Privacy Policy
Introduction
Falak AI: More Than Flashcards ("Falak") is an AI-powered study app for students. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have. By using Falak you acknowledge the practices described here. If you do not agree, please do not use the app.
This is a study product that processes content with AI. Your chat messages and any study materials you upload are sent to AI providers to generate responses — see the "AI processing disclosure" section.
Who We Are (Data Controller)
Falak Group is the controller responsible for your data. Contact us at support@falak.pro for any privacy request. Our website is falak.pro.
What Data We Collect and Why
Account & Identity
- Authentication & identity: account ID (UUID), email address, login/session tokens — created and managed via Supabase Auth, to create and secure your account.
- Profile data: display name, username, bio, avatar and banner images, country, gender, birth date.
Academic & Education Profile
- Education type (school student, university student, graduate, teacher, business owner), grade level, academic track (e.g. scientific/literary), school name, university affiliation, major/field of study, graduation year, teacher expertise areas, and (for business accounts) business name and category — to personalize your learning experience and tailor content.
Learning & Study Data
- Study paths and learning plans, canvas/board states, course enrollments, community-path progress and file submissions, generated study notes, flashcards, quizzes and exams.
Sky AI Chat & Uploads
(See the "AI processing disclosure" section for processing detail.)
- AI conversation history (sessions and messages), your prompts, and file attachments (images, PDFs, documents) you send to Sky.
- AI tool-activity and run events generated during chat.
Knowledge Bank (Your Private Files)
- Files you upload to your personal Knowledge Bank, and the derived data we generate from them: text chunks, vector embeddings, token counts, and extracted page images/captions — used to let Sky read and answer questions about your own materials.
Library & Community Content
- Documents you upload to the shared Library, posts, comments, likes, story views and watch durations, download and rating counts. Library documents you share are discoverable by other users.
Social & Gamification
- Followers/following relationships; points, coins, prestige/support scores, badges, supporter tier, activation state, and a public-points-visible flag. Some of these are public-facing for leaderboards and social comparison if you choose to make points visible.
Subscriptions & Purchases
- In-app purchase and subscription data processed via RevenueCat: your app user ID, subscription status, product ID, expiry, and store (Apple). We store subscription status (active/inactive, plan, store) to grant the Falak Pro entitlement.
- In-app marketplace activity: items, purchases, ratings, coupons.
Devices, Notifications & Diagnostics
- Push notification tokens (Expo push token, native APNS tokens), platform, OS version, device name, and an "active/inactive" status — to deliver notifications.
- Device identifiers and metadata used for notification registration and diagnostics.
- Crash and error reports sent to our error-monitoring provider in production builds (disabled in development).
- App performance metrics, which may include device info and limited user context.
Referrals & Personalization
- Referral and invite codes, referral relationships and qualifications; character archetype / avatar selections; theme and wallpaper preferences.
App Configuration
- App-wide settings and feature flags (this configuration is not linked to your identity).
AI Processing Disclosure (Important)
Falak's AI tutor "Sky" does not run on your device. To generate responses:
- Your prompts and attachments (images, PDFs, documents) are transmitted over HTTPS to the Sky AI backend and processed by a third-party large-language model (MiniMax).
- Files you add to your Knowledge Bank are uploaded to BunnyCDN and sent to the Sky backend for chunking, embedding generation, and vision (image) processing.
- Your profile and learning-path state may be synced to the Sky AI workspace using your authenticated session token to personalize tutoring.
- AI chat history is stored persistently in our database (Supabase). Content sent to Sky is readable by the Sky infrastructure that processes it. Do not share information in chat that you would not want processed externally.
- A restricted admin review capability exists for support and quality purposes; access is limited to authorized administrators.
Third-Party Processors and Partners
We share data with the following service providers strictly to operate the app:
- Supabase — Backend platform: authentication, database, real-time APIs, access controls, file-storage signing.
- Sky AI backend / MiniMax — Processes your prompts, attachments and Knowledge Bank files; runs the AI model that generates responses.
- RevenueCat — Manages in-app purchases and subscriptions; receives store purchase events.
- BunnyCDN — Hosts and delivers uploaded Library documents and Knowledge Bank images.
- Apple App Store — iOS distribution and in-app purchases (via RevenueCat); APNS push tokens.
- Error-monitoring provider — Receives crash and error reports from production builds.
- Expo — App framework and push-notification delivery infrastructure.
We do not sell your personal data.
Legal Bases (Where GDPR or Similar Applies)
We process data to perform our contract with you (account, subscriptions, core features), based on your consent (e.g. optional notifications, optional public points), for our legitimate interests (security, diagnostics, abuse prevention, product improvement), and to meet legal obligations.
Data Retention
- Account and profile data: kept while your account is active.
- Chat history, Knowledge Bank files, embeddings and Library uploads: kept until you delete them or close your account, subject to backup cycles.
- Diagnostic/crash logs: retained for a limited period for stability and security.
- Subscription records: retained as required for billing, tax, and dispute purposes.
We delete or anonymize data within a reasonable period after it is no longer needed. [Exact retention periods: _____]
Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, restrict, object to, or delete your personal data, and to withdraw consent. To exercise these rights, contact support@falak.pro.
Account & Data Deletion
You can request account deletion from within the app or by emailing support@falak.pro. Deletion removes your profile, chat history, Knowledge Bank files and derived data, and Library uploads, subject to records we must keep by law (e.g. transaction records). [In-app account-deletion flow location: _____]
Children and Education
Falak is an educational app used by students, including minors (school students roughly ages 10–18). We collect academic and profile data from these users to provide the service. If you are under the age of digital consent in your country, you should use Falak only with the involvement and permission of a parent, guardian, or school. We do not knowingly process children's data beyond what is needed to provide the educational service. Parents/guardians may contact us at support@falak.pro to review or delete a minor's data. [Age-gating and parental-consent obligations to confirm with counsel: _____]
International Data Transfers
Our providers (including Supabase, the Sky AI backend, BunnyCDN, RevenueCat, Expo, Apple, and our error-monitoring provider) may process and store data in countries outside your own. Where required, transfers rely on appropriate safeguards. By using Falak you understand your data may be processed internationally.
Security
We use HTTPS in transit and provider-level access controls (e.g. row-level security). Note that content sent to the AI backend is readable by that infrastructure to perform processing; we do not apply additional application-level encryption to that content. No system is perfectly secure.
Changes to This Policy
We may update this policy. We will revise the "Last updated" date and, for material changes, provide in-app notice.
Contact
Privacy questions or requests: support@falak.pro — Falak Group. Website: falak.pro.
[Company registered address: _____]