Mdali
CompatibilitySupportLinkedIn
CompatibilitySupportLinkedIn
Last Updated: November 1, 2025

Privacy Policy

Introduction

Mdali ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App"). Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the App.

We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.

Our Privacy-First Approach

Mdali is built on the principle of privacy by design. We believe your educational data belongs to you and should stay on your device. Here's what makes our approach different:

  • Offline-First AI: Our AI models are downloaded once and run entirely on your device. No internet connection is required for the AI to function
  • Local Chat Storage: Your conversations with the AI assistant are stored only on your device. We never see, access, or store your chats on our servers
  • No Chat Recovery: If you delete the app or your chat history, we cannot recover it because we never had access to it
  • Minimal Cloud Data: We only store essential account information (phone number, name, preferences) in the cloud
  • Anonymized Analytics: Performance and usage data shared with our team and partners is aggregated and anonymized, making it impossible to identify individual users

This privacy-first approach ensures that your learning journey remains completely private while allowing us to improve the app's performance and effectiveness.

Information We Collect

Personal Information You Provide to Us

We collect personal information that you voluntarily provide to us when you register on the App, express an interest in obtaining information about us or our products and services, when you participate in activities on the App, or otherwise when you contact us.

The personal information that we collect depends on the context of your interactions with us and the App, the choices you make, and the features you use. The personal information we collect may include the following:

  • Phone Number: Used for authentication and account creation
  • Name: Provided during onboarding to personalize your experience
  • User Preferences: Educational level, subjects of interest, learning goals

Automatically Collected Information

When you access the App, we automatically collect certain information about your device, including:

  • Device Information: Device type, operating system version, unique device identifiers, mobile network information
  • Usage Data: App features used, session duration, time spent on specific screens, interaction patterns, frequency of use, time of day usage patterns
  • Performance Data: Crash reports, error logs, diagnostic information, app performance metrics, AI model performance on your device, battery usage metrics, device resource utilization
  • IP Address: For security and fraud prevention purposes
  • Location Data: General location based on IP address (not precise GPS location)

Important: All performance and usage data collected is aggregated and anonymized. This data does not personally identify individual users and is used solely to improve app performance and assess the effectiveness of our AI models on various devices.

Information from Third-Party Analytics

We use third-party analytics services to help us understand how users interact with the App. These services may collect information sent by your device, including:

  • Analytics Data via Mixpanel: User engagement metrics, feature usage patterns, session information, device characteristics, user flow through the app, AI model performance metrics
  • The data collected through analytics is used in aggregate form and does not personally identify individual users
  • Aggregated, anonymized usage data may be shared with our development team and strategic partners solely to assess app effectiveness and improve the educational experience

How We Use Your Information

We use the information we collect or receive to:

  • Provide Services: Create and manage your account, authenticate your identity, provide AI-powered educational assistance
  • Improve Our App: Analyze usage patterns to enhance features, fix bugs and technical issues, develop new features
  • Personalize Your Experience: Customize content and recommendations, remember your preferences and settings
  • Download AI Models: Manage and optimize the downloading of AI models for offline use
  • Send Notifications: Notify you about completed downloads, app updates and new features, quiz reminders (if enabled), important account or security updates
  • Protect Our Services: Monitor for and prevent fraud, enforce our terms and conditions, protect against malicious or illegal activity
  • Comply with Legal Obligations: Respond to legal requests and prevent harm

Data Storage and Security

Local Storage

The following data is stored locally on your device:

  • AI Models: Large language models downloaded for offline functionality (500-750MB). Once downloaded, these models run entirely on your device without requiring internet connectivity
  • Chat History: Your conversations are stored exclusively on your device. We do not monitor, access, or backup your chat history to any cloud servers
  • User Preferences: App settings and customization options
  • Cache Data: Temporary data to improve app performance

Privacy by Design: Your chat conversations remain completely private and are stored only on your device. If you delete the app or your chat history, this data cannot be recovered. We have no ability to access, view, or restore your conversations.

Device Security Responsibility: All data stored locally on your device relies on your device's built-in encryption and security features. We strongly recommend:

  • Enabling device encryption on your smartphone
  • Using a strong device passcode or biometric authentication
  • Keeping your operating system updated with the latest security patches
  • Being cautious when exporting data, as exported files are in plain text format

The security and encryption of data stored on your device is your responsibility. We provide the tools to keep your data local and private, but the physical security of your device and its encryption settings are under your control.

