01 Data at a glance
If you read nothing else, read this table. It covers every category of data the app touches, where it actually lives, and whether it ever leaves your device.
| Data | Where it lives | Leaves your device? | Why |
|---|---|---|---|
| Profile (name, grade, school, student ID, avatar) | On-device database | Never | Personalizes your Learn/Journal/Toolkit screens |
| Journal entries & service log | On-device database | Never | Your reflection & hours-served history |
| Journal photos (camera) | On-device app storage | Never | Attach evidence of service to an entry |
| Toolkit data (Budget, Research, Decisions, Conflict, Leadership, Data Collection, Social Enterprise plans) | On-device database | Never | Save your work between sessions |
| Portfolio export file | On-device / your chosen share target | Only if you share it | Print or hand in your portfolio |
| AI Hub chat messages | Sent over HTTPS for the request only | Yes — to generate a reply | Powers Reflect / Brainstorm / Roleplay / Review Plan |
| Anonymous AI Hub identity & session tokens | On-device (private app storage) + Supabase | Yes — no name/email attached | Lets the AI Hub enforce a fair daily limit |
| Daily AI usage counter | Supabase database, keyed to the anonymous ID | N/A — server-side only | Prevents abuse of the shared AI quota |
| App update checks | Google Play services | Handled by Google, per Google's policy | Prompts you to update the app |
Anything not in this table — location, contacts, microphone, biometrics, payment details, browsing history — the app does not access, request, or collect, full stop.
02 Information we collect
Information you type in, that stays on your phone
Almost everything you do in this app — filling in your profile, writing a journal entry, logging service hours, running a Budget Calculator, working through the Decision Wizard, building a Social Enterprise plan, recording a Conflict Resolution attempt, taking a Leadership Assessment, or capturing a journal photo — is written straight to a local Room database and local app storage on your device. We never see it, because it never reaches a server we operate.
The "Student ID" field on your profile, if you fill it in, is a free-text field you define yourself — the app does not validate it against any school system or send it anywhere.
Information created automatically for the AI Hub
The first time you open AI Hub, the app silently creates an anonymous identity for your install using Supabase Authentication — no name, email, or password involved. It stores an access token, a refresh token, and that anonymous user ID in a private, app-only preferences file on your device. This identity exists solely so the AI Hub can apply a fair, per-install daily usage limit; it is not linked to your Profile name or any other information you've entered elsewhere in the app.
Information you send when you use the AI Hub
When you send a message in Reflect, Brainstorm, Roleplay, or Review Plan mode, the text you type — and, in Roleplay mode, the character name and scenario text for that exercise — is sent to our backend to generate a reply. See Section 3 for exactly where that goes.
Information we do not collect
- No email address, phone number, or password — the app has no account system beyond the anonymous AI Hub identity described above.
- No analytics events, no crash reports, no usage telemetry.
- No location data (the app never requests location permission).
- No contacts, calendar, microphone, or biometric data.
- No payment or financial information collected by us directly — any in-app purchase is processed by the app store (e.g. Google Play), not by us.
03 The AI Hub, in detail
Because this is the only feature where your words leave your device, we're explaining it more thoroughly than a typical privacy policy would.
When you send a message, here's the exact path it takes:
What we ask you not to type
Because AI Hub messages are processed by a third-party model, please avoid typing your full name, school ID, address, phone number, or anything else you wouldn't want processed by an external AI service — even though we don't store it, it's good practice never to share identifying details with any chat AI.
Rate limits, not surveillance
The daily usage cap exists to keep the AI Hub free and available for everyone, not to profile you. Your anonymous ID cannot be traced back to your name, Profile information, or journal content — those never leave your device in the first place.
04 How we use information
Because nearly everything is local-only, "use" mostly means the app reading its own local database to show you your own content back. The narrow exceptions:
- Generating AI Hub replies — your message text is used only to produce the response you asked for.
- Enforcing the AI Hub daily limit — your anonymous ID and a request count are used to decide whether to allow another request today.
- Checking for app updates — Google Play services checks whether a newer version is available and can prompt an in-app update.
We do not sell your information to data brokers, train our own models on your journal content, or make automated decisions about you. We don't currently run ads — if that changes, we'll explain here exactly what an ad network would use before it ships, not after.
05 Third parties we rely on
We keep this list intentionally short. These are the only outside services the app talks to, and only when you use the AI Hub or check for updates.
Supabase
Hosts the anonymous sign-in, the daily-usage counter, and the Edge Function that relays AI Hub requests. Supabase's own privacy practices are described at supabase.com/privacy.
OpenAI
Generates the actual AI Hub reply text from the message you sent, server-side — the model never runs on your device and OpenAI's key never ships inside the app. See openai.com/policies/privacy-policy.
Google Play services
Powers the in-app update prompt (Google Play's In-App Update API) and, if the app was installed from Google Play, standard Play Store distribution. Governed by Google's Privacy Policy.
