Privacy Policy (POPIA)
Last updated: 2 October 2026 (Version 2026-10-02)
This Privacy Policy explains how personal information is collected, used, protected and shared when you use StudyMeneer. It is issued in compliance with Section 18 of the Protection of Personal Information Act, 4 of 2013 (POPIA).
1. Responsible Party & Information Officer
StudyMeneer is owned and operated by Bokano Tech (Pty) Ltd (trading as StudyMeneer), a private company incorporated in the Republic of South Africa.
- Company Registration Number: 2026/649274/07
- Information Regulator Registration Number: 2026-064447 (registered 14 August 2026)
In accordance with Section 55(1) of POPIA, our Information Officer is Siphesihle Moloi (appointed 14 August 2026). Questions, requests to exercise your rights, and complaints about this policy can be sent to support@studymeneer.com.
2. Information We Collect
We collect only the personal information needed to deliver our study tools:
- Account Data: Email address, optional display name, and a password hash (managed by Supabase Auth; we never see or store your plain-text password). If you sign in with Google, we receive your email address and name from Google.
- Study Content: Notes, tasks, flashcards, subjects, study schedules, Meneer conversations and quiz statistics you create in the app.
- Device & Usage Data: AI usage counters (used to apply your daily limit), session timers, streaks and theme preferences.
3. Purpose and Legal Basis for Processing
We process personal information to run your account and the features you use (contractual necessity), to keep the service secure and prevent abuse (legitimate interest), and where you have given consent. We use it for nothing else. We do not sell, rent or trade personal information, and we do not use it for third-party advertising.
4. Local vs. Cloud Data Separation
- Synced to the cloud: Notes, tasks, flashcards and subjects sync to our cloud database with Row Level Security (RLS), so only your account can read them.
- Device-only (IndexedDB): Textbook PDFs and recorded lecture audio stay on your device. They are not uploaded to our servers. Clearing your browser data removes them, and they are not backed up.
5. Third-Party Service Providers & Cross-Border Transfers
Some operators process data on servers outside South Africa, as permitted by Chapter 9 of POPIA, under contractual and security safeguards:
- Supabase (account sign-in, cloud database and our AI gateway): stores your account and synced study content.
- Google (Gemini API), Groq and OpenAI (United States): when you ask Meneer a question or request a summary, quiz or breakdown, the relevant text is sent through our server gateway to one of these AI providers to generate the reply. Our gateway holds the provider keys, so they never reach your device.
- Netlify (United States / global): serves the website and app files.
- Google (sign-in): only if you choose Sign in with Google.
AI replies can contain mistakes, and you should not put information in your questions that you would not want processed by these providers.
6. Data Retention & Deletion
- Account and synced study content: kept while your account is active.
- Deleting your account: you can do this at any time in Settings > Account > Delete Account, which deletes your account and associated cloud data. Copies held only on your own device stay there until you clear your browser data.
- AI usage counters: kept only as long as needed to apply daily limits and prevent abuse.
7. Your Rights
Under Sections 23 to 25 of POPIA you may ask us to confirm what personal information we hold about you and give you a copy, to correct or delete it, and to stop processing it or withdraw your consent. Contact the Information Officer at support@studymeneer.com.
Right to complain: you may lodge a complaint with the Information Regulator of South Africa: website inforegulator.org.za, general enquiries enquiries@inforegulator.org.za, POPIA complaints POPIAComplaints@inforegulator.org.za.
8. Children
StudyMeneer is used by learners in Grades 8 to 12, so many users are under 18. Under Section 35 of POPIA, if you are under 18 you must have the consent of a parent or legal guardian before creating an account. A parent or guardian may contact the Information Officer to ask what we hold about their child, or to have it corrected or deleted.
9. Information Security
In line with Section 19 of POPIA we take reasonable technical and organisational measures to protect your information:
- All traffic is encrypted in transit (HTTPS).
- Passwords are stored only as salted hashes, by Supabase Auth.
- Row Level Security means each account can read only its own data.
- AI provider keys are held server-side and are never sent to your browser.
No system is perfectly secure. If a breach affects your personal information we will notify you and the Information Regulator as POPIA requires.
10. Changes to this Policy
We may update this policy as the app or the law changes. When we make material changes we will update the date and version at the top, and tell account holders in the app.