Skip to main content
ekkul
Back to Home

Privacy Policy

Last Updated: March 2026

Ekkul ("we," "our," or "us") operates the Ekkul exam preparation platform, including our website, mobile applications, and related services (collectively, the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform.

By accessing or using the Platform, you agree to the terms of this Privacy Policy. If you do not agree with the practices described here, please do not use the Platform.

1. Information We Collect

1.1 Personal Information

When you create an account or use our Platform, we may collect the following personal information:

  • Account Information: Name, email address, username, password (hashed), profile picture, country, language preference, and date of birth.
  • Profile Data: Educational background, exam preferences, selected topics, grade level, and onboarding responses.
  • Communication Data: Messages sent through our Study Buddy AI chat feature, study group posts and comments, feedback, and support requests.
  • Voice Data: When you use text-to-speech (TTS) features, we store your voice preference settings (provider, voice, speed, language). We do not record or store your voice; TTS generates audio from text content only.

1.2 Usage Data

We automatically collect certain information about how you interact with the Platform:

  • Learning Activity: Test results, scores, practice session history, question responses, time spent on topics, performance analytics, learning path progress, milestone completions, focus area progress, flashcard review history, and spaced repetition data.
  • AI Interaction Data: Queries made to AI features (Study Buddy Chat, Concept Explainer, Exam Simulator, AI-generated notes, AI-generated flashcards), AI-generated content viewed, and credit usage.
  • Social Activity: Study group memberships, posts, comments, likes, poll votes, quiz answers, and challenge participations within study groups.
  • Canvas and Drawing Data: Whiteboard drawings and annotations created within the classroom feature are stored per-milestone and per-focus-area.
  • Device Information: Browser type, operating system, device type, screen resolution, IP address, and general location data (city/region level).
  • Cookies and Tracking: We use cookies and similar technologies to maintain sessions, remember preferences, and analyze Platform usage. See Section 11 (Cookie Policy) for more details.

1.3 Payment Information

When you purchase a subscription, model test set, credit pack, or voice character pack, payment processing is handled by our third-party payment processor, Stripe. We do not store your full credit card number, CVV, or bank account details on our servers. We may receive and store:

  • Last four digits of your payment card
  • Card brand (e.g., Visa, Mastercard)
  • Billing address and email
  • Transaction history, subscription status, and purchase records
  • Credit balance and credit transaction history
  • Voice character credit balance and usage

1.4 Learning Path and Marketplace Data

When you create or purchase learning paths, we collect and store:

  • Created Paths: Path structure, milestones, focus areas, resources, notes, flashcards, and question sets you create.
  • Purchased Paths: Purchase records, progress tracking, and completion status for paths you acquire from the marketplace.
  • Published Paths: If you publish a learning path to the marketplace, the path content, pricing, and your display name as the creator become publicly visible.

2. How We Use Your Information

We use the information we collect to:

  • Provide and Improve the Platform: Deliver exam preparation content, model tests, practice questions, learning paths, flashcards with spaced repetition, and personalized learning experiences.
  • Power AI Features: Generate personalized performance analyses, study plans, AI mentor messages, concept explanations, chat responses, exam simulations, area notes, and flashcard suggestions based on your learning data.
  • Enable Social Features: Facilitate study group interactions, social feed posts, comments, polls, quizzes, and member score comparisons.
  • Text-to-Speech Services: Generate audio versions of educational content, AI responses, and study materials using your selected voice preferences.
  • Personalize Your Experience: Adapt content difficulty, recommend topics, track learning streaks, calculate predictive scores, and tailor the Platform to your learning goals and preferences.
  • Process Transactions: Handle subscription payments, one-time purchases, credit pack purchases, voice character pack purchases, and billing management.
  • Communicate with You: Send account notifications, service updates, achievement alerts, daily challenge notifications, and respond to support inquiries.
  • Analytics and Research: Analyze aggregated usage patterns to improve our content quality, AI models, question databases, and Platform features.
  • Ensure Security: Detect and prevent fraud, unauthorized access, rate limit abuse, and other security threats.
  • Comply with Legal Obligations: Meet applicable legal requirements, resolve disputes, and enforce our terms.

