Privacy Policy
How ALE handles learner data. Written to be actually read. GDPR-aligned and compliant with the Kenya Data Protection Act 2019 and the equivalent East African data-protection frameworks where they apply.
The one-line version
Your mastery record and everything you produce on ALE belongs to you. We collect what we need to run the adaptive loop, we don't sell it, we don't share it with advertisers, and you can export or delete it at any time.
Who we are
ALE (Adaptive Learning Engine) is operated by Lindela Learning Ltd (Kenya). References to we, us, and ALE in this policy mean Lindela Learning Ltd. Our privacy contact is privacy@lindela.io.
What we collect
- Account information — for adult accounts: email address, display name, authentication provider (Google, Microsoft, or Keycloak) and provider-issued identifier. For kid accounts: chosen username, hashed PIN, display name, self-declared age, and the guardian email address for confirmation.
- Learning activity — every diagnostic, adaptive question response, hint request, layered-explanation view, tutor-chat turn, oral-assessment recording, and time on task. This is what powers the adaptive loop; without it, ALE cannot personalise.
- Mastery state — per-concept mastery probability, FSRS spaced-repetition state, IRT ability estimate, and derived analytics (progress, weekly digest, gap map).
- Device and session — IP address at request time, browser user-agent, device type, and locale. Retained in access logs for security and abuse investigation only.
- Payment metadata — for paid accounts we store the payment-provider transaction identifier and status. We never store card numbers, CVVs, or M-Pesa PINs — those live only with the payment processor.
What we use it for
- Running the adaptive learning loop for the account it belongs to.
- Showing you (and, for kid accounts, your guardian) your own progress and mastery map.
- Delivering the service you asked for — diagnostics, adaptive sessions, tutor chat, ALE Assist matching.
- Preventing abuse and defending the service from scraping, account-takeover, and bulk-extraction attempts.
- Metering AI-credit usage so we can bill you correctly for the compute you invoke.
- Aggregated, de-identified analytics we use internally to improve the platform. Never sold, never linked back to you.
What we never do
- Sell learner data to third parties. Ever. This is not a business we are willing to be in.
- Share learner data with advertising networks. There are no ads on ALE.
- Use learner data to train third-party foundation models. Prompts sent to LLM providers are subject to no-training terms in our provider contracts.
- Share individual learner data with a school or institution without the account-holder’s (or, for a minor, the guardian’s) consent.
- Read tutor-chat transcripts for any purpose other than delivering the tutor-chat feature, keeping the account-holder’s record, and safety review.
Children under 18
ALE is designed for learners of every age from about 8 upward. We follow the Kenya Data Protection Act 2019 rules on minors and are aligned to COPPA (US) and GDPR-K (EU) for learners covered under those frameworks.
- A learner under 13 can create a kid account with a username and PIN. A guardian email is collected at signup and a confirmation email is sent immediately. The account has a 7-day soft-lock — it can be used during that window but requires guardian confirmation to remain active beyond it.
- Guardians can view, export, or delete a minor learner’s data at any time by emailing privacy@lindela.io from the confirmed guardian address.
- We do not target advertising to minors, we do not profile minors for any purpose other than the adaptive loop, and we do not share minor learner data with any third party except processors under strict data-processing agreements.
Where data lives
Learner data is stored in PostgreSQL databases operated by ALE on servers located in the European Union (Contabo, Germany). Cross-border transfer to processors (payment providers, the LLM inference provider used for AI features) is done under standard contractual clauses aligned to GDPR and KDPA 2019.
- Primary and standby PostgreSQL 17 databases with row-level security per learner.
- Encrypted backups retained on redundant object storage; encrypted at rest.
- TLS 1.2+ in transit for every request; HSTS enforced on the public domain.
How long we keep it
- Active learner data — retained for the life of the account.
- Deleted accounts — hard-deleted within 30 days of deletion request, except for records we are legally required to retain (tax invoices for paid accounts).
- Access logs — 90 days, then purged.
- Backups — encrypted, rolling 35-day retention; a deletion request is honoured across restored backups.
Your rights
You (or the guardian of a minor learner) have the right to:
- Access all data we hold about the account, in a standard exportable format.
- Correct any inaccurate data.
- Delete the account and all associated data (subject to legal retention obligations).
- Restrict processing while a query is being resolved.
- Withdraw consent to processing that relies on consent, at any time.
- Lodge a complaint with the Office of the Data Protection Commissioner (Kenya) or the equivalent authority in your country.
To exercise any of these rights, email privacy@lindela.io. We respond within 30 days.
Cookies and session storage
ALE uses HTTP-only cookies to keep you signed in and to remember your interface-mode preferences (adult / kid, language). We do not use tracking cookies, third-party advertising cookies, or cross-site profiling. A short-lived cookie (ale_age_ok, 5 minutes) caches the age-gate check so protected routes don’t make repeated API calls on every page load.
Anti-scraping and content protection
The content library — every lesson, worked example, past paper, and Kamusi entry — is free to read for signed-in learners. It is not free for competitors, LLM training runs, or scraper farms. To keep the library free for actual learners we bind every request to a learner-ID, rate-limit per account, and do not offer a bulk-export API. Learners can export their own notes and mastery record at any time; nobody exports the library.
Changes to this policy
We update this policy from time to time. Substantive changes are announced by email to all account holders at least 30 days before they take effect. The current version is always available at this URL.
Last updated 2026-08-09. Questions? privacy@lindela.io