Oostad legal
Privacy Policy
Last updated: July 15, 2026
This policy explains how Oostad collects, uses, shares, and keeps information when students, parents, teachers, and administrators use the Oostad website, mobile apps, Quran learning tools, classroom features, messaging, billing, and support services.
Scope
Who this policy covers
Oostad is used by learners, parents or guardians, teachers, school or cohort administrators, and internal support users. Some learners may be children or minors whose account is created, paid for, invited, or supervised by a parent or guardian.
The service includes web and mobile account access, teacher-led Quran learning, self-paced practice, homework, pronunciation review, live classroom surfaces, messages, uploaded teaching materials, reports, subscriptions, and teacher payout tools.
Collection
Information we collect
Account, profile, and role data
Identifiers such as user ID, email address, display name, account role, account status, onboarding state, 13+ eligibility status, policy version, confirmation timestamp and source, teacher share code, selected avatar, and any profile photo uploaded from a device. We use a binary 13+ confirmation and do not collect a full birth date for direct-account eligibility. Uploaded avatar photos are resized before being saved as profile data.
Parent, student, teacher, and learner relationship data
Parent-student links, teacher-student links, cohort membership, managed learner display name, relationship label, age band, level, goals, availability, selected course, selected teacher, child email for invite delivery, claim codes, invite timestamps, consent preferences, access settings, teacher notes, recommendations, recap summaries, and related onboarding state.
Learning, homework, and Quran progress data
Course enrollment, assigned modules, lesson and drill attempts, points, streaks, lives, placement diagnostic results, suggested starting module, Quran page or square selections, homework assignments, worksheets, answers, teacher review status, reports, feedback, and related timestamps.
Messages and conversation metadata
Conversation titles, members, roles, read states, drafts, pinned messages, message text, edits, deletes, reactions, mentions, attachments, link previews, typing and presence events, muted or removed status, delivery or read receipts, and conversation channel metadata.
Voice recordings, pronunciation attempts, transcripts, and grading data
Audio uploaded for pronunciation, placement, homework, teacher grading, and tutoring features; storage references; content type; file size; duration; attempt IDs; expected and actual recitation text; transcript segments; AI draft annotations; teacher notes; teacher voice feedback; voice-note transcripts; grading feedback; model output; reviewed labels; and processing metadata such as sample rate, codec, checksums, confidence, errors, and timestamps.
Audio playback and cache data
Audio playback URLs, signed-read access metadata, lesson recording status, classroom recording metadata, and temporary app or operating-system cache files used for playback, retrying uploads, or continuing a background upload.
Teacher materials, documents, annotations, and worksheets
Files uploaded by teachers, including PDF, DOC, and DOCX materials; original and safe filenames; MIME type; storage location; size; upload status; generated previews; rendered pages; saved classroom annotation snapshots; worksheet content; teacher-created notes; and Quran teaching-material references.
Device, app, push, logs, and diagnostics
Push notification tokens, platform, environment, bundle ID, locale, app version, request IDs, user-agent and content-type headers, rate-limit state, idempotency keys, upload failures or successes, error logs, performance or latency measurements, and diagnostic data needed to secure and operate the service.
Billing, subscription, payout, and support records
Stripe customer, subscription, price, invoice, charge, refund, dispute, connected-account, Global Payouts recipient, transfer, OutboundPayment, and payout identifiers; plan keys; billing status; renewal dates; cancellation state; teacher earning summaries; payout readiness and payout status; billing correction or claim details; service recovery credits; support requests; and admin review notes. Oostad does not store full card numbers, full payment credentials, bank account details, card numbers, or identity documents collected by Stripe.
Use
How we use information
- -Create and secure accounts, authenticate users, apply roles, and keep existing-account mobile access working.
- -Connect parents, child learners, students, teachers, cohorts, and support conversations.
- -Deliver Quran learning features, live teaching, homework, practice drills, placement, reports, classroom tools, worksheets, messages, notifications, and support.
- -Record, transcribe, assess, and review pronunciation attempts, homework audio, teacher feedback, and tutor interactions.
- -Maintain subscriptions, billing access, teacher storage add-ons, teacher payouts, corrections, disputes, and claim reviews.
- -Operate storage, realtime messaging, websocket sessions, push notifications, logging, debugging, abuse prevention, service safety, analytics, and reliability monitoring.
- -Improve grading quality, curriculum, feedback, and models where permitted by account settings, consent preferences, product configuration, and applicable law.
Sharing
Who can see or receive information
- -Parents, students, and teachers see information needed for their learning relationship, such as learner profile data, assignments, progress, messages, feedback, recordings, and reports.
- -Oostad staff and administrators may access information to provide support, investigate safety or billing issues, review quality, secure the platform, and comply with legal obligations.
- -Service providers process data for authentication, payments, subscriptions, payouts, object storage, databases, hosting, email, realtime messaging, push notifications, transcription, AI tutoring, document preview, logging, diagnostics, and app operation.
