Privacy Policy
# SomaSkul Privacy Policy
Version 1.0 — Draft for legal review Effective date: [NOT YET PUBLISHED — set on legal sign-off] Last updated: 2026-08-29
## 1. Who operates SomaSkul
SomaSkul ("SomaSkul," "we," "us") is a study companion application for Kenyan secondary
students, built around the CBC and KCSE curricula. [LEGAL REVIEW REQUIRED: insert
the operating entity's legal name, registration details, and physical/postal address
here — not present in the codebase and must come from the business.]
## 2. Scope
This policy covers the SomaSkul mobile application (Android/iOS, built with Expo/React Native) and the SomaSkul backend service it communicates with. It does not cover the separate SomaSkul administrative console, which is an internal tool used by SomaSkul staff, not by students or the public.
## 3. Information you provide to us
When you create a SomaSkul account, you provide:
- Your name — used to personalize the app and, in ZANA (SomaSkul's AI tutor)
conversations, to address you directly.
- Your phone number — this is your account identifier and how you log in. SomaSkul
does not use a password or a one-time SMS code; your phone number alone identifies your account on each login. Your phone number is also the account M-Pesa payments are matched against if you subscribe to a paid plan.
- Your curriculum, class level, and subjects — so SomaSkul can show you the right
content.
SomaSkul does not currently ask for your email address, date of birth, or school name. These fields do not exist in SomaSkul's signup flow today.
### 3.1 Content you submit while using SomaSkul
- Photos of homework questions or report cards, submitted through the camera or
photo picker, so SomaSkul's AI can read and respond to them. These photos are not stored by SomaSkul. They are sent to our AI provider (Google's Gemini API) for processing and are not saved to any SomaSkul database — they exist only for the moment it takes to generate a response.
- Questions and messages you type to ZANA, SomaSkul's AI tutor.
- Report card / exam results you choose to enter, if you use the Performance
Analysis feature — after SomaSkul's AI extracts data from a photo, you must confirm it is correct before anything is saved. Unconfirmed extractions are never persisted.
## 4. Information automatically associated with your use of SomaSkul
- A locally generated device identifier — not your phone's hardware ID, generated
by the app itself, used to prevent abuse of free-trial and referral offers.
- Study activity — questions answered, scores, streaks, flashcard reviews, and
similar progress data, so your progress can sync between sessions and (if you use more than one device) between devices.
- ZANA session summaries — SomaSkul records the subject/topic and a general summary
of a tutoring session (for example, to track which topics ZANA has covered with you). Your full, message-by-message ZANA conversation history stays only on your device — it is never uploaded to SomaSkul's servers. If you uninstall the app or clear its storage, that history is gone and cannot be recovered by SomaSkul, because we never had a copy.
- A small number of fragments of what you've typed to ZANA may be retained on our
servers as part of how ZANA learns to answer future students' questions better — see §7 below.
## 5. How SomaSkul uses your information
- To create and operate your account.
- To personalize content to your curriculum and class level.
- To power ZANA (your AI tutor), the homework-solving camera feature, flashcards,
practice exams, and revision tools.
- To process payments and activate your subscription.
- To sync your study data between devices, if you use SomaSkul on more than one device.
- To detect and prevent abuse of trials, referrals, and payment flows.
- To maintain and improve the app.
SomaSkul does not use your information for advertising, does not sell your information, and does not share it with data brokers. SomaSkul has no advertising SDK of any kind integrated into the app.
## 6. AI processing — ZANA, homework solving, and the Research Engine
SomaSkul's tutoring and homework-solving features are powered by Google's Gemini API. When you use these features:
- Your question, and any photo you submit, is sent to Google's servers to generate a
response.
- ZANA's instructions to the AI include your class level and curriculum, so it
can tailor its teaching to your grade and follow the right examination conventions. As of 2026-08-28, your name is no longer included in this — SomaSkul minimized this to only the information ZANA actually needs to teach correctly.
- **If you photograph a report card or a homework page that has your name printed on
it, that name is still visible to Google as part of the image itself** — removing
your name from ZANA's written instructions (above) does not remove it from a photo
that shows it. SomaSkul does not crop, blur, or otherwise redact names from submitted
photos. See docs/legal/GEMINI_PROVIDER_VERIFICATION.md §4.
- Google's own terms govern how it processes API requests, and **differ by billing
tier: [BUSINESS DECISION REQUIRED — urgent, verified 2026-08-29] on Google's
paid tier, prompts and responses are not used to improve Google's products and
are logged only briefly for abuse detection; on the free tier**, Google's own
terms state submitted content *is* used to improve its products and may be read by
human reviewers, and Google explicitly advises against submitting personal
information to it. SomaSkul's operator must confirm which tier production traffic is
billed under, and record that confirmation (docs/legal/GEMINI_PROVIDER_VERIFICATION.md
§7-9), before this policy can state a settled position either way.
If SomaSkul's optional "Research Engine" feature is active (it is switched off by
default), a version of your question — including its literal wording — may also be
sent to Tavily, a web-search provider, to help ZANA ground its answer in current
information. [LEGAL REVIEW REQUIRED / UNVERIFIED: confirm Tavily's current terms
regarding data retention and model training.]
See docs/legal/AI_EDUCATIONAL_DISCLAIMER.md for more about the limits of AI-generated
answers.
## 7. What SomaSkul retains from AI interactions
SomaSkul's AI tutor "learns" from strong, verified exchanges with students in order to improve future answers to similar questions — this is a background process that never blocks or is visible to you while you study.
