Scire
Terms Privacy Parent Consent
Legal

Privacy Policy

Last Updated: August 08, 2026
Effective Date: August 08, 2026

1. Overview

This Privacy Policy explains how Learn with Scire ("Scire," "we," "us") collects, uses, and protects personal information when you use the Scire web application. Because our users include minors and our answers are generated by AI, we treat privacy, safety, and data minimization as core architectural requirements, in compliance with India's Digital Personal Data Protection Act (DPDP Act, 2023) and global standards.

2. Data Controller and Contact Information

  • Data Controller: Learn with Scire
  • Postal Address: Chennai, Tamil Nadu - 600058, India
  • Privacy & General Support Contact:

Where Scire is deployed by a school or institution, that institution may act as a joint data controller or independent controller for its learners' data.

3. Information We Collect

We collect the minimum data necessary to operate a grounded, age-appropriate educational service.

3.1 Account and Profile Data

  • Email address and a one-way hashed password (bcrypt).
  • Learning stage / Persona (Junior, Mid-School, High School, Graduate), which dictates source routing, safety rules, and UI rendering.
  • Account type (Learner, Teacher, or Institutional Staff).

3.2 Learning Content

  • Queries and Generated Answers: The questions you ask and the AI-generated responses.
  • Study Library: Successful turns are auto-saved to your private, per-user database record to allow for revision, renaming, and deletion.

3.3 Usage and Telemetry

  • Journey Signals: Anonymous session identifiers, turn IDs, and interaction origins to measure feature efficacy.
  • Performance Metrics: Search and synthesis timings displayed in the trust footer.
  • Device Identifiers: Locally generated device hashes used strictly to enforce license device-limits. We do not use invasive cross-site device fingerprinting.

3.4 Voice Input (Optional)

If you use browser-based voice dictation, audio is processed by your browser’s native speech provider (e.g., Google or Apple). Recognized text is placed in the composer for your review and is never auto-submitted. A one-time consent modal identifies the provider before first use. Scire does not store audio recordings.

4. How AI Generation Works (Privacy Implications)

Scire’s architecture is designed to prioritize factual accuracy and data protection.

4.1 Retrieval-Augmented Generation (RAG)

Before an answer is generated, our "Librarian" engine retrieves material from trusted, keyless academic sources (e.g., Wikipedia, PubMed, arXiv, Project Gutenberg) or our curated premium database. The "Professor" engine then synthesizes an answer strictly from that retrieved context, mandating inline citations.

4.2 Hybrid Local and Cloud Engines

  • On-Device (Local): Answers can be synthesized by a model running locally on our secure servers or your local deployment. This path is entirely private.
  • Cloud Engine: For complex tasks (e.g., Deep Dive mode), queries and retrieved context may be transmitted to a secure, enterprise-grade cloud LLM provider. The UI explicitly displays an "off-device" indicator when the Cloud engine is active.

4.3 Premium Data-Leak Protection

When our protected premium library feature is enabled, any answer that draws on the proprietary premium corpus is cryptographically and architecturally forced to generate on-device. This content is never transmitted to third-party cloud models, ensuring licensed textbook material remains strictly contained.

5. Third-Party Sources and Services

We rely on public, academic, and open-access APIs to keep content costs low and avoid unnecessary data sharing.

  • Academic Sources: We send search queries to Wikipedia, PubMed, arXiv, Semantic Scholar, and others. We do not share user profiles or PII with these endpoints.
  • Cloud LLM Providers: When the Cloud engine is used, the prompt and retrieved context are processed by our cloud AI partner under strict enterprise data-processing agreements (no training on user data).
  • Imagery: Images are sourced from public-domain or Creative Commons repositories (Wikimedia, The Met, NLM Open-i) or licensed stock providers (e.g., Pexels).

6. Legal Bases for Processing

In accordance with the DPDP Act and global privacy frameworks, we process your data based on:

  • Contract: To provide the educational Service you or your institution requested.
  • Legitimate Interests: For service security, fraud prevention, device-limit enforcement, and aggregated product improvement.
  • Consent: For optional features like voice dictation, and for processing the data of children as required by law.
  • Legal Obligation & Vital Interests: To respond to lawful requests or address immediate safeguarding/self-harm concerns.

7. Children's Privacy and Safeguarding

Protecting minors is our highest priority.

  • Age-Appropriate Personas: The Service applies strict, deterministic safety filters. Junior (6–10) and Mid-School (11–14) personas receive enhanced moderation.
  • No Advertising: We do not serve third-party behavioral advertising, nor do we build advertising profiles of any user.
  • Self-Harm Protocols: Queries indicating self-harm trigger a supportive, non-judgmental response encouraging the user to speak to a trusted adult, bypassing standard search results.
  • Institutional Consent: For school-managed accounts, the educational institution is responsible for securing verifiable parental consent.

8. How We Share Information

We do not sell personal data. We share data only:

  • With your Institution: If your school manages your account, administrators may view usage analytics, roster data, and progress metrics.
  • With Service Providers: Cloud hosting, LLM inference (when Cloud engine is used), and email delivery services, bound by strict confidentiality agreements.
  • For Safety and Legal Compliance: To protect the rights, property, or safety of Learn with Scire, our users, or the public, or to comply with legal subpoenas.

9. Data Retention and Erasure

  • Active Accounts: Account data and Study Library threads are retained as long as the account is active.
  • Trial Expiration: If a trial lapses and is not converted to a paid license, premium features lock, but core account data is retained until deletion is requested or institutional policy dictates removal.
  • Cascade Erasure: When a user account is deleted, all learner-scoped content (Study Library threads, device bindings, and personal telemetry) is permanently erased in the same database transaction.
  • Audit & Telemetry Logs: Administrative actions, security logs, and usage analytics are retained for 48 months for governance, compliance, and product improvement purposes. Credentials and passwords are never written to audit logs.

10. Security Measures

We implement enterprise-grade security controls, including:

  • Authentication: Bcrypt password hashing, JWT bearer tokens with rotation, and real-time session revocation.
  • Access Control: Deny-by-default middleware, strict Role-Based Access Control (RBAC), and server-side entitlement enforcement.
  • Infrastructure: Transport Layer Security (TLS), strict CORS allowlists, and environment-level fail-safes that prevent the application from booting if security configurations are misconfigured.

11. Your Rights

Depending on your location and applicable law (including the DPDP Act), you may have the right to:

  • Access, correct, or export your personal data.
  • Request deletion of your account and Study Library (Right to Erasure).
  • Object to or restrict certain processing activities.
  • Withdraw consent.

To exercise these rights:

  • Self-Managed Accounts: Use the in-app settings to delete threads or contact .
  • School-Managed Accounts: Direct requests to your school's IT administrator or data protection officer, who controls the institutional roster. We will respond to verifiable requests within 30 days.

12. International Data Transfers

Scire operates globally. When data is transferred across international borders (e.g., to cloud inference servers or across Country Workspaces), we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) and strict tenant-isolation architectures to ensure data remains secure and compliant with local regulations.

13. Changes to This Policy

We will update this Privacy Policy periodically to reflect changes in our practices or for operational, legal, or regulatory reasons. Material changes affecting children's data or core privacy rights will be communicated via prominent notice in the Service or via email prior to taking effect.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

  • Email:
  • Postal Address: Learn with Scire, Chennai, Tamil Nadu - 600058, India

© 2026 Learn with Scire. All rights reserved. · hello@learnwithscire.com

↑ Back to top