๐ Overview
Effective date: June 8, 2026 ยท Last updated: August 6, 2026
Eskwela ("the App") is a student scheduler built for Filipino students, developed by Ivan (independent developer, Minglanilla, Cebu, Philippines). This policy explains what data we collect when you use the Eskwela Android app, how we use it, and who we share it with. By using the App, you agree to this policy.
This App is intended for users 13 years of age or older. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal information, please contact us so we can delete it.
๐ฆ Data We Collect
We collect only what's necessary to provide the App's features:
| Data | Why we collect it | Where it's stored |
|---|---|---|
| Google account (name, email, profile photo) | Sign-in via Google OAuth โ so you have a personal account | Supabase (our database) |
| Email & password (if you sign up with email instead of Google) | Creates and secures your account; a 6-digit code is emailed to verify it's really you | Supabase (passwords are hashed โ we never see or store them in plain text) |
| Display name & user code | Used for your profile and so friends can find and add you by name or code | Supabase |
| Class schedule & tasks | Core feature โ saving your schedule and to-do items locally on your device | Device only (SharedPreferences / local storage) |
| Esky AI chat history | Saved locally so your conversation persists between sessions | Device only (SharedPreferences) |
| Friends list & friend requests | To connect with other Eskwela users and manage friend requests | Supabase |
| Friend-to-friend chat messages | Real-time messaging between friends inside the App | Supabase |
| Developer support messages | When you send a message to the developer through the in-app chat feature; the developer can reply directly | Supabase |
| Esky AI chat messages (Groq) | Sent to Groq to generate a response. Groq does not retain inference inputs/outputs by default, but may temporarily log them for up to 30 days if needed to troubleshoot reliability issues or investigate suspected abuse โ subject to Groq's privacy policy. | Not stored by us (Groq only) |
| Schedule image (Gemini import) | If you use the photo-to-schedule import feature, the image is sent to Gemini for parsing | Not stored by us (Gemini only) |
| Google Classroom data (course names, assignment titles, due dates, instructions) | Optional โ if you choose to connect Google Classroom, used to import your assignments into your task list | Device only (SharedPreferences) โ never uploaded to our servers |
โ๏ธ How We Use Your Data
Your data is used solely to operate Eskwela's features:
โข To authenticate you and maintain your account
โข To save your class schedule, tasks, and Esky chat history locally on your device
โข To power the Friends feature โ finding users, sending/accepting requests, and messaging
โข To enable the Developer Support chat so you can contact us and receive replies
โข To power the Esky AI tutor (chat messages are sent to Groq per session; Groq does not retain them by default but may log them temporarily per their policy)
โข To allow you to import schedules from photos via Gemini
โข To display Philippine public holidays in your calendar (fetched from the Nager.Date API โ no personal data is sent)
โข If you choose to connect Google Classroom, to read your course list and coursework due dates so they can be imported into your task list
We do not sell your data, use it for advertising, or use it for any purpose beyond operating the App.
๐ Third-Party Services
The App uses the following third-party services. Each has its own privacy policy:
-
Supabase Stores your account info, display name, user code, friends list, friend chat messages, and developer support messages. supabase.com/privacy
-
Google OAuth Handles sign-in. Your Google profile info is accessed for account creation. policies.google.com/privacy
-
Groq API Processes your Esky AI chat messages to generate responses. Groq does not retain inference inputs/outputs by default. However, Groq may temporarily log inputs and outputs for up to 30 days when troubleshooting reliability issues or investigating suspected abuse. You can learn more at groq.com/privacy-policy and console.groq.com/docs/your-data.
-
Google Gemini API Used for the photo schedule import feature. Images are processed and not stored by us. ai.google.dev/terms
-
Nager.Date API Fetches Philippine public holidays for calendar display. No personal data is sent to this service.
-
Google Classroom API Optional โ if you choose to connect your Google Classroom account, we read your class list and coursework due dates using read-only scopes. This data is used only to populate your task list and is stored locally on your device, never on our servers. policies.google.com/privacy
-
Cloudflare Turnstile Used only when you sign up, sign in, or reset your password with email โ silently verifies you're a real person, not a bot, to prevent abuse. It runs invisibly and shows no visual challenge. See Cloudflare's Turnstile Privacy Policy.