- What's saved is a distilled study note (a definition, an example, common
mistakes to avoid) — not a copy of your conversation.
- However, **a short excerpt of the question that prompted the note (up to roughly
2,000 characters) is saved alongside it**, to help our team verify the note's
accuracy later. This excerpt is not linked to your name or account in our database
— it exists in a shared knowledge table with no owner field — but it is retained
indefinitely today, and SomaSkul does not yet have an automatic process to delete these
excerpts. [This is disclosed here because our audit found it retained in a way
that doesn't match a strict "we never keep raw text" claim — see
DATA_RETENTION_POLICY.md.]
## 8. Payments
If you subscribe to a paid plan, SomaSkul processes your payment through Safaricom's M-Pesa service. SomaSkul does not process or store credit/debit card numbers — SomaSkul has no card-payment integration.
- Paybill (the standard way to pay): SomaSkul shows you a paybill number and asks you
to pay using your own phone number as the account reference, from your phone's M-Pesa menu. This step does not send any data to SomaSkul's servers — you are interacting directly with your phone's M-Pesa app.
- STK push (optional, off by default): if enabled, SomaSkul can request a payment
prompt be sent directly to your phone. This requires sending your phone number and the payment amount to Safaricom's payment API.
- Your subscription is only ever activated by Safaricom's official payment
confirmation — never by anything the app itself reports. See
SUBSCRIPTION_BILLING_TERMS.md.
- SomaSkul keeps a record of your M-Pesa receipt code, amount, and plan for accounting
and to resolve payment disputes. See DATA_RETENTION_POLICY.md for how long.
## 9. Children's privacy
SomaSkul is a study app intended for use by secondary school students, some of whom may
be minors. As of this policy's effective date, SomaSkul does not have a separate parent
account, parental consent flow, or age-verification step — account creation is
self-service, using only a name and phone number. [LEGAL REVIEW REQUIRED /
BUSINESS DECISION REQUIRED: SomaSkul's operator must determine (a) SomaSkul's actual target
age range, and (b) whether that requires building an age-gate, parental-consent flow,
or other child-data safeguard before or shortly after publishing this policy. See
LEGAL_COMPLIANCE_AUDIT.md §1 for the full finding and PARENT_GUARDIAN_NOTICE.md for
guidance in the meantime.]
If you are a parent or guardian and believe your child has provided personal
information to SomaSkul and you would like it reviewed or removed, see §14 (How to
Contact Us) and DATA_SUBJECT_REQUESTS.md.
## 10. Data sharing
SomaSkul shares information only:
- With Google (Gemini API), to generate AI tutoring/solving responses (§6).
- With Safaricom, to process payments (§8).
- With Tavily, only if the optional Research Engine feature is active (§6).
- With Supabase, our database and file-storage provider, which hosts SomaSkul's data
under access controls SomaSkul configures (see THIRD_PARTY_DATA_PROCESSORS.md).
- If required by law, or to protect SomaSkul's rights, users, or the public.
SomaSkul does not sell personal information. SomaSkul has no advertising SDK and does not share data with advertisers or data brokers.
## 11. Data security
SomaSkul restricts database access using row-level security, so that (with the exception
noted below) one student's data cannot be read by another student. Payment
confirmation is verified server-side and can never be set by anything the app itself
reports. [Note for legal review, not for public copy: our own audit found that every
SomaSkul staff account with admin access can currently read a student's name and phone
number, including roles intended to be read-only or content-only — see
LEGAL_COMPLIANCE_AUDIT.md §5.6. This is an internal access-control gap the engineering
team is addressing, not a claim to soften in the public policy — if this policy states
"only authorized staff with a need to know can access your data," that statement
should not be published until it is actually true.]
No method of transmission or storage is 100% secure, and SomaSkul cannot guarantee absolute security.
## 12. Data retention
See DATA_RETENTION_POLICY.md for the full, per-category retention table.
RETENTION DECISION REQUIRED for several categories — SomaSkul does not currently
have engineering-enforced retention limits for most data; most information is kept
indefinitely today.
## 13. Account and data deletion
[LEGAL REVIEW REQUIRED / LAUNCH BLOCKER] As of this policy's drafting, SomaSkul does
not have a self-service "delete my account" button in the app. If you would like your
account or data deleted, contact us using the details in §14, and see
DATA_SUBJECT_REQUESTS.md for what to expect. SomaSkul's engineering team is required to
resolve this gap — see DATA_DELETION_POLICY.md and LEGAL_LAUNCH_CHECKLIST.md — and
this section must be rewritten once a deletion process (in-app or otherwise) exists,
rather than published as-is with a manual-request-only process, if Google Play or
legal counsel determines a manual process is insufficient.
## 14. How to contact us
[BUSINESS DECISION REQUIRED: insert a real support email/contact channel. SomaSkul's
codebase has no support-contact mechanism built in today — this must be a real,
monitored channel before publishing.]
## 15. Changes to this policy
We will update the "Last updated" date above when this policy changes. Material
changes will be highlighted in the app. [BUSINESS DECISION REQUIRED: decide the
actual mechanism for notifying users of policy changes — no such mechanism exists in
the app today; see CONSENT UX section of LEGAL_LAUNCH_CHECKLIST.md.]
*This document is Version 1.0 of SomaSkul's Privacy Policy and has not yet been reviewed
by legal counsel or published. Do not treat it as SomaSkul's operative privacy policy
until the effective date above is set and all [LEGAL REVIEW REQUIRED] /
[BUSINESS DECISION REQUIRED] markers are resolved.*