Privacy Policy
What information the site, AskZ and ZAPP handle, where it goes, how long it stays, and your rights over it.
In plain English
- No sign-up is needed for anything. Your progress, streaks and preferences stay in your own browser unless you choose to sign in.
- Optional account: sign in with your email (a one-time code — no password) and we keep a copy of your progress on our server so it syncs across your devices. Delete it any time from /account.
- Analytics (Google Analytics, IP addresses anonymised): in the EU/EEA, UK and Switzerland it stays off until you allow it on the cookie banner; elsewhere it is on by default and “Cookie settings” in the footer turns it off. A Global Privacy Control signal turns it off everywhere.
- Anything you type into AskZ is sent to our server on Cloudflare and to an AI model provider to generate the answer. Don't type passwords, addresses or other people's details into it.
- If you ask AskZ about joining classes, it may collect your name, level, school/city and WhatsApp number and email them to ZAK so the admissions team can call you back.
- We never sell your data and we never show ads.
- You can ask us to see, correct or delete anything we hold about you — email contact@cswithzak.com.
The summary helps you read the document; the full text below is what applies.
1. Who is responsible
The data controller for cswithzak.com and the AskZ chat on it is Zafar Ali Khan (“ZAK”), an individual educator based in Karachi, Sindh, Pakistan, trading as CS with ZAK.
- Email: [contact@cswithzak.com](mailto:contact@cswithzak.com) (put “Privacy” in the subject line)
- WhatsApp / phone: +92-3-111-222-ZAK (+923111222925)
- Post: available on request by email.
We have not appointed a Data Protection Officer because we are a small operation and are not required to; ZAK personally handles privacy requests.
This policy covers the website, the AskZ drawer and /askz page on the website, testimonial submissions, enrolment enquiries that come through the site, and — once released — the ZAPP app (section 9). The stand-alone AskZ service at chat.askzbot.com and AskZ on WhatsApp are governed by their own notice on that site.
2. Our principles
- Free for students means free. No ads, no ad-tech, no data brokers, no selling or renting personal information — ever.
- Local first. Whatever can live in your browser, does. We only receive data when you deliberately send it (a chat message, a testimonial, an enquiry), plus anonymised analytics unless you turn it off.
- Minimal. We ask only for what a teacher genuinely needs to help you.
- Honest about AI. AskZ uses third-party AI models; we tell you which and where.
- Children first. Most of our users are under 18. We design and write for them, and we are cautious with their data.
3. What we collect, and why
a) Data that never leaves your browser (no collection by us)
The My Progress dashboard, quiz history, weak flashcards, exam planner settings, your pseudocode, Python, SQL, assembly and Prolog drafts, the Smart Notes and assignments you have opened (with your answers, self-marks and mastery ticks), your chosen level and theme are stored only in your browser's local/session storage and IndexedDB. We never receive them — unless you sign in (section 3l), in which case the progress document is also kept on our server. The full list of keys is in the Cookies & Local Storage notice.
b) Server logs (all visitors)
When your browser requests a page, our hosting provider (Vercel) and, for AskZ requests, Cloudflare automatically receive your IP address, browser type and version, device type, the page requested, the referring page and a timestamp. These are standard web-server logs used to keep the site running, secure and fast (legal basis: our legitimate interest in operating and protecting the site). They are retained for a short period by those providers under their own policies (typically days to a few weeks) and we do not build profiles from them.
c) Analytics (on by default — you can turn it off)
We use Google Analytics 4 with IP anonymisation switched on. It tells us, in aggregate, which pages and tools are used, roughly where visitors are (country/city level), what devices they use and how they arrived. It sets the cookies listed in the Cookies notice. We do not use Google Signals, advertising features, demographic reports or cross-device tracking. Google's own explanation of what it does with this data is at google.com/policies/privacy/partners.
Whether it runs depends on where you are, because the law differs:
- EU/EEA, United Kingdom, Switzerland (where the ePrivacy rules, PECR and the FADP require your prior consent for analytics cookies): nothing is loaded until you press Allow analytics on the cookie banner. If you press No thanks, or never answer, no analytics script is loaded and no analytics cookie is set. Legal basis: your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time from “Cookie settings” in the footer.
- Everywhere else: analytics is on from your first page view and you can turn it off at any time from “Cookie settings” in the footer (the script then stops immediately and is not loaded again). Legal basis: our legitimate interest in understanding which parts of a free site are used, with an easy opt-out.
To tell the two apart, our server looks at the country code Cloudflare attaches to your request; it is used for that one answer and not stored, and no location permission is ever requested. If that lookup fails, your browser's time zone is used instead, erring on the side of asking you. On either path you can also use Google's opt-out add-on, and a Global Privacy Control signal from your browser turns analytics off automatically wherever you are.
