What we collect, why, who else sees it, and what you can ask us to do with it.
Last updated: 8/6/2026
This policy explains what KankorAsan collects when you use KankorAsan, why we collect it, who else can see it, and what you can ask us to do with it. It covers the website, the mobile app and the API behind them.
KankorAsan is operated by KankorAsan in Afghanistan. For anything in this policy, write to privacy@kankorasan.af.
Account information: your name, email address, and — if you choose to give it — your phone number, province, school, Kankor year, the university fields you are aiming for, and a profile photo. Email and password are required; the rest exist to make analytics and predictions meaningful. If you sign in with Google instead of a password, Google gives us your name, email address and profile picture — nothing else, and never your Google password.
Study data: every practice session, mock exam, answer, score, review rating and streak. This is the raw material for your analytics and your field predictions. Without it the product does not work.
AI conversations: the messages you send the AI tutor, and the question you were looking at when you sent them.
Technical data: IP address, browser and device type, a session identifier, and — in the mobile app — a push-notification token that identifies your device to the notification service. Used for sign-in security, abuse and exam-integrity detection, delivering the notifications you have turned on, and aggregate usage measurement.
Payment data: which plan you bought, when, for how much, and the reference our payment provider returns. Card numbers are handled by the payment provider and never reach our servers.
When you ask the AI tutor a question, request an explanation, or generate a study plan, the text of your request and the relevant question or performance summary are sent to a third-party AI provider that generates the response. Your name, email address and payment details are not sent. The provider processes the request on our instructions and is not permitted to use it to build its own products. The exchange is then stored on your account so you can read it again.
AI output can be wrong. Explanations and study plans are study aids, not a replacement for your teacher.
We do not sell personal data and we do not share it for anyone else’s advertising.
If you join a class or cohort run by a school or preparation centre, the staff of that institution can see your participation, attempts and scores within that class. That is the purpose of joining it, and you can leave.
If you appear on a leaderboard, other students see your display name, rank and score. Leaderboard participation is a setting you control.
We use service providers that process data on our behalf under contract: MongoDB Atlas (database hosting), Google Cloud (application hosting), Vercel (website hosting), Resend (transactional email), Cloudinary (image hosting), Firebase (push notifications and Google sign-in), our AI provider (section 4) and our payment provider.
We disclose data to authorities only where a valid legal obligation applies, and we tell you unless we are prohibited from doing so.
Our database and application servers are hosted outside Afghanistan by the providers listed above. Using KankorAsan means your data is transferred to and stored in those countries.
KankorAsan is built for Kankor candidates, and many are under 18. You must be at least 13 to hold an account. If you are under 18, use the platform with the knowledge of a parent or guardian, who may contact us at privacy@kankorasan.af to see, correct or delete your data. We do not knowingly collect data from children under 13, and we delete such an account when we learn of it.
You can see and edit most of your data in your profile settings, and delete your account there. You can also ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. Write to privacy@kankorasan.af; we answer within 30 days. Deleting your account is permanent — scores, history and review queue go with it.
Passwords are stored hashed, never in readable form. Traffic is encrypted in transit. Administrative access requires two-factor authentication and is logged. No system is perfect: if a breach affects your data, we will tell you and describe what happened.
When this policy changes materially we update the date on this page and notify you in the platform. Continuing to use KankorAsan after that means the new version applies.