Privacy notice
Last updated 16 September 2026.
The short version
HiMwalimu is operated by an adult — you. We collect your email address, and the academic information you choose to record about your student. We never sell it, never show advertising, never share it with anyone for their own purposes, and we use no tracking or analytics tools at all. You can read everything we hold about your student inside the app, and you can delete it yourself at any time.
Who we are
HiMwalimu is an academic-insight and career-exploration service for students in Kenya, operated by the individual publishing this service. For any privacy question, or to exercise any right described below, contact lighttreepeople@gmail.com.
We are the data controller for the information described here. If you believe we have handled your information improperly, you may complain to Kenya's Office of the Data Protection Commissioner.
Accounts are held by adults, not students
Only a parent or guardian can hold an account. A student has a profile, not a login — there is no way for a student to sign in, and the service creates no student accounts. This is deliberate: it keeps an adult in control of a child's information.
There is no messaging, chat or social feature of any kind, so a student cannot be contacted by anyone through this service.
What we collect
About you, the guardian
Your email address, and a password which is stored only as a cryptographic hash — we cannot read it. That is all. We do not ask for your name, phone number, address or payment details.
About your student
- Their name, as you enter it
- Their birth year, and birth month if you choose to give it — we never ask for a date of birth
- Their curriculum and grade
- Their school name, if you choose to give it
- Your relationship to them (mother, father, guardian, other)
- The assessment results you record: subjects, scores, term and date
From those results we work out strengths, weaknesses, subject trends, improvement plans and career fields worth exploring. Those are calculated from what you recorded — they are not opinions collected from anywhere else.
What we deliberately never collect
No photographs, no audio or video, no location, no device or advertising identifiers, no biometric information, no national ID, no home address, and no contact details for the student — no student email address and no student phone number.
Why we collect it, and on what basis
We use it for one purpose: to show you your student's academic strengths and weaknesses, and career fields that may be worth exploring with them. We do not use it for anything else, and we will not start doing so without telling you and asking again.
Our basis for processing a child's information is your consent, given as their parent or guardian when you add them. You can withdraw that consent at any time (see below), and withdrawing it does not require you to give a reason.
Who else sees it
Nobody, for their own purposes. We do not sell your information. We do not share it with advertisers, data brokers, schools, or anyone else. We show no advertising of any kind, and we use no analytics, tracking or profiling tools — the service loads no third-party code at all.
Three companies process information on our behalf, purely to run the service: Vercel hosts the application, Railway hosts the database, and Resend delivers our emails to you. They act on our instructions and are not permitted to use the information for their own purposes. Their infrastructure is located outside Kenya, which means your information is transferred abroad to be stored and processed.
Our email provider only ever receives your email address and the text of the message. We deliberately keep your student's name and results out of the emails we send — when we need to tell you something about a student, the email says to open the app rather than repeating the details. So no information about your student passes through it.
We may disclose information if we are legally required to, or where it is necessary to protect a child from harm.
Your rights, and how to use them today
You do not need to email us to exercise most of these — they are built into the app:
- See everything we hold about your student — it is all visible in your account.
- Correct it — you can edit a recorded assessment, and change subjects.
- Withdraw consent for a student, from their privacy page.
- Delete your student's record entirely, from the same page. You will be asked to type their name to confirm, because it cannot be undone.
- Delete your whole account and every student under it, from your profile page.
You also have the right to object to processing, to request a copy of the information in a portable form, and to complain to the Office of the Data Protection Commissioner. For those, email us at the address above.
One limit we want to be straight about: deleting a record removes it from the live service, but a copy may persist in an encrypted database backup until that backup expires. We cannot selectively erