Privacy Policy
Effective date: August 31, 2026
This Privacy Policy explains how ClassOS ("ClassOS", "we", "us", or "our") collects, uses, and protects information when you use the ClassOS website, web application, and mobile app (together, the "Service"). ClassOS is an AI-powered learning platform for students, parents, and schools following the SABIS and other international curricula.
The Service is operated by ClassOS, based in Iraq.
1. Information we collect
Account and profile information. When you register, we collect your name, email address, account role (student, parent, or admin), and — for students — profile details such as grade/stage, curriculum, school name, and (for family accounts) a parent-child link created via an invite code. Parents create a separate parent profile and link to their child's account; they do not see the child's raw password or authentication credentials.
Google sign-in data. If you choose "Sign in with Google," we receive your name, email address, and profile photo from Google via our authentication provider (Supabase Auth) to create or sign in to your ClassOS account. We do not receive your Google password, and we only request the minimum Google profile scopes needed for authentication.
Learning, activity, and progress data. This includes the subjects, courses, lessons, and homework you access; quiz and exam attempts and scores; study-plan and study-schedule preferences; skill-mastery and adaptive-learning progress; and exam-prep session data (e.g. IELTS/SAT practice attempts). For family accounts, a linked parent can view their child's progress data through the parent dashboard.
AI-related inputs. When you use an AI feature — the AI Teacher, AI tutor chat, homework/material analysis, or practice-quiz generation — we process what you submit to it: typed questions and chat messages, and any documents, slides, or images you upload for analysis. These inputs (and the resulting AI responses) are stored so you can revisit a conversation or a past analysis, and are used to generate the explanations, quizzes, and study material the Service provides.
Payment information. For paid subscriptions, payment is handled by our third-party payment processors (see Section 3). ClassOS stores transaction records (plan, amount, status, and provider reference) but does not store your full card or payment-account credentials — those are entered directly with the payment provider.
Technical and usage data. We collect standard technical data such as device/browser type, IP address, and app usage events (e.g. feature usage, error logs) to operate, secure, and improve the Service.
2. How we use your information
- To create and maintain your account and authenticate you securely.
- To provide the core educational service: lessons, homework, quizzes, exam prep, AI tutoring, and progress tracking.
- To let a parent account view the progress of a child account they are legitimately linked to.
- To process subscription payments and maintain billing records.
- To personalize learning content and AI responses to your curriculum and level.
- To communicate service-related notices (e.g. account, billing, or product updates).
- To detect, investigate, and prevent abuse, fraud, and violations of our Terms.
- To maintain and improve the reliability, security, and performance of the Service.
3. Service providers and infrastructure
We rely on the following categories of third-party service providers to run ClassOS:
- Supabase — database, authentication (including Google OAuth), and file storage for the Service.
- AI providers — AI features are served through an AI routing layer (OpenRouter) and/or Google's Gemini API, which process the inputs described in Section 1 to generate responses, explanations, and quizzes.
- Payment processors — subscription payments in Iraq are processed by QiCard and SwiftPayIQ. Card/payment details are handled directly by these providers, not stored by ClassOS.
- Hosting and delivery — the website and app are hosted on Vercel.
Each provider only receives the data needed to perform its function and is expected to protect it under its own privacy and security terms.
4. Data security
We use industry-standard safeguards to protect your information, including encrypted connections (HTTPS/TLS) between your device and our servers, database-level access controls (row-level security policies that restrict data to its owner and, for family accounts, their linked parent), and role-based access for administrative functions. No method of transmission or storage is 100% secure, so while we work to protect your information, we cannot guarantee absolute security.
5. Data retention, access, and deletion
We retain account and learning data for as long as your account is active, and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You can request access to, correction of, or deletion of your personal data, or ask us to close your account, by contacting us at the phone number in Section 9. We will respond within a reasonable time and delete or anonymize your data except where we are required or permitted to keep it (e.g. financial/transaction records for tax or fraud-prevention purposes).
6. Children's and student privacy
ClassOS is an educational platform designed for use by students, including minors, typically in the context of a school or family. Where a student is a minor, we intend for their account to be used with the involvement of a parent or guardian — ClassOS's parent-account feature lets a parent link to their child's account (via an invite code issued by the child's account) to view learning progress. We collect only the information described in Section 1 that is needed to provide the educational Service, and we do not knowingly use student data for third-party advertising.
If you are a parent or school administrator and believe a student's account was created or information was submitted without appropriate consent, contact us at the phone number in Section 9 and we will investigate and take appropriate action, including deletion where required.
7. Your choices
- You can review and update your profile information from your account settings.
- You can disconnect Google sign-in by managing connected apps in your Google Account settings; this does not delete your ClassOS account.
- You can request account deletion as described in Section 5.
8. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Service or applicable law. We will update the "Effective date" above when we do, and, for material changes, provide additional notice where appropriate.
9. Contact us
Questions about this Privacy Policy or how your data is handled can be sent to us by phone at 07717099007.