Privacy Policy

Version 1.0 · Effective August 26, 2026

A Russian translation of this document is not published yet, so the English text is shown. The English version is the one that applies in any case.

This policy explains what personal information Taalim holds, why we hold it, who else sees it, and how long we keep it. It is written to be read, not to be skimmed past.

1. Who we are, and our two different roles

Taalim is operated by Isabek Mamatkulov, Bishkek, Kyrgyz Republic. You can reach us at privacy@taalimapp.com.

We handle personal information in two distinct roles, and the difference matters:

  • As a controller, for information about the consulting companies who buy Taalim and the staff who use it. We decide how that information is used.
  • As a processor, for information about students. The consulting company that invited a student decides what is collected and why. We only act on that company's instructions. If you are a student and want your information changed or deleted, start with your consulting company. We explain the fallback route in section 10.

2. What we collect

Company and staff account information. Name, email address, company name, region, role in the workspace, and the invitations you send.

Student records. Name, date of birth, contact details, country and city, school and graduation year, academic profile including grades and test scores, target countries and programs, budget and funding needs, application status and deadlines, shortlisted universities and scholarships, consultant notes, and task history.

Documents that companies and students upload. The Service is designed to hold application paperwork, which by category can include transcripts, diplomas, letters of recommendation, passports and national identity documents, IELTS and TOEFL score reports, SAT and other standardised test reports, CVs, financial documents such as bank statements and sponsorship or affidavit-of-support letters, personal statements and essays, and passport photographs.

AI interaction data. Tutoring conversation messages, answers to practice questions and mock exams, essay drafts, the feedback and scores generated on them, and the resulting progress history.

Technical information. IP address and browser user agent recorded at signup, when an invite code is used, and when a document is downloaded; authentication session cookies; and error reports generated when something breaks.

Telegram chat identifier, only where a user chooses to connect the optional notification bot.

We do not ask for and do not want payment card numbers. Invoices are paid by bank transfer and we never see card details.

3. Why we process it

PurposeInformation used
Providing the platform to your consulting companyAccount and student records
Generating university matches, essay feedback, and tutoringAcademic profile, essays, tutoring messages
Sending transactional email such as invitations and password resetsName, email address
Optional Telegram notificationsTelegram chat identifier
Security, rate limiting, and abuse preventionIP address, user agent, access logs
Billing and invoicingCompany name, contact details, plan
Diagnosing errors and keeping the service workingError reports, technical metadata

Our legal bases are the performance of our contract with the consulting company, our legitimate interest in operating and securing the Service, and, where required, the consent that the consulting company is responsible for collecting from the student and their guardian.

4. Who else sees this information

We use the following providers. We do not sell personal information, and we do not share it for advertising.

ProviderWhat they do for usWhat reaches them
SupabaseDatabase, authentication, and file storageAll account data, student records, uploaded documents
AnthropicAI tutoring, essay feedback, university matchingTutoring messages, essay text, academic profile
GoogleAI tutoring and matching workloads (Gemini models)Tutoring messages, essay text, academic profile
ResendSending transactional emailName, email address
SentryError monitoringError traces and technical metadata
TelegramOptional notification botChat identifier, notification content
RailwayApplication hostingTraffic in transit
U.S. College ScorecardPublic university statisticsNothing. No personal information is sent

We may also disclose information where we are legally required to, or to establish or defend a legal claim.

5. How AI processing works, stated plainly

Some features send your information to an AI provider in order to work. Specifically:

  • Essay feedback sends the text of the essay draft.
  • AI tutoring and mock exams send the conversation and the student's answers.
  • University matching sends the academic profile and preferences.

This information goes to Anthropic and Google under their commercial API terms. Under those terms, content submitted through the API is not used to train their models. Each provider retains API content for its own limited period under its published API policy, and we do not control that retention.

Uploaded documents are not sent to any AI provider. Only a document's file name is used, so that the Service can tell which items on an application checklist have been satisfied. The contents of a passport, transcript, or bank statement are never transmitted to an AI model.