- -We may disclose information if required by law, to protect users or the service, to investigate fraud or abuse, or as part of a merger, acquisition, financing, or sale of business assets.
- -We do not sell personal information, and we do not use child learner data for third-party behavioral advertising.
Processors
Third-party services and SDKs
Oostad uses processors and SDKs only as needed to operate the service, process payments, deliver app features, improve quality, and meet security or legal obligations. The exact provider list can change as the service changes, but the main categories include:
- -Clerk for authentication, sessions, account identity, and sign-in providers such as email, Google, or Apple where enabled.
- -Stripe, Stripe Connect, and Stripe Global Payouts for checkout, subscriptions, billing portals, invoices, payment method handling, refunds, disputes, connected accounts, recipient onboarding, and teacher payout processing.
- -Database, hosting, and storage infrastructure, including Google or Google Cloud infrastructure, S3-compatible storage, and Cloudflare R2-style storage where configured.
- -Realtime and websocket infrastructure, including Socket.IO and related mobile websocket libraries, for messages, presence, typing, receipts, and live app updates.
- -Apple Push Notification service and, where applicable, Android push infrastructure for mobile notifications.
- -OpenAI or other configured AI providers for speech-to-text, pronunciation support, realtime tutoring, grading assistance, summaries, and quality workflows.
- -Email, support, logging, and diagnostics providers, including Sentry where enabled for error reporting.
- -App SDKs and client libraries used to provide the mobile experience, such as Clerk, Socket.IO or Starscream, PhoneNumberKit, image loading libraries such as Nuke, and animation libraries such as Lottie.
Children
Children and minor learners
Direct Oostad accounts are for people aged 13 or older. A learner under 13 may use Oostad only through a profile controlled by a parent or legal guardian and may not independently sign in. When an existing student tells us they are under 13, direct access is blocked while a secure, expiring parent handoff is completed. The handoff preserves the learner's existing educational history.
For a parent-managed learner, Oostad may process the learner's profile, age band, courses, progress, homework, messages, recordings, transcripts, teacher relationships, reports and subscription entitlement. The parent controls the profile and can contact us to request access, correction, deletion or restriction. Teachers and support users receive only the access needed for learning, support, safety, billing and operation.
Retention
How long we keep information
- -Account, profile, role, relationship, subscription, and entitlement records are kept while the account is active and for as long as needed for security, billing, audit, tax, legal, support, and service-continuity purposes.
- -Messages, classroom records, homework, reports, teacher feedback, and learning history are kept while needed to provide the learning record and support the parent, student, or teacher relationship. Some classroom recordings, saved annotations, signed URLs, caches, and temporary files are designed to expire or be deleted sooner.
- -Audio attempts, transcripts, grading artifacts, reviewed labels, and model-evaluation data are kept for learning feedback, teacher review, quality, evidence, and permitted improvement workflows. Training or evaluation use may be limited by consent preferences and product configuration.
- -Push tokens are disabled or removed when a device signs out, token deletion is requested, or the token stops being valid.
- -Logs, diagnostics, rate-limit state, idempotency records, and security records are retained for limited operational periods unless they are needed longer to investigate reliability, fraud, abuse, billing, or legal issues.
Choices
Deletion, correction, and controls
You can update some profile information in the app, including avatar selection. You can also contact us to request access, correction, export, deletion, restriction, or objection, depending on your location and the type of data involved.
Account deletion and learner deletion requests may require us to verify the requester, preserve billing, payout, tax, safety, abuse-prevention, audit, or legal records, and remove or anonymize service data in a staged way. Some records may remain where another user needs them for the learning relationship, where retention is legally required, or where deletion would compromise security or billing records.
Push notifications can be controlled in the mobile operating system. Device push tokens can be disabled when you sign out or when the app asks us to delete the token.
Transfers
International data transfers
Oostad and its providers may process information in the United Kingdom, United States, European Economic Area, and other countries where our infrastructure, support, payment, storage, authentication, AI, and app services operate. When data moves across borders, we rely on provider agreements, contractual safeguards, and other lawful transfer mechanisms where required.
Security
How we protect information
We use authentication, role-based access controls, scoped API authorization, signed storage URLs, rate limits, audit and diagnostic logs, provider security controls, and operational monitoring to protect information. No online service can guarantee perfect security, so users should keep credentials private and report suspected account or data issues promptly.
Rights
Your privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. You may also have the right to withdraw consent where processing depends on consent.
We do not sell personal information. We do not use personal information for third-party tracking or behavioral advertising unless the policy, product behavior, and app privacy disclosures are updated to say so.
Links and contact
Legal, support, and privacy contact
Our terms are available at /terms. Billing correction and cancellation information is available at /refunds.
For privacy questions or requests, email [email protected]. For product support, email [email protected].