-
Resend Delivers the email containing your 6-digit verification or password-reset code when you use email sign-up/sign-in. resend.com/legal/privacy-policy
๐๏ธ Data Retention & Deletion
Your account data (profile, friends, friend chat messages, and developer support messages) is stored in Supabase for as long as you have an active account.
Your class schedule, tasks, Esky AI chat history, and any assignments imported from Google Classroom are stored locally on your device only โ they are never uploaded to our servers. Clearing the App's data or uninstalling the App will remove this local data. You can disconnect Google Classroom access at any time from within the App, or by revoking Eskwela's access directly at myaccount.google.com/permissions.
To request deletion of your account and all associated server-side data, contact us at ivancreatordeveloper@gmail.com. We will delete your account and all associated data within 30 days. You may also submit a data deletion request via the Eskwela website.
AI chat messages (Esky/Groq) and schedule import images are not stored by us โ they are only sent to Groq/Gemini per request and are subject to their respective data retention policies.
๐ Security
All data transmitted between the App and our services is encrypted via HTTPS/TLS, and Supabase encrypts data at rest.
Your profile, friends list, and friend chat messages are protected by database-level Row Level Security (RLS) โ rules enforced by the database itself, not just checks inside the App:
โข Profile visibility is limited to yourself and your friends. Your display name, friend code, avatar, and grade/year are only readable by you and by users you've already added as friends โ not by every signed-in user.
โข Messages are readable only by the two people in that conversation, and can only be sent between users who are already accepted friends โ enforced at the database level, so this holds even if the App's own checks were ever bypassed.
โข Adding a friend by code uses a narrow, exact-match lookup. It can confirm a code you already have, but cannot be used to browse, list, or scrape other users' profiles.
โข Friend requests are protected against race conditions by a database-level uniqueness rule, preventing duplicate or conflicting requests even if two people add each other at the same moment.
โข Friend requests are rate-limited to prevent automated scripts from mass-adding accounts or probing large ranges of friend codes.
Schedule, task, and chat data stored locally on your device is protected by Android's standard app sandboxing โ other apps cannot access it.
Friend chat messages are not end-to-end encrypted โ they're stored securely on our servers (encrypted in transit and at rest) to support features like message history, but not in a way that prevents authorized server-side access. No method of transmission or storage is 100% secure; please avoid sharing passwords, financial details, or other sensitive personal information in chat messages.
๐ฆ Children's Privacy
Eskwela is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us and we will delete it promptly.
๐ก๏ธ Your Rights & Choices
You have the following rights regarding your personal data:
โข Access โ You can request a copy of the personal data we hold about you (name, email, friends list, chat messages stored in Supabase).
โข Correction โ You can update your display name and profile at any time within the App.
โข Deletion โ You can request deletion of your account and all associated server-side data by contacting us at ivancreatordeveloper@gmail.com. We will complete the deletion within 30 days. Data stored locally on your device (schedule, tasks, Esky chat history) can be deleted at any time by clearing the App's data or uninstalling it.
โข Opt-out of AI processing โ You can choose not to use the Esky AI tutor or the photo schedule import feature to avoid sending data to Groq or Gemini.
โข Disconnect Google Classroom โ Connecting your Google Classroom account is entirely optional. You can disconnect it at any time within the App, or revoke access directly at myaccount.google.com/permissions.
โข Manage permissions โ You can revoke the App's permissions (e.g. camera) at any time through your Android device settings.
To exercise any of these rights, contact us at ivancreatordeveloper@gmail.com.
๐ Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we'll update the "Last updated" date at the top. Continued use of the App after changes constitutes acceptance of the updated policy.
Questions or Data Requests?
If you have any questions about this Privacy Policy or want to request access, correction, or deletion of your data, reach out directly.
๐ง ivancreatordeveloper@gmail.com
Contact via Eskwela Site