Privacy Policy

Last Updated: March 20, 2026  •  Effective Date: March 20, 2026

Plain-language summary: We collect only what we need to provide the service. We do not sell your personal data. We use industry-standard security. You can request deletion of your data at any time. If you are in the EU, UK, or California, you have additional rights described below.

1. Introduction

Pedagion Inc. ("Pedagion," "we," "us," or "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your personal information when you use our website at pedagion.ai, our applications, and all related services (collectively, the "Service").

This policy applies to all users globally and is designed to comply with the General Data Protection Regulation (GDPR) (EU/EEA), the UK Data Protection Act 2018, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Personal Information Protection and Electronic Documents Act (PIPEDA) (Canada), the Children's Online Privacy Protection Act (COPPA) (United States), the Australian Privacy Act 1988, Brazil's Lei Geral de Proteção de Dados (LGPD), and other applicable data protection laws.

2. Data Controller

Pedagion Inc. is the data controller for the personal information collected through the Service. For all privacy inquiries, contact:

Pedagion Inc.
Email: privacy@pedagion.ai

3. Information We Collect

3.1 Information You Provide

Data TypeExamplesPurpose
Account InformationName, email address, date of birth, country, password (hashed)Account creation, authentication, age verification, service personalization
Payment InformationBilling details processed via StripeSubscription billing (we do not store full credit card numbers)
Uploaded ContentPDFs, documents, files you upload for curriculum generationAI processing to generate educational content
Learning ActivityCompleted chapters, quiz responses, XP earned, study timeProgress tracking, gamification, service improvement
CommunicationsSupport requests, feedback submitted through contact formsCustomer support, service improvement

3.2 Information Collected Automatically

Data TypeExamplesPurpose
Device InformationBrowser type, operating system, device typeService optimization, security
Usage DataPages visited, features used, interaction patternsService improvement, analytics
Log DataIP address, access times, error logsSecurity monitoring, debugging, fraud prevention

3.3 Information We Do NOT Collect

4. Legal Bases for Processing (GDPR/UK GDPR)

For users in the European Economic Area, United Kingdom, and other jurisdictions requiring a legal basis for data processing, we rely on the following:

Legal BasisProcessing Activities
Contract Performance (Art. 6(1)(b) GDPR)Account management, service delivery, billing, content generation
Legitimate Interest (Art. 6(1)(f) GDPR)Service improvement, security monitoring, fraud prevention, analytics
Consent (Art. 6(1)(a) GDPR)Marketing communications (where required), optional analytics cookies
Legal Obligation (Art. 6(1)(c) GDPR)Tax records, regulatory compliance, responding to lawful requests

5. How We Use Your Information

We use collected information to:

6. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information. We may share data only in the following limited circumstances:

RecipientPurposeSafeguards
Google Cloud PlatformInfrastructure hosting, data storage, AI processingData Processing Agreement, SOC 2 certified
Google AI (Gemini)AI content generationData is processed per Google's AI Terms; not used to train Google's models
StripePayment processingPCI DSS Level 1 compliant
Firebase (Google)Authentication, databaseData Processing Agreement
Law EnforcementWhen required by valid legal processWe review all requests and challenge overbroad demands
Business TransferIn connection with a merger, acquisition, or asset saleSuccessor entity bound by this policy; users notified in advance

7. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence, including the United States and Canada, where our infrastructure and service providers operate. For transfers from the EEA/UK, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission, or other lawful transfer mechanisms. For transfers from other jurisdictions, we comply with applicable local data transfer requirements.

8. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes described in this policy:

9. Your Rights

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal information:

RightDescriptionApplicable Jurisdictions
AccessRequest a copy of your personal dataGlobal (GDPR, CCPA, PIPEDA, LGPD)
RectificationCorrect inaccurate or incomplete dataGlobal
Erasure / DeletionRequest deletion of your personal dataGDPR, CCPA, LGPD, PIPEDA
PortabilityReceive your data in a structured, machine-readable formatGDPR, LGPD
RestrictionLimit how we process your dataGDPR, LGPD
ObjectionObject to processing based on legitimate interestGDPR
Withdraw ConsentWithdraw previously given consent at any timeGlobal
Non-DiscriminationNot be discriminated against for exercising your rightsCCPA/CPRA
Lodge a ComplaintFile a complaint with a supervisory authorityGDPR (DPA), LGPD (ANPD)

To exercise any of these rights, contact us at privacy@pedagion.ai. We will respond within 30 days (or the shorter period required by your applicable law). We may request verification of your identity before processing your request.

10. Children's Privacy

Pedagion is designed for users aged 13 and older. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA/UK without parental consent). If you are a parent or guardian and believe your child under 13 has provided personal information to us, please contact us at privacy@pedagion.ai and we will promptly delete such information.

For users between 13 and 18, we collect only the minimum information necessary to provide the Service and apply enhanced protections including content safety filters and restricted features.

11. AI Processing and Automated Decision-Making

Pedagion uses artificial intelligence to generate educational content, personalize learning paths, and assess quiz responses. This processing is necessary for the performance of our contract with you (providing the Service).

We do not use automated decision-making that produces legal or similarly significant effects on you. The AI does not make decisions about your eligibility for services, creditworthiness, or employment. XP calculations and content filtering use rule-based algorithms, not AI profiling.

Under GDPR Article 22, you have the right not to be subject to decisions based solely on automated processing that significantly affect you. If you believe any automated processing has significantly affected you, contact us to request human review.

12. Security Measures

We implement industry-standard technical and organizational measures to protect your personal information, including:

No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with applicable law (within 72 hours for GDPR).

13. Cookies and Tracking

Pedagion uses minimal cookies and local storage for essential functionality:

14. California-Specific Disclosures (CCPA/CPRA)

If you are a California resident, you have the following additional rights under the CCPA/CPRA:

In the preceding 12 months, we have collected the categories of personal information described in Section 3. We have not sold personal information and do not intend to do so.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered address at least 30 days before the changes take effect. The "Last Updated" date at the top of this page indicates when the most recent revisions were made. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised policy.

16. Contact Us

For any privacy-related questions, concerns, or requests, contact us at:

Pedagion Inc. — Privacy Team
Email: privacy@pedagion.ai
General Support: support@pedagion.ai
Website: pedagion.ai

For users in the EEA/UK, if you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.