Privacy Policy
Last updated: 2026-06-27
1. Who we are
Eaalim Lessons is a Quran and Arabic learning platform operated by Eaalim (the "Service"). When this document says "we" or "us", we mean Eaalim. "You" means the person reading this — whether you're a teacher, a student, a parent, or an administrator on the platform.
2. What we collect
We try to keep data collection to a minimum. Here's the full list:
- Teachers: name, email address, password (stored as a scrypt hash — we never see your plaintext password), optional bio.
- Students: display name, Arabic name (optional), Student ID (auto-generated, e.g. STU-001), lesson attempts + scores, audio recordings the student submits for teacher review, certificates earned.
- Parents / Family accounts: name, email, billing information (handled by Stripe — see Section 5).
- Administrators (Eaalim staff): name, email, password (same hashing as teachers).
- Usage data: when you sign in, which pages you visit, IP address (kept for 90 days for security audit), and anonymous interaction events (only if you opt in to analytics — see Section 6).
3. Why we collect it
- To run the platform: sign-in, assignments, grading, certificate issuance.
- To communicate with teachers / admins: transactional email (welcome, password reset, lesson approved / rejected, certificate ready) via Resend.
- To process payments: family-plan subscriptions via Stripe — we never store credit card numbers on our servers.
- To improve lessons (with your permission): opt-in product analytics + crash reporting. Off by default.
- To meet legal obligations: tax records, audit logs of admin actions kept for compliance.
4. The legal basis (GDPR Art. 6)
For users in the European Union, United Kingdom, or other GDPR-aligned jurisdictions, we rely on the following lawful bases:
- Contract — to provide the Service you signed up for (assignments, grading, certificates, billing).
- Legitimate interest — security audit logs, anti-abuse rate limiting.
- Consent — analytics + performance tracking; you can withdraw at any time via cookie preferences.
- Legal obligation — financial records, COPPA compliance.
5. Who we share data with (third-party processors)
We use the following service providers. Each one is bound by a Data Processing Agreement and processes data on our behalf only.
- Neon — Postgres database hosting (EU-West region).
- Stripe — payment processing (certified under the EU-US Data Privacy Framework).
- Resend — transactional email delivery.
- UploadThing — audio + certificate file storage.
- Pusher — real-time updates (e.g. teacher notifications when a student submits audio).
- Inngest — background jobs (certificate generation, email scheduling).
- PostHog — product analytics (only if you opt in).
- Sentry — crash reporting (only if you opt in).
We do not sell or rent your personal data to anyone. We do not use it for advertising or marketing profiling.
6. Cookies and tracking
We use three categories of cookies / browser storage:
- Strictly necessary:sign-in session, security tokens, language preference. The platform cannot function without these and they don't require consent.
- Analytics: aggregate usage patterns via PostHog. Opt-in only.
- Performance + errors: crash reports via Sentry. Opt-in only.
You can review and change your preferences anytime at /cookies.
7. Children under 13 (COPPA)
Eaalim Lessons is designed for children including those under 13. In the United States, the Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before we can collect personal information from a child.
See our dedicated COPPA notice for parents for the full description of what we collect from children, why, retention period, and your rights as a parent or guardian.
8. How long we keep your data
- Active accounts: for as long as you use the Service.
- Deleted accounts: we soft-delete (mark as removed) for 30 days so you can recover, then hard-delete.
- Audit logs: 90 days, then auto-purged.
- Financial records: 7 years (legal obligation).
9. Your rights
Under GDPR (EU/UK), UK Data Protection Act 2018, and similar regimes, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (subject to legal retention obligations).
- Restrict or object to processing.
- Receive your data in a portable format.
- Withdraw consent at any time (e.g. by toggling cookie preferences off).
- Lodge a complaint with your local data protection authority — for UK users, that's the ICO (ico.org.uk).
To exercise any of these rights, contact us. We'll respond within 30 days.
10. Security
We protect your data with industry-standard measures: TLS encryption for all traffic, scrypt password hashing, regular dependency updates, restricted database access, audit logging of admin actions, and least-privilege role-based authorization. No system is 100% secure; if a breach occurs we'll notify affected users + the ICO (or equivalent regulator) within 72 hours per Article 33 GDPR.
11. International transfers
Some of our processors (Stripe, Inngest, PostHog, Sentry) operate servers in the United States. For users in the EU / UK, transfers are protected by Standard Contractual Clauses + the EU-US Data Privacy Framework certification.
12. Changes to this policy
We may update this policy as the Service evolves. Material changes will be announced via email (for teachers and admins) and an in-app banner. The "Last updated" date at the top reflects the most recent revision.
13. Contact
Questions? Contact us.