Privacy Policy

Version 1.0 — Draft for legal review · Effective: [NOT YET PUBLISHED — set on legal sign-off] · Last updated: 2026-08-29

# SomaSkul Privacy Policy

Version 1.0 — Draft for legal review Effective date: [NOT YET PUBLISHED — set on legal sign-off] Last updated: 2026-08-29


## 1. Who operates SomaSkul

SomaSkul ("SomaSkul," "we," "us") is a study companion application for Kenyan secondary students, built around the CBC and KCSE curricula. [LEGAL REVIEW REQUIRED: insert the operating entity's legal name, registration details, and physical/postal address here — not present in the codebase and must come from the business.]

## 2. Scope

This policy covers the SomaSkul mobile application (Android/iOS, built with Expo/React Native) and the SomaSkul backend service it communicates with. It does not cover the separate SomaSkul administrative console, which is an internal tool used by SomaSkul staff, not by students or the public.

## 3. Information you provide to us

When you create a SomaSkul account, you provide:

  • Your name — used to personalize the app and, in ZANA (SomaSkul's AI tutor)

conversations, to address you directly.

  • Your phone number — this is your account identifier and how you log in. SomaSkul

does not use a password or a one-time SMS code; your phone number alone identifies your account on each login. Your phone number is also the account M-Pesa payments are matched against if you subscribe to a paid plan.

  • Your curriculum, class level, and subjects — so SomaSkul can show you the right

content.

SomaSkul does not currently ask for your email address, date of birth, or school name. These fields do not exist in SomaSkul's signup flow today.

### 3.1 Content you submit while using SomaSkul

  • Photos of homework questions or report cards, submitted through the camera or

photo picker, so SomaSkul's AI can read and respond to them. These photos are not stored by SomaSkul. They are sent to our AI provider (Google's Gemini API) for processing and are not saved to any SomaSkul database — they exist only for the moment it takes to generate a response.

  • Questions and messages you type to ZANA, SomaSkul's AI tutor.
  • Report card / exam results you choose to enter, if you use the Performance

Analysis feature — after SomaSkul's AI extracts data from a photo, you must confirm it is correct before anything is saved. Unconfirmed extractions are never persisted.

## 4. Information automatically associated with your use of SomaSkul

  • A locally generated device identifier — not your phone's hardware ID, generated

by the app itself, used to prevent abuse of free-trial and referral offers.

  • Study activity — questions answered, scores, streaks, flashcard reviews, and

similar progress data, so your progress can sync between sessions and (if you use more than one device) between devices.

  • ZANA session summaries — SomaSkul records the subject/topic and a general summary

of a tutoring session (for example, to track which topics ZANA has covered with you). Your full, message-by-message ZANA conversation history stays only on your device — it is never uploaded to SomaSkul's servers. If you uninstall the app or clear its storage, that history is gone and cannot be recovered by SomaSkul, because we never had a copy.

  • A small number of fragments of what you've typed to ZANA may be retained on our

servers as part of how ZANA learns to answer future students' questions better — see §7 below.

## 5. How SomaSkul uses your information

  • To create and operate your account.
  • To personalize content to your curriculum and class level.
  • To power ZANA (your AI tutor), the homework-solving camera feature, flashcards,

practice exams, and revision tools.

  • To process payments and activate your subscription.
  • To sync your study data between devices, if you use SomaSkul on more than one device.
  • To detect and prevent abuse of trials, referrals, and payment flows.
  • To maintain and improve the app.

SomaSkul does not use your information for advertising, does not sell your information, and does not share it with data brokers. SomaSkul has no advertising SDK of any kind integrated into the app.

## 6. AI processing — ZANA, homework solving, and the Research Engine

SomaSkul's tutoring and homework-solving features are powered by Google's Gemini API. When you use these features:

  • Your question, and any photo you submit, is sent to Google's servers to generate a

response.

  • ZANA's instructions to the AI include your class level and curriculum, so it

can tailor its teaching to your grade and follow the right examination conventions. As of 2026-08-28, your name is no longer included in this — SomaSkul minimized this to only the information ZANA actually needs to teach correctly.

  • **If you photograph a report card or a homework page that has your name printed on

it, that name is still visible to Google as part of the image itself** — removing your name from ZANA's written instructions (above) does not remove it from a photo that shows it. SomaSkul does not crop, blur, or otherwise redact names from submitted photos. See docs/legal/GEMINI_PROVIDER_VERIFICATION.md §4.

  • Google's own terms govern how it processes API requests, and **differ by billing

tier: [BUSINESS DECISION REQUIRED — urgent, verified 2026-08-29] on Google's paid tier, prompts and responses are not used to improve Google's products and are logged only briefly for abuse detection; on the free tier**, Google's own terms state submitted content *is* used to improve its products and may be read by human reviewers, and Google explicitly advises against submitting personal information to it. SomaSkul's operator must confirm which tier production traffic is billed under, and record that confirmation (docs/legal/GEMINI_PROVIDER_VERIFICATION.md §7-9), before this policy can state a settled position either way.

If SomaSkul's optional "Research Engine" feature is active (it is switched off by default), a version of your question — including its literal wording — may also be sent to Tavily, a web-search provider, to help ZANA ground its answer in current information. [LEGAL REVIEW REQUIRED / UNVERIFIED: confirm Tavily's current terms regarding data retention and model training.]

See docs/legal/AI_EDUCATIONAL_DISCLAIMER.md for more about the limits of AI-generated answers.

