Security Overview
A plain-language overview of the controls Studymancer uses to protect accounts and study material.
Last updated 25 July 2026.
Core controls
Studymancer uses private storage, owner checks, database row-level security, least-privilege grants, short-lived signed downloads, bounded queues, and server-only secrets.
Signed-in product routes revalidate the session server-side. Feature flags that move money, send email, or open external calendars stay fail-closed until deliberately enabled.
Payments
Purchases use Stripe-hosted Checkout. Stripe collects payment-method details; Studymancer keeps customer, subscription, purchase, and fulfilment identifiers rather than full card numbers.
Incidents
If a privacy breach has caused or is likely to cause serious harm, the privacy owner must assess and make the notifications required by the Privacy Act as soon as practicable.
To report a suspected security issue, use the Security Report page or email the privacy contact on the Privacy notice.
Privacy and contact
For the full privacy notice, see Privacy. Questions: pattora.nz@gmail.com.