Privacy Policy
Last updated: October 6, 2026
1. Who this covers
This policy explains what personal information Mwalimu AI collects from the teachers who use it, why, who it is shared with, how long it is kept, and what you can do about it. It is written to match what the app actually does today.
2. What we collect
Information you give us:
- Account: your email address and a password (stored only in scrambled, hashed form), or your name, email address and profile picture from Google if you sign in with Google.
- Profile: your name, school, county, the subjects and grades you teach, your CBC experience level, and your language and accessibility settings.
- What you do in the app: lessons completed, quiz and assessment answers and scores, lesson reflections, needs-assessment answers, goals, journal entries, community posts and replies, and support tickets and their messages.
- Your AI Coach and AI tool conversations, which are saved so you can return to them.
- Messages you send through the Contact and Support forms: your name, the email address you type, and your message. Our replies are kept with them. If you are not signed in, you are given a private link to the conversation (we store only a scrambled form of it, never the link itself). We check that the address's domain can receive mail but do not send email to it.
Information created as you use the service:
- Certificates you earn (a serial number, the path, the date and, until you delete your account, your name).
- The days you were active, used for streaks, and in-app notifications.
- Your plan and billing status. Card payments are handled by Stripe; we receive a customer and subscription reference and the plan status, never your card number.
- If you join a school: that membership.
- A random device identifier kept in your browser, used so that an account is open on one device at a time.
- Technical error reports (the error message, the page it happened on and your browser type) kept to fix bugs. They are not meant to include what you wrote.
- Counts of AI requests per day, to apply the daily allowance.
3. Why we use it
- To run your account: sign you in, save your progress, issue and verify certificates, and show your dashboard.
- To give you AI answers: your message is sent to an AI provider (see section 5).
- To take payment and apply your plan.
- To answer your tickets and messages. Replies stay in the app (your Support page, or your private conversation page); we do not email learners.
- To keep the service safe and working: limits on AI use, spam protection on the forms, moderation of reported community posts, and bug reports.
- To understand how the service is used, in aggregate: for example counts of completed lessons and how many people picked each answer in the needs assessment. These counts are not tied to your name.
We do not sell your personal information, and we do not use your conversations to train AI models.
4. Who can see it
- Other learners see your name on your community posts and replies, and nothing else.
- Your head teacher, only if you join a school with its code: your lessons finished, certificates and when you were last active. Not your journal, AI conversations, messages or contact details. You can leave at any time and they lose access at once.
- Our staff see what they need for their job through a console that requires a second sign-in step. Support staff can see your profile and progress and the tickets you send them; they cannot read the contents of your journal or AI conversations. Staff actions are logged.
- Anyone can check a certificate by its serial number on the Verify page; it shows whether it is genuine and which path it is for.
5. Companies that process data for us
We use these providers to run the service. Each receives only what its job needs.
- Convex: our database and backend, which stores your account and learning data.
- Vercel: hosts the website. If you accept analytics cookies, Vercel Web Analytics also measures page visits.
- Groq: generates AI Coach and AI tool replies. It receives the message you send and the lesson context needed to answer it.
- Stripe: takes card payments and manages subscriptions.
- Resend: sends a few emails to our own staff, such as staff invitations. We do not use it to email learners.
- Google: only if you choose Continue with Google.
These providers operate outside Kenya, including in the United States, so your information can be processed there.
6. Cookies and local storage
We set one cookie to remember your cookie choice (mwalimu_cookie_consent, kept for 180 days). Your sign-in session, language, accessibility settings, device identifier and any lessons you save for offline use are stored in your browser's local storage on your device. Analytics runs only if you accept it in the cookie banner.
7. How long we keep it
- Your account data: until you delete your account.
- Technical error reports: 90 days.
- Daily AI usage counts: about two months.
- Support tickets: two years after they are resolved.
- Notifications you have read or dismissed: six months.
- Contact-form messages that staff have dealt with: one year after they arrived.
- A certificate's verification record stays so the certificate remains checkable, but it no longer shows your name once you delete your account.
- Records of staff actions are kept for accountability.
8. Your rights and how to use them
Under Kenya's Data Protection Act, 2019 you can see, correct and delete your personal data, ask for a copy, and object to how it is used. In the app:
- See or take a copy: Settings → Download My Data gives you a file with your profile, progress, certificates, activity, journal, AI conversations, community posts and support tickets.
- Correct: change your profile and settings in Settings.
- Delete: Settings → Delete Account removes your profile, progress, journal, AI conversations, activity and support tickets, and your community posts. If you have a paid plan, cancel it first.
- Password: change it in Settings → Change password. If you are locked out, ask support on the Support page and they will give you a temporary password.
For anything else, send us a message through the Contact page. If you are not satisfied with our answer you can complain to the Office of the Data Protection Commissioner.
9. Security
- The site is served over HTTPS only.
- Passwords are stored hashed, never in plain text.
- Staff tools need a second sign-in step and each staff role can only do what it needs to; every change is logged.
- No system is perfectly secure. If a breach affects you we will tell you and the authorities as the law requires.
10. Children
Mwalimu AI is for adult teachers and is not meant for children. Please do not put learners' personal details into the journal, community or AI tools.
11. Changes
If we change this policy in a way that matters, we will update the date at the top of this page. Earlier versions are not kept on this page.
