Last updated: 30 July 2026. These terms are binding for use of Kaaw Kaaw. If you do not agree, do not use the Services.
1. Who we are
This Privacy Policy (“Policy”) explains how Foxpers Technologies Private Limited (“Foxpers”, “we”, “us”, or “our”) processes personal data in connection with Kaaw Kaaw (https://kaawkaaw.com), including the marketing website, learner product, organization / business product, APIs, mobile or progressive web experiences, and related support channels (collectively, the “Services”).
Controller / operator: Foxpers Technologies Private Limited, with primary operations in Bengaluru, Karnataka, India. Contact for privacy requests: hello@kaawkaaw.com.
If you use Kaaw Kaaw under an organization contract, your organization may be an independent controller for learner/employee data it uploads or administers. In that case, we typically act as a processor for that organization-controlled data, and as a controller for account, billing, security, and product-operations data.
2. Scope and acceptance
This Policy applies to personal data processed when you visit our sites, create an account, authenticate, upload content, generate learning experiences, interact with AI features, purchase or trial paid plans, contact support, or otherwise use the Services.
By accessing or using the Services, you acknowledge this Policy. If you do not agree, do not use the Services. Where consent is required by law, we will request it separately.
This Policy does not cover third-party websites, apps, payment processors, identity providers, or model providers that you choose to interact with outside our controlled interfaces, except as described in our subprocessors disclosures.
3. Personal data we collect
Account and identity data: name, display name, email address, password or authentication tokens, OAuth identifiers (for example Google / Apple where enabled), profile preferences, organization membership, role, and account settings.
Billing and commercial data (if applicable): plan type, subscription status, invoices, tax identifiers where required, and limited payment metadata from our payment processor. We do not store full card numbers on Kaaw Kaaw servers when a PCI-compliant processor is used.
Learner and product content: topics you enter, uploaded files/URLs (where enabled), notes, workspace state, concept paths, learning progress, practice answers, questions you ask, suggestion interactions, saved storyboards, bookmarks, library items, and revision history.
AI and media processing data: prompts, teaching/context payloads, model inputs derived from your content, generation logs needed for quality/safety, illustration or media job metadata, and related failure/retry telemetry. Model providers may transiently process inputs to return outputs under our contracts with them.
Usage and device data: feature interactions, pages viewed, referrers, session identifiers, approximate location derived from IP, device/browser type, operating system, language, timestamps, performance metrics, and diagnostic events.
Security and integrity data: IP address, authentication events, rate-limit signals, abuse/fraud indicators, audit trails, and support correspondence.
Communications: messages you send to us (email, forms, in-product feedback), and operational notices we send to you.
We do not intentionally collect special-category data (for example health, biometric templates for identification, or precise religious/political beliefs) as a product requirement. Do not upload sensitive personal data unless strictly necessary and lawful. If you do, you are responsible for having a lawful basis and any required notices/consents.
4. Sources of data
Directly from you (account forms, uploads, prompts, settings, support).
Automatically from your device and our Services (cookies, logs, analytics, security telemetry).
From your organization administrator when they invite you, assign experiences, or provision seats.
From identity providers you choose (OAuth).
From service providers that help us operate the Services (hosting, email, payments, error monitoring, AI inference, media generation, storage).
5. Purposes and lawful bases
Provide and operate the Services (contract / pre-contract steps): authentication, workspaces, learning paths, AI teaching beats, media generation, progress, library, and customer support.
Secure the Services (legitimate interests / legal obligation): prevent abuse, fraud, unauthorized access, malware, and service attacks; investigate incidents; enforce policies.
Improve quality and reliability (legitimate interests): debugging, product analytics, model/prompt quality evaluation on de-identified or aggregated signals where feasible, and UX improvement. We do not sell personal data.
Communicate with you (contract / legitimate interests / consent where required): service notices, security alerts, billing, and—only with consent or soft opt-in where allowed—product updates. You may opt out of non-essential marketing.
Comply with law (legal obligation): tax, accounting, lawful requests, and regulatory duties.
AI processing disclosure: your content and prompts may be processed by AI systems to generate learning structure, explanations, visuals, suggestions, and related outputs. This processing is necessary to deliver core product features you request.
6. AI-specific privacy terms
Kaaw Kaaw is an AI-assisted Learning OS. Inputs you provide (topics, uploads, questions, interaction history) may be transformed into structured learning experiences, visuals, and suggestions.
We configure providers under contractual terms intended to restrict use of your content for unrelated advertising and, where available, to limit training on your customer content. Provider capabilities and defaults can change; enterprise customers may request stricter contractual addenda.
AI outputs can be incomplete, incorrect, or unsuitable for your purpose. Do not treat outputs as professional advice (legal, medical, financial, safety-critical, or academic-certification advice).
Do not submit credentials, payment card numbers, government ID numbers, or others’ sensitive personal data into prompts or uploads unless you have a clear lawful basis and the feature specifically requires it.
We may log safety, quality, and abuse signals associated with AI requests to protect users and the platform.
7. Children's privacy and educational institutions
The Services are not directed to children under 13 (or under 16 where a higher digital consent age applies). We do not knowingly create accounts for children below the applicable age without verifiable parental/guardian consent where required.
If you are a parent/guardian and believe a child provided personal data without required consent, contact us at hello@kaawkaaw.com. We will take reasonable steps to delete the data and close the account where appropriate.
Schools or organizations that onboard minors are responsible for obtaining all required parental/guardian consents and for configuring the product lawfully for their jurisdiction.
