Legal · Private beta
Privacy Policy
This policy describes how the Qamishlo private beta actually works today. It is not formal legal advice and may change as the product evolves. Contact gidi@qamishlo.org with questions or deletion requests.
Who we are
Qamishlo is an invite-only audio learning app operated by Gidrono (gidi@qamishlo.org). The public site is qamishlo.org. The beta API runs on the operator’s configured host.
Who this applies to
Private-beta testers who use the Android app or web preview with an invite token. There is no public account signup and no email/password identity in this beta.
What we collect and process
-
Invite identity. Access uses a revocable invite token. We associate usage
with an invite-bound
user_id(a label/slug), not your real name or email unless you type that into a free-text learning topic. - Course inputs. Subject, learning goal, and level you submit to generate courses.
- Generated learning content. Lesson scripts, synthesized lesson audio, playback progress, and related catalog data stored on our servers (and may be stored in Azure Blob storage).
- Voice Q&A. When you ask a spoken question, a short microphone clip (about 30 seconds or less) is uploaded so we can transcribe it with Microsoft Azure OpenAI speech-to-text. We do not keep the raw audio file after transcription. Question and answer text may be stored; answer audio may be stored for playback.
-
Crash and error diagnostics (Android azureDev builds). Technical
crash/error reports (app version, OS version, device model, exception message/stack,
invite
user_id, optional session/course/lesson ids) may be sent to our API and optionally to Azure Application Insights. We scrub secrets and signed URL query parameters before sending. -
Operational records. Estimated AI spend, activity events, and generation
job metadata tied to your invite
user_id.
What stays on your device
- Onboarding questionnaire answers used in the app UI are not sent to our servers in this beta.
- Commute detection. Activity recognition (walking / in-vehicle) and car Bluetooth connection signals are used only on the device to show an optional local “ready to listen?” reminder. We do not upload commute, motion, or Bluetooth payloads to Qamishlo servers. Google Play services may process activity recognition on Google’s side; Qamishlo does not receive that stream.
- Invite token is stored locally on the device (or in browser storage for the web preview).
Permissions (Android)
- Microphone — speak questions mid-lesson; short clips are transcribed as described above.
- Activity recognition — optional commute reminders (on-device only).
- Bluetooth connect — optional reminders when car Bluetooth connects (on-device only).
- Notifications — course-ready and commute nudge alerts.
You can deny these permissions; the app still works with reduced features (for example, typed questions instead of voice).
Processors and third parties
Depending on the feature, we use:
- Microsoft Azure — OpenAI chat, speech-to-text, text-to-speech, hosting/storage, Application Insights.
- ElevenLabs — lesson narration audio synthesis (when configured).
We do not run marketing or product-analytics SDKs (no advertising ID collection) in this beta.
Retention and deletion
Beta data is retained while the private beta operates and as needed for debugging, cost
control, and the shared course catalog. To request deletion of data associated with your
invite user_id, email
gidi@qamishlo.org. We may revoke your invite at
any time.
Children
The private beta is not directed at children under 13 (or the equivalent minimum age in your region). Do not use it if you are under that age.
Changes
We may update this policy as the beta changes. Material updates will bump the version shown in the app’s accept screen. Continued use after you accept a new version means you agree to the updated policy.