Eduraa
FeaturesFor institutionsPricingAboutContact
Sign inBook a demo

Privacy Policy

Last updated: July 19, 2026

This Privacy Policy explains how Eduraa ("Eduraa", "we", "us") collects, uses, and protects personal data when you use the Eduraa learning platform — the web application, the mobile apps, and the services behind them. Eduraa is a multi-tenant Learning Management System: independent educational institutions ("Institutions") run their own branded academies on our infrastructure. When you study with an Institution, that Institution is the data controller for your course activity and Eduraa acts as its data processor; Eduraa remains the controller for the platform-level account data described below.

1. Information we collect

  • Account data: your name and email address, provided when you register. Personally identifying fields such as your email are encrypted at rest in our database.
  • Authentication data: a securely hashed password, session and refresh tokens, and — if you choose to sign in with Google or Apple — the basic profile (name, email) those providers share with us. We never see your Google or Apple password.
  • Learning data: enrollments, lesson and course progress, quiz answers and scores, certificates, and video watch analytics (which parts of a video you watched, for how long, and playback quality) used to track your progress and improve course content.
  • Payment data: records of your purchases and subscriptions (amount, currency, item, status). Card and wallet details are collected and processed directly by Stripe or PayPal — we never receive or store your card number.
  • Device and security data: device characteristics (a device fingerprint), app integrity signals on mobile (such as root/jailbreak detection results), and IP address — collected to protect paid course content and prevent account abuse.
  • Push notification tokens: if you enable notifications, we store a Firebase Cloud Messaging (FCM) token for your device.
  • Diagnostics: error and crash reports (via Sentry) that may include your IP address, device/browser details, and the actions that led to the error.

2. How we use your information

  • To create and operate your account and deliver the courses you enroll in.
  • To track and display your learning progress and issue certificates.
  • To process payments and maintain billing records through Stripe and PayPal.
  • To protect course content from unauthorized copying and account sharing (see the content-protection section below).
  • To send you service notifications — enrollment confirmations, live-class reminders, and announcements from your Institution.
  • To diagnose errors, keep the platform secure, and improve performance.

Where the GDPR applies, we rely on performance of a contract (operating your account and the courses you buy), our legitimate interests (securing the platform and protecting paid content), legal obligations (tax and accounting records), and your consent (push notifications), as the legal bases for these uses.

3. Content protection technologies

Institutions sell paid video courses on Eduraa, so the platform includes technical measures against piracy. We want to be transparent about what these do:

  • Forensic watermarking: video streams may carry an invisible or periodically visible marker tied to your account, so that leaked copies can be traced back to the session that produced them.
  • Device fingerprinting: we derive a technical identifier from your device's characteristics to limit how many devices can stream protected content from one account and to detect account sharing.
  • Screen-capture prevention: the mobile app blocks screenshots and screen recording on protected screens, and the apps detect rooted or jailbroken devices because they can bypass these protections.

These signals are used solely for content protection and platform security — never for advertising or cross-site tracking.

4. Payments

All card and wallet payments are processed by Stripe (stripe.com) or PayPal (paypal.com) on their own secure pages. Eduraa receives only the outcome of the payment and a transaction reference. We do not collect, transmit, or store card numbers, CVVs, or banking credentials. Stripe and PayPal process your data under their own privacy policies.

5. Cookies

Eduraa uses a small set of strictly necessary cookies: HttpOnly authentication cookies that keep you signed in, a CSRF token cookie that protects forms against forgery, and your language/theme preference. We do not use advertising or third-party analytics cookies. Because these cookies are essential for the service to function, they do not require a consent banner; blocking them in your browser will prevent sign-in.

6. Push notifications

With your permission, the mobile app sends push notifications through Firebase Cloud Messaging (FCM, a Google service) — for example live-class reminders or new-lesson announcements. You can withdraw permission at any time in your device settings or in the app, and we delete the device token when you log out or disable notifications.

7. Error reporting

We use Sentry to capture application errors and crashes so we can fix them. Reports contain technical context (device or browser type, app version, stack trace, IP address) and are retained only as long as needed for debugging. We configure Sentry to avoid collecting message bodies or sensitive form contents.

8. Who we share data with

We do not sell your personal data. We share it only with:

  • Your Institution: the academy you study with sees your name, email, enrollment, progress, and quiz results — it needs them to teach you and is responsible for them as data controller.
  • Service providers acting on our instructions: Stripe and PayPal (payments), Google and Apple (optional sign-in), Firebase/FCM (push notifications), Sentry (error reporting), and our cloud hosting and storage providers.
  • Authorities, where the law requires it or to defend our legal rights.

9. International transfers

Some of the providers above operate globally, so your data may be processed outside your country of residence. Where data of EEA/UK residents is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses with each provider.

10. Data retention

  • Account and learning data: kept while your account is active, then deleted or anonymized within 90 days of account deletion.
  • Payment records: kept for the period required by tax and accounting law (typically 5–10 years depending on jurisdiction).
  • Security logs, device fingerprints, and watermark session records: kept up to 12 months, longer only if needed for an active abuse investigation.
  • Error reports: retained per our Sentry data-retention settings (90 days by default).

11. Security

We protect your data with TLS encryption in transit, encryption at rest for identifying fields such as email addresses, hashed passwords, HttpOnly authentication cookies, strict tenant isolation between Institutions, audit logging of administrative access, and regular security reviews. No system is perfectly secure, but we treat security findings as our highest-priority work.

12. Your rights

Depending on your location (and always for EEA/UK residents under the GDPR), you have the right to access, correct, export, restrict, object to the processing of, and delete your personal data. Eduraa supports these directly:

  • Export: request a machine-readable copy of your data from your account (Profile → Export my data) — the platform provides a self-service data-export endpoint.
  • Deletion: request account deletion from Profile → Delete account. Institution-managed accounts require institution-admin approval, and administrator accounts are retained to protect administrative continuity. Some records (e.g. invoices) are kept where the law requires.
  • Complaints: you can lodge a complaint with your local data-protection authority at any time.

13. Children's privacy

Eduraa is not directed at children under 13 (or the higher minimum age your country sets, e.g. 16 in parts of the EEA). Institutions that teach minors are responsible for obtaining the consents their local law requires. If you believe a child provided us data without such consent, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the platform evolves. For material changes we will notify you in the app or by email at least 30 days before they take effect. The "Last updated" date at the top always reflects the current version.

15. Contact us

For any privacy question or to exercise your rights, contact us at support@eduraa.com. If your question concerns data held by your Institution, we will forward it to them or you can contact them directly.

Eduraa

The white-label LMS your institution will actually deploy.

Product

  • Features
  • For institutions
  • For learners
  • Pricing

Company

  • About
  • Contact
  • Book a demo

Resources

  • Privacy
  • Terms
  • DPA
  • Security

Contact

  • info@eduraa.com
  • support@eduraa.com
  • admin@eduraa.com

© 2026 Eduraa. All rights reserved.

Built with care in Cairo • Riyadh • Dubai