United States schools (COPPA “school official” exception): where a US school or district provides Kaaw Kaaw to students under 13, we treat the school — not the individual student or parent — as authorized to consent on parents' behalf for use strictly limited to an educational purpose, consistent with FTC COPPA guidance. This requires a signed order form or data-protection addendum with the school confirming that authorization, restricting our use of student data to the educational purpose directed by the school, and prohibiting behavioral advertising to known children. Schools may request this addendum from hello@kaawkaaw.com.
FERPA (US educational records): for US school and university customers, student education records uploaded to or generated within an organization workspace are controlled by that institution. Where required, we act as a “school official” with a legitimate educational interest under FERPA, using student data only to provide, secure, and support the Services at the institution's direction, and not for independent commercial purposes such as advertising. Institutions remain responsible for their own FERPA obligations, including notices to students/parents and authorization for any third-party disclosure.
8. How we share data
We do not sell personal data.
Service providers / subprocessors: cloud hosting, databases, object storage, email delivery, authentication, payments, observability, and AI/media providers process data only to provide services to us and under confidentiality/security obligations.
Organization administrators: if you join an organization workspace, admins may see membership, assignment, and progress data according to role permissions.
Legal and safety: we may disclose data if required by law, court order, or to protect rights, safety, security, or integrity of users, the public, or Foxpers.
Business transfers: in a merger, acquisition, financing, or sale of assets, personal data may transfer subject to continued confidentiality and notice where required.
With your direction: when you export, share, or publish content features (if enabled).
9. International transfers
We operate primarily from India and may use infrastructure or AI providers in other countries (including the United States and EU/EEA regions).
Where required, we use appropriate transfer safeguards (for example contractual clauses, provider DPAs, and transfer assessments).
By using the Services, you understand that your data may be processed in countries with different data-protection laws than your home country.
EU/UK representative: where required by Article 27 of the GDPR or UK GDPR because we process EEA/UK residents' data at qualifying scale, we will appoint an EU and/or UK representative and publish their contact details on this page and in the app.
10. Retention
We retain personal data only as long as needed for the purposes in this Policy, including service delivery, security, dispute resolution, backups, and legal compliance.
Typical retention (may vary by product mode and contract): active account data for the life of the account; learning/workspace content until deletion or account closure; security/audit logs for a limited operational period; billing records for statutory retention; backups for a rolling window before irreversible purge.
When you delete content or close an account, we will delete or de-identify personal data within a commercially reasonable period, except where retention is required for legal, security, fraud-prevention, or accounting reasons, or remains in encrypted backups until rotated.
11. Security
We implement administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, access controls, least privilege, logging, and environment separation where applicable.
No method of transmission or storage is perfectly secure. You are responsible for safeguarding credentials, enabling available security features, and notifying us promptly of suspected unauthorized access.
Breach notification: where we are a controller and a personal-data breach creates a risk to your rights, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, as required by GDPR/UK GDPR, and will notify the India Data Protection Board and affected Data Principals as required by the DPDP Act. Where we are a processor (for example, for organization-controlled learner data), we notify the relevant customer without undue delay so they can meet their own notification duties.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or port personal data, and to withdraw consent where processing is consent-based.
India (DPDP Act, as applicable): you may request correction, erasure, and grievance redressal through our contact channels, and, if unresolved, may complain to the Data Protection Board of India, subject to verification and legal exceptions.
EEA/UK/Switzerland (GDPR/UK GDPR as applicable): you may also lodge a complaint with your local supervisory authority (for example, your national data protection authority or the ICO in the UK).
California (CCPA/CPRA, as applicable): if you are a California resident, you may have the right to know what personal information we collect, request deletion, request correction, and opt out of the “sale” or “sharing” of personal information (as those terms are defined by California law) and out of certain automated-decision-making profiling. We do not sell personal data for money, and we honor Global Privacy Control (GPC) browser signals as a valid opt-out request where legally required. We will not discriminate against you for exercising these rights. Submit requests to hello@kaawkaaw.com or use in-product privacy controls where available; we may need to verify your identity before completing a request.
To exercise rights generally, email hello@kaawkaaw.com with sufficient detail for us to verify your identity and locate the data. We may refuse or limit requests where permitted (for example, legal privilege, others’ rights, freeloading/abuse, or disproportionate requests).
Organization-managed accounts: some requests must be directed to your organization administrator first.
13. Cookies and similar technologies
We use cookies and similar technologies as described in our Cookie Policy. Essential cookies are required for authentication and security. Analytics/preference cookies are used where enabled and, where required, with consent.
14. Automated decision-making
Kaaw Kaaw uses automated systems (including AI) to generate learning content, recommendations, and progress estimates. These features are assistive product functions, not solely automated legal/significant decisions about you of the kind that create formal legal effects without human involvement.
Predicted recall or mastery estimates are approximate learning signals, not certified assessments.
15. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date will change when we do. Material changes will be notified via the Services, email, or a prominent notice where required by law. Continued use after the effective date constitutes acceptance of the updated Policy where permitted.
16. Contact and grievance
Privacy / data requests: hello@kaawkaaw.com
General support: hello@kaawkaaw.com
Postal / operations: Foxpers Technologies Private Limited, Bengaluru, Karnataka, India
If you have an unresolved privacy concern, contact us first. We will investigate in good faith within a reasonable period consistent with applicable law.
Legal entity: Foxpers Technologies Private Limited, Bengaluru, Karnataka, India. Contact: hello@kaawkaaw.com. Effective across the Legal library as of 30 July 2026, unless a document states a later date. Policies may be updated; continued use after notice constitutes acceptance where permitted by law. This library is provided for operational transparency and should be reviewed by qualified counsel for your jurisdiction before high-stakes reliance.