Edupledge

Privacy Policy

How Edupledge collects, uses, shares, and protects your information.

Effective 16 September 2026

1. Who we are

Edupledge is operated by Edupledge LTD, a company registered in England and Wales (“Edupledge”, “we”, “us” or “our”). We are the controller of personal information processed through the Edupledge app, except where a university, employer, or other challenge sponsor separately tells you that it is a controller.

Our service and business address is 66 Paul Street, London EC2A 4NA, United Kingdom.

For privacy questions or to exercise your rights, email luizmutua57@gmail.com.

2. Who can use Edupledge

Edupledge is designed for students aged 13 and over in the United Kingdom. You must not create an account if you are under 13.

We write our privacy information to be understandable for young people. If anything is unclear, ask a parent, guardian, teacher, or another trusted adult to help you, or contact us.

3. Information we collect

4. How we use information

5. Study-proof photo review and automated processing

When you submit a study-proof photo, Edupledge may send a reduced-detail copy to an AI vision service to decide whether visible study context is clear. The review looks for things such as notes, textbooks, worksheets, revision cards, academic work on a laptop, or a recognisable study workspace.

The review is instructed not to identify people, perform facial recognition, or infer identity, age, emotion, clothing, appearance, or location. An unclear or unavailable automated result must not approve a reward automatically. Reports and flagged proofs may be reviewed by an authorised human moderator.

This processing can affect whether a study proof is approved and whether related PledgePoints or pledge progress are awarded. You may contact us to question a decision and ask for human review.

6. Our legal reasons for processing

7. Universities, employers, and challenge sponsors

A separate sponsor feature, disclosure, and consent flow is pending. Until it is released, do not treat this policy as authorisation for sponsor sharing. If it launches, we will identify the sponsor and show the relevant sharing before you join.

Sponsors do not receive your private messages, unrelated pledge activity, precise location, calendar contents, screen-time details, or study-proof photos through the standard sponsor reporting described here. A sponsor must give you separate information before any wider use.

Do not join a sponsored challenge if you do not want the identified sponsor to receive your email and challenge progress. Leaving may stop future sharing but will not undo information already lawfully provided.

8. Service providers

We use service providers only for the functions described below. Their public terms identify processor or service-provider roles and international-transfer safeguards where stated. Account-specific plans, settings, routed-AI retention, and provider-side deletion evidence remain part of our release review.

9. International transfers

Our Supabase project is hosted in London. Other providers and their subprocessors may process information outside the United Kingdom, including in the United States. Public provider terms identify safeguards including adequacy arrangements, the UK Extension to the EU–US Data Privacy Framework, Standard Contractual Clauses with the UK Addendum, or the UK International Data Transfer Agreement where applicable.

The actual production hosting geography and the processing location and retention controls used for Replit-routed AI requests must still be confirmed before release. You may contact us for the current provider and transfer record.

10. How long we keep information

This retention schedule was reviewed on 10 September 2026 for the target 16 September 2026 release. It is the operator’s policy target and must be applied only where necessary and lawful: active account records, account-owned social media, and device-token rows are deleted after a verified Profile deletion request; the account is deleted last and the server fails closed if owned media cannot be removed.

Safety and moderation reports are kept privately for 24 months after the case is closed, then deleted or anonymised. Open cases, safeguarding concerns, security investigations, disputes, and records needed for a legal obligation are kept until the relevant matter is resolved and any lawful hold is lifted. A legal hold overrides the ordinary period and is reviewed regularly. When an account or reported post is deleted, report identity links are detached rather than deleting the report itself.

Our operational target is to remove ordinary application logs within 30 days, and to keep security, safeguarding, moderation, and dispute records only for the periods above. Transactional email and push-provider copies, AI input/output records, caches, and backups follow the provider’s documented controls; as of this review, their account-specific deletion and overwrite timing has not been independently confirmed, so this policy does not claim that a Profile deletion instantly removes those provider-side copies.

The 10 September 2026 code and schema review verified the in-app deletion ordering and report-preservation migration. It did not verify live provider deletion, backup overwrite, or AI retention. We will record the provider name, account region, control/contract reference, test date, propagation result, and reviewer in the release record before describing those controls as verified.

11. Your UK data-protection rights

Email luizmutua57@gmail.com to exercise a right. We may need to verify that the request concerns your account.

12. Security and safety

The audit found authenticated requests and private media paths in the application. The full access-control design, encryption configuration, administrative access, backups, and incident safeguards require operational verification before release. No online service can guarantee absolute security.

13. Cookies and analytics

The mobile app does not currently use advertising trackers or third-party behavioural analytics. Essential local storage and authentication information are used to keep you signed in, preserve pending invitations, and remember app state. If we introduce non-essential tracking, we will update this notice and request consent where required.

14. Changes

We may update this policy as Edupledge changes. We will show the updated date and provide appropriate notice before a material change takes effect. If a change requires consent, we will ask for it.

Release review status

This is the current release-review text for the 16 September 2026 target release. It is general information, not legal advice, and does not say that a solicitor or regulator has approved it.

Before publication, the operator must confirm processor roles and contracts, international-transfer safeguards, provider-side deletion, backup deletion, moderation-record retention, and the study-photo AI provider’s data handling. A qualified UK solicitor must review this document set and confirm any required changes.

Contact the operator · UK ICO complaints