uni.africa

Legal · uni.africa

Privacy Policy

How we collect, use, share and protect your information when you use uni.africa's website, mobile app and AI tutor.

Draft — not yet in effect. Prepared 12 July 2026 for the Phase-1 pilot build. This draft is compiled from uni.africa's internal Data Protection Impact Assessment, product requirements and system specification so the platform has a complete, accurate privacy policy to build against and test consent flows with — it is not a substitute for review by qualified counsel.

It must be reviewed and formally approved before it is published as a live, binding policy or linked from a production consent checkbox. See README.md in this folder for sourcing notes and open items.

1.Who this policy covers

This policy explains how uni.africa ("uni.africa", "we", "us", "the Platform") handles personal data for anyone who visits our website, registers for an account, uses the mobile app, or interacts with the AI tutor. It applies to the countries we operate in at any given time, starting with Kenya.

Operator detail pending: the formal registered entity name, registration number and registered address that will appear here are still being finalised alongside incorporation and legal counsel (see README.md). Until that's settled, treat "uni.africa" in this document as referring to the platform operator generally.

2.Information we collect

We collect the minimum information needed to run the platform, deliver courses, process payments and keep accounts secure:

Categories of personal data we process
CategoryExamplesSource
Identity dataName, email address, phone numberYou, at registration
Authentication dataHashed password (we never store your plain-text password), one-time login codesGenerated when you register or sign in
Profile dataCountry, language preference, date of birth (for the age check below)You
Learning dataCourse progress, quiz attempts and scores, AI tutor questions and session history, certificates earnedGenerated as you use the platform
Financial dataTransaction reference and payment status (never your card number or M-Pesa PIN — see §6)Our payment processor
Device dataDevice model, OS version, available storage/RAMCollected automatically, to serve you a working offline pack
Usage dataPages visited, session duration, sync events, crash reportsCollected automatically
Location dataCountry-level only, derived from your IP addressCollected automatically; used only to route you to the right regulatory and payment setup — we do not collect precise GPS location

We do not intentionally collect sensitive categories of data (health status, biometric data, religious or political beliefs). Course content that happens to touch on sensitive subjects is not linked to a structured profile field about you.

3.Age requirement

uni.africa currently requires learners to be 18 years or older to register. We ask for your date of birth at sign-up specifically to enforce this. If you're under 18, you can't create an account yet — we keep a waitlist message for when a supervised experience for younger learners becomes available, with a parental-consent process required by law before that opens.

4.How and why we use your information

We rely on one of three legal bases for each way we use your data:

  • To deliver the course you enrolled in or purchased (contract performance) — account access, progress tracking, certificates, customer support.
  • Legitimate interests — keeping the platform secure, preventing fraud and abuse, understanding aggregate usage so we can improve the product, and improving the AI tutor using de-identified data.
  • Your consent — for anything optional, like marketing messages or beta features. You can withdraw consent at any time; we stop using your data for that purpose from then on.

We do not sell your personal data. We do not use it to build advertising profiles.

5.The AI tutor and your data

When you ask the AI tutor a question, here's what actually happens: your question is matched against the course content you're enrolled in, and that combination — course excerpts plus your question text — is sent to our AI provider to generate an answer. Your name, email, phone number and learner ID are never included in that request. The response is logged against your account (so your tutor history is there when you come back), but the provider itself only ever sees the course-content-plus-question exchange, not who you are.

If the AI tutor can't reach the network (you're offline), your question is queued on your device and answered once you're back online — it is never invented or guessed at locally without the same grounding.

You can rate any tutor response with a thumbs up or down. Low-rated responses may be reviewed by a human as part of quality and safety moderation. Ratings feed into improving the tutor over time.

Who answers your questions: our primary AI provider is Anthropic (Claude). If that service is unavailable, questions are automatically routed to a self-hosted fallback model instead — either way, the no-personal-data-in-the-prompt rule above applies.

6.Who we share information with

We share the minimum necessary data with a small set of service providers who help us run the platform. We do not permit them to use your data for their own purposes.

