Privacy Policy

Effective Date: 1 January 2026  ·  Last updated: 11 May 2026

At SHULE.AI, your privacy matters. This policy explains what data we collect, why we collect it, and how we keep it safe.

1. Information We Collect

We collect information you provide directly, information generated through your use of the platform, and information from third-party services.

1.1 Account Information

  • Full name, email address, and phone number
  • Date of birth and physical address
  • Profile photo (optional)
  • Login credentials (passwords are stored as salted hashes and never in plain text)

1.2 Educational Information

  • School name, grade level, and admission number
  • Subjects of interest and learning preferences
  • Questions asked, AI responses received, and exam results
  • Daily usage statistics (number of questions per day)

1.3 Payment Information

  • M-Pesa phone number and transaction reference codes
  • Subscription tier, billing period, and payment status
  • Card payments are processed by Paystack — we do not store card numbers or CVVs on our servers

1.4 Technical Information

  • IP address, browser type, and device information
  • Pages visited, time spent, and click-through data
  • Error logs and crash reports

2. How We Use Your Information

We use the information we collect to:

  • Deliver the service — create your account, authenticate you, and provide AI-powered tutoring sessions
  • Personalize learning — track your progress and tailor AI responses to your curriculum and grade level
  • Process payments — verify M-Pesa transactions, activate subscriptions, and issue payment receipts
  • Improve the platform — analyse usage patterns to improve features, content quality, and AI accuracy
  • Communicate with you — send account confirmations, subscription reminders, and important service updates
  • Ensure safety — detect and prevent fraudulent, abusive, or illegal use of the platform

We will never sell your personal information to advertisers or third parties for marketing purposes.

3. Data Storage & Security

Your data is stored on secure cloud servers located within regions compliant with applicable data protection laws. We implement the following safeguards:

  • TLS/HTTPS encryption for all data in transit
  • AES-256 encryption for data at rest where applicable
  • HTTP-only, secure, same-site cookies for session tokens
  • Role-based access controls — only authorised staff can access user data
  • Regular security audits and vulnerability assessments
  • Automatic token rotation — access tokens expire after 1 hour; refresh tokens after 30 days

While we take all reasonable measures, no method of transmission over the internet is 100% secure. We will notify you promptly in the event of a data breach that affects your personal information.

4. Data Sharing

We do not sell your data. We may share your information only in the following limited circumstances:

  • Service providers — trusted third parties (e.g., Paystack for card payments, Firebase for authentication, cloud hosting) that process data on our behalf under strict data processing agreements
  • Educational institutions — if your school has an arrangement with SHULE.AI, aggregate (non-personally identifiable) usage reports may be shared with school administrators, with your prior consent
  • Legal requirements — if we are compelled by law, court order, or government authority to disclose information, we will do so and notify you where permitted
  • Business transfers — in the event of a merger, acquisition, or asset sale, user data may be transferred as part of the transaction; you will be notified before your data is transferred or becomes subject to a different privacy policy

5. Cookies & Tracking

We use the following types of cookies:

  • Strictly necessary cookies — session management, authentication tokens, and security cookies required for the platform to operate
  • Functional cookies — remember your preferences such as theme settings and sidebar state
  • Analytics cookies — anonymous usage statistics that help us understand how users interact with the platform (no personally identifiable information is stored)

You can control cookies through your browser settings. Disabling strictly necessary cookies will prevent you from using the platform.

6. Children's Privacy

SHULE.AI is designed for students, including those under 18. We take the protection of minors' data very seriously:

  • Users under 13 years of age require verifiable parental or guardian consent before creating an account
  • We collect only the minimum personal data necessary for students under 18
  • We do not display behavioural advertising to users under 18
  • Parents or guardians may request access to, correction of, or deletion of their child's data at any time by contacting us at hello@shule.ai

7. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — request that we correct inaccurate or incomplete data
  • Deletion — request that we delete your account and personal data ("right to be forgotten")
  • Portability — request your data in a structured, machine-readable format
  • Objection — object to certain types of processing, including direct marketing
  • Restriction — request that we restrict processing of your data while a dispute is being resolved

To exercise any of these rights, email us at hello@shule.ai with the subject line "Data Request". We will respond within 30 days.

8. Data Retention

We retain your data for the following periods:

  • Active accounts — data is retained for as long as your account is active
  • Deleted accounts — personal data is purged within 30 days of account deletion; anonymised usage statistics may be retained indefinitely
  • Payment records — transaction records are retained for 7 years as required by Kenyan tax and financial regulations
  • Content reports — report logs are retained for 2 years for safety and audit purposes

9. Third-Party Links

Our platform may contain links to third-party websites or services (e.g., payment gateways, social login providers). These third parties have their own privacy policies, and we are not responsible for their content or practices. We encourage you to read the privacy policy of every website you visit.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send an email notification to registered users at least 14 days before the changes take effect
  • Display a prominent notice on the platform on or before the date the changes take effect

Continued use of SHULE.AI after the effective date constitutes acceptance of the revised policy.

11. Contact Us

If you have any questions, concerns, or requests related to this Privacy Policy, please contact our Data Protection team:

Effective Date: 1 January 2026 · Last updated: 11 May 2026

Also see: Terms of Service · Support & FAQs