Privacy, in plain words.
Qobi only works with your ALU account. We read your inbox read-only and never send, write, or delete anything. We only look at senders Qobi recognises as ALU-relevant. Your access tokens are encrypted, we don't sell your data, and you can disconnect any time.
Who this covers.
This policy explains how Qobi ("we", "us") handles information when you use the Qobi web app and related services. Qobi is built for students of African Leadership University (ALU) and only accepts ALU email accounts.
What we access, and why.
We ask for the minimum we need to make your daily brief useful — nothing more.
- Your ALU Google account — your name and email, used to sign you in and verify you have an ALU domain. We request a read-only Gmail scope only.
- Your inbox (read-only) — we read messages from senders Qobi recognises as ALU-relevant (e.g. Canvas, the registrar, student life, immigration) to surface deadlines and obligations. We never send, modify, label, or delete email.
- Canvas — if you connect it (via an access token or a calendar-feed URL), we read your assignments, due dates, and submission status.
- Your profile — the details you give us (program, year/trimester, funding type, progression tier, residency) so the guidance is relevant to you.
- Notifications — if you opt in, a device/push token so we can send your daily brief and reminders.
Read-only means read-only. Qobi has no permission to send, reply to, label, or delete anything in your inbox. The token we hold from Google literally cannot perform those actions.
How we use it.
To generate your daily brief, reason about how obligations connect across your academics, finances, standing, and immigration, and send you briefings and reminders. That's it.
AI processing.
To produce your brief, relevant text is sent to our AI provider (Anthropic) for reasoning. We minimise and scrub personal details before processing where possible, and our provider does not use this content to train their models. Qobi's reasoning is generated automatically and may be incomplete — see the Terms.
Storage & security.
Data is stored on managed infrastructure (Supabase / Postgres) with row-level security so only your account can access your data. Your Google and Canvas access tokens are encrypted at rest. We keep only what we need to run the service.
Your controls.
You can disconnect Gmail or Canvas at any time, revoke Qobi's access from your Google Account security settings, and request deletion of your account and associated data. Contact us to export or delete your data.
Data retention.
We retain your data while your account is active and delete it (or anonymise it) within a reasonable period after you disconnect or request deletion.
Eligibility.
Qobi is for ALU students and requires an ALU email. It is not intended for children under the age required by ALU or applicable law.
Where your data lives.
Your data may be processed in regions where our providers operate. By using Qobi you consent to this processing. [Add specific regions / transfer basis if required.]
Changes.
We may update this policy; we'll change the "Last updated" date and, for material changes, notify you in-app or by email.
Contact.
Questions or requests:
[privacy@qobi-copilot.xyz]