3. Information Sharing

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: We share data with trusted third-party service providers who assist in operating the Platform, including:
    • Neon (PostgreSQL database hosting and authentication)
    • Convex (real-time backend services)
    • Stripe (payment processing)
    • OpenAI (AI features including chat, concept explanations, exam simulations, and text-to-speech)
    • Anthropic (alternative AI model provider for select features)
    • ElevenLabs (premium text-to-speech voice generation)
    These providers are contractually obligated to protect your data and use it only to provide services to us.
  • Leaderboard and Social Features: If you participate in leaderboards, challenges, or study groups, your username, scores, rankings, posts, and comments may be visible to other users. You can control your visibility in your account settings.
  • Learning Path Marketplace: If you publish a learning path to the marketplace, your display name and path content are visible to all users. Purchase counts and ratings may also be displayed.
  • Organizations and Instructors: If you are part of an organization (school, institution), your learning progress and performance data may be shared with authorized administrators and instructors within that organization.
  • Study Group Members: Within study groups you join, other members can see your username, posts, comments, poll votes, quiz answers, and score history for the group's topic.
  • Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or property of Ekkul, our users, or the public.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of the transaction. We will notify affected users of any change in ownership or data practices.

4. AI Data Processing

Our Platform uses artificial intelligence to provide personalized educational experiences. It is important to understand how your data is used in this context:

  • Data Sent to AI Providers: When you use AI features, relevant context data (such as your performance statistics, weak/strong topics, current question content, or conversation history) is sent to our AI providers (OpenAI and/or Anthropic) to generate responses. We minimize the personal information included in these requests.
  • No AI Training: We have agreements with our AI providers that your data submitted through our Platform will not be used to train their general-purpose AI models. Your interactions remain private to your session.
  • AI Response Caching: We cache certain AI responses (e.g., concept explanations) using content-based hashing to improve performance and reduce costs. Cached responses do not contain personally identifiable information and expire after a set period (typically 30 days).
  • AI-Generated Content: Notes, flashcards, study plans, and other content generated by AI are stored in your account and treated as your User Content. You can edit or delete AI-generated content at any time.

5. Data Security

We implement industry-standard security measures to protect your personal information, including:

  • Encryption of data in transit (TLS/SSL) and at rest for sensitive data.
  • Secure authentication via Neon Auth with session token management and support for OAuth providers (Google, GitHub).
  • Hashed passwords using modern cryptographic algorithms (passwords are never stored in plain text).
  • Row-level security policies on database tables to ensure users can only access their own data.
  • Rate limiting on AI features and API endpoints to prevent abuse.
  • Regular security reviews and vulnerability assessments of our infrastructure.
  • Access controls limiting employee and contractor access to personal data on a need-to-know basis.

While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any breach in accordance with applicable laws.

6. Children's Privacy (COPPA Compliance)

Ekkul is committed to protecting the privacy of children. Our Platform may be used by students of all ages for exam preparation. We comply with the Children's Online Privacy Protection Act (COPPA) and take the following measures:

6.1 Age Verification

During account registration, we require users to provide their date of birth. If a user is identified as being under the age of 13, we implement additional safeguards before collecting any personal information.

6.2 Parental Consent

For users under the age of 13, we require verifiable parental or guardian consent before collecting, using, or disclosing any personal information. The parent or guardian must:

  • Provide consent through a verified method (e.g., signed consent form, credit card verification, or direct communication with our support team).
  • Acknowledge and agree to this Privacy Policy on behalf of their child.

6.3 Data Collected from Children

When parental consent is obtained, we may collect the following limited information from children under 13:

  • First name or username (we encourage use of a pseudonym rather than a real name).
  • Parent or guardian's email address (for consent verification and account management).
  • Learning activity data (test scores, practice results, and topic progress) necessary to provide the educational service.

We do not collect more information from children than is reasonably necessary to provide our educational services. Children's accounts have restricted features, including disabled social features (leaderboard participation, study groups, and public profiles) unless explicitly enabled by a parent or guardian.

6.4 Parent and Guardian Rights

Parents and guardians of children under 13 have the right to:

  • Review the personal information we have collected from their child by submitting a request to privacy@ekkul.com.
  • Request Deletion of their child's personal information. Upon receiving a verified request, we will delete the child's data within 30 days, except where retention is required by law.
  • Withdraw Consent at any time. Withdrawing consent will result in the deactivation of the child's account and deletion of associated personal data.
  • Refuse Further Collection of their child's data without requiring deletion of previously collected data.

6.5 Contact for Parents

If you are a parent or guardian and have questions about your child's privacy, wish to review or delete their data, or need to manage consent, please contact us at:

We will respond to all parental requests within 30 days of receiving a verified request.

7. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purpose for collecting the information, and the categories of third parties with whom we share it.
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions (e.g., completing a transaction, detecting security incidents, complying with legal obligations).
  • Right to Correct: You have the right to request correction of inaccurate personal information we maintain about you.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioral advertising. If this practice changes, we will provide a "Do Not Sell or Share My Personal Information" link and update this policy accordingly.
  • Right to Limit Use of Sensitive Personal Information: You can request that we limit the use and disclosure of your sensitive personal information to what is necessary to provide the Service.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights. You will not receive different pricing or quality of service for making a privacy request.

