Privacy Policy
Last updated: July 14, 2026
1. Overview
This Privacy Policy explains how EduRise (eduorise.com) collects, uses, stores, and shares personal data when you use our learning platform, teacher tools, and center management features.
EduRise is operated from Alexandria, Egypt. For privacy inquiries or to exercise your rights, email info@eduorise.com.
2. Roles and Responsibilities
For core platform accounts (students, teachers, parents, staff), EduRise acts as the data controller for account and authentication data we process to run the service.
Teachers who operate Center products and maintain center student rosters act as independent controllers for center-specific records (attendance, billing, homework, etc.) they enter about their students. They are responsible for obtaining appropriate consent from students and guardians.
3. Information We Collect
Account and profile data — name, email, hashed password, phone, country, role, profile image, account status, and locale preference.
- Student profile data — grade, national ID (optional), birth date (optional), address (optional), guardian phone, course enrollments, favorites, ratings, and certificates earned.
- Teacher profile data — bio, degree, specialization, subjects taught, public teacher page information, subscription status, and Bunny/FlexiCloud video library identifiers.
- Parent data — national ID and job title linked to a parent user account.
- Staff data — permissions for LMS and Center sections assigned by the employing teacher.
- Authentication and device data — session IDs, IP address, user-agent, remember-me tokens, and for students: device token, device user-agent hash, device name label, device IP, and device lock timestamp.
- Learning activity — lesson progress, video checkpoint answers, content notes, quiz attempts, individual answers, scores, time spent, focus/tab-switch violation counts, quiz heartbeats, and wrong-answer review history.
- Wallet and payments — per-teacher wallet balances, recharge code redemptions, payment records, and wallet recharge requests including uploaded proof attachments (image/PDF), notes, and review status.
- Center operations — center student identity and contact data, QR/student codes, group assignments, attendance scans, absences, homework submissions and files, manual exam results, points, teacher notes, invoices, payments, expenses, and salary records for center crew.
- Communications — password reset tokens, email verification status, platform notifications, and teacher announcements delivered in-app.
- Advertising events — ad impression, click, skip, and completion events with creative ID, optional course ID, page name, and your user ID when signed in.
- Technical logs — server and application logs, rate-limit counters, and cached playback session tokens for protected video streaming.
4. How We Use Your Information
We use personal data to:
- Create and authenticate accounts, enforce device binding for students, and maintain secure sessions.
- Deliver courses, stream videos, process quiz attempts, issue certificates, and show learning progress to you and your teachers.
- Operate wallets, recharge codes, invoices, and center finance features.
- Enable teachers and authorized staff to manage students, attendance, homework, and reports.
- Send transactional emails (password reset, verification, billing notices where applicable).
- Measure feature usage, diagnose errors, prevent fraud and abuse, and improve the Platform.
- Display and measure in-platform advertisements.
- Comply with legal obligations and enforce our Terms of Service.
5. Legal Bases for Processing
Depending on your location, we rely on: (a) contract performance — to provide the service you signed up for; (b) legitimate interests — security, fraud prevention, product improvement, and advertising measurement, balanced against your rights; (c) consent — where you accept policies at registration or opt into optional features; and (d) legal obligation — where we must retain or disclose data under applicable law.
6. Cookies and Local Storage
We use the following browser technologies:
- Session cookie — maintains your signed-in session (name configured per deployment; HttpOnly; SameSite=Lax).
- Remember-me cookie — optional long-lived cookie when you select "Remember me" at login, linked to a token stored hashed on your user record.
- device_token cookie — HttpOnly cookie for student device binding (up to five years).
- CSRF token — protects form submissions from cross-site attacks.
- localStorage — auth pages may store dark/light theme preference (
darkMode) on your device only; this is not transmitted to our servers.
7. Device Binding and Security Practices
Student accounts bind to one device using a random device token stored in our database and mirrored in a secure cookie, combined with a hashed normalized user-agent string for recovery when cookies are cleared on the same browser.
We record IP addresses at login and device binding for security auditing. Teachers and administrators can reset device bindings when you legitimately change devices.
We apply security headers (frame protection, content-type sniffing protection, referrer policy, content security policy, and HSTS on HTTPS connections). Login and registration endpoints are rate-limited.
When you log in, other database-stored sessions for your account are invalidated to reduce session hijacking risk.
8. Video Playback and File Uploads
Protected videos are delivered through time-limited playback sessions (Bunny.net Stream, FlexiCloud HLS proxy, or embedded providers). Session tokens are stored in server cache and are not shared with other users.
You may upload files including profile images, homework submissions, wallet recharge proofs, course attachments, and center registration documents. Files are stored on our servers or connected object storage (including FlexiCloud R2) and accessible only to authorized roles.
9. Who We Share Data With
We share personal data only as needed to operate the Platform:
We do not sell your personal data. Teachers receive student data only for students enrolled with them or registered at their center.
- Your teachers and their authorized staff — enrollment, progress, quiz results, wallet activity, and center records relevant to their classes.
- Parents — where parent accounts are linked to student progress per product configuration.
- Infrastructure providers — hosting, database, cache, email delivery, Bunny.net, FlexiCloud/R2 storage, and PDF generation libraries running on our infrastructure.
- Platform administrators — for billing, subscription management, support, and security investigations.
- Legal authorities — when required by valid legal process or to protect rights, safety, and integrity of the Platform.
10. International Data Transfers
Our primary operations are in Egypt. Video CDN and cloud storage providers may process data in other countries. When data is transferred internationally, we implement appropriate safeguards consistent with applicable law and provider agreements.
11. Data Retention
We retain account and learning data while your account is active and for a reasonable period afterward to comply with law, resolve disputes, and maintain academic records at a teacher's or center's request.
Session records expire according to session lifetime settings. Device tokens remain until reset. Advertising event logs and server logs are retained for analytics and security for limited periods.
You may request deletion of your account by contacting info@eduorise.com; some records (payment history, invoices, or data held by teachers as separate controllers) may be retained where legally required or where the teacher maintains independent center records.
12. Your Rights
Subject to applicable law, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing or withdraw consent where processing is consent-based.
To exercise these rights, email info@eduorise.com with sufficient information to verify your identity. We respond within reasonable timeframes required by law.
You may lodge a complaint with your local data protection authority if you believe our processing violates applicable regulations.
13. Children and Guardians
The Platform is designed for students in formal education. We collect guardian phone numbers at student registration to support account recovery and teacher communication.
Parents or guardians should supervise minor students' use of the Platform and contact us or the student's teacher regarding access, device resets, or data concerns.
14. Changes to This Policy
We will post updates on this page with a revised "Last updated" date. Material changes may also be communicated through the Platform or email where appropriate.
15. Contact
EduRise — Alexandria, Egypt
Email: info@eduorise.com