Start with a simple threat model
A study tool can touch more than the question you deliberately submit. Depending on its design and permissions, it may be able to read page content, know which sites you visit, connect activity to an account, or send content to an external AI provider. The right question is not only “Is this tool safe?” but “What information could this tool access, what does it actually collect, and what would happen if that information were exposed?”
Use extra caution when the material contains student records, unpublished assessments, disability accommodations, private instructor comments, research data, workplace information, or another person's work. When the possible consequence is serious, use an institution-approved tool or ask an instructor or IT administrator before submitting anything.
Before installing a browser extension
Chrome explains that permissions let extensions use browser features or change website data. Read the permission list in the store before installing and treat broad access such as “read and change all your data on all websites” as a reason to investigate further—not as automatic proof of wrongdoing.
- Read the Chrome extension permission warnings.
- Ask whether each requested permission is necessary for the feature you want.
- Check whether the extension works only after a click, on selected sites, or on every site.
- Look for a current privacy policy, named support channel, company or developer identity, and deletion process.
- Review recent update notes and store reviews for unexpected changes in behavior.
Chrome also lets users change an extension's site access after installation. Its extension-management guidance explains how to allow access on click, on specific sites, or on all sites when the extension supports those controls. Prefer the narrowest access that still makes the feature work.
Before creating an account
Separate convenience from necessity. If a tool asks for a full profile, school email, phone number, date of birth, or learning-platform login, ask why each field is required. Use a unique password and enable multi-factor authentication when offered. Do not reuse your school password on a third-party study service.
A school-provided product and a direct-to-consumer app may operate under different contracts, policies, and oversight. The U.S. Department of Education's Student Privacy Policy Office guidance provides resources for students, families, educators, and institutions, but the rules applying to a specific service depend on context. This checklist is practical product guidance, not legal advice.
Before submitting a question or document
Apply data minimization: send only the information needed to get useful help.
- Remove names, email addresses, student IDs, grades, class sections, access codes, and private instructor feedback.
- Replace real people, organizations, and case details with neutral placeholders when they are irrelevant to the question.
- Do not upload restricted exam content, answer keys, clinical information, unpublished research, or another person's work.
- Check whether submitted content is stored, how long it is retained, who receives it, and whether it may be used for model training or product improvement.
- Confirm whether you can delete individual submissions as well as the entire account.
For a text-only question, paste the smallest self-contained excerpt rather than a full worksheet or course page. If the problem depends on a diagram or confidential context, an instructor, tutor, or approved institutional service may be the safer route.
Ask six questions about the privacy policy
| Question | What a useful disclosure should tell you |
|---|---|
| What is collected? | Account fields, submitted content, page data, device data, cookies, diagnostics, and payment metadata |
| Why is it collected? | The specific service, security, analytics, support, personalization, or model-improvement purpose |
| Who receives it? | AI providers, hosting services, analytics vendors, payment processors, schools, or other third parties |
| How long is it kept? | A clear retention period or a meaningful rule for deciding it |
| What control do I have? | Access, correction, export, submission deletion, account deletion, and marketing choices |
| What changes for minors? | Age limits, parental or school authorization, and any restricted features or collection |
Vague statements such as “we may use information to improve services” deserve a closer look when they do not identify the information, purpose, retention period, or recipients. UNESCO's guidance for generative AI in education and research emphasizes a human-centered approach, data privacy, and age-appropriate use—useful principles when evaluating a product even where the document is not a binding rule.
Before paying
Privacy and billing overlap because a purchase can connect identity, account activity, and payment metadata.
- Verify the merchant name, total price, currency, renewal date, and whether a trial converts automatically.
- Read cancellation and refund terms before checkout.
- Prefer a recognized payment processor and avoid sending card details through email or chat.
- Save the receipt, plan terms, and cancellation confirmation.
- After canceling, confirm whether the account and study history remain stored separately.
Before deleting the tool
Removing an extension from Chrome does not necessarily delete a server-side account or earlier submissions. First export anything you need, then use the service's deletion process, revoke connected-account access, and remove the extension. Check for a confirmation email or status page rather than assuming deletion happened immediately.
If deletion instructions are missing or do not work, contact the published support channel and keep a copy of the request. Review your browser's remaining extension list and site permissions afterward.
A 60-second student privacy check
Before using a new AI study tool, stop if you cannot answer all five questions:
- What can it access?
- What am I about to share?
- Where will that information go?
- How can I delete it?
- Is this tool permitted for this course and this device?
This short check will not eliminate every risk, but it prevents the most avoidable oversharing. Pair it with the AI answer verification guide because privacy and reliability are separate questions: a private response can still be wrong, and an accurate response can still require too much data.
ExamNinja's web-tool boundary
The free web tools are designed to avoid persisting raw submitted question text and raw IP addresses. Operational records are limited to request status, tool type, a content hash, provider usage, and latency. Production behavior and vendors must match the published disclosure, so review the current ExamNinja privacy policy for the applicable details.
You can start with the text-only answer checker or compare products using our AI study tool evaluation framework. Read the editorial policy and research methodology to see how ExamNinja separates verified facts, product claims, and limitations.
Sources and further reading
- Google Chrome Web Store Help: Permissions requested by apps and extensions
- Google Chrome Web Store Help: Install and manage extensions
- U.S. Department of Education: Student Privacy Policy Office guidance
- UNESCO: Guidance for generative AI in education and research
- ExamNinja privacy policy
Study with the explanation, not just the answer
Try a free ExamNinja study tool, then verify important work against your course material.
Explore free tools