To exercise your CCPA/CPRA rights, contact us at privacy@ekkul.com. We will verify your identity before processing any request and respond within 45 days.

8. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

8.1 Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide the Service you have requested (e.g., account management, delivering learning content, processing payments).
  • Legitimate Interests: Processing necessary for our legitimate interests, such as improving the Platform, preventing fraud, and ensuring security, where these interests are not overridden by your rights.
  • Consent: Processing based on your explicit consent, such as receiving marketing communications or enabling optional analytics tracking. You may withdraw consent at any time.
  • Legal Obligation: Processing necessary to comply with applicable laws and regulations.

8.2 Your GDPR Rights

Under the GDPR, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete personal data.
  • Erasure: Request deletion of your personal data ("right to be forgotten"), subject to applicable exceptions.
  • Restriction: Request that we restrict the processing of your personal data in certain circumstances.
  • Data Portability: Request a machine-readable copy of your personal data to transfer to another service.
  • Objection: Object to the processing of your personal data for certain purposes, including direct marketing and profiling.
  • Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing that produce legal or significant effects. Our AI features provide recommendations and suggestions only and do not make automated decisions with legal effects.

To exercise your GDPR rights, contact us at privacy@ekkul.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority.

8.3 International Data Transfers

Your personal data may be transferred to and processed in countries outside of your jurisdiction, including the United States, where our servers and service providers are located. When we transfer data internationally, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Data processing agreements with all service providers.
  • Encryption of data in transit and at rest.

9. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with our services. Specific retention periods include:

  • Account Data: Retained until you delete your account. After account deletion, data is permanently removed within 30 days, except where required by law.
  • Learning Activity Data: Retained for the duration of your account to provide personalized learning experiences, analytics, and predictive scores.
  • AI Interaction Data: Chat conversations and AI responses are retained for up to 12 months. Cached AI responses (e.g., concept explanations) are retained for up to 30 days for performance optimization.
  • Study Group Data: Posts, comments, and interactions within study groups are retained for the lifetime of the group. If you leave a group, your posts remain visible but are disassociated from your profile upon account deletion.
  • Learning Path Data: Created learning paths, milestones, focus areas, notes, flashcards, and resources are retained for the lifetime of your account. Published marketplace paths remain available even after account deletion unless explicitly removed.
  • Voice Audio Cache: Generated TTS audio files are cached for up to 30 days for performance optimization, then automatically deleted.
  • Payment Records: Transaction records are retained for 7 years to comply with financial and tax regulations.
  • Usage Logs: Server and analytics logs are retained for up to 90 days for security and debugging purposes.

10. Your Rights and Data Controls

Regardless of your jurisdiction, we provide the following data controls to all users:

  • Data Export: You can export all your personal data in a machine-readable format through your account settings. This includes your profile, test results, purchases, chat conversations, achievements, streaks, and privacy settings.
  • Account Deletion: You can permanently delete your account and all associated data through your account settings. This action is irreversible and will remove your data from all active systems within 30 days.
  • Marketing Preferences: You can opt in or out of marketing emails at any time through your privacy settings.
  • Analytics Tracking: You can disable optional analytics tracking through your privacy settings. Essential analytics required for the Service to function will continue.
  • Profile Visibility: You can control whether your profile, scores, and rankings are visible on leaderboards and to other users.

To exercise any of these rights, visit your account settings or contact us at privacy@ekkul.com. We will respond to your request within 30 days.

11. Cookie Policy

We use cookies and similar technologies to operate the Platform:

  • Essential Cookies: Required for the Platform to function, including authentication tokens, session management, and security cookies. These cannot be disabled.
  • Preference Cookies: Store your settings such as language preference, theme (dark/light mode), and display options.
  • Analytics Cookies: Help us understand how users interact with the Platform to improve our services. These can be disabled in your privacy settings.

We do not use third-party advertising cookies or tracking pixels. We do not serve advertisements on the Platform.

12. Third-Party Links and Services

The Platform may contain links to third-party websites, resources, or services (e.g., external learning resources added to learning paths). We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party websites you visit.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Notify registered users via email or an in-app notification at least 14 days before the changes take effect.
  • For changes affecting children's data, we will obtain new parental consent where required.

Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • Email: privacy@ekkul.com
  • General Inquiries: support@ekkul.com
  • COPPA / Parental Requests: privacy@ekkul.com with subject line "COPPA - Parent Request"
  • GDPR / Data Protection: privacy@ekkul.com with subject line "GDPR Request"

We are committed to resolving any concerns about your privacy and our collection or use of your personal information. We will respond to all inquiries within 30 days.