Back to home
Privacy policy

Privacy Policy

Last updated: 2026-05-21

1. Introduction

My Smart AI Teacher ("we", "our", "us") operates the platform at https://mysmartaiteacher.com (the "Service"). This privacy policy explains how we collect, use, share, and protect your personal information.

This policy complies with the General Data Protection Regulation (GDPR — EU 2016/679), the California Consumer Privacy Act (CCPA/CPRA), the Personal Information Protection and Electronic Documents Act (PIPEDA — Canada), and Quebec's Law 25.

2. Data controller and contact

Data controller: My Smart AI Teacher.

Single point of contact (GDPR / Law 25 / CCPA): [email protected]

For EU residents: you have the right to lodge a complaint with your competent supervisory authority (CNIL in France, ICO in the UK, etc.).

3. Data we collect

Data you provide directly: email, first name, last name, date of birth, hashed password, profile picture (if Google OAuth).

Transaction data: Stripe customer ID, amount, currency, purchase date, plan purchased, remaining credits. Card numbers never reach our servers (handled by Stripe — PCI DSS Level 1).

Technical data: IP address (anonymized for rate-limiting), user-agent, preferred language, approximate timezone.

AI Coach usage data: prompts you send and responses generated, retained to enable conversation resumption. These are never sold or used to train third-party models.

Analytics data (only with consent): anonymized heatmaps and session recordings via Microsoft Clarity; conversion events via X Pixel and Google Tag Manager.

4. Purposes of processing

Service delivery: account creation, authentication, access to purchased content, AI Coach operation.

Payment and billing management via Stripe.

Transactional communication: purchase confirmations, login codes (magic links), important Service changes.

Newsletter (only with explicit opt-in): new features, educational content, promotional offers.

Service improvement: anonymized usage analysis (only if analytics consent given).

Ad measurement: conversion tracking (only if marketing consent given).

Legal obligations: invoice retention (10 years in France), responding to lawful requests from authorities.

5. Lawful basis (GDPR)

Performance of contract (art. 6.1.b GDPR): account creation, payment, Service access.

Consent (art. 6.1.a GDPR): non-essential cookies, newsletter, marketing.

Legal obligation (art. 6.1.c GDPR): accounting retention, fraud prevention.

Legitimate interest (art. 6.1.f GDPR): Service security, abuse prevention, aggregated statistics.

6. Retention periods

User account: active as long as the account exists. Deleted within 30 days of erasure request (GDPR art. 17).

Billing data: 10 years (accounting obligation).

AI Coach conversations: contract duration + 30 days.

Technical logs: 6 months maximum.

Analytics data (Clarity): 12 months.

Consent cookies: 6 months (CNIL recommendation).

7. Subprocessors and third parties

We use subprocessors located in the EU, the United States, and Canada. Each is bound by an agreement compliant with GDPR Article 28.

Hosting and database: Supabase (EU/US — SCCs in place).

Payment: Stripe Inc. (Ireland for EU / US — DPA available).

Transactional and newsletter emails: Mailjet (France).

Captcha: Cloudflare Turnstile (US — SCCs).

Analytics (with consent): Microsoft Clarity (US — SCCs).

Marketing (with consent): X Corp. (US), Google LLC (US) via Google Tag Manager — SCCs.

No subprocessor has the right to use your data for their own purposes.

8. International transfers

Some subprocessors are based in the United States. These transfers are governed by Standard Contractual Clauses (SCCs) issued by the European Commission and, where applicable, by the EU-US Data Privacy Framework.

For Canadian residents, we apply equivalent safeguards under PIPEDA and Quebec Law 25.

9. Cookies and trackers

We use three categories of cookies:

• Strictly necessary cookies (always on): authentication, CSRF security, language preferences. Legal basis: contract performance / legitimate interest.

• Analytics cookies (opt-in): Microsoft Clarity to understand usage. Legal basis: consent.

• Marketing cookies (opt-in): X Pixel, Google Tag Manager for ad measurement. Legal basis: consent.

You can change your preferences anytime via the "Cookie preferences" link in the footer. We automatically honor the Global Privacy Control (GPC) signal sent by your browser.

10. Your rights (GDPR / Law 25)

Right of access: obtain a copy of your data. Automatic download available in My Account > Your data.

Right to rectification: correct inaccurate information via My Account.

Right to erasure (right to be forgotten): delete your account via My Account > Danger zone.

Right to data portability: JSON export available in My Account.

Right to restrict processing.

Right to object to processing based on legitimate interest.

Right to withdraw consent at any time.

Right to lodge a complaint with a supervisory authority.

To exercise these rights, contact us at [email protected]. We respond within 30 days maximum.

11. California residents (CCPA/CPRA)

If you are a California resident, you have additional rights:

• Right to know which categories of data we collect and with whom we share them.

• Right to request deletion of your data.

• Right to correct inaccurate data.

• Right to opt out of the "sale" or "sharing" of your personal information for advertising (Do Not Sell or Share My Personal Information).

• Right to non-discrimination for exercising your rights.

To exercise the opt-out right, visit: /privacy-choices. We also honor the Global Privacy Control signal.

12. Canadian residents

PIPEDA (federal): you have rights of access, rectification, and withdrawal of consent. You may file a complaint with the Office of the Privacy Commissioner of Canada.

Quebec Law 25: since September 22, 2024, consent for non-essential cookies must be explicit and granular. You also have a right to de-indexing and to ceasing dissemination. You may file a complaint with the Commission d'accès à l'information du Québec.

Our privacy officer can be reached at [email protected].

13. Minors

Our "AI Training for Teens" offering is intended for minors aged 13 and over. For minors under 16 in the EU (or 13 in the US under COPPA), parental or legal guardian consent is required.

If you believe a minor has provided data without parental consent, contact us immediately at [email protected] for deletion.

14. Security

We implement technical and organizational measures to protect your data: TLS 1.3 encryption in transit, at-rest encryption on Supabase and Stripe, rate-limiting, Cloudflare Turnstile captcha, principle of least privilege, SQL access via Row Level Security.

No system is foolproof. In case of a data breach affecting your rights, we will notify you within 72 hours in accordance with GDPR Article 33.

15. Changes to this policy

We may update this policy. The "Last updated" date at the top indicates the version. For substantial changes (new major subprocessor, new purpose, etc.), we will notify you by email or in-app banner at least 30 days before the effective date.

16. Contact

For any question about this policy or to exercise your rights:

Email: [email protected]

Postal address: available upon request to the above email.

Standard response time: within 30 days (sometimes extended to 90 days for complex requests, with reasoned notification).

Legal disclaimer: This document is a template. It must be reviewed and customized by qualified legal counsel before production use. Exact obligations depend on your jurisdiction, processing volume, and offering specifics.