SStudyFlow

SECURITY · EDUCATIONAL APPLICATION

Conventional, privacy-conscious web security.

StudyFlow is delivered over HTTPS using modern browser protections and a small first-party application footprint.

Transport and browser protections

HTTPS is enforced. The site uses modern TLS, HSTS, Content Security Policy, clickjacking protection, MIME-type sniffing protection, a restrictive Permissions Policy and a referrer policy.

Data architecture

The current planner has no user accounts, backend database, uploads or authenticated API. Study planning data is stored locally in the browser. The offline cache is limited to the public application shell, not planner data.

Safe product boundaries

StudyFlow does not offer a proxy, VPN, tunnel, remote browser, arbitrary URL fetcher, anonymous relay, public chat or public file-sharing functionality. It makes no behavioural changes for school filters.

Reporting a security issue

See the contact page for the current reporting route. Please do not include personal academic data in a report. The coordinated-disclosure information is published at security.txt.

Return to StudyFlow