Operating Entity & Scope
This Privacy Policy explains how Ilmvia (Private) Limited (Karachi, Pakistan), operating as Ilmvia, handles personal information on our website and waitlist and in our education platform: the web app, the browser extension, and the iOS and Android apps.
We do not show advertising, sell personal information, or share it with data brokers.
Information We Collect
We collect the information needed to run accounts and workspaces and to communicate with you:
- Account & Role: Name, email address, sign-in details, language preference, your role (educator, learner, parent or institution administrator), the workspaces you belong to and, if you add one, a phone number.
- Children's Profiles: A parent or guardian can add a child's name, date of birth, grade, language and interests.
- Academic Records & Content: Classes, lessons, assessments, submissions, grades, attendance, timetables, report cards and messages added by you or by the workspaces you belong to, including photos, documents or recordings you choose to submit.
- Health Information (optional): A parent or an institution may record a learner's blood group, conditions, medications, emergency contacts and care needs, and an institution may record school clinic visits. Only people the family or institution authorizes can see them.
- Workspace Fees: If a workspace you join charges fees, the bank details its owner registers for members to pay into (account title, IBAN and, if added, a Raast ID), the fee and invoice records the workspace keeps, the transfer references and receipts members submit, and any payment disputes. We store the bank details, transfer references and receipts encrypted.
- Sign-in, Notifications & Paid Plans: If you sign in with Google, we use your name, email address and Google account identifier. If you allow notifications, we store a device token to send them. If you buy a paid plan, you enter card or wallet details on our payment provider's page and the provider holds them, not us; we keep your plan, the billing name, email and any tax registration number you give, invoices and refunds, and the label the provider gives a saved payment method (such as the card type and last four digits).
- Technical Data: IP address, browser or app version, operating system and error logs on our servers, used to keep the service working, secure and free of abuse.
- Waitlist & Direct Communications: If you join the waitlist, your email address, the page that referred you, your browser's user agent and a one-way hash of your IP address (to prevent abuse). Messages, feedback or pilot requests you send us.
- Device Permissions: The mobile apps ask for camera, microphone or photo access only when you use a feature that needs it, and you can turn each off in your device settings.
- Browser Extension: If you use the Ilmvia browser extension, the text you select on a page, the page's address, title and description, any note you add and, if you choose, a screenshot of the tab are sent to us only when you press the capture shortcut, click save, or choose an AI action. The extension keeps your sign-in session in your browser's extension storage, and signing out clears it. It does not read pages in the background or collect your browsing history.
We do not use advertising cookies, cross-site trackers or marketing pixels, and we do not sell or share personal information for advertising. This website uses Google Analytics, with its advertising features turned off, to count visits in aggregate; you can block it in your browser settings. The website and web app use your browser's storage to keep you signed in and to remember preferences such as display mode and language. We do not collect precise location, contacts or advertising identifiers.
We use what the extension sends us only to provide the clipping and assistant features you use, and share it only with the providers that run them. We never sell it, use it for advertising or use it to judge creditworthiness, and our staff read it only with your consent or when security or the law requires. This follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
Children & Workspaces
- Workspace Records: Whoever runs a workspace, whether a teacher, a family or an institution, decides who can see the records kept in it, such as grades and attendance. Questions about those records should go to them first.
- Children: Anyone under 18 uses Ilmvia through an account or profile that a parent or guardian, or their school acting with the family's authority, creates, invites them to or approves. We do not knowingly let a child open an account without that authority, and if we learn of one we may suspend it until a parent, guardian or school confirms it.
- Parents' Rights: A parent or guardian can view and correct their child's profile and can ask us at contact@ilmvia.com to delete their child's information.
- No Selling or Profiling: We never sell, rent or trade anyone's information, and never use it for advertising or to build marketing profiles.
- Human Authority: In classes, grades for written work and formal reports are released only after an educator confirms them; AI only suggests. Objective questions, such as multiple choice, can be marked and released automatically if the educator chooses. In self-study outside a class, AI feedback can appear straight away.
- AI Features: When you use an AI-assisted feature, including the Ayn assistant and the assistant in the browser extension, the text, files and records needed for that request are sent to our AI provider, Google (Gemini API), solely to generate the response. This can include clinic-visit and medical-accommodation records when staff authorized to see them ask the assistant about them. We do not train AI models on your data. AI output can be wrong, so do not enter anything you do not want processed this way.
Data Security & Storage
- Encryption: Traffic between our website, apps, browser extension and servers is encrypted in transit (HTTPS/TLS). Stored records are encrypted at rest by our infrastructure providers, and workspace fee payment details and receipts are additionally encrypted by us.
- Access Controls: Role-based permissions and per-workspace scoping restrict each account to the workspaces, classes and records it is authorized to see.
- Service Providers: We use a limited set of providers, each handling data only to provide their service to us and bound by their data-protection terms: Google Cloud and Firebase (hosting, the waitlist and push notifications), MongoDB Atlas (database and uploaded files), Resend (email), LiveKit Cloud (live-session audio and video), Google (Gemini API for AI features, Google sign-in, and Google Analytics on this website) and, once paid plans open, a payment provider we will name here.
Data Retention & Deletion
- Deleting Your Account: You can delete your account yourself in the web and mobile apps (Profile → Delete account) or by emailing contact@ilmvia.com. An account that owns a workspace other people still use must transfer or close it first.
- Deletion Timeline: Deleting an account signs you out on every device and starts a thirty (30) day grace period, during which signing in again restores it. After that, the name, email address and sign-in details on the account are permanently replaced with anonymous values. Records other people rely on, such as grades, attendance and submissions, stay attached to the anonymous account. To have other details removed as well, such as a phone number on your profile, email contact@ilmvia.com.
- Browser Extension Clips: Deleting a clip also deletes its screenshot, and signing out of the extension clears the session stored in your browser.
- Your Choices: You can ask us to access, correct or delete your information at any time, turn off notifications and device permissions in your settings, and leave the waitlist with the unsubscribe link in each email.