Skip to main content
AI Courses for Every Industry · Learn at Your Own Pace
EducationPals
CoursesArticlesStart Learning

Privacy Policy

How we collect, use, and protect your personal information.

Last updated: March 14, 2026

EducationPals.ai ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. [FIRST DRAFT — pending counsel review.]

Information We Collect

We collect information you provide directly (account details, course progress, notes, bookmarks), information collected automatically (device information, IP address, browser type, pages visited), and information from third parties (authentication providers such as Google and GitHub via Clerk).

How We Use Your Information

We use your information to provide and maintain the platform, personalize your learning experience, track course progress and issue certificates, send service-related communications, analyze usage patterns to improve the platform, and comply with legal obligations.

Legal Basis for Processing (EU/UK)

If you are in the EU, EEA, or UK, we rely on the following lawful bases under Article 6 of the GDPR: contractual necessity (Art 6(1)(b)) for delivering the courses, lessons, notes, and other features that make up your account; consent (Art 6(1)(a)) for analytics and marketing cookies and any optional communications; legitimate interests (Art 6(1)(f)) for platform security, fraud prevention, abuse detection, and ensuring the service runs reliably; and compliance with legal obligations (Art 6(1)(c)) for billing, tax, and lawful requests from authorities. You can withdraw consent at any time from Settings > Privacy or the Cookie Preferences link in the footer; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Cookies and Tracking

We use cookies and similar technologies as described in our Cookie Policy. You can manage your cookie preferences at any time through the cookie settings in the footer of our site.

Data Sharing

We do not sell your personal data. We share information only with sub-processors who help us run the platform (see the sub-processor section below), with payment networks where you make a purchase, when required by law, or with your explicit consent.

Sub-processors

We rely on a small set of sub-processors to operate the platform. As of the last-updated date above: Clerk (authentication, US); Amazon Web Services (hosting, storage, compute — primary regions us-west-2 and us-east-1, US); Stripe (payments, US); PostHog (product analytics, proxied through our domain, US); Google (Tag Manager and Analytics under Google Consent Mode v2, US/global); Meta Platforms (Facebook/Instagram Pixel for ads measurement when you have granted marketing consent, US/global); and AI model providers used to power tutoring and content generation (US). We update this list before adding any new sub-processor that processes personal data; material changes are reflected on this page.

International Data Transfers

Your data is stored and processed in the United States (primarily AWS regions us-west-2 and us-east-1). Where we transfer personal data from the EU, EEA, UK, or other jurisdictions with cross-border restrictions, we rely on the European Commission's Standard Contractual Clauses (SCCs, 2021 modules) together with supplementary measures including encryption in transit and at rest, role-based access controls, multi-factor authentication on administrative access, and a documented Transfer Impact Assessment. For UK transfers we rely on the UK Addendum to the SCCs. We do not currently offer EU-resident hosting; if your engagement requires it, contact us before signing up. [FIRST DRAFT — counsel to confirm SCC modules and DPF self-certification status.]

EU Representative (Art 27)

Because we offer services to individuals in the EU/EEA without an EU establishment, we have appointed (or will appoint before public EU launch) a representative under Article 27 GDPR. Their contact details will be listed here once the engagement is finalized. [FIRST DRAFT — placeholder; founder to engage Prighter / EDPO / VeraSafe and update this section.]

UK Representative (UK GDPR Art 27)

We have similarly appointed (or will appoint before public UK launch) a UK representative as required by Article 27 of the UK GDPR. Their contact details will be listed here once the engagement is finalized. [FIRST DRAFT — placeholder; same vendor typically covers both EU and UK.]

Data Protection Contact

We are not currently required to appoint a Data Protection Officer under Article 37 GDPR — we do not carry out large-scale monitoring of individuals or process special categories of data on a large scale. You can reach our privacy team at privacy@educationpals.ai for any data-protection question, including to exercise your rights or raise a concern. [FIRST DRAFT — counsel to confirm DPO non-required stance.]

Data Retention

We retain personal data only for as long as needed for the purpose it was collected. Concrete retention periods today: account profile and learning content — until you request deletion, after which a 30-day soft-delete window applies before permanent purge; cookie consent records — 365 days, then re-prompted; consent audit trail — 3 years for routine entries, with permanent retention of pseudonymized records of erasure events as required for accountability under Article 5(2) GDPR; tutor conversations — 90 days; concept mastery — 365 days; billing and invoicing records — for the period required by applicable tax law (typically 7 years); operational logs — 90 days for application logs and up to 1 year for security/audit logs. You can request export or deletion at any time from Settings > Privacy. [FIRST DRAFT — counsel to confirm tax-record retention by jurisdiction and add backup-retention period.]

Your Rights

Depending on your location, you may have the right to access, correct, or delete your personal data, object to or restrict processing, data portability, withdraw consent at any time, and lodge a complaint with a supervisory authority. To exercise these rights, visit Settings > Privacy in your dashboard or contact us at privacy@educationpals.ai. We respond within 30 days under the GDPR and within the equivalent statutory window in your jurisdiction.

Automated Decision-making

We use machine learning and AI to personalize your learning experience — for example, to suggest next lessons, generate practice questions, and surface weak concepts. These features do not produce legal or similarly significant decisions about you under Article 22 GDPR (we do not use automated systems for grading-of-record, employment screening, credit decisions, or any other determination that legally binds or significantly affects you). If we change posture in the future, we will update this section and provide a meaningful right to human review. [FIRST DRAFT — re-review whenever AI scope expands.]

Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit and at rest, regular security assessments, role-based access controls, and a documented incident-response process. No system is perfectly secure, and we will notify you and the appropriate authorities of any qualifying personal-data breach in line with our legal obligations.

Children's Privacy

Our platform is not directed to children under 18. We do not knowingly collect personal data from children under 18 without verifiable parental consent in the jurisdictions that require it (under 13 in the United States under COPPA, between 13 and 16 in the EU under Article 8 GDPR depending on member state, and under 18 in India under the DPDPA). If you believe a child has created an account, contact us at privacy@educationpals.ai and we will delete the account and any associated data. [FIRST DRAFT — counsel to confirm strictest-threshold global stance vs jurisdiction-branched.]

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Where required by law, we will obtain fresh consent before relying on the updated policy.

Contact Us

If you have questions about this Privacy Policy, contact us at privacy@educationpals.ai.

privacy@educationpals.ai

© 2026 EducationPals.ai. All rights reserved.

About Us·Our Mission·Privacy Policy·Terms of Service·Cookie Policy·Accessibility·