Privacy Policy
Last updated: February 2026
1. Introduction
EduEco Africa ("we", "us", or "our") operates the EduEco Africa platform, a digital storybook service that teaches African children about environmental conservation. This Privacy Policy explains what personal information we collect, how we use it, and the rights you have regarding your data.
By using our platform you agree to the collection and use of information as described in this policy. If you are a parent or guardian creating an account on behalf of a child, this policy applies to that child's data as well.
2. Information We Collect
Account Registration
When you create an account we collect:
- Email address — used to identify your account and send important updates
- Username — a display name chosen by you (3–20 characters)
- Age — used to tailor content appropriately
- Role — whether you are a learner, teacher, or parent
- Password — stored securely as a hashed value by Supabase; we never see your plain-text password
Student Accounts (Teacher-Created)
Teachers may create student accounts on behalf of learners. In this case we collect the student's username and age. A temporary password is generated and shared with the teacher so they can distribute login credentials to students or their parents.
Reading Activity
- Favorites — stories a user saves for later reading
- Reading progress — current page, total pages, and completion timestamps for assigned stories
Contact Form
If you send us a message via the contact form we collect your name, email address, subject, and message. This is emailed to our team and not stored long-term in the database.
Newsletter
If you subscribe to our newsletter we collect your name and email address and store them to send you updates about new content and features.
Payment Information
Subscription payments are handled entirely by Stripe. We do not store card numbers or payment details on our servers. We receive a Stripe customer ID that links your account to your subscription status.
3. Children's Privacy
EduEco Africa is designed for children aged 4–14. We take children's privacy seriously and comply with applicable laws including the US Children's Online Privacy Protection Act (COPPA) and South Africa's Protection of Personal Information Act (POPIA).
- Children under 13 should only create accounts with verifiable parental or guardian consent.
- Teacher-created student accounts operate under the school or institution's responsibility. Teachers act as the intermediary between the platform and the child's parent or guardian.
- We do not knowingly collect personal information from children under 13 without appropriate consent. If you believe we have done so inadvertently, please contact us at eduecoafrica@gmail.com and we will delete the information promptly.
4. How We Use Your Information
- Provide and operate the EduEco Africa platform
- Authenticate users and maintain secure sessions
- Display reading progress and saved favorites
- Allow teachers to monitor their students' reading activity
- Process subscription payments via Stripe
- Respond to contact form enquiries
- Send newsletter updates to subscribers who have opted in
- Improve and develop our content and features
We do not sell your personal information to third parties.
5. Third-Party Services
We use the following trusted third-party services to operate the platform:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database & authentication | All account and activity data |
| Stripe | Payment processing | Email, subscription metadata |
| Resend | Transactional email | Name, email, message content |
| Google OAuth | Optional social sign-in | Google account email & profile |
| Vercel | Hosting & CDN | IP address, request metadata |
Each service has its own privacy policy governing how they handle your data.
6. Cookies & Sessions
We use cookies to keep you logged in between visits. When you sign in, a secure session cookie is stored in your browser. This cookie contains an encrypted token — not your password — and is used to verify your identity on each page load.
We do not use advertising cookies or tracking cookies. The only cookies we set are those required for authentication and security.
7. Data Storage & Security
- All data is stored on Supabase's managed PostgreSQL database hosted on secure cloud infrastructure.
- Row Level Security (RLS) policies ensure users can only access their own data — your favorites and profile are not visible to other users.
- Passwords are hashed by Supabase's authentication system using bcrypt; we never have access to plain-text passwords.
- All data is transmitted over HTTPS (TLS encryption).
8. Data Retention
We retain your personal data for as long as your account is active. If you delete your account, your profile, favorites, and reading progress are permanently removed from our database. Newsletter subscribers can unsubscribe at any time by contacting us.
9. Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Correct — update inaccurate information via your profile settings
- Delete — request deletion of your account and associated data
- Unsubscribe — opt out of newsletter communications at any time
To exercise any of these rights, contact us at eduecoafrica@gmail.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the platform after changes are posted constitutes acceptance of the revised policy.
11. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please reach out:
EduEco Africa
Email: eduecoafrica@gmail.com