Cloud Storage

The following data is stored on secure cloud servers:

  • Authentication Data: Phone number and account credentials
  • User Profile: Name, preferences, and settings
  • Usage Analytics: Aggregated, anonymized usage data (via Mixpanel)

What We Do NOT Store in the Cloud: Your chat history and conversations with the AI assistant are never uploaded to our servers or any cloud storage. All conversations remain exclusively on your device.

Security Measures

We implement appropriate technical and organizational security measures to protect your personal information, including:

  • Encryption: All data transmission uses industry-standard encryption (HTTPS/TLS)
  • Secure Authentication: Phone-based OTP authentication
  • Access Controls: Limited employee access to personal data
  • Regular Security Audits: Periodic review of security practices
  • No Plain Text Storage: Sensitive data is never stored in plain text

However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

Third-Party Service Providers

We share limited, aggregated information with third-party service providers that perform services on our behalf:

Mixpanel (Analytics)

  • Purpose: App analytics, user behavior tracking, performance monitoring, and AI model effectiveness assessment
  • Data Shared: Device information, usage patterns, app interactions, AI model performance metrics (battery usage, device resource utilization, time of day usage)
  • Privacy Policy: https://mixpanel.com/legal/privacy-policy/
  • Location: United States

Expo (Development Platform)

  • Purpose: App updates, push notifications, and development tools
  • Data Shared: Device tokens, update metadata, error logs
  • Privacy Policy: https://expo.dev/privacy
  • Location: United States

Strategic Partners

  • Purpose: Assess app effectiveness and improve educational outcomes
  • Data Shared: Aggregated, anonymized usage data only. No personally identifiable information is shared
  • Usage: Partners use this data solely to evaluate the educational effectiveness of the platform

These service providers and partners are contractually obligated to protect your information and only use it for the purposes we specify. Important: Your chat conversations are never shared with any third parties, as they remain exclusively on your device.

App Tracking Transparency (iOS)

On iOS 14.5 and later, we request permission to track your activity across apps and websites owned by other companies. We use this tracking for:

  • Analytics: Understanding how you use the app
  • Performance Monitoring: Identifying and fixing issues
  • User Experience Improvement: Optimizing features based on usage patterns
  • Personalization: Providing more relevant content

You have the right to refuse tracking. To manage tracking preferences:

Settings → Privacy & Security → Tracking → Mdali

Refusing tracking will not affect the core functionality of the app.

Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

Access Rights

  • Request a copy of the personal data we hold about you
  • Receive information about how we process your data

Correction Rights

  • Update or correct inaccurate or incomplete personal information
  • Modify your profile and preferences in-app

Deletion Rights

  • Request deletion of your account and associated data stored in the cloud
  • Delete chat history directly from your device (stored locally only)

Data Portability Rights

  • Export your user profile and preferences data from our servers
  • Export your chat history and locally stored data directly from the app as plain text
  • Receive your data in a commonly used format (plain text/JSON)
  • All exported data never leaves your device unless you choose to share it

Important: When you export your locally stored data (chat history, AI models), it is provided to you in plain text format. The security of this exported data becomes your responsibility. We recommend using your device's built-in encryption features to protect sensitive exported data.

Opt-Out Rights

  • Disable analytics tracking
  • Unsubscribe from notifications
  • Refuse app tracking (iOS)

Withdrawal of Consent

  • Withdraw consent for data processing at any time
  • Note: Withdrawal may limit app functionality

To exercise any of these rights, please contact us at:

Email: yauvan@mdali.co.za
Response Time: We will respond within 30 days

Children's Privacy

The App is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us. If we learn that we have collected personal information from a child under 13 without verification of parental consent, we will delete that information promptly.

Background Processing

The App uses background processing capabilities for the following purposes:

Background Fetch

  • Purpose: Syncing data and checking for updates
  • Frequency: Periodic background refreshes
  • Data Usage: Minimal data transfer for updates

Background Processing

  • Purpose: Downloading large AI models (500-750MB)
  • Duration: Downloads may take several minutes to hours depending on model size
  • User Control: You can manage downloads and cancel them at any time

You can manage background app refresh in your device settings:

iOS: Settings → General → Background App Refresh → Mdali

Push Notifications

We may send you push notifications for the following purposes:

  • Download Notifications: Alert you when AI model downloads complete
  • App Updates: Inform you about new features or important updates
  • Quiz Reminders: Remind you about scheduled quizzes (if enabled)
  • Account Notifications: Important account or security updates

You have full control over notifications. To manage notification preferences:

iOS: Settings → Notifications → Mdali

Disabling notifications will not affect core app functionality but may impact your user experience.

Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this privacy policy:

Active Accounts

  • Personal data retained while your account is active
  • Chat history stored on your device only and retained until you delete it or uninstall the app
  • Usage data retained for up to 2 years

Deleted Accounts

  • Account data deleted within 30 days of deletion request
  • Chat history is automatically deleted when you uninstall the app (it is not stored in our systems)
  • Anonymized, aggregated data may be retained for analytics
  • Legal obligations may require longer retention of certain data

Analytics Data

  • Aggregate, anonymized analytics retained for up to 2 years
  • Individual session data retained for up to 90 days
  • Crash reports and performance metrics retained for up to 90 days

Local Device Data

  • Chat history and AI models are stored only on your device
  • This data is not backed up to our servers and cannot be recovered if deleted or if the app is uninstalled
  • You have complete control over this data and can delete it at any time from within the app

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States, where data protection laws may differ from those in your country.

By using the App, you consent to the transfer of your information to the United States and other countries where our service providers operate. We ensure that appropriate safeguards are in place to protect your information in accordance with this privacy policy.

South African Privacy Rights (POPIA)

Under the Protection of Personal Information Act (POPIA), South African residents have specific rights regarding their personal information:

Right to Access

  • Request confirmation of whether we hold your personal information
  • Obtain a copy of your personal information in a reasonable format
  • Receive information about how we collect, use, and share your data

Right to Correction

  • Correct or update inaccurate or incomplete personal information
  • Request that we update your profile and preferences

Right to Deletion

  • Request deletion of your personal information where retention is no longer necessary
  • Request deletion where you have withdrawn consent
  • Request deletion where processing is unlawful

Right to Object

  • Object to processing of your personal information for direct marketing
  • Object to automated decision-making that affects you
  • Object to processing where you believe it is causing unwarranted harm

Right to Lodge a Complaint

  • Lodge a complaint with the Information Regulator of South Africa
  • Contact details: SALU Building, 316 Thabo Sehume Street, Pretoria, 0001
  • Email: inforeg@justice.gov.za
  • Website: https://inforegulator.org.za/

Legal Basis for Processing

Under POPIA, we process your personal information based on:

  • Consent: You have given us explicit consent to process your data
  • Contract Performance: Processing is necessary to provide app services
  • Legitimate Interest: For app improvement, security, and fraud prevention
  • Legal Obligation: To comply with South African laws and regulations

Responsible Party Details

Responsible Party: Mdali
Information Officer: infrastructure@mdali.app
Contact: yauvan@mdali.co.za
Location: Johannesburg, South Africa

Links to Other Websites

The App may contain links to third-party websites or services that are not owned or controlled by us. We are not responsible for the privacy practices of these third-party sites. We encourage you to review the privacy policies of any third-party sites you visit.

Do Not Track Signals

Some web browsers and mobile devices include a Do Not Track (DNT) feature or setting. Because there is not yet a common understanding of how to interpret DNT signals, our App does not currently respond to DNT signals.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Last Updated" date at the top of this Privacy Policy. We will notify you of material changes by:

  • Updating the "Last Updated" date
  • Posting a notice in the App
  • Sending an in-app notification
  • Sending an email notification (if you have provided your email)

Your continued use of the App after changes are posted constitutes your acceptance of the updated Privacy Policy.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Email: yauvan@mdali.co.za
Information Officer: infrastructure@mdali.app
Response Time: We aim to respond to all inquiries within 30 days

Consent

By using the Mdali App, you hereby consent to this Privacy Policy and agree to its terms.


End of Privacy Policy

Note: This privacy policy is comprehensive and covers requirements for:

  • Apple App Store compliance
  • Google Play Store compliance
  • POPIA (Protection of Personal Information Act — South Africa)
  • GDPR considerations (for international users)
  • COPPA (Children's privacy)
  • App Tracking Transparency (iOS)

AI built in Africa, stays in Africa.

Johannesburg, South Africa

CompatibilityPrivacySupportv2LinkedIn