Legal

Privacy Policy

Last updated: October 7, 2026

This Privacy Policy explains what information ElimuApp receives, stores, and uses when you create an account, use learning resources, contact us, or make a subscription payment.

1. Who is responsible for your information?

ElimuApp is operated by Online Tutors LTD. Questions about this policy or your information may be sent to examvista16@gmail.com.

2. Information collected during registration

When you register, the application requires your email address, password, first name, last name, phone number, and institution. The selected package may be received during registration, but new accounts are created on the Free plan; paid access is applied only after confirmed payment.

Passwords are stored as hashes rather than as readable passwords. Password-reset requests create a time-limited reset token; the database stores a hash of that token, not the raw token. Reset links may be delivered by the configured email provider or logged server-side when email delivery is not configured.

3. Account and profile information

The user record can include your email, name, phone number, institution, package, account status, sponsorship value, role, payment date, and account creation or update dates. Administrative fields are used to operate access and the service. Authentication creates an API token with an expiry; the client authentication module manages the signed-in session in the browser.

4. Learning and activity information

ElimuApp stores and processes learning resources and their associations with categories, school levels, classes, subjects, and creators. Resource records include titles, descriptions, file or external-resource details, access settings, visibility, and archive information. The service increments resource view and download counters. These counters are aggregate resource activity in the current implementation; the code does not create a per-user learning-history table for every view or download.

5. Subscription and M-Pesa information

When a payment is initiated, the server records the user, amount, M-Pesa phone number, checkout request ID, selected plan, status, timestamps, and, after a successful payment, the M-Pesa receipt number. Payment confirmation updates the account package, active status, and payment date. Plan prices are checked and set on the server.

M-Pesa processing uses Safaricom’s Daraja service. ElimuApp does not receive or store your M-Pesa PIN. Payment credentials and callback secrets are configured server-side and are not exposed to the client. Safaricom may process information under its own privacy terms.

6. Technical information, cookies, and similar technologies

The codebase does not show an ElimuApp-owned advertising tracker or analytics SDK. The application does load Drift as a client-side customer-messaging service, which may use cookies or similar technologies according to Drift’s own settings and privacy policy. Google Fonts are loaded for the interface. Authentication and service modules may use browser-managed session storage such as tokens or cookies; the exact browser mechanism is controlled by the configured Nuxt authentication module and can vary by deployment.

Other browser storage found in bundled third-party interface libraries is used for technical functions such as layout or media behavior. We have not identified a separate ElimuApp purpose for advertising or cross-site profiling in the application code.

7. How information is used

  • to create, authenticate, secure, and administer accounts;
  • to provide learning resources and enforce plan-based access;
  • to process, confirm, reconcile, and support M-Pesa payments;
  • to respond to password-reset, support, and service requests;
  • to maintain, troubleshoot, and protect the platform; and
  • to produce aggregate resource, user, and payment reporting for authorized administrators.

8. Sharing and service providers

Information may be shared with service providers only as needed to run the features described above, including Safaricom for M-Pesa, Drift for customer messaging, the configured email provider for password resets, hosting or infrastructure providers, and authorized administrators. The current code does not establish a list of provider locations, subprocessors, or international transfer safeguards, so those details must be confirmed by the business owner before publication as final legal terms.

We do not sell personal information. We may disclose information when required by law, to protect the platform or users, or as part of a lawful business reorganization.

9. Storage and retention

Account, resource, activity-counter, and purchase records are stored in the application database and related server storage. Uploaded resource files may be stored on the configured application drive. The codebase does not define a complete retention schedule for each category of information. Records may be retained for as long as needed to provide the service, resolve disputes, meet accounting or legal obligations, and maintain security. The business owner should confirm the final retention periods.

10. Security

The application uses password hashing, expiring authentication tokens, authenticated endpoints for account and payment actions, server-side plan pricing, protected payment callbacks, and scoped payment-status lookups. No online service can guarantee absolute security. Keep your password and M-Pesa PIN private and contact us immediately about suspected unauthorized access.

11. Children and young learners

ElimuApp is presented for learners including ages 4–18. A parent, guardian, school, or other responsible adult should help a child create and use an account and should provide any required consent. The codebase does not record a separate age, date of birth, or parental-consent field, so the business owner should confirm the operational process and legal requirements for children’s data before launch.

12. Your choices and rights

You may review or update available profile information, request assistance with incorrect information, reset your password, and request deletion of your account. The authenticated API includes an account-deletion operation that deletes the user record and logs out the current session. Deletion may not immediately remove records that must be retained for payment, legal, security, backup, or legitimate operational reasons.

To make a privacy request, contact examvista16@gmail.com. The business owner should confirm the applicable Kenyan data protection rights, response timelines, verification process, and complaint authority before this policy is finalized.

13. Changes to this policy

We may update this policy when the platform, providers, or legal requirements change. The revised policy will be posted here with a new “Last updated” date. Continued use after an effective update means the revised policy applies to future use, subject to any notice required by law.

14. Contact

Online Tutors LTD
examvista16@gmail.com