Study Stash

Privacy policy

Everything stays on your own computers.

Study Stash is an app you run yourself, not a service. There's no Study Stash account, no Study Stash server and no analytics. This page says exactly what the app reads, where it keeps it, and how to take it back.

Last updated 28 September 2026

In short

  • Your recordings, transcripts, notes and everything else Study Stash makes are kept on your own computers: your laptop, and your library's computer if you use one. Nothing is sent to the people who make Study Stash, and we have no way to see it.
  • The audio never leaves the computer that recorded it. Whisper transcribes it on that computer.
  • No analytics, tracking, advertising or crash reporting. The app has no code that reports on you, and this website has no cookies, trackers or third-party scripts.
  • Calendars and Canvas are read-only and reached with your own sign-in. What Study Stash reads goes only to your own library, and you can revoke it at any time.
  • The AI that writes your notes is the one you choose. With Ollama, nothing leaves your computer. With Claude Code, Codex or Gemini, your transcripts go to that company under your own account.

Study Stash is free, open-source software under the MIT licence. Everything on this page can be checked in its source code.

What stays on your computers

Study Stash keeps its data in one folder, ~/.study-stash in your home folder (on Windows, C:\Users\<you>\.study-stash), unless you choose another place. In it are:

  • your recordings and their transcripts;
  • your study notes, as plain Markdown files in a folder per class, and the lecture database;
  • your classes, settings, and the questions you've asked and their answers;
  • what Study Stash has copied from Canvas and your calendars (below);
  • the sign-ins it needs: your library's password, and the tokens that let it read your calendars. Files holding secrets are written so only your own user account can read them.

Between your own computers. With a laptop and a library, the laptop sends each lecture to the library, and the library sends back notes, over your home network or over Tailscale, a private network you set up with your own Tailscale account. The library is protected by its password. A phone you pair (see the phone guide) reaches the library over Tailscale's HTTPS and is let in by a pairing code you make in Settings; you can remove a phone at any time. Tailscale is a separate service with its own privacy policy; it sees which of your devices are connected, not what they send each other.

Deleting it. Delete a lecture, a class or a phone in the app, or delete the .study-stash folder to remove everything. Uninstalling the app leaves the folder in place, so your notes aren't lost by accident.

Calendars (Google, Microsoft, Apple and calendar links)

If you connect a calendar, Study Stash uses it to show your upcoming classes and events, and to work out which class a recording belongs to and what to call it. Connecting one is optional, and everything else works without it.

What it reads

Study Stash asks only for read-only access. It can't create, change or delete anything in your calendars.

Google CalendarRead-only access to your calendars and their events (Google's read-only calendar permission), and your account's email address so Settings can show which account is connected.
Microsoft (Outlook, Microsoft 365)Read-only access to your calendars (Calendars.Read), your basic profile's name and email address (User.Read) to show which account is connected, and offline_access so it can keep reading without asking you to sign in each time.
Apple Calendar, calendar linksOn a Mac, the calendars macOS lets it read once you allow it; or a calendar link (.ics) you paste in.

From those, Study Stash reads your list of calendars (their names and colours) and the events in the calendars you choose: each event's title, start and end, whether it's all day, its location, its attendees, its link and whether it's cancelled. It reads events from around now to a few days ahead, not your whole history.

What it does with it

  • Shows your upcoming classes and events in the app, on your library's pages and in your phone app.
  • Matches an event to one of your classes, so a lecture recorded at that time is filed under the right class and named after it, and (only if you turn it on) so Study Stash can start recording when a class begins.

Where it goes

  • Calendars are read by the laptop that records. It keeps what it read on that computer and sends the next seven days of events (title, times, location, and the class it matched) to your own library, which, with one computer, is the same computer.
  • Your calendar data is never sent to the developers of Study Stash or to anyone else. It isn't sold, used for advertising, or used to train AI models. Study Stash doesn't give it to the AI engine that writes your notes; only the name of the class it matched is used.
  • The sign-in tokens for Google and Microsoft are stored on your laptop, readable only by your user account, and are sent only to Google or Microsoft.

