1. Information We Collect
We adhere to the principle of data minimization and only collect information strictly necessary to provide and optimize our educational AI services.
User-Provided Information
- Account credentials and profile details (e.g., name, email address, optional phone number).
- Educational inputs, including text prompts, study queries, uploaded learning material, and questions submitted directly to the AI features.
- Communications and feedback submitted directly to our support or administrative team.
Automatically Collected Telemetry
- Device attributes: Operating system version, device model, hardware specifications, and unique device identifiers.
- Technical log data: Internet Protocol (IP) address, browser type, crash logs, and interaction timestamps (time spent, features accessed).
Tracking & Analytics
- Necessary operational tokens, SDKs, and telemetry to maintain session integrity and app stability. Non-essential tracking is deployed only where consent has been affirmatively granted in accordance with applicable statutory frameworks.
2. Artificial Intelligence (AI) Features & Data Usage
Academy Ai utilizes artificial intelligence and machine learning models to deliver educational content, contextual responses, and personalized study workflows.
- Purpose of Processing: User prompts and inputs are processed solely to generate real-time AI responses and maintain conversational context within your learning session.
- No Unauthorized Model Training: We do not sell, rent, or use your personal data, queries, or submitted learning materials to train, fine-tune, or improve foundational third-party AI models without your explicit, opt-in consent.
- AI Sub-Processors: Where cloud-hosted AI inference infrastructure (such as OpenAI, Anthropic, or Google Cloud Vertex AI) is utilized, prompts are transmitted via enterprise APIs subject to strict confidentiality, zero-data-retention-for-training agreements, and data minimization protocols.
3. Third-Party Service Providers (Sub-Processors)
We do not sell, lease, or monetize your personal information to data brokers or advertising networks. We partner strictly with infrastructure and performance vendors who are contractually bound to process data only on our behalf:
- Google Play Services: Core mobile infrastructure and operating-system-level runtime services (Google Privacy Policy).
- Google Analytics for Firebase & Firebase Crashlytics: Aggregated application telemetry, crash diagnostics, and performance optimization (Firebase Privacy Policy).
- Expo: Cross-platform application framework and runtime maintenance (Expo Privacy Policy).
Any data shared with external vendors for analytics or crash diagnosis is aggregated and anonymized wherever technically feasible.
4. Legal Grounds for Processing
Depending on your jurisdiction, we process personal data under the following lawful bases:
- Performance of a Contract / Service Delivery: To register your account, maintain infrastructure, deliver educational content, and execute AI queries.
- Consent: For marketing communications, non-essential cookies/trackers, and optional features (which you may withdraw at any time).
- Legitimate Interests / Lawful Uses: To safeguard cybersecurity, prevent malicious activity, and optimize system stability.
- Compliance with Legal Obligations: To satisfy statutory accounting, tax, or lawful law enforcement demands under applicable regional acts.
5. International Data Transfers
Your information may be transferred to, and processed on, secure servers located outside of your state, province, or country of residence. Whenever personal data is transferred internationally (including outside the EEA, UK, or India), we implement adequate statutory safeguards:
- Standard Contractual Clauses (SCCs) approved by competent regulatory bodies.
- Binding corporate agreements with enterprise-grade encryption standards.
- Compliance with transfer restrictions and blacklists established under applicable data protection statutes.
6. Data Retention & Account Deletion
We do not retain personal information longer than is necessary to serve the operational purposes outlined in this policy.
- Account Data & Prompts: Retained actively while your account remains active.
- Account Deletion: You may delete your account and associated personal data at any time via the in-app settings (Settings > Account > Delete Account) or by emailing contact@qbitlog.com. Upon verified deletion, your personal identifiers and prompt histories are permanently purged or irreversibly anonymized within 30 calendar days, except where retention is strictly mandated by statutory record-keeping laws.
- System Telemetry: Anonymized crash reports and aggregate analytical metrics are retained for a maximum of 12 months, after which they are systematically deleted.
7. Statutory Rights & Regional Disclosures
A. Digital Personal Data Protection Act, 2023 (India)
For users located in India, Qbitlog operates as the "Data Fiduciary" regarding your digital personal data:
- Right to Access & Summary: You have the right to obtain a summary of the personal data we process, the identities of all third-party Data Processors with whom your data has been shared, and any other relevant information.
- Right to Correction & Erasure: You may request the correction of inaccurate or misleading personal data, completion of incomplete data, and the updating or erasure of your personal data when it is no longer necessary for the purpose for which it was collected.
- Right to Nominate: In the event of death or incapacity, you have the right to nominate an individual who shall exercise your data rights in accordance with the provisions of the DPDP Act.
- Grievance Escalation: If you are dissatisfied with our response to your data access or erasure request, you may write to our Grievance Officer at contact@qbitlog.com. If your grievance remains unaddressed within 30 days, you retain the statutory right to escalate the matter to the Data Protection Board of India.
B. GDPR (EEA & UK) & CCPA/CPRA (California)
- Access, Portability & Erasure: You may request a machine-readable export of your personal information or demand complete erasure ("Right to be Forgotten").
- Non-Sale of Personal Data: We do not sell or "share" personal information for cross-context behavioral advertising under the California Consumer Privacy Act.
- Non-Discrimination: We will never deny services, charge differentiated prices, or degrade feature quality because you exercised your statutory privacy rights.
8. Child Privacy Protection
Academy Ai is not directed toward, nor intended for, children under the age of 16 (or the applicable minimum age of digital consent in your jurisdiction; 18 in India without verifiable parental consent). We do not knowingly solicit or collect personal information from minors.
If we identify that an account belongs to an underage user without verified parental consent, we will promptly terminate the account and permanently delete all associated data. Parents or guardians who believe their child has provided us with personal information should contact us immediately at contact@qbitlog.com.
9. Security Safeguards & Breach Notification
We employ industry-standard technical and organizational security controls—including TLS/SSL transport layer encryption, AES-256 at-rest database encryption, network firewalls, and least-privilege administrative access controls—to protect your personal information against unauthorized access, loss, or destruction.
In the event of a security incident that compromises your personal data, we will notify affected individuals and competent supervisory authorities (including the Indian Computer Emergency Response Team / CERT-In where applicable) in accordance with statutory timelines.
10. Privacy Policy Amendments
We reserve the right to revise this Privacy Policy to reflect technical, operational, or legal developments. When material changes occur, we will update the "Last Updated" date at the top of this document and provide notice through an in-app prompt, dashboard banner, or email alert prior to modifications taking effect.