XYSHIMA owl logoXYSHIMAAI STUDY PLATFORM
TRUST CENTER

Clear safeguards. Honest limits. No borrowed badges.

Students and parents should be able to understand what XYSHIMA does with data, where AI is used, how younger users are protected, and what the platform can—and cannot—promise.

Privacy informationAI disclosureGuardian authorisationHuman support
AT A GLANCE

What XYSHIMA does today.

Student privacy

XYSHIMA explains the account, learning, support and legal-preference data it processes, why it is needed, the providers involved, retention principles and user rights.

Age-aware access

Independent accounts are not permitted for users under 14. Users aged 14–17 require parent or legal-guardian authorisation, including for paid subscriptions.

Visible AI use

Students are told when AI is involved. Tutor answers, generated practice and learning estimates are guidance—not official grades or guaranteed academic outcomes.

Safer learning design

Guided tutoring is designed to ask for attempts, provide hints and diagnose misunderstandings before revealing a complete answer.

Security controls

Production access uses authentication, server-side controls and restricted database permissions. AI-provider credentials are kept server-side rather than exposed in browser code.

Correction and reporting

Students can report questionable AI questions, responses and flashcards. Important academic information should still be checked against teachers and official course materials.

READ THE DETAILS

Trust should be inspectable.

These pages describe the current rules and safeguards behind the service. They are the source of truth—not a decorative badge row.

DATA & AI

What may be processed to provide the service.

Learning context

Subjects, curriculum, uploaded materials, notes, attempts, confidence, timing, review activity, tutor conversations and learning-model outputs may be used to personalise study support.

Specialist providers

XYSHIMA currently identifies Supabase for authentication/database services, Cloudflare for hosting/security, OpenAI for AI functionality and PayPal for payments.

Your choices

Depending on applicable law, users may request access, correction, deletion, restriction, objection or portability, and may withdraw consent where processing relies on consent.

AI limits

AI can hallucinate, miscalculate or misunderstand a syllabus rule. No automated system can guarantee zero errors, and important information deserves independent verification.

CERTIFICATIONS

No third-party certification is claimed yet.

XYSHIMA does not currently claim SOC 2, ISO 27001, COPPA Safe Harbor, Digital Promise certification, or any other independent trust badge. If XYSHIMA earns a credential, this page will identify the awarding organisation, scope and validity clearly. Legal alignment and internal safeguards are not presented as independent certification.

CONTACT & ACCOUNT RIGHTS

Ask a question or exercise a privacy right.

Email support@xyshima.com for privacy requests, safety concerns, account deletion, billing questions or suspected security issues. Include only the information needed to identify and handle the request.