If you would prefer a student's essays and tutoring not to be processed this way, that student should not use the AI features. There is no way to use them without this processing.

6. Where the information is held

We are based in the Kyrgyz Republic, but the providers above store and process information outside it, including in the United States and the European Union. By using the Service, you understand that information is transferred to those countries, which may have different data protection rules.

7. How long we keep it, and what gets deleted automatically

Identity and financial documents are deleted automatically. Documents in the passport, financial, and photo categories are given a retention clock of 180 days from upload. When it runs out, the file is permanently deleted from storage. We keep only a record that a document of that category existed and when it was purged, never the file itself. A consultant can extend the clock while an application is genuinely still in progress, and the remaining time is shown in the interface.

We do this because the safest way to protect a passport scan is not to be holding it.

Everything else:

  • Other documents such as transcripts, essays, and CVs are kept until deleted by the student or their consulting company.
  • Student records, tutoring history, and essay feedback are kept for as long as the student's record exists in the workspace.
  • Account information is kept for the life of the workspace, then 30 days after termination, then deleted.
  • Document download logs are kept for 12 months as a security record.
  • Signup and invite-attempt logs containing IP addresses are kept for 12 months.
  • Records of acceptance of our Terms are kept indefinitely, because they are the evidence that an agreement was made. They contain a user identifier, a document version, a timestamp, and an IP address.
  • Error reports follow our monitoring provider's retention, currently 90 days.

8. How we protect it

  • Every company's data is isolated at the database level by row-level security, so one company's workspace cannot read another's.
  • Uploaded files live in a private storage bucket with no public access and no direct client access. Every upload and download is routed through an authenticated route in the application, which checks the caller's permission first.
  • Downloads are served by short-lived links that expire after 60 seconds and force the file to be saved rather than opened in the browser.
  • Uploaded files are checked by inspecting the file's actual contents, not by trusting its name or extension.
  • Every document download is logged with who did it, which file, and when.
  • Data is encrypted in transit, and encrypted at rest by our hosting provider.
  • Access to production systems is limited to the operator of the Service.

We want to be straightforward about the limits: we do not hold any security certification, we have not undergone a SOC 2 audit or a third-party penetration test, and we do not scan uploads for viruses. Taalim is a small operation. If your organisation requires any of these, tell us before you commit.

9. Cookies

We set only the cookies needed to keep you signed in. We do not use advertising cookies, cross-site trackers, analytics profiling, or session recording, and we do not build advertising profiles. This is why you are not being shown a cookie consent banner: there is nothing to consent to beyond what is strictly necessary to operate the Service.

10. Your rights

Depending on where you live, you may have the right to access your information, correct it, delete it, export it, restrict or object to processing, and complain to a data protection authority.

If you are a student: ask your consulting company first. They control your record and can view, correct, export, and delete it directly in the Service. If they do not respond, or you cannot reach them, write to privacy@taalimapp.com and we will help.

If you are a consulting company: you can exercise your own rights, and handle your students' requests, from within the Service. Write to privacy@taalimapp.com for anything the interface does not cover.

We respond to requests within 30 days.

11. Children and young people

Taalim is used by school-age students, and many of them are under 18.

Student accounts are not created by us and cannot be created by a member of the public. A student enters the Service only when a consulting company creates their record or issues them an invite code.

Obtaining consent from a parent or legal guardian is the responsibility of the consulting company, which warrants in our Terms of Service that it has done so. At signup we also ask each student to confirm that, if they are under 18, a parent or guardian has read and agreed to the terms with them.

We do not market to children, we do not profile children for advertising, and we do not sell their information.

If you are a parent or guardian and you want to see, correct, or delete what is held about your child, contact the consulting company your child is working with, or write to us at privacy@taalimapp.com and we will route it.

12. Changes to this policy

We may update this policy. For a material change, we give at least 30 days' notice by email and by notice inside the Service. The version number and effective date at the top of this page always tell you which version you are reading.

13. Contact

Questions, requests, or complaints: privacy@taalimapp.com

Isabek Mamatkulov, Bishkek, Kyrgyz Republic