Privacy policy

What we collect, why, and what you control.

Last updated: May 31, 2026

Informations que nous collectons

Nous collectons des données pour fournir et améliorer nos services

Account & identity:
Nom, e-mail, rôle (étudiant ou éducateur) et jetons d'authentification stockés via le flux d'authentification API.
Course activity:
Inscriptions, progression des modules, tentatives de quiz, soumissions de devoirs, présence aux cohortes et certificats émis.
Content & uploads:
Médias stockés via le générateur de programme (vidéos, PDF, ressources de leçon) avec leurs métadonnées (durée, taille de fichier).
Billing & payouts:
Historique d'achat, tarification, partage de revenus et comptes de paiement configurés dans le tableau de bord éducateur.
Appareil et diagnostics :
Cookies, adresses IP et journaux d'API qui aident à sécuriser les comptes, à corriger les erreurs et à maintenir les performances du service.
Phone & messaging preferences:
Phone number (optional), country code, and your choices for receiving WhatsApp live-class reminders, SMS fallbacks, and course updates. Provided only when you opt in.
Push notification tokens:
When you install our mobile app or enable browser push, we store an FCM/Expo token, your platform (iOS, Android, or web), and a device label so we can deliver class reminders, chat alerts, and order updates. You can disable notifications at any time from system settings.
Live class audio, video & chat:
Live sessions are powered by Daily.co. Your camera, microphone, and screen-share streams are routed through Daily.co only while you are in a session, and recordings are stored on our AWS S3 bucket only when the educator enables recording. In-call chat messages are processed by Daily.co for the duration of the session.
In-app messages & community:
Chat messages, attachments (images, files) you share in course discussions, mentorship conversations, and reactions. We never sell or share these with advertisers.
AI features (voice & avatar):
If you choose to clone your voice or generate an AI avatar, audio and image samples you submit are sent to our AI processors (HeyGen and D-ID) to produce your custom voice or avatar, and the resulting media is stored on our infrastructure. You can delete your custom voice or avatar from your educator settings at any time.
AI assistance for course content:
When you use the AI Course Wizard, AI tutor, or quiz auto-grading, the text you submit is sent to OpenAI or AWS Bedrock for processing under our enterprise agreements; these processors do not train their models on your data.
Educator payout details:
Educators who receive payouts provide bank account details, routing information, and tax identifiers (e.g., BVN/TIN) needed to disburse earnings. This data is stored encrypted and shared only with our payment processors.
Accessibility preferences (sensitive):
If you complete the accessibility setup, your self-reported vision, hearing, motor, and screen-reader needs are stored to personalize the interface. This is sensitive data, we never share it and you can clear it from settings.
Marketing attribution:
When you arrive via a referral link or marketing campaign, we capture UTM parameters and referral codes in your session so educators can credit referrers and we can measure campaign effectiveness.

Comment nous utilisons vos informations

Vos données alimentent votre expérience d'apprentissage

Offrir des expériences :
Personnaliser les tableaux de bord, reprendre les leçons, émettre des certificats et alimenter les sessions en direct via la console éducateur.
Exploiter la plateforme :
Traiter les transactions, calculer les paiements, envoyer les rappels de cohorte et exécuter les analyses visibles sur les tableaux de bord éducateur et étudiant.
Improve LearnKasts:
Les analyses agrégées et les retours d'utilisation des fonctionnalités (générateur de programme, devoirs, centre d'aide) guident les décisions produit.
Protéger la communauté :
Détecter la fraude, faire respecter les règles de la communauté et se conformer aux demandes légales liées au contenu des cours ou à l'activité financière.
Communiquer avec vous :
Envoi d'alertes système, conseils d'intégration, notes de version et réponses du support lorsque vous ouvrez un ticket.

Vos contrôles et sécurité

Vous contrôlez vos données

Account settings:
Mettez à jour vos informations de profil, modifiez les rôles et gérez les préférences de notification depuis votre tableau de bord.
Exports et suppression de données :
Les éducateurs peuvent exporter les données de cours ; les apprenants peuvent demander la suppression de leur compte. Nous ne conservons que ce qui est requis pour la conformité (paiements, dossiers fiscaux).
Media ownership:
Les éducateurs contrôlent leurs téléversements. Nous les stockons en toute sécurité via les services configurés dans ce code (par ex. pilotes S3).
Security practices:
Les jetons API, les cookies de session et l'état Livewire sont protégés par HTTPS, validation côté serveur et journaux d'activité conservés dans les services d'analytique.
Contact support:
Contactez-nous via la page de contact pour toute question ou pour exercer vos droits sur les données.

Third-party processors

Services that help us run LearnKasts

Paystack, payment processing
Card and bank details are entered on Paystack-hosted checkout. We receive only transaction references, status, and the last 4 digits of cards.
Daily.co, live video classrooms
Real-time audio/video, in-call chat, and recording when enabled by an educator.
HeyGen and D-ID, AI avatar & voice generation
Voice samples and reference photos used to create your custom avatar or voice.
OpenAI and AWS Bedrock, AI text generation
AI Course Wizard, tutor responses, automated quiz grading, and AI website-builder content. No training on your data.
Amazon Web Services (AWS S3, CloudFront)
File storage for course videos, lesson assets, recordings, and uploaded images, served via CDN.
Mailgun and MailerLite, email delivery
Transactional emails (password resets, receipts, course updates) and marketing automations.
Firebase Cloud Messaging and Expo, push notifications
Routing push notifications to your device.
Pusher, real-time updates
Live progress, chat presence, and notifications inside the app.
Google, single sign-on, Translate, Analytics
OAuth login (your Google account email and profile name), translation of UI strings, and aggregated traffic analytics.
Meta (Facebook) Pixel
Conversion tracking on marketing pages. You can opt out via the cookie banner.
Laravel Nightwatch, error & performance logs
Application error traces and request performance metrics for debugging.

Compliance & contact

How long we keep your data
Account data is kept while your account is active. After deletion we keep only what we are legally required to retain (financial records: 7 years; tax records: as required by Nigerian, EU, and US law). Anonymized analytics may be retained indefinitely.
International transfers
Our infrastructure is hosted on AWS regions that may be outside your country (e.g., us-east-1, eu-west-1). Where required, transfers are governed by Standard Contractual Clauses or equivalent safeguards.
Children & minors
LearnKasts is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13 (or 16 in some EU/UK jurisdictions). If we learn that we have collected data from a child below the applicable age, we will delete it. Parents and guardians may contact us to request review or deletion.
Legal bases (GDPR/NDPR)
We process your data based on: (a) the contract to deliver the courses you enrol in; (b) your consent for marketing emails, the AI avatar/voice features, and analytics cookies; (c) our legitimate interests in security, fraud prevention, and product improvement; and (d) legal obligations (tax, payouts, compliance requests).
Your rights
You may request access to, correction of, export of, or deletion of your personal data, and you may object to or restrict certain processing. Use the in-app data export and deletion tools, or email us at the address below.
Privacy contact (DPO)
Email privacy@learnkasts.com for any privacy request or complaint. We aim to respond within 30 days. You may also lodge a complaint with the Nigeria Data Protection Commission (NDPC) or your local supervisory authority.

Questions about your data?

Des questions sur vos données ?

Contact our DPO