Site visits counter (no cookie, no personal data). The footer shows how many visits the site has had today, this week, this month, this year and in total. Each page you open sends one tick to our AskZ server (Cloudflare) which adds 1 to that day's count; the first page of a browser session also adds 1 to the day's visits, remembered by a zak-visit flag in session storage that disappears when you close the tab. Only the numbers are kept — no IP address, browser details, page path or visitor id is stored, so nothing can be traced back to you, and it runs whether analytics is on or off (it is not analytics: it cannot tell one visitor from another). Legal basis: our legitimate interest in showing how the site is used, with no impact on you.
d) AskZ conversations
When you send a message to AskZ from this site, we receive: the text you typed, a random conversation ID generated for that chat, and the page context (which course, topic and page you are on). The AskZ server (a Cloudflare Worker run by us) then:
- checks the message with an automated content-moderation API run by our AI safety provider to filter abusive or unsafe content;
- retrieves relevant passages from our own knowledge index (Cloudflare Vectorize);
- sends your message, the retrieved passages and the recent conversation history to a large language model run by our AI model provider (API-only, no training on our traffic; data centre in Singapore) to generate the reply;
- stores the conversation (last 80 messages) under the random conversation ID in Cloudflare KV for 90 days, so the chat can continue when you come back in the same browser tab, then deletes it automatically.
Conversations are keyed by a random ID, not by your name, and we do not link them to your IP address. But anything you type is content we process — so please do not type passwords, home addresses, ID numbers, other people's details or anything you would not say in a classroom. Legal basis: performance of the service you asked for (the chat), and our legitimate interest in keeping it safe. The AskZ & AI Transparency notice has more detail.
AskZ on Discord. In the CS with ZAK Discord server you can ask AskZ with the /askz command or by choosing “Ask Z about this” on a message. Discord sends that command to the same AskZ Worker together with your Discord user ID and username, the channel's ID and name, and — for “Ask Z about this” — the text of the message you chose. The answer is posted back into the channel, where everyone in it can read it. The conversation is kept for 90 days under an ID made from the channel and your Discord user ID (so a follow-up /askz continues it), and we do not combine it with anything else we hold. The daily question, MCQ and trace-it posts in the server are sent by us through Discord webhooks and involve no personal data. Discord itself processes your account and messages under Discord's privacy policy.
e) Generated assignments and notes
When you open a topic's Smart Notes or assignment reader, the page asks the same AskZ Worker for that document. If nobody has opened it before, the Worker builds it — the request carries only the topic's name and syllabus outline, never anything about you, and the Worker retrieves ZAK's own material for the topic and has it written by our AI model provider. The finished document is stored in Cloudflare KV under the topic key (not under any user) and served to every student who opens it; a copy is kept in your browser (IndexedDB for notes, local storage for assignments — see the cookies policy) so it works offline. Answers you type, marks you give yourself and the sections you tick as mastered never leave your device. Generation requests are rate-limited per hour using your IP address, which is not stored. Highlighting a passage in the notes and choosing “Ask Z” sends that passage to AskZ as a normal chat message (section 3d).
f) Enrolment and Success Pack enquiries (“leads”)
If you ask AskZ about joining ZAK's classes, buying a Success Pack or ZAKATHON, it may ask for your name, level, school or city, preferred mode (online, in-person, self-study) and WhatsApp number so the admissions team can contact you. If you provide them, AskZ sends them, together with a transcript of that conversation, by email (via Resend) to ZAK's mailbox, and keeps a copy in Cloudflare KV for 12 months. They are used solely to respond to your enquiry and arrange enrolment. Legal basis: steps taken at your request before entering into a contract. You can decline to give any of it — AskZ will still answer your questions and give you the admissions WhatsApp number instead.
g) Contact by WhatsApp, phone or email
When you message or call us, we receive whatever you send, your number or email address, and (on WhatsApp) your profile name and picture. We use it to reply and, if you enrol, to run your classes. WhatsApp is operated by Meta and has its own privacy policy. Legal basis: your request / contract, and our legitimate interest in responding.
h) Testimonials
If you submit a testimonial you give us your name, role, level, school, city, session, result, “where you are now”, your quote, and — for verification only — your email address and phone number. The email and phone are never published; they let ZAK check the testimonial is genuine and contact you about it. Your IP address is stored briefly (1 hour) to limit spam. See the Testimonials & User Content policy for publication and withdrawal.
