Privacy policy
TaleemPK collects the data required to operate the platform, does not sell any category of personal data, and provides every user with the ability to export or delete their data directly from account settings. This document sets out each category of data individually, in the interest of specificity over generality.
Last updated September 2026. Material changes affecting users will be communicated in advance of taking effect.
1. Categories of data collected
1.1 Data provided directly by the user
- Name, username, email address and password. Passwords are cryptographically hashed and stored in a form that cannot be reversed, including by the platform operator.
- Optional profile data: photograph, cover image, biography, city, class, board, subjects and institute.
- Content submitted by the user: posts, uploads, comments and messages.
- Phone number, where the user elects to verify it.
- Documents and details submitted in support of a verification application.
- Where the user participates in the creator earnings programme: the account name and number to which payment is to be made, and, solely where tax withholding is applicable, a CNIC or NTN.
1.2 Data recorded automatically through use of the platform
- IP address and browser information, retained for security and abuse-prevention purposes.
- Sign-in timestamps and associated devices, enabling a user to identify unrecognised access. This record is viewable in account settings.
- Search queries and download activity, used to improve the relevance of platform recommendations.
- Records of posts read. Where a user is signed in, the platform records that a post was opened, once per post per calendar day. This record is the basis for the calculation of creator earnings, and prevents a single reload from being counted twice. Individual-level records of this kind are deleted after 45 days; only aggregate daily totals are retained beyond that period.
2. Purposes of processing
Data is processed for the following purposes only: operation of the platform; security of user accounts; delivery of material relevant to a user's class and board; calculation of creator earnings; response to user correspondence; and prevention of misuse. No purpose beyond this list applies.
3. Messaging data
This category is addressed separately, given its significance to users.
- Standard messages are stored on platform servers in readable form. They are not reviewed as a matter of routine. They may be reviewed where a specific conversation is the subject of a report, or where required by law.
- End-to-end encrypted messages, which a user may enable at their discretion, are encrypted on the user's device using a key derived from a passphrase never transmitted to or received by the platform. The platform retains only the encrypted content, without the means to decrypt it. No party, including a platform administrator, is able to access the content of these messages. A forgotten passphrase results in permanent loss of access to the associated messages; recovery is not possible by any means.
- Within an encrypted group conversation, a specific limitation applies: members exchange encryption keys through the server, and rely on the server's representation of group membership. A compromised server could, in principle, misrepresent that membership. A one-to-one conversation is not subject to this limitation. This is disclosed for transparency rather than presumed.
- Metadata remains visible to the platform at all times — the identity of sender and recipient, the time of a message, the size of an attached file, and the duration of a voice note. This information is necessary for platform functionality and is not concealed by encryption.
4. Data practices expressly excluded
- Personal data is not sold to any party, under any circumstance.
- Advertisers are not provided with a user's name, email address, message content or academic results.
- The content of private messages is not used to determine what is shown to a user.
- No profile of a user is compiled for sale to a third party.
5. Categories of recipients
- Other users may view data a user has elected to make public: profile, posts and uploads. An email address is displayed only where the user has enabled this, and then only to signed-in users.
- Moderators may view reported content, and may view the identity of the author of an anonymous question where it is the subject of a report. Moderators cannot access encrypted messages.
- A Page's administrative team may view messages sent to that Page, which function as a shared inbox accessible to all current team members, including those who join subsequently.
- Service providers engaged for hosting and email delivery process data solely on the platform's instructions and for no independent purpose.
- Advertising networks, where advertisements are displayed, may set cookies to determine advertisement selection. They do not receive a user's name, email address or messages.
- Law enforcement authorities, where a valid and properly served legal request is received. Users are notified where legally permissible.
6. Data retention periods
- Account and associated content — retained until account deletion.
- Individual-level reading records — 45 days, thereafter deleted.
- Aggregate daily view totals (not attributable to an individual) — two years, to allow verification of a disputed earnings calculation.
- Verification documents — retained for the duration of the verification process, then removed.
- Payout records — retained for the period required by applicable financial recordkeeping law.
- Security logs — 90 days.
- Responses to group membership questions — deleted upon determination of the application, whether accepted or declined.
7. User rights in respect of their data
- Access. Account settings include an export function providing all data held in connection with the account, including message history, as a downloadable file.
- Rectification. All profile data is editable at any time.
- Erasure. Available in account settings. This is a permanent deletion, not a status flag, and removes associated posts, uploads, comments, messages, and any groups or Pages owned by the user.
- Objection. May be raised via the support desk and will receive a substantive response.
The first three rights are exercised directly by the user, without the need for a request to the platform.
8. Cookies
A session cookie is used to maintain sign-in state, together with a limited number of preference cookies, such as display theme. Cookies are not used to track users across other websites. Where advertisements are displayed, the relevant advertising network sets its own cookies, which may be controlled through browser settings.
9. Minors
A substantial proportion of the user base is of school age, and the platform is designed accordingly. Users under the age of thirteen are not permitted to create an account. Where an account is identified as belonging to a child under thirteen, it is removed and the associated data deleted.
10. Security measures
Passwords are hashed. Active sessions may be terminated remotely from account settings. Sign-ins from an unrecognised device are recorded for user visibility. Actions involving a transfer of funds require re-entry of the account password, regardless of existing session status. No system offers absolute security, and this policy describes the measures in place rather than asserting invulnerability.
11. Amendments to this policy
Material amendments will be announced on the platform prior to taking effect. The date shown above indicates the publication date of the current version.
12. Enquiries
The support desk is available to signed-out users, provides a reference number, and is reviewed by a member of the team.