1. Who we are
EthioPrep operates the EthioPrep exam-preparation platform for students sitting the Ethiopian ESSLCE examination. For anything in this policy, write to privacy@ethioprep.et, call +251 91 234 5678, or post to Bole Sub-City, Woreda 03, Addis Ababa, Ethiopia.
2. What we collect
Only what the product needs to function:
- Account details — your name, your grade, and an email address if you signed up with one.
- Learning activity — the questions you answer, whether you got them right, how long you spent, and the mastery scores derived from that.
- Group membership — the family or school you belong to, and your class if your school uses them.
- Payment records — what plan was bought, when, and the transaction reference. Card and mobile-money details are handled by Chapa and never reach our servers.
- Support messages — what you send us through the contact form, so we can reply.
- Basic technical data — the browser and device type, and a one-way hash used only to rate-limit our public forms.
Students provisioned by a school or a guardian are created with a name and a grade only. We do not ask a child for an email address or a phone number, because we do not need one — they sign in with a personal code instead.
3. Why we use it
- To run the product: serve questions, mark them, and track progress.
- To tell you what to study — the diagnosis and study plan are computed from your own activity.
- To let a guardian or an assigned teacher see the progress of a student in their care.
- To take payment and grant the right plan.
- To answer you when you contact us.
- To keep the service secure and to investigate abuse.
We do not sell your data, rent it, or use it to target advertising. We do not build advertising profiles.
4. Who can see a student's data
Visibility is deliberately narrow and one-directional:
- You always see your own data.
- A guardian sees the children in their family account.
- A school owner sees the students in their school.
- A teacher sees only the students in the classes they are assigned to — never the whole school.
- A student cannot see another student's data, and cannot see their teacher's.
- Our staff access accounts only where it is necessary for support, security, or content review, and those actions are logged.
Leaderboards show a display name, level and progress to other students. Nothing about your answers, your weak topics or your account is visible there.
5. Children and guardian consent
Our users are mostly secondary-school students, and many are minors. When a guardian creates an account for a child, we record who gave consent, when, and the exact wording they agreed to. That record is kept for as long as the account exists and is available on request.
A guardian can export everything we hold about their child, or delete the account outright, at any time from the child's page. Deleting removes the account and the learning data attached to it.
6. Who we share it with
We use a small number of service providers, and only for the purpose named. We do not share data with anyone else unless the law requires it.
- Supabase — database, authentication and file storage.
- Chapa — payment processing. They receive the payment details; we receive the result.
- Vercel — application hosting and delivery.
- Our AI provider — only the specific question and textbook passage needed to answer a tutor request. We do not send your identity or your account history.
7. How long we keep it
- Learning data is kept while your account is open, because progress over time is the product.
- Payment records are kept for as long as tax and accounting rules require.
- Support messages are kept for two years, then deleted.
- Technical rate-limiting hashes are kept for 30 days.
- When an account is deleted, its learning data goes with it.
8. Your rights
You can ask us to:
- Give you a copy of your data in a machine-readable file.
- Correct anything that is wrong.
- Delete your account and its data.
- Stop using your data for a particular purpose.
Guardians and schools can do the first and third of these themselves for accounts they created. For everything else, email privacy@ethioprep.et and we will act within 1 business day for simple requests, and within 30 days for anything that needs verification.
9. How we protect it
Access is enforced at the database level, not only in the application, so a bug in one screen cannot expose another student's records. Every cross-account read goes through a single audited rule, and administrative actions are written to an audit log. Traffic is encrypted in transit. We do not store payment card details at all.
10. Changes to this policy
If we change this policy we update the effective date at the top and, for anything material, tell account holders directly. Continuing to use EthioPrep after a change means you accept the updated policy.