← Back to site

Privacy Policy

Effective date: 1 July 2026 · Last updated: 1 July 2026

This policy explains what personal data Apex — Junior GCSE ("Apex", "we", "us") collects, why, and how we protect it. We designed Apex to be safe for young learners: no advertising, and we never sell your data.

1. Data we collect

DataWhy
Email addressTo create and verify your account (one-time passcode) and contact you about your account.
Password (stored only as a secure hash)To sign you in. We never store your password in readable form.
Learning progress (lessons completed, streak, board, tier)To save your place and show progress across devices.
Parent–child link (a code you generate)To let a parent view their own child's progress on Silver/Gold.
Plan & payment statusTo give you the access you paid for. Payments run through PayPal; we receive confirmation of payment, not your card details.
Forum posts (paid plans)To operate the student forum.
Minimal technical dataBasic, privacy-respecting usage information to keep the Service secure and working.

2. How we use your data

We do not sell your data, and we do not show advertising.

3. Children's privacy & parental consent

Apex is intended for GCSE-level learners. If a learner is under 16, a parent or guardian should create and manage the account and provides consent for the processing of the child's data described here. Parents may access, correct or delete their child's data by contacting us. We collect only what is needed to run the Service for the learner.

4. Parent monitoring — how it works

On Silver and Gold, a parent links to their child using a one-time code. The parent then sees the child's progress in a separate, read-only dashboard within the parent's own login. This monitoring data is the child's learning progress only; it is not shared with anyone else, and it is not surfaced in the child's study screen.

5. Who we share data with

We share data only with service providers that help us run Apex, under appropriate safeguards:

We may disclose data if required by law. We never sell personal data.

6. Cookies & local storage

We use your browser's local storage to remember your progress and keep you signed in. We do not use advertising or cross-site tracking cookies. If we add privacy-respecting analytics in future, we will update this policy and, where required, ask for consent.

7. How long we keep data

We keep your account and progress data while your account is active. If you delete your account (or ask us to), we delete or anonymise your personal data within a reasonable period, except where we must retain limited records (for example, payment records) to meet legal obligations.

8. How we protect data

9. Your rights

You (or a parent on a child's behalf) can ask to access, correct, export or delete personal data, and object to or restrict certain processing. To exercise these rights, contact us using the details below. You also have the right to complain to your local data protection authority.

10. International transfers

Our providers may process data in other countries. Where they do, we rely on appropriate safeguards to protect your data.

11. Changes to this policy

We may update this policy and will change the "Last updated" date; material changes will be notified where reasonable.

12. Contact

For any privacy question or request, email privacy@apexacademy.co.ke.

This policy is a plain-language starting point. Before relying on it commercially, have it reviewed by a qualified privacy/data-protection professional for your jurisdiction (for example, Kenya's Data Protection Act and, if you serve UK/EU learners, UK GDPR / GDPR).