Service providers we currently use (updated as our stack changes)
ProviderWhat they doWhat they see
FlutterwaveProcesses M-Pesa and card paymentsPayment details needed to process your transaction. We only ever receive back a transaction reference and status — never your card number or mobile money PIN.
Africa's TalkingSends SMS one-time login codesYour phone number and the code itself, only when you request one
Anthropic (Claude API)Powers the connected AI tutorCourse excerpts and your question text — never your name, contact details or account ID (see §5)
Hosting & infrastructure (Hetzner, Cloudflare)Runs our servers and protects the site from abuse/DDoSWhatever passes through our servers, protected by the safeguards in §9
Email deliverySends transactional email — verification, receipts, certificatesYour email address and the message content

We may also disclose information where required by law, to enforce our Terms of Service, or to protect the rights, property or safety of uni.africa, our learners or the public.

7.International data transfers

Our primary database runs on servers in the European Union. If you're joining us from Kenya (or another market outside the EU), that means your data crosses a border to reach it. We rely on the safeguards required for that: our AI provider is covered by Standard Contractual Clauses, and we document cross-border transfers as required under Kenya's Data Protection Act 2019 (§48–49) as part of our regulatory registration.

8.How long we keep your information

  • Active accounts: for as long as your account is active and for as long as needed to provide the service.
  • After you delete your account: your account is deactivated immediately and your data is scheduled for permanent deletion 30 days later (see §10 for how to request this). This includes uploaded files such as certificates and avatars.
  • AI tutor logs: de-identified (pseudonymised) after 90 days regardless of whether you've deleted your account — a session log is no longer traceable back to you after that point.
  • Crash and diagnostic logs: deleted after 30 days.
  • Marketing data (e.g. a waitlist signup): kept only until you withdraw consent or ask us to delete it.
  • Anonymised aggregate analytics (statistics that can no longer be tied to you): may be retained indefinitely to understand how the platform is used over time.

9.Security measures

We take a defence-in-depth approach:

  • Passwords are hashed with argon2id — we cannot see or recover your actual password.
  • Sign-in sessions use short-lived (15-minute) access tokens with a separate, revocable refresh token.
  • All traffic is encrypted in transit (TLS 1.3, with 1.2 as a fallback only for older Android devices).
  • Data at rest is encrypted on our servers (full-disk encryption) and in object storage.
  • On your device, downloaded course packs and progress data are encrypted with a device-bound key.
  • Login and one-time-code attempts are rate-limited to slow down attackers.
  • We run automated dependency and vulnerability scanning, and no code with a known high-severity vulnerability is deployed.

No system is perfectly secure, and we can't guarantee absolute security — but the measures above reflect what we consider proportionate for the data we hold, reviewed as the platform grows.

10.Your rights and choices

Depending on where you live, you may have rights under the Kenya Data Protection Act 2019, the EU GDPR, Nigeria's NDPR, South Africa's POPIA, or a similar law. In summary, you generally have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data — most profile fields can be edited directly in the app.
  • Delete your account and data ("right to erasure") — request this any time from the app (Settings → Delete account) or by emailing us. We soft-delete immediately and permanently erase within 30 days, per §8.
  • Object to or restrict certain processing, e.g. marketing.
  • Data portability — request an export of the data you provided us.
  • Lodge a complaint with your local data protection authority (in Kenya, the Office of the Data Protection Commissioner) if you believe we've mishandled your data.

To exercise any of these rights, contact us using the details in §14. We'll respond within the timeframe required by applicable law.

11.Automated decision-making

We use an automated recommendation feature that looks at your quiz results and progress to suggest what to study next. This is a convenience, not a gate: it doesn't decide whether you pass a course, whether you get a certificate, or anything else with a legal or similarly significant effect on you, and you're always free to ignore its suggestion and pick your own path. The AI tutor itself generates responses automatically, grounded in your course content, as described in §5.

12.Cookies and tracking

Our marketing website uses no cookies and no third-party trackers — see the site footer. The mobile app authenticates with a security token stored on your device, not a browser cookie, and does not embed third-party advertising SDKs. If that changes (for example, if we add privacy-respecting product analytics), we'll update this section first.

13.Changes to this policy

We may update this policy as the platform evolves or as required by law. If a change is material, we'll notify you in the app or by email before it takes effect. The "last updated" date at the top of this page always reflects the current version.

14.Contact us

Questions, rights requests, or concerns about this policy: privacy@uni.africa

Data Protection Officer contact detail: to be added once appointed and confirmed as part of ODPC (Kenya) registration — see README.md.

↑ Back to top