Taking it back

  • In Study Stash, remove the account from Settings. It deletes the account's token and the events it copied from that computer.
  • You can also revoke access from your account at any time: for Google at myaccount.google.com/connections; for a Microsoft personal account at account.live.com/consent/Manage, and for a work or school account at myapps.microsoft.com. Once access is revoked, Study Stash can't read anything more.

Google API data: Limited Use

Study Stash's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, data Study Stash receives from Google Calendar is:

  • used only to provide the features described above, which you can see in the app;
  • transferred only to your own Study Stash library (a computer you control), and only to provide those features; never to the developers of Study Stash or any other third party, except as needed to comply with the law;
  • never used or transferred for advertising, including retargeting or personalised or interest-based advertising;
  • never used to train or improve AI or machine learning models, general or otherwise;
  • never sold, and never used to determine creditworthiness or for lending;
  • never read by a person. The developers have no access to it at all: it exists only on your computers.

The same promises apply to what Study Stash reads from Microsoft.

Canvas

Study Stash copies your Canvas courses (what's due, assignments and rubrics, your submissions and feedback, modules, files, pages, announcements, quizzes and discussions) into your library, so they sit next to your lectures. It does this through the Study Stash for Canvas Chrome extension, using your own Canvas sign-in in Chrome. Study Stash never sees your Canvas password, and the extension never reads your cookies: Chrome sends them to Canvas as it would for any page you open.

  • It only reads. Nothing on Canvas is changed or submitted.
  • What it reads goes only to your own library, on a computer you control. Not to the developers, not to anyone else.
  • The extension can reach only your school's Canvas, Canvas's file storage and your library: the sites you give it.
  • To stop, remove the extension from Chrome. To delete what was copied, delete the class's Canvas folder in your library.

AI engines

Study Stash writes notes and answers questions with an AI engine you choose in Settings, running on your library's computer:

  • Ollama runs entirely on your computer. Nothing leaves it.
  • Claude Code, Codex or Gemini are programs from Anthropic, OpenAI and Google that you install and sign in to with your own account and plan. When you choose one, Study Stash gives it the lecture's transcript (or the notes and passages a question needs) and the company's service writes the answer. That company handles it under its terms and privacy policy, with your account. Study Stash's developers never see it.
  • Claude and other MCP apps can read your library only if you set that up in Settings → AI tool access, and only read. Internet access for claude.ai is off unless you turn it on, and it's protected by signing in with your library password.

Without an engine, lectures are still transcribed and filed.

What the app contacts

Apart from your own computers and the services you connect (your calendars, Canvas, and the AI engine you choose), Study Stash contacts:

  • GitHub, to check for and download updates from Study Stash's own releases. Each download is checked against the release's checksums. You can turn automatic updates off.
  • Hugging Face, once, to download the Whisper transcription model, and ollama.com if you ask it to install Ollama or a model.
  • jsDelivr, a public CDN, when your library's web pages show formulas: your browser loads the KaTeX maths typesetter from it.
  • Cloudflare's public DNS, only when you check whether claude.ai can reach your library, to look your library's address up the way the internet would.

None of these requests include your notes, recordings, calendar or Canvas data, and none identify you beyond what any web request does (your IP address).

This website

This site is static pages hosted by Firebase Hosting. It sets no cookies, runs no analytics and loads nothing from other sites. Google, as the host, may keep standard server logs (such as IP addresses) under the Google Privacy Policy. Download links go to GitHub.

Your choices

Because your data is on your own computers, you're in control of all of it: you can open, copy, export (every lecture's notes download as Markdown) or delete it at any time, without asking anyone. We hold no data about you, so there's nothing for us to hand over, correct or delete. Revoking calendar or Canvas access is described above.

Study Stash is made for students and isn't directed at children under 13.

Changes

If this policy changes, the new version is posted here with a new date, and every earlier version stays in the site's history on GitHub. If Study Stash ever needs to read something new, it will ask you first.

Contact

Questions about privacy: open an issue on GitHub. To report a security problem privately, use the repository's Report a vulnerability form. See Support for more.