Privacy Policy
Privacy Policy
Last updated: 14 September 2026Applies to the Bnyat app (Android and iOS) and bnyat.krd
This page explains what Bnyat collects when you use the app and the website, why we need it, where it lives and how to delete it. It is written to be read, not scrolled past — if anything is unclear, email hello@bnyat.krd and a person will answer.
Who we are and who Bnyat is for
Bnyat is a learning app for high-school students in the Kurdistan Region of Iraq — Grades 10 to 12, scientific and literary tracks. It is built and run by the Bnyat team (“Bnyat”, “we”). You can reach us at hello@bnyat.krd.
Bnyat is for students aged 13 and over. It is not directed at children under 13 — see Children below.
What we collect
We collect only what the app needs to work. This is the full list.
- Sign-in details
- Students sign in with Google or Apple; we never receive their passwords. The provider sends us your name, email address and profile picture. If you use Apple’s Hide My Email, we receive a private relay address instead of your real one. For staff and reviewer email sign-in, our authentication service stores a protected password hash.
- Your profile
- What you tell us during onboarding and in Edit profile: grade, study track (scientific or literary), country, city, school, gender, phone number, preferred language, the subjects you focus on, your learning goal and an avatar. The phone number is used only so the Bnyat team can reach you about your account and payments; we never verify it with an SMS code. Gender and phone number are optional: you can skip both during onboarding and add or change them later in Edit profile. The avatar is either a preset or a photo you choose from your device; that photo is uploaded to our storage. Photo selection is optional. You can also choose images for flashcards, and pictures or PDF files to upload to community posts.
- Your student code
- Every account gets a generated code in the form
BNY-XXXX-NN. It is a reference for payments and support, not a login credential. - Your devices
- The device model and OS version, plus an identifier the app generates when it is installed. We use these to apply the one-device-per-account rule for paid video playback and to show you your signed-in devices. If you allow notifications we also store a Firebase push token. The app notes whether you are online or offline so it can sync your progress when you are back.
- Learning activity
- Courses you are enrolled in, videos you have watched and how far, flashcard reviews and the spaced-repetition schedule built from them, study streaks, daily quiz answers and scores, and live quiz participation.
- Things you create
- Flashcard decks and cards you make (private by default), decks you share by link, decks you submit to the community, and the notes, comments, pictures and files you post in the National Exam community. Community posts are shown with your name and avatar.
- Community safety
- Reports you submit about shared or community decks, National Exam posts or comments, or their authors, including your reason and any details you provide. We also store your blocked-user preferences and the version and time of your community terms acceptance. Block preferences are not shown publicly.
- Messages to us
- If you email or message us, we keep the conversation so we can answer and follow up. Optional feedback sent during account deletion is stored without an account reference; avoid including personal details in that feedback.
How we use it
- Sign you in and keep your progress in sync across launches and offline sessions.
- Verify purchases, manage refunds and grant access to courses or flashcards on your account.
- Apply the one-device rule for paid videos and show your signed-in devices.
- Show your progress, streaks, quiz results and review schedule.
- Review community submissions and reports about content or authors, apply your blocks, and record acceptance of the community terms before you post or share.
- Send the notifications you have allowed (see Notifications).
- Answer support requests.
- Keep the service secure and stop abuse.
- Understand how Bnyat is used overall. The Bnyat team can see aggregate, non-identifying statistics in our admin dashboard — for example how many students finished a lesson — to improve the product.
We do not use your data for advertising, and we do not make automated decisions about you that have legal or similarly significant effects.
Payments
Payment options depend on the app version and where it is distributed. Where FIB checkout is available, First Iraqi Bank processes the payment in its own service. Bnyat sends the order amount, currency, item description and order reference to FIB and verifies the result before granting access. We also keep records of access arranged through the Bnyat team.
We do not collect payment card numbers or your bank login details. Your bank or payment app keeps its own records under its own privacy policy. Our order and accounting records include your student name and code, account reference, purchased content, amount, currency, payment reference, status, and payment or refund dates. These records remain after account deletion for payment reconciliation, refunds and accounting.
Where your data is stored
These providers support Bnyat’s features. Their own privacy policies also apply when you use their sign-in, payment or content services.
- Supabase, self-hosted on Hetzner (Germany, EU)
- Accounts, the database and file storage: your profile, student code, learning activity, decks and flashcard images, community posts and uploaded pictures or PDFs, payment records, device records and avatar photo.
- Cloudflare R2
- Video storage for lessons. Videos are served through signed links that expire.
- Firebase Cloud Messaging (Google)
- Delivers push notifications. Holds your push token if you allow notifications.
