Privacy Policy

Last updated:

EduAI is in open beta. The service is free, we do not take payments, and we collect no card or billing details. This policy describes what actually happens today — not what a future version might do.

1. Who we are

EduAI is an exam-preparation platform for Azerbaijani learners. We are the controller of the personal data described here. This policy explains what we collect, why, who else sees it, how long we keep it, and what you can make us do about it.

It is written to meet the Law of the Republic of Azerbaijan on Personal Data and the EU General Data Protection Regulation (GDPR), whichever gives you more protection. For anything in this policy, or to exercise any right in section 12, write to privacy@eduaz.org.

2. What we collect

  • Account details your name, email address, chosen language, and a hash of your password. Passwords are hashed with Argon2id and never stored or logged in a readable form. If you sign in with Google instead, we receive your Google account id, email, and name — never your Google password.
  • Learning activity the questions you answer, whether you got them right, how long each answer took, the confidence you report before answering, your diagnostic and readiness estimates, per-topic mastery, streaks, XP, flashcard reviews, and notes you write.
  • AI conversations what you type into the tutor and other AI features, and what the model replies. See section 5.
  • Exam outcomes you submit if you tell us how a real exam went, we store the score you claim and — where you attach one — a photograph of your score report. See section 7. This is sensitive and we treat it accordingly.
  • Security and sign-in records the IP address, approximate time, and device or browser description for each sign-in attempt; and, if you turn on two-factor authentication, an encrypted TOTP secret plus hashed recovery codes.
  • Technical data IP address and request timestamps, used for rate limiting and abuse prevention. When you register we send a Cloudflare Turnstile token for bot checking; Turnstile sees your IP and browser signals, and we see only its pass or fail verdict.
  • Diagnostics if the application errors, a stack trace and request context are sent to our error tracker with passwords, tokens, secrets, and API keys stripped out before transmission. Session recording is off.
  • Notification settings only if you turn on browser notifications: the push endpoint your browser issues, its encryption keys, your quiet hours, and a log of what we sent so we do not send it twice.
  • Profile picture only if you upload one. We keep the image, not the file name you gave it.

We do not collect payment or card details, because there is nothing to pay for. We do not buy personal data about you from anyone, and we do not track you across other websites.

3. What we use it for

  • Running the service signing you in, saving your work, and showing you your own history.
  • Estimating what you know your answers, your timing, and your stated confidence feed the models that produce your readiness estimate, your knowledge map, and what we ask you next. This is the core of the product.
  • Checking whether our estimates are true we compare readiness estimates we made in the past against outcomes we later observe, so we can tell you how well calibrated the number is. Where this leaves the individual level, it is aggregated.
  • Improving question quality answer patterns across learners tell us which items are miscalibrated, ambiguous, or broken. This uses aggregates, not your identity.
  • Security and abuse prevention rate limiting, bot checks at signup, detecting account sharing or automated scraping, and capping AI spend per account.
  • Talking to you password resets, email verification, security notices, and — only if you switch them on — study reminders and progress digests.
  • Measuring the product understanding which parts of the service people reach and where they get stuck. See section 6.

We do not use your data for advertising, we do not profile you for anyone else's benefit, and no decision with a legal or similarly significant effect on you is made automatically.

4. Our legal bases

  • Performance of a contract everything needed to deliver the service you signed up for — your account, your learning record, and the estimates built from it.
  • Legitimate interests security, abuse and fraud prevention, keeping the service running, and improving question quality using aggregates. We have weighed these against your interests and use the least identifying data that works.
  • Consent notifications, optional emails, submitting an exam-outcome attestation, and sharing a progress link with a parent or guardian. You can withdraw any of these at any time without losing access to the rest of the service.
  • Legal obligation where the law requires us to keep or produce records.

5. AI processing

AI features — the tutor, explanations, generated practice, and note generation — are powered by large language models operated by Anthropic. What you type into those features, and the relevant learning context we attach to it, is sent to Anthropic to produce a reply. Anthropic processes it as our service provider under contract and does not use it to train its models.

Do not type anything into the tutor that you would not want stored. Tutor conversations are deleted automatically after 90 days without activity, and immediately when you delete your account or the conversation. Separately, we keep a small operational log of AI calls that records sizes and costs, not the content of your messages; the raw text of generated content is cleared after 30 days.

AI output can be wrong. Nothing the tutor says is verified by a teacher before you see it.

6. Analytics

When product analytics are enabled, we use PostHog to record a small, named set of events — sign-up, sign-in, page views inside the app, completed tests, and similar milestones — so we can see where the product works and where it fails. Analytics requests are routed through our own domain, so your browser does not contact PostHog directly.

If you are signed in, those events are linked to your account id together with your email address, role, and plan. We do not send your answers, your tutor messages, or your readiness numbers to PostHog. We do not run advertising, marketing, or cross-site tracking pixels of any kind.

7. Exam-outcome attestations

You may voluntarily tell us how a real exam went, and attach a photograph of your score report as evidence. This is the only way we learn whether our readiness estimates were true, so it matters — but it is entirely optional, and nothing in the product is withheld if you skip it.

A score report is sensitive personal data and we handle it separately from everything else. Evidence images are stored on our own server, never in the public bucket that serves profile pictures, and are never reachable from a public URL. Only reviewing staff can open them, and only to check the claim against the score you entered. The stored file is renamed on upload, so the name of the file on your phone is discarded.

You can delete an image yourself at any time. Withdrawing a submission that is still in review, or was not accepted, deletes it together with its image. Deleting the image of a verified result keeps the verified result. Every image is also deleted automatically 13 months after it was uploaded, and when you delete your account.

Your exam result is never published, never shown to other learners, and never attached to a leaderboard.

8. Sharing a progress link

Where the feature is available, you — the learner — can issue a link that lets a parent or guardian see an honest snapshot of your progress: your readiness estimate and how well evidenced it is, the topics you are actually weakest in, and how recently you practised. Nobody can request this link on your behalf, and you can revoke it at any time, which takes effect immediately.

The link does not expose your email address, your tutor conversations, or your individual answers.

9. Who else processes your data

We share personal data only with providers who process it on our instructions under a written contract, and only for the purposes listed here:

  • Anthropic AI inference for the tutor and content features.
  • PostHog product analytics, where enabled — the events described in section 6.
  • Sentry error diagnostics, with sensitive fields scrubbed.
  • Resend transactional email — verification, password reset, digests.
  • Cloudflare bot checking at registration (Turnstile).
  • Google only if you choose to sign in with Google.
  • Our hosting and storage providers running the servers and holding the database and its off-site backups.

We do not sell personal data, and we do not share it with data brokers, advertisers, or your school unless you joined a classroom yourself. If we are ever compelled to disclose data by a lawful order, we will tell you unless we are legally barred from doing so.

10. How long we keep things

  • Your account and learning record for as long as your account exists. You control this — see section 11.
  • Tutor conversations 90 days after the conversation goes idle.
  • AI operational logs 30 days.
  • Sign-in records 180 days.
  • Notification send logs 90 days.
  • Password reset and email verification tokens 1 hour and 24 hours respectively; only a hash is stored, never the token itself.
  • Attestation evidence images 13 months after upload, or sooner if you delete the image or your account. A verified result itself is kept as part of your learning record.

11. Deleting your account

You can delete your account yourself from your profile settings. It is immediate and it is not reversible.

Deletion removes your account, your learning record and ability estimates, your notes and flashcards, your tutor conversations, your AI generation history, your attestations and their evidence images, your profile picture, your push subscriptions, your support messages, and the free text you wrote anywhere else in the product. Where you contributed to something shared — a match another learner played, a squad, a help request you answered for someone else — we keep the shared artefact and strip your identity out of it rather than destroying another person's record.

Three narrow categories survive deletion, and we would rather say so plainly:

  • Audit records an administrative action log that records the actor's email address and IP. It exists so that privileged actions can be investigated after the fact, which is precisely why it cannot be edited by the person being investigated. Retained on the basis of legitimate interests.
  • Moderation evidence reports made about the account's conduct. References to you as the reporter or reviewer are cleared.
  • Financial and remedy records where any ever exist, kept for tax and chargeback purposes. Today there are none, because the beta is free.

Everything else is gone. If you believe something personal survived deletion, tell us at privacy@eduaz.org and we will treat it as a defect, not a support question.

12. Your rights

You have the right to know what we hold about you, to get a copy of it, to correct it, to have it deleted, to restrict or object to how we use it, and to withdraw consent you previously gave. You can exercise the correction and deletion rights yourself in the product; deletion is described in section 11.

There is no self-service export button yet. Ask at privacy@eduaz.org and we will send you a machine-readable copy of your data within 30 days, free of charge. We will ask you to confirm you control the account's email address before we send anything.

If you think we have handled your data badly, please tell us first — but you are entitled to complain to your national data protection authority regardless, and we will not hold it against your account.

13. Cookies and local storage

Your session is held in a cookie that your browser will not let JavaScript read, sent only to us and only over an encrypted connection. It exists so that you stay signed in. We also keep your chosen interface language in your browser's local storage.

That is the whole list. There are no advertising cookies, no tracking pixels, and no third-party cookie banners, because there is nothing that would need consent.

14. Where your data is processed

Our providers operate outside Azerbaijan, so your data is processed abroad — principally in the European Union and the United States. Where a transfer leaves a jurisdiction whose protection is not recognised as adequate, we rely on the European Commission's standard contractual clauses or an equivalent safeguard, and we can send you the relevant terms on request.

15. Age

EduAI is intended for learners aged 13 and over. If you are under the age at which you can consent to online services on your own in your country — 16 in much of the EU — a parent or guardian must agree on your behalf, and either of you may contact us to have your data deleted.

We do not knowingly collect data from children under 13. If you believe a child under 13 has an account, write to privacy@eduaz.org and we will delete it.

16. Security

Traffic is encrypted in transit. Passwords are hashed with Argon2id. Two-factor secrets are encrypted at rest and recovery codes are stored hashed. Password reset and verification links are stored only as hashes, expire quickly, and are invalidated as soon as a newer one is issued. Uploaded images are validated by inspecting their actual bytes rather than trusting what the browser claims they are. Staff access to attestation evidence is restricted and logged.

No system is perfectly secure. Use a password you use nowhere else, and turn on two-factor authentication. If you find a vulnerability, report it to privacy@eduaz.org — we will not pursue anyone who reports a flaw in good faith and does not exfiltrate other people's data.

17. Changes to this policy

If we start processing your data in a way this policy does not already describe, we will update the policy before that processing begins — not after. Material changes are announced by email, where we have your address, or by a notice in the application.

The date at the top of this page always reflects the current version.

18. Contact

Privacy questions and data-subject requests: privacy@eduaz.org. Everything else: legal@eduaz.org.