SASHA Privacy Policy

Effective August 26, 2026
Owner-published web notice. Qualified-counsel approval is not claimed.
This operational notice maps the current application code and production retention configuration. Versioned documents presented during account setup remain the operative acceptance record for an account until a newer applicable bundle is presented and accepted.
Operator and scope
This policy covers SASHA on Android, iOS, and sasha.network. The individual developer currently identified on Google Play is Tonderai Shekede, 2501 N Blackwelder Ave, Oklahoma City, OK 73106-1402, United States, telephone +1 405-510-5857. Privacy requests: privacy@sasha.network. Support: support@sasha.network. SASHA identifies any additional local representative when one is required for a particular country or service.
Information SASHA handles
Depending on the features chosen, SASHA may handle name, username, email, role, account and relationship identifiers; birth date, age band, country, guardian or school-authority contact; school, class, subject, assignment, schedule, progress, grade, attendance, accommodation, and support information; messages, reviews, reports, calendar events, files, images, video, documents, voice or audio submitted for a feature; purchase, tutoring, shipping, refund, and payment-provider references; approximate or precise coordinates submitted for nearby results; app version, operating system, push or installation identifiers, security events, crash diagnostics, search and feature activity, and privacy-request evidence. SASHA does not directly store full payment-card numbers.
Why it is used
SASHA uses this information to provide tutoring, academic intake, protected scheduling, reports, collaboration, safety, account support, fulfillment, fraud prevention, and app reliability. Optional AI, upload, messaging, payment, notification, and location features remain off until the required account and contextual permissions are satisfied.
AI and school content
Approved school content may be sent to contracted model or document-processing providers to extract, summarize, explain, and personalize the learner’s current experience. Sensitive extracted facts remain pending until review where required. Learner sources and derived evidence are excluded from shared model training by default and are not silently added to public datasets.
Children and the pre-account privacy check
The sign-up flow asks for birth date and country before email or password and keeps that first-screen selection on the device until account creation is chosen. At account creation, SASHA sends the email, an authentication record, birth date, country, and a protection flag to its authentication service so the applicable setup can continue. When adult or school authority is required, restricted AI, messaging, payments, location, sharing, timetable uploads, notifications, and model-sensitive processing remain locked while verification is pending. SASHA keeps those features locked until the applicable direct notice, adult or school authority, jurisdiction threshold, and unanswered-request lifecycle are configured and verified. This owner-published notice does not claim qualified-counsel approval of a jurisdiction-specific method.
Parent, guardian, learner, and school choices
After identity and authority are verified, a parent, guardian, eligible learner, or authorized school may ask what child information SASHA holds, review or correct it, receive an export, withdraw optional consent, refuse further optional collection or use, or request deletion. Refusing an optional feature does not remove unrelated learning tools, but SASHA may be unable to provide a feature that requires that information. Requests can be started in Settings, at the public account-deletion page, or through privacy@sasha.network. Send only the account email and request type at first; SASHA will provide a protected verification step and will not disclose child information merely because someone knows an email address.
Visibility, identifiers, voice, and location
Profile details, reviews, classroom content, and messages may be visible to authenticated people allowed by the relevant relationship, classroom, offering, or directory controls; SASHA does not intentionally publish a child profile to the unrestricted web. Supabase creates account identifiers when an account is created. On Android, Firebase Messaging automatic registration is disabled and an installation-backed push token is requested only after legal setup, notification consent, device permission, and channel settings allow it. Voice, camera, file, and precise-location data are submitted only when the user activates the related feature. SASHA does not rely on a child-voice immediate-deletion exception; voice features remain unavailable for protected child accounts unless the required consent and retention controls are active.
Processors and other recipients
Current code can use Supabase for hosting, authentication, database, storage, and server functions; Firebase Cloud Messaging and Expo for push delivery; Resend for transactional email; Sentry for privacy-scrubbed crash and performance diagnostics; Google Gemini, Anthropic, and Groq for selected AI, document, or voice features; Stripe for payment processing; Google Places or Address Validation for selected address features; and Agora for selected live audio or video sessions. A verified school, guardian, educator, tutor, vendor, marketplace participant, or support operator may receive relationship-scoped information needed for the requested service. SASHA does not sell personal information or serve behaviorally targeted advertising. A provider feature may be enabled only after its contract role, processing location, retention, deletion support, and applicable child-data terms are confirmed against current agreements; a code integration alone does not prove a service-provider exemption.
Retention and deletion schedule
Active profile, personalization, and private-file information is deleted or de-identified through the verified deletion workflow when no exception applies. The current production schema sets maximum scheduled retention of 2,555 days for minimized privacy-request audit evidence, security or abuse audit evidence, and financial or fulfillment records, and 365 days for redacted learning audit evidence. Operational content may be kept only while the account or requested service needs it and is removed through the applicable lifecycle. A valid legal hold or mandatory recordkeeping rule may require a different period, but the exact legal basis must be documented. A deletion request is not marked complete until required database categories and downstream processor treatments have evidence.
Security, transfers, and rights
Protections include encrypted transport, private storage for sensitive files, row-level database controls, role and verified-relationship checks, restricted service credentials, privacy scrubbing, audit evidence, and deletion verification. No system is perfectly secure. Providers may process information outside the user’s country; SASHA evaluates the applicable transfer safeguard and any required local representative before enabling the relevant processing. Depending on location, users may also have access, correction, portability, objection, restriction, complaint, or appeal rights. Contact privacy@sasha.network to begin a protected request.
Contact and requests
Privacy and child-safety requests can be sent to privacy@sasha.network. General support is available at support@sasha.network. Do not email passwords, identity documents, medical records, or sensitive school documents unless SASHA provides a protected upload method.