- Google and Apple
- Sign-in providers. They tell us who you are; their own privacy policies cover the sign-in itself.
- First Iraqi Bank (FIB), where checkout is available
- Processes payments and refunds and returns payment references and status to Bnyat.
- YouTube (Google)
- Community notes can display YouTube preview images loaded from Google’s servers. Loading a preview sends your IP address and a network request to Google. Opening a linked video or website is covered by that service’s privacy policy.
- Vercel
- Hosts bnyat.krd. Standard web-server logs (IP address, browser, page requested) when you visit the site.
Some of these providers are in the EU and the United States, so your data can leave Iraq. We choose providers that protect it to a high standard and we keep the list short.
What we don't do
- No advertising SDKs and no ad networks — the app shows no third-party ads.
- No analytics or tracking SDKs. We do not track you across other apps or websites.
- We do not sell personal data. Sharing is limited to the providers listed above, content you choose to share with other students, and disclosures required by law.
- We do not store your Google or Apple password, payment card numbers or bank login details.
Your decks and the community
Decks you create are private by default — only you can see them.
If you share a deck by link, anyone with the link can view it and save a copy to their own decks. You can stop sharing at any time from the deck’s menu, which disables the link; copies stay with the students who already saved them.
If you submit a deck to the community, the Bnyat team reviews it before it is published. Approved decks are visible to other Bnyat students with your name shown as the author. Published community decks stay in the catalog even if you later delete your account — email us if you want yours removed as well.
You can report shared or community decks, National Exam posts and comments, or their authors from the community safety menu. Our team reviews reports and may remove content or restrict accounts. You can also block an author to hide their community content and limit interaction. Manage or undo your blocks in Profile → Privacy & data → Blocked users. Personal copies you already saved remain in your own decks.
Notifications
Bnyat sends two kinds of notifications: study reminders scheduled on your own device, and occasional pushes from the Bnyat team about new courses, offers or quiz results. Both need your permission.
Turn them off any time in Profile → Push notifications or Profile → Learning reminders, or in your phone’s notification settings. Disabling push notifications stops us from using your push token.
Offline downloads and content protection
Lessons you download for offline viewing are stored encrypted on your device. They are removed when you delete them in Profile → Downloaded lessons or uninstall the app.
Lesson videos stream over HTTPS using signed links that expire, and the player blocks screenshots and screen recording. These measures protect the teachers’ work; they are not used to monitor you.
How long we keep data
We keep your account and learning data while your account exists. Account deletion removes your sign-in, student profile, personal learning progress, private decks, National Exam posts and comments, and device records. Before deleting the account, the app removes your uploaded avatar, flashcard images, and community pictures or PDF files. If file cleanup fails, account deletion stops so you can retry or ask us for help.
Payment, refund and access records remain, including the name and student code recorded at purchase. Approved community decks, copies saved by other students and anonymised statistics can also remain. Optional deletion feedback is kept without an account reference. Removing your uploaded images also affects shared decks or copies that link to those images. Files already downloaded by other people are outside Bnyat’s control. Backup copies are separate from active account data and may also remain after deletion. Contact hello@bnyat.krd for information about retained records and backups, or to request removal of retained content.
Deleting your account
You can delete your account in the app — Profile → Delete account — or by emailing hello@bnyat.krdfrom your account’s email address with your student code. For email requests, we confirm your identity before processing deletion. In-app account deletion is immediate and permanent, subject to the retained records described above, and paid course access cannot be restored afterwards. Step-by-step instructions are on the Delete your account page.
Your rights
- See and correct your data. Your profile is editable in the app under Profile → Edit profile. Ask us for anything you cannot see there.
- Delete your data. See Deleting your account.
- Withdraw consent.Turn notifications off at any time; manage photo access in your phone’s settings.
- Ask questions or complain. Email hello@bnyat.krd.
To protect your account we may ask you to write from the email address you signed up with, or to confirm your student code.
Security
Every connection uses HTTPS. Our database enforces row-level security, so a student can only read their own records. Staff access follows least privilege — the Bnyat team sees only what their role needs. No method is 100% secure, so if you spot a problem, tell us at hello@bnyat.krd and we will act on it.
Children
Bnyat is for students aged 13 and over and is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you are a parent or guardian and believe a child under 13 has created an account, email hello@bnyat.krd and we will delete it.
Changes to this policy
When we change this policy we update the date at the top of this page. If a change affects how we use your data in a meaningful way, we will also tell you in the app before it takes effect.
Questions about your data?
Email the Bnyat team with questions about your data. For account deletion, see the Delete your account page.