Privacy Policy
Last updated: 9 August 2026
Edapt ("Edapt", "we", "us") is operated from Australia and complies with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). This page explains, in plain English, what we collect, why, and what you can do about it.
1. Who we are
Edapt is a personal AI learning platform that adapts study material to your VARK learning style. The website at edaptlearn.com and any associated apps are owned and operated by Edapt. If you have a privacy question or want to make a request under the APPs, see section 13.
2. What we collect
- Account information, name, email, password (hashed), country/region, (optional) school and year level, and how you heard about Edapt. When you sign up with email and password we send a short-lived verification code to confirm you control the address; we store only a cryptographic hash of that code, never the code itself, and it is deleted once your address is confirmed. If you choose "Sign in with Google", we receive your name, email address and profile photo from your Google account instead of a password, and no code is needed. If you sign up through a friend's referral link, we also record which account referred you.
- Learner profile, your VARK answers, declared interests, declared goals, strengths and struggles, mastered concepts, review queue, preferred examples, tone and pacing, and reflections you write into Edapt.
- Lesson content, topics you generate lessons for, and any text, PDFs, photos or voice notes you upload as input. Voice you speak to the AI tutor in Talk mode is transcribed and that audio is not stored after transcription. Audio, video or photo reflections you record and attach to a lesson are stored until you delete them.
- Progress and gamification data, your XP, coins, streaks, badges, quiz and test results, study-session activity, and items you unlock in the shop.
- Social data, friends you add and, if you take part, your leaderboard standing and the public profile (display name, avatar and level) you choose to share with other learners.
- Children's profiles (Kids mode), if you set up Kids mode as a parent, we store the child profiles you create: display name, year level, avatar, country, school, chosen subjects, learning style and their progress (XP, coins, streaks, mastery). Children don't have passwords or PINs; a child signs in by choosing their profile from the parent's signed-in account. You create and control these on your child's behalf.
- Usage data, pages visited, lessons generated, features used, error logs and approximate location derived from IP address.
- Billing data. If you subscribe to a paid plan (Plus or Max) or make a voluntary donation, payment is handled by Stripe: we never see or store your full card number, only limited details such as the last four digits, card brand, expiry, your subscription status and a Stripe customer ID. The Free plan collects no payment details at all.
- Device data, browser, operating system, device type, screen size, and (with your permission) microphone audio when you record a voice memo.
3. How we use it
We use your information to:
- Generate lessons adapted to your VARK profile and country's curriculum.
- Personalise the next lesson based on your reflections, quiz answers and mastered concepts.
- Operate the service, sign-in and email verification, billing, support, security, fraud prevention.
- Improve Edapt, debug errors, measure feature usage, understand which subjects need better content.
- Send service emails, receipts, a short welcome series when you join, and occasional reminders about your streaks, study sessions and progress. Every one of these has a one-click unsubscribe link that stops them all. Weekly progress digests are separate and only sent if you turn them on.
- Measure whether our emails are useful: our email provider (Resend) reports delivery, opens and link clicks back to us.
4. AI model training
We do not train our own AI models on your personal content. Edapt sends prompts to large-language-model providers, primarily Groq, Cerebras and Google (Gemini), with OpenRouter as an occasional fallback. When you upload a document, we extract its text on our own servers where possible; scanned documents and photos are read by Google (Gemini) or, as a fallback, Anthropic (Claude).
Being specific about Google (Gemini). We currently use Google's free Gemini API tier. Under Google's own terms, content sent on that free tier may be reviewed by Google and used to improve their models. That applies to lesson topics you type and to text extracted from documents and photos you upload. If you would rather that did not happen, avoid uploading material you consider sensitive. We are working to move this to a paid tier, which carries no-training terms.
Where a provider does offer zero-retention or no-training terms we use them, so on those providers your inputs and the generated lessons are not retained beyond the time it takes to return a response and are not used to train that provider's public models. Some fallback providers may briefly retain requests for abuse monitoring under their own policies.
Internally, we use de-identified, aggregated usage signals (e.g. "28% of lessons in Year 11 chemistry trigger Listen mode") to improve product behaviour. We do not train AI models on your personal lesson content or reflections.
6. Where it's stored
Account, learner-profile and lesson data is stored in an encrypted PostgreSQL database (Neon) hosted in the EU/US. Files you upload or generate (PDFs, photos, audio, video) are stored in Vercel Blob, encrypted at rest. Backups are encrypted. Stored files are served from long, unguessable links rather than behind a sign-in, so anyone you give a file's exact link to can view that file.
7. How long we keep it
- Account data, kept while your account is active.
- Lessons and reflections, kept while your account is active. You can delete any one at any time.
- Child profiles (Kids mode), kept while the parent's account is active. The parent can delete any profile at any time.
- Uploaded files (PDFs, photos, voice memos), kept until you delete them.
- Logs, 90 days.
- Billing records, 7 years (Australian tax law).
When you delete your account, your personal data is erased from our live systems immediately, and from encrypted backups within 30 days, except billing records that we're legally required to keep.
8. Your rights
Under the APPs you can:
- Access the personal information we hold about you.
- Correct anything that's wrong (or use the in-app Memory page to edit/forget).
- Ask us to delete your account and all personal data (within 30 days).
- Export your lessons and reflections.
- Complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you think we've mishandled your data.
To exercise any of these, email edaptlearn@gmail.com.
9. Children and minors
Edapt's main accounts are designed for school-age learners (typically 13+). If you are under 13, you may not create your own Edapt account without verifiable parental or guardian consent.
For younger children, Edapt offers a separate Kids mode. A parent or guardian sets it up from their own account, creates a child profile, and decides what it contains (display name, year level, avatar and subjects). The child signs in by choosing their profile from the parent's signed-in account, no password or PIN of their own. The parent provides consent, controls the profile, and can edit or delete it at any time from their account. We only collect a child's information to run the learning features the parent has enabled, and we don't use it for advertising or show children's details on public leaderboards.
Parents who believe a child has registered a standalone account without consent, or who want a child profile removed, can contact us and we'll delete it.
10. Security
We use TLS for all traffic, hash passwords with bcrypt, and store session tokens using modern, signed JWTs. Vendor access is least-privilege and audited. No system is perfectly secure, if we ever detect a breach affecting you, we will notify you and the OAIC under the Notifiable Data Breaches scheme within 72 hours.
12. Changes to this policy
We may update this policy from time to time. The current version is always on this page, and the "Last updated" date above shows when it last changed.
13. Contact us
Privacy questions: edaptlearn@gmail.com
General support: edaptlearn@gmail.com
See also: Terms of Service.