Plain English first. Elphup helps children practise school subjects and helps parents keep up with school. A parent creates the family account, adds each child, and pairs the child's tablet with a code. We store what the apps need to work: answers, progress, points, the school material a parent shares, and the parent's conversations with the coach. AI services grade written work and generate coaching, and they see the child's first name and answers to do it. We never sell data, never show advertising, and never use your data to train AI models. A parent can delete everything at any time; deletion completes within 30 days, with a week to change your mind.
What Elphup Is
Elphup is an adaptive learning service for school-age children in India, covering CBSE, ICSE and IB work and Olympiad practice. It is delivered through two Android apps distributed on Google Play — Elphup for parents and Elphup Kids for children — and this website. Access is by invitation: a parent needs an access code to create a family account. There is no public sign-up.
Who This Policy Covers
Parents and guardians — adults who sign in with a Google account, create the family, add children and use the parent app. The person who creates the family is its owner; the owner may invite other adults.
Children — added by a parent as a profile inside the family, identified by a first name, grade and board. A child has no account, email address or password. The Elphup Kids app is paired to the family by the parent with a short code, and the parent can un-pair it at any time.
Other people who appear in school material — teachers, staff and classmates named in notices, timetables and results that a parent shares with Elphup. We store that material as shared and use it only to build the child's schedule.
Elphup is operated from India and processes children's data only with a parent's consent, given when the parent creates the family and adds the child.
Data We Collect
From parents
Data
Why
Google account email address, name and profile picture
Sign-in and identifying the parent account. We verify the sign-in token with Google and read nothing else from the Google account.
Family details: children's first names, grade, board, and optionally school and section
Choosing the right curriculum, content and school calendar for each child.
Points awards, assignments and settings you make for a child
Shown in the child's app and in the parent's history.
Questions you ask the coach, typed or spoken
Spoken questions are transcribed by Azure Speech and the audio is discarded; the transcript and the coach's reply are kept as your conversation history so you can continue it.
Device pairings (a label such as "Living-room tablet", when it was paired) and, if you enable notifications, a push-notification token
Letting you see and revoke the devices your children use; sending you daily practice summaries.
School material you share: timetables, notices, homework, exam dates, as photos, documents or forwarded messages
Building your child's schedule, reminders and exam readiness. This material may name teachers and other pupils; we store it as shared and use it for nothing else.
From children's learning activity
Data
Why
Each question attempted, the child's answer, whether it was correct, and how long it took
Adapting difficulty, choosing the next questions, and showing progress and mistakes to the parent.
Derived from the attempts above to personalise practice.
Points, XP, level, streaks and the reasons points were awarded
Motivation features in the child's app.
Photographs of handwritten work (the camera is used only when the child chooses to submit a written answer)
Sent to the AI grader, which returns a transcription and a score. The photograph itself is not stored; the transcription and the score are.
Reading aloud (the microphone is used only during a read-aloud exercise)
Streamed to Azure Speech for a pronunciation score. The recording is not stored by Elphup; only the score is.
Technical data
IP addresses, kept in short-lived counters that protect the service from abuse and expire within hours.
Server logs and error reports, including the request path and the signed-in account, kept for 30 days to run and secure the service.
On this website, browser security reports that contain the page and blocked address involved, and nothing about you.
What we do not collect: location, contacts, browsing history, advertising identifiers or any analytics or advertising SDK data. Neither app contains advertising or third-party analytics.
How Data Is Used
To deliver and adapt practice, grade work, and plan each child's day.
To show parents progress, mistakes, readiness and school schedules, and to answer their questions through the coach.
To send the notifications a parent has turned on.
To keep the service secure: sign-in verification, device pairing, rate limits and abuse prevention.
Data is never sold, used for advertising, shared with other families, or used to train AI models.
AI Processing
Elphup uses Microsoft Azure AI services under Microsoft's business terms, which do not permit our data to be used to train their models. Because the AI does the grading and coaching, it sees real data, not anonymised data:
Azure OpenAI receives the child's first name, questions and answers, attempt history, photographs of written work for grading, the text of school material you share, and the parent's coach questions.
Azure Speech receives the child's voice during read-aloud exercises and the parent's voice during spoken coach questions. To recognise names correctly it is also given the children's first names as hints.
Elphup's operator can access stored data to run, support and debug the service.
Third-Party Services
Service
What it receives
Purpose
Google Sign-In
The parent's sign-in token, which we verify with Google
Parent authentication
Google Firebase Cloud Messaging
A device token and the text of each notification, which can include a child's first name and a score
Push notifications, only if the parent turns them on
Microsoft Azure (storage, compute, Key Vault, monitoring)
No data is sent to advertising networks, analytics platforms or social media services. An earlier web version of Elphup recorded YouTube viewing; that feature has been retired and any remaining records are deleted with the family's data.
Where Data Is Stored
Elphup runs on Microsoft Azure. Application data is stored in Sweden Central, voice assessment runs in UK South, and this website is served from West Europe. This means your family's data, including your children's, is transferred to and stored outside India. By creating a family account the parent consents to this transfer. Microsoft holds independent certifications for these data centres, and data is encrypted in transit and at rest.
Consent comes from the parent, by construction. Only a signed-in parent can add a child or pair a child's device. A child cannot create an account, enter an email address, or change what is collected.
No account for the child. The Elphup Kids app holds only a pairing token the parent issued, which the parent can revoke.
No advertising, no tracking, no behavioural profiling beyond the learning progress the app exists to measure. Elphup does not sell or share children's data.
Data minimisation. Photographs and voice recordings are processed and discarded; only the derived scores and transcriptions are kept.
Withdrawal of consent is the same as deletion: see Your Rights below.
Security
All traffic uses HTTPS. Sign-in is verified with Google on every request, and every request is limited to the signed-in parent's own family.
Children's devices hold a revocable pairing token rather than a password.
Secrets live in Azure Key Vault; the service is monitored, rate-limited and reviewed. Nothing is perfect: report a security issue to security@elphup.com.
Data Retention and Deletion
Family data is kept while the family account is active.
Abuse-prevention counters expire within hours; server logs are kept for 30 days.
When a parent asks for deletion, every device is un-paired immediately, there is a seven-day window in which the owner can cancel, and then all family records and files are erased automatically. Deletion completes within 30 days of the request.
School notices and timetables that belong to a class rather than to your family are kept for the class, with the link to your family removed.
We keep a deletion ledger that records that an erasure happened and how many records it removed, using a one-way hash rather than any name or identifier.
Your Rights
Access — the parent app shows your family's data; for a full copy, email us and we will provide it within 30 days.
Correction — names, grades and school details can be changed in the parent app; email us for anything else.
Deletion — see Delete your family's data for the steps. Deletion removes every child in the family and the parent accounts.
Grievances — write to privacy@elphup.com. We acknowledge within 7 days and resolve within 30.
Changes to This Policy
If we make material changes, we will update the date at the top and notify the family owner by email before the changes take effect.