personalization/profiling or “learning memories” are activated as an optional functionality or require explicit agreement, in accordance with the Operator’s internal policies).
7.5.4 Provider regime and contractual guarantees
AI providers:
- process data only on the Operator’s instructions and do not have the right to use it for their own purposes;
- are subject to contractual obligations of confidentiality, security, and GDPR compliance (including, where applicable, rules regarding sub-processors);
- implement appropriate technical and organizational measures for data security (e.g., encryption in transit, access controls, logging, incident prevention measures).
7.5.5 Retention and use for model improvement
The Operator seeks to ensure that data transmitted to AI providers is retained by them only for the duration necessary for the provision of the service and in accordance with the applicable contractual settings/conditions.
To the extent that a provider offers options for limiting retention (e.g., reduced retention) and these are compatible with the operation of the Application, the Operator may use them.
Regarding the use of data for improvement of provider models:
- The Operator does not authorize the use of user data for the providers’ own purposes, beyond the provision of services to the Operator, within the applicable contractual limits.
7.6 Other entities
The Operator may collaborate, on a case-by-case basis, with other external providers or consultants (e.g., maintenance, IT support, external audit), who will have access to data only on the basis of a confidentiality agreement and within the limits strictly necessary for the fulfillment of delegated duties.
7.7 Guarantees and limitations
All contractual partners are obligated to:
- not process data for their own purposes;
- not transmit data to third parties without written authorization;
- implement security measures pursuant to Art. 32 GDPR;
- notify the controller in the event of a security incident.
8BYTES DIGITAL VENTURES SRL monitors compliance with these obligations and conducts internal audits on how data is managed by third parties.
Chapter 8 – Transfer of Data Outside the European Union
The Operator seeks, as a rule, to process and store data in the EU/EEA. Depending on the providers used and the technical configuration (e.g., service region), certain processing may involve transfers to states outside the EEA, in which case the safeguards provided for in Art. 45–46 GDPR apply, in accordance with the provisions of Regulation (EU) 2016/679 (GDPR).
Data is processed only by partners and providers that:
- carry out their activities in the EU/EEA;
- provide sufficient guarantees regarding data protection;
- are contractually obligated to comply with the requirements imposed by European legislation in the field.
8.1 Possibility of transfer in exceptional cases
In the event that, in the future, for the provision of certain technical services or for the integration of new functionalities, the transfer of certain data outside the European Union becomes necessary (e.g., to the United States), the Operator shall ensure:
- that the transfer is carried out only to countries for which the European Commission has issued an adequacy decision (Art. 45 GDPR); In the case of transfers to the USA, the Operator will prioritize the use of providers certified under the EU-U.S. Data Privacy Framework (DPF), approved by the European Commission’s Adequacy Decision of July 10, 2023 (C(2023) 4745). The main providers mentioned in Chapter 7 (Google/Firebase, Microsoft Azure, OpenAI) hold or may hold DPF certification, which ensures an adequate level of protection pursuant to Art. 45 GDPR. The Operator will periodically verify the maintenance of their certification;
- or, in the absence of such a decision, that appropriate safeguards will be established, pursuant to Art. 46 GDPR (e.g., standard contractual clauses approved by the European Commission, binding corporate rules – BCRs);
- and in all cases where these measures cannot be applied, the express consent of the user will be requested, after complete information (Art. 49(1)(a) GDPR).
Users will be informed in advance about any such transfer and will have the possibility to accept or refuse the transfer, without affecting access to the essential functionalities of the application.
Chapter 9 – Cookies and Similar Technologies
The eStudent AI Application is a native mobile application (available through the App Store or Google Play, as well as a web version), which means that it does not use cookies in the traditional sense applicable to websites, but uses equivalent technologies in the web version of the platform, in accordance with applicable legislation, including Directive 2002/58/EC (ePrivacy) and Law no. 506/2004.
9.1 Technologies that may be used
Within the application, the following equivalent technologies may be implemented:
- persistent authentication tokens – used for maintaining the active user session, without requiring repeated re-authentication;
- anonymous device identifiers – used for diagnostics and error reporting (e.g., Firebase Crashlytics);
- temporary local storage (cache) – to improve loading times and avoid repetitive downloads;
- push technologies – based on OneSignal, for sending relevant notifications.
All these mechanisms are used exclusively within the mobile application, do not allow tracking of activity outside the application, and are not accessible to other applications or external entities.
9.2 User rights
Since these technologies do not involve traditional cookies (which entail storage in the browser and cross-site tracking), express consent for their use is not required, pursuant to Art. 5(3) of the ePrivacy Directive, as transposed into national legislation.
However, the user may at any time:
- limit or block push notifications (through the operating system settings of the device);
- disable the application’s access to certain functions or data (e.g., access to storage or network), with possible consequences for application functionality;
- request additional information about how these technologies work.
eStudent does not use these mechanisms for behavioral advertising, remarketing, or commercial tracking.
Chapter 10 – Audit, Updates, and Policy Modifications
8BYTES DIGITAL VENTURES SRL reserves the right to periodically review and update this Privacy Policy, for the purpose of alignment with legislative changes, technological developments, and internal operational adjustments.
Updates will be made in the following situations, without limitation:
- changes to the technical infrastructure (e.g., introduction of new processors or providers);
- expansion of application functionalities;
- legislative changes or new applicable regulations;
- findings resulting from internal or external audits.
10.1 Audits and compliance checks
The Operator periodically conducts internal and external audits on the management of personal data, for the purpose of:
- verifying compliance with data protection procedures;
- identifying potential risks and improving the GDPR compliance system;
- documenting compliance with the obligations provided for in Art. 24–32 of the GDPR.
The audit may also be carried out by independent consultants, on the basis of a confidentiality agreement.
10.2 User notification
In the event that significant changes are made to the content of this policy, users will be visibly notified by:
- displaying a message in the application;
- sending an email, if available;
- requesting reconfirmation of consent, where applicable.
Continued use of the application after notification of the changes constitutes tacit acceptance of the new version. The version in force will always be available in the dedicated section of the application and on the official website.
Chapter 11 – Contact
For any questions, requests, or complaints regarding this Privacy Policy or in connection with the exercise of the rights provided for by GDPR, users may contact the eStudent team as follows:
Personal data controller:
8BYTES DIGITAL VENTURES SRL, as developer and administrator of the eStudent AI application.
Registered office / Correspondence address:
Trade Register No.: J2024000560137
Tax Identification Code (CUI): RO 49612762
Registered office: Constanța County, Constanța Municipality, Bd. Ferdinand no. 94, Bl. F19B, Sc. B, Et. Parter, Ap. 12
Email address: [email protected]
Data Protection Officer (DPO / RPD): attorney Emil Mihail Tatu
Dedicated email address: [email protected]
Requests will be analyzed promptly, and a response will be sent within a maximum of 30 calendar days from the date of registration of the request. For complex requests, the deadline may be extended pursuant to Art. 12(3) of the GDPR, with prior notification to the requester.