## 7. What SomaSkul retains from AI interactions

SomaSkul's AI tutor "learns" from strong, verified exchanges with students in order to improve future answers to similar questions — this is a background process that never blocks or is visible to you while you study.

  • What's saved is a distilled study note (a definition, an example, common

mistakes to avoid) — not a copy of your conversation.

  • However, **a short excerpt of the question that prompted the note (up to roughly

2,000 characters) is saved alongside it**, to help our team verify the note's accuracy later. This excerpt is not linked to your name or account in our database — it exists in a shared knowledge table with no owner field — but it is retained indefinitely today, and SomaSkul does not yet have an automatic process to delete these excerpts. [This is disclosed here because our audit found it retained in a way that doesn't match a strict "we never keep raw text" claim — see DATA_RETENTION_POLICY.md.]

## 8. Payments

If you subscribe to a paid plan, SomaSkul processes your payment through Safaricom's M-Pesa service. SomaSkul does not process or store credit/debit card numbers — SomaSkul has no card-payment integration.

  • Paybill (the standard way to pay): SomaSkul shows you a paybill number and asks you

to pay using your own phone number as the account reference, from your phone's M-Pesa menu. This step does not send any data to SomaSkul's servers — you are interacting directly with your phone's M-Pesa app.

  • STK push (optional, off by default): if enabled, SomaSkul can request a payment

prompt be sent directly to your phone. This requires sending your phone number and the payment amount to Safaricom's payment API.

  • Your subscription is only ever activated by Safaricom's official payment

confirmation — never by anything the app itself reports. See SUBSCRIPTION_BILLING_TERMS.md.

  • SomaSkul keeps a record of your M-Pesa receipt code, amount, and plan for accounting

and to resolve payment disputes. See DATA_RETENTION_POLICY.md for how long.

## 9. Children's privacy

SomaSkul is a study app intended for use by secondary school students, some of whom may be minors. As of this policy's effective date, SomaSkul does not have a separate parent account, parental consent flow, or age-verification step — account creation is self-service, using only a name and phone number. [LEGAL REVIEW REQUIRED / BUSINESS DECISION REQUIRED: SomaSkul's operator must determine (a) SomaSkul's actual target age range, and (b) whether that requires building an age-gate, parental-consent flow, or other child-data safeguard before or shortly after publishing this policy. See LEGAL_COMPLIANCE_AUDIT.md §1 for the full finding and PARENT_GUARDIAN_NOTICE.md for guidance in the meantime.]

If you are a parent or guardian and believe your child has provided personal information to SomaSkul and you would like it reviewed or removed, see §14 (How to Contact Us) and DATA_SUBJECT_REQUESTS.md.

## 10. Data sharing

SomaSkul shares information only:

  • With Google (Gemini API), to generate AI tutoring/solving responses (§6).
  • With Safaricom, to process payments (§8).
  • With Tavily, only if the optional Research Engine feature is active (§6).
  • With Supabase, our database and file-storage provider, which hosts SomaSkul's data

under access controls SomaSkul configures (see THIRD_PARTY_DATA_PROCESSORS.md).

  • If required by law, or to protect SomaSkul's rights, users, or the public.

SomaSkul does not sell personal information. SomaSkul has no advertising SDK and does not share data with advertisers or data brokers.

## 11. Data security

SomaSkul restricts database access using row-level security, so that (with the exception noted below) one student's data cannot be read by another student. Payment confirmation is verified server-side and can never be set by anything the app itself reports. [Note for legal review, not for public copy: our own audit found that every SomaSkul staff account with admin access can currently read a student's name and phone number, including roles intended to be read-only or content-only — see LEGAL_COMPLIANCE_AUDIT.md §5.6. This is an internal access-control gap the engineering team is addressing, not a claim to soften in the public policy — if this policy states "only authorized staff with a need to know can access your data," that statement should not be published until it is actually true.]

No method of transmission or storage is 100% secure, and SomaSkul cannot guarantee absolute security.

## 12. Data retention

See DATA_RETENTION_POLICY.md for the full, per-category retention table. RETENTION DECISION REQUIRED for several categories — SomaSkul does not currently have engineering-enforced retention limits for most data; most information is kept indefinitely today.

## 13. Account and data deletion

[LEGAL REVIEW REQUIRED / LAUNCH BLOCKER] As of this policy's drafting, SomaSkul does not have a self-service "delete my account" button in the app. If you would like your account or data deleted, contact us using the details in §14, and see DATA_SUBJECT_REQUESTS.md for what to expect. SomaSkul's engineering team is required to resolve this gap — see DATA_DELETION_POLICY.md and LEGAL_LAUNCH_CHECKLIST.md — and this section must be rewritten once a deletion process (in-app or otherwise) exists, rather than published as-is with a manual-request-only process, if Google Play or legal counsel determines a manual process is insufficient.

## 14. How to contact us

[BUSINESS DECISION REQUIRED: insert a real support email/contact channel. SomaSkul's codebase has no support-contact mechanism built in today — this must be a real, monitored channel before publishing.]

## 15. Changes to this policy

We will update the "Last updated" date above when this policy changes. Material changes will be highlighted in the app. [BUSINESS DECISION REQUIRED: decide the actual mechanism for notifying users of policy changes — no such mechanism exists in the app today; see CONSENT UX section of LEGAL_LAUNCH_CHECKLIST.md.]


*This document is Version 1.0 of SomaSkul's Privacy Policy and has not yet been reviewed by legal counsel or published. Do not treat it as SomaSkul's operative privacy policy until the effective date above is set and all [LEGAL REVIEW REQUIRED] / [BUSINESS DECISION REQUIRED] markers are resolved.*