
Privacy Policy — Temelie
1) Who provides Temelie
Temelie is provided by Saifullah Ahad. Temelie helps a learner and one trusted helper locate an unsettled mathematics foundation and coordinate one short, human-led activity.
Privacy contact: www.saifullah.ai@gmail.com
Website: https://saifullah.ai
Location: Dhaka, Bangladesh
2) No child account or public community
Temelie has no child-facing sign-up, public profile, search, follower system, stranger matching, class roster, or chat. A helper creates a device-bound learner space and gives its one-time code directly to a learner they already know. The learner receives only a credential scoped to that space.
3) Information Temelie processes
- Helper device security: a random device identifier, a public cryptographic key, and a hashed recovery secret. The private signing key remains in Android Keystore.
- Learner-space data: a short name or nickname chosen by the helper, hashed pairing credentials, role, and creation time. Temelie does not ask for a surname, date of birth, school, address, contact list, or location.
- Diagnostic evidence: mathematics item identifiers, the selected answer or “I do not know,” and event time. These are used to compute a starting point. Learners are not assigned a grade, score, rank, percentage, or comparison.
- Helper evidence: one of three session outcomes and an optional short note.
- Optional shared content: learner work or a helper note typed by a user, plus reports or block actions submitted for safety.
- Notifications: a Firebase Cloud Messaging installation identifier when notifications are enabled.
- Abuse prevention: one-way hashes derived from connection addresses, short-lived request nonces, event identifiers, and timestamps used for replay protection and rate limiting.
4) Why this information is used
We process this limited information to create and pair a learner space, synchronise evidence between the two known participants, recompute the prerequisite starting point, deliver the helper’s next action, send requested update notifications, honour deletion/blocking, investigate reports, and protect the service from replay or abuse. We do not use it for advertising, profiling across apps, school reporting, selling data, or automated marketing.
5) Service providers and transfers
- Cloudflare: Worker, Durable Objects, and D1 operate Temelie’s API, synchronisation, and encrypted-at-rest cloud records. Cloudflare also processes ordinary request/network metadata needed to deliver and protect the service. See Cloudflare’s Privacy Policy.
- Google Firebase Cloud Messaging: Google processes the app instance’s notification installation identifier and a minimal data notification containing the learner-space identifier when updates are enabled. See Firebase Privacy and Security.
Data may be processed in countries where these providers operate. All app-to-service traffic uses HTTPS. We do not sell personal information and do not share it for advertising.
6) Local storage and app lock
Temelie keeps learner spaces, diagnostic events, helper cards, shared work, reports, settings, and pending offline changes in Android app-private storage. Android backup is disabled. An optional Temelie-only PIN is stored as a salted one-way hash. Optional biometric unlocking is handled by Android; Temelie never receives biometric data.
7) Retention and deletion
- One-time join codes expire after 10 minutes and become unusable after the learner joins.
- Active learner-space data remains until the helper deletes that space. In-app deletion removes its active events, shared work, notification tokens, and connection state. A minimal deleted-space tombstone prevents reuse; it contains no learner name or content.
- Safety reports may be retained for up to 180 days so abuse can be reviewed. When a learner space is deleted, report details and reporter-device links are removed; only an anonymised report category/status may remain until expiry.
- Push tokens that have not been refreshed for 90 days are removed. Expired replay nonces and rate-limit records are routinely removed.
- De-identified item-calibration counts may remain because they no longer identify a learner, helper, device, or learner space.
Helpers can delete a selected cloud learner space and either participant can clear local app data from Temelie Settings. Clearing Android app storage or uninstalling removes the local copy. Full instructions are at Temelie data deletion.
8) Your controls
- Notifications are optional and can be disabled in Temelie or Android Settings.
- Either participant can report each shared item and block the paired connection.
- The helper can delete a learner space; users can erase all local data.
- The About screen’s feedback action opens the user’s email app. Temelie itself does not transmit that email.
9) Children and safety
Temelie is designed for a learner aged 13 or older working with a trusted helper or family member. It does not allow a child account or contact with strangers. We maintain zero tolerance for child sexual abuse and exploitation. Read our separate Child Safety Standards. If we learn that information from a child under 13 was provided contrary to these terms, contact us so it can be deleted.
10) Security
Temelie uses TLS, scoped learner credentials, P-256 signed helper requests, replay nonces, rate limits, Android Keystore, idempotent event identifiers, least-privilege cloud access, optional app lock, reporting, blocking, and deletion controls. No system can guarantee absolute security; report a concern to the contact above.
11) Changes and contact
Material changes will be posted at this URL with a new effective date. Questions, access concerns, or deletion requests can be sent to www.saifullah.ai@gmail.com.