As of this policy's effective date, we haven't integrated an analytics platform, advertising network, or crash-reporting SDK — there isn't a fourth row to add to this list yet. If we add an ad network later (for example, to keep the app free while offering optional paid content), we'll add it here — and to the summary table in Section 1 — before it ships, not after.
06 Permissions, explained
Camera
Used only when you tap "Add photo" in a Journal entry. Photos are written straight to the app's own local storage — they're never uploaded or shared unless you export or share them yourself.
Internet
Required only for AI Hub requests and update checks. Every other screen — Learn, Journal, and all seven Toolkit tools — works completely offline.
Notifications
Used for local reminders you set yourself (e.g. a service-log nudge), scheduled entirely on your device. We do not send push notifications from a server.
Storage
Requested only on older Android versions (9 and below) to save exported portfolio files and photos where the system requires it. Modern Android versions don't need this permission at all.
07 Storage & security
- On-device data sits inside the app's private, sandboxed storage area, which Android isolates from other apps by default. It's as secure as your device's own lock screen and encryption.
- AI Hub traffic travels over HTTPS/TLS between your device and Supabase, and again between Supabase and OpenAI.
- Secrets stay server-side. The OpenAI API key is never bundled inside the app — it's held only in the server-side function that talks to OpenAI. The "anon" key shipped inside the app is a public project identifier, not a secret, and it's constrained by database-level access rules so it can't be used to read other users' data.
- No method of transmission or storage is 100% secure, and we can't guarantee absolute security — but we've deliberately minimized what ever leaves your device in the first place, which minimizes what there is to secure.
08 Retention & deletion
| What | How long it's kept | How to delete it |
|---|---|---|
| Profile, journal, Toolkit data, photos | Until you delete it or uninstall | Profile → Reset my data, or uninstall the app |
| Anonymous AI Hub session tokens | Until app data is cleared or the app is uninstalled | Clear app storage in Android Settings, or uninstall |
| AI Hub message content | Only for the moment it takes to generate a reply — not retained afterward | Nothing to delete — it isn't stored server-side |
| Daily AI usage counter | Rolls over daily; tied only to your anonymous ID | Contact us — see Section 13 |
Tapping Reset my data in your Profile permanently and immediately wipes your local database. This cannot be undone, and we cannot recover it for you — we never had a copy.
09 Students & children's privacy
This app is built for CBC (Competency-Based Curriculum) learners, many of whom are minors. We designed it local-first specifically so that a student can use every core feature — Learn, Journal, and all seven Toolkit tools — without creating an account, entering an email address, or sending personal information anywhere.
We do not knowingly collect personal information from children beyond what a student chooses to type into their own on-device Profile or Journal (which never leaves the device) or into an AI Hub message (see Section 3 for exactly how that's handled). As of this policy's effective date, the app does not serve ads. If we introduce advertising in the future, we'll design it to be appropriate for a student audience — never targeted using a child's personal information — and update this section, along with Section 5, before it ships.
If you're a parent, guardian, or teacher and believe a student has shared personal information through the AI Hub that concerns you, contact us at the address in Section 13 — because we don't retain AI Hub message content or tie it to a real identity, in most cases there is nothing further stored to remove, but we're glad to explain the specifics of your situation.
10 Your rights & choices
Wherever you are, and whatever privacy law applies to you (GDPR, CCPA, Kenya's Data Protection Act, or another), here's how those rights map onto an app that stores almost nothing about you on our servers:
Access & portability
Everything we hold about you that's readable is already visible inside the app. Use Portfolio Export to generate a copy of your journal and service history for yourself.
Deletion
Profile → Reset my data deletes your on-device data instantly. Uninstalling the app removes everything, including the local AI Hub session.
Opt out of network use entirely
Simply don't open AI Hub. Every other part of the app works fully offline, so you can use the whole app without a single network request.
Control notifications
Disable reminder notifications anytime from your device's system settings for this app.
11 International processing
When you use the AI Hub, your message is processed by infrastructure operated by Supabase and OpenAI, which may run in countries other than your own (typically the United States or the European Union, depending on the provider's regional setup). Those providers maintain their own safeguards for cross-border data transfer under their respective privacy policies, linked in Section 5. If you'd rather your messages not be processed outside your country, the safest choice is to not use the AI Hub — every other feature stays entirely on your device, wherever you are.
12 Changes to this policy
If we change what data the app collects or how the AI Hub processes messages, we'll update the "Effective" date at the top of this page and, for material changes, call it out in the app's release notes. We encourage checking back here occasionally, especially before a major app update.
13 Contact us
Questions, concerns, or a request related to this policy — including asking us to look into the daily usage counter tied to an anonymous ID? Reach out:
Please include "Privacy" in the subject line so it reaches the right inbox.
This policy is written in plain language on purpose. If any section is unclear, that's on us to fix — tell us and we'll clarify it.