i) Tuition students and parents
Students who enrol (and their parents/guardians) give us contact details, school, level and payment records through the centre or WhatsApp; we also keep attendance, test results and class notes. This is described in the Tuition Terms and the Safeguarding policy. Legal basis: contract, and our legitimate interest in teaching well.
j) Security and abuse
We may keep records of attempted attacks, abusive messages or rate-limit events (IP address, timestamps, the offending request) for as long as needed to protect the service and, if necessary, to report them. Legal basis: legitimate interest / legal obligation.
k) The Python Playground runtime
Python runs entirely in your browser (CPython compiled to WebAssembly — Pyodide). The first time you run Python, your browser downloads that runtime from the open-source CDN jsDelivr, which receives your IP address and browser type as any web request does and sets no cookies. Your code, its input and its output never leave the page. The SQL, assembler and Prolog labs and the pseudocode playground are bundled with the site and fetch nothing.
l) Your account (optional — progress sync)
If you choose to sign in on /account we ask for your email address only. We email you a six-digit code (through Resend, our email provider) to prove the address is yours; there is no password. Once signed in, your browser keeps a random sign-in token (see the cookies notice) and sends your progress document — display name, chosen level, XP (counted per device), streak, last-active date, completed topics, bookmarks, quiz results, keys of questions seen and missed, exam-question attempts and flashcards reviewed — to the AskZ server (a Cloudflare Worker run by us) whenever it changes, and fetches it when you open the site, so every device you sign in on shows the same progress. We store, in Cloudflare KV: your email address, that progress document, when you created the account and last signed in, and for each signed-in browser a hashed token with the browser type and the date. Codes are hashed and expire after 10 minutes; sign-in tokens expire after 180 days; your IP address is used only to rate-limit code requests (kept for at most an hour). We do not send you any other email — no newsletters, no marketing. Legal basis: performance of the service you asked for. Sign out forgets that browser only; Delete my account on /account erases the email, the progress document and every device's token from our server immediately and permanently (what is already on your device stays there until you reset it).
4. What we do not do
- We do not sell, rent or trade personal information.
- We do not run advertising, ad networks, retargeting or affiliate tracking.
- We do not use analytics to build individual profiles, and we do not use Google's advertising features.
- We do not use your AskZ conversations to train AI models. (Our model providers' terms also prohibit them from training on API traffic — see section 6.)
- We do not use facial recognition, biometrics, precise geolocation or fingerprinting. The Exam Planner guesses your Cambridge zone from your device's time-zone setting only, inside your browser; it never asks for your location.
- We do not knowingly collect personal information from children under 13 (section 8).
6. International transfers
We are in Pakistan; our providers are in the United States, Singapore, the EU and on global networks. Your data therefore crosses borders. Where a provider is in a country without a data-protection adequacy decision from your jurisdiction, we rely on the provider's standard contractual clauses / data-processing terms and on the fact that the data involved is minimal. Provider commitments we rely on: Vercel's DPA, Cloudflare's DPA and its statement that Workers AI/Vectorize data is not used to train models, our AI model provider's API data-privacy terms (no training on API inputs), our AI safety provider's API terms (no training on API data), Resend's DPA, Google's Ads Data Processing Terms for Analytics.
7. How long we keep things
| Data | Kept for |
|---|---|
| Browser-stored progress and preferences | Until you clear it — it is on your device, not ours |
| Analytics cookies (unless you opt out) | Up to 2 years (Google's default); consent record 12 months |
| Hosting / edge server logs | Short rolling window set by Vercel and Cloudflare (days to weeks) |
| AskZ conversation history | 90 days from the last message, then auto-deleted; you can clear it earlier with the chat's “clear” button (deletes it from your browser) |
| Enrolment leads captured by AskZ | 12 months in KV; the email copy in ZAK's mailbox until the enquiry is closed or you ask us to delete it |
| Testimonials | Published ones: until you withdraw them; pending/rejected ones: deleted within 12 months of submission |
| Testimonial rate-limit IP entry | 1 hour |
| Notes/assignment generation rate-limit counter | 1 hour |
| Generated Smart Notes and assignments | Per topic, until regenerated — they contain no personal data |
| Tuition records (students/parents) | Duration of enrolment plus up to 3 years for references, results tracking and accounting |
| Security/abuse records | As long as needed for the specific incident |
When a retention period ends we delete or irreversibly anonymise the data.
8. Children and parents
Under 13. The Services are not directed at children under 13 and we do not knowingly collect their personal information. If you are a parent or guardian and believe a child under 13 has sent us personal information (for example through AskZ or a testimonial), email [contact@cswithzak.com](mailto:contact@cswithzak.com) and we will delete it promptly and confirm to you. Where a law such as the US COPPA Rule applies, we will obtain verifiable parental consent before collecting personal information from a child under 13, or not collect it at all.
13 to 17. You can use the free site without giving us any personal information. Before you give AskZ your name and WhatsApp number for an enrolment enquiry, please make sure a parent or guardian agrees; enrolment itself is always arranged with a parent or guardian. Where the law where you live sets a higher age for consenting to online services on your own (for example 16 under the GDPR in some EU countries), that age applies and a parent's consent is needed for anything based on consent (such as an account).
Parents and guardians may exercise any of the rights in section 10 on behalf of their child. We may ask for reasonable proof that you are the parent or guardian.
9. ZAPP (the mobile app)
ZAPP is in private beta. When it is released, this section is its privacy notice and will be updated before launch.
- Progress and sync. Progress can stay on your device only (default) or, if you create an optional account, be synced through our server so it is the same on your phone and laptop. An account needs only an email address or an Apple/Google sign-in; no password is stored by us if you use sign-in-with-Apple/Google.
- AskZ in the app works exactly as on the website (section 3d), plus optional voice input — audio is transcribed on-device where the platform supports it, otherwise sent to our transcription provider and not retained.
- Camera (“Snap a question”) is used only while you take a photo of a question; the image is sent to the AskZ server to find the matching past-paper question and is not stored after the answer is returned.
- Notifications are opt-in and are scheduled on your device; we do not run a marketing push service.
- No ads, no third-party SDK trackers. Crash reporting, if enabled, is anonymous.
- You can delete your account and all synced data from inside the app, or by emailing us.
The store listings (Apple App Store privacy “nutrition label”, Google Play Data safety) will mirror this section.
10. Your rights
Whatever country you are in, you can ask us to:
- access the personal data we hold about you and get a copy;
- correct it if it is wrong;
- delete it (“right to be forgotten”);
- restrict or object to how we use it, including objecting to any processing based on legitimate interests;
- port it — receive it in a common machine-readable format;
- object or withdraw consent at any time — turn analytics off from “Cookie settings” in the footer, or delete your account — without affecting what was done before;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you — we make no such decisions; AskZ's answers are study help, not decisions about you.
To exercise a right, email [contact@cswithzak.com](mailto:contact@cswithzak.com) with “Privacy request” in the subject. Tell us what you want and, for AskZ conversations, the approximate date/time and the first message, since conversations are not tied to your name. We will respond within 30 days (we may need to verify you are who you say you are, and we may extend by a further 30 days for complex requests, telling you why). Requests are free unless they are manifestly unfounded or excessive.
If you are in the EU/EEA or the UK, the GDPR / UK GDPR gives you these rights and the right to complain to your national supervisory authority (for the UK, the ICO). If you are in California, the CCPA/CPRA gives you the rights to know, delete, correct and to opt out of “sale” or “sharing” — we do not sell or share personal information as those terms are defined, and we do not use sensitive personal information to infer characteristics. If you are in Pakistan, Article 14 of the Constitution protects your privacy, the Prevention of Electronic Crimes Act 2016 protects you against unauthorised access to and misuse of your data, and we will comply with the Personal Data Protection Act as soon as it is enacted and in force; you can also complain to the Federal Investigation Agency's Cybercrime Wing or, once operating, the National Commission for Personal Data Protection. We will honour these rights for everyone, wherever you are.
11. How we protect data
All traffic to the site and to AskZ is encrypted (HTTPS/TLS). The AskZ server checks that requests come from cswithzak.com, rate-limits abuse and moderates content. Secrets and API keys are held in provider secret stores, not in code. Administrative pages (testimonial moderation, lead lists) sit behind Cloudflare Access with named-user login. Only ZAK, and the admissions administrator for enrolment leads, can see personal data. We do not store payment card data at all — payments are made at centres or through bank transfer/mobile wallets you control.
No system is perfectly secure. If we discover a breach that is likely to put you at risk, we will tell affected people and any regulator we are required to tell without undue delay. Our Security & Responsible Disclosure page explains how to report a vulnerability.
12. Changes to this policy
We will update this policy when the site changes — for example when ZAPP launches or if we change an AI provider. The date at the top tells you when. Material changes will be flagged on the /legal hub for at least 30 days, and, for tuition students, mentioned in class or on the class WhatsApp group.
13. Contact
Privacy questions, requests and complaints: [contact@cswithzak.com](mailto:contact@cswithzak.com) · WhatsApp +92-3-111-222-ZAK · Contact page. We aim to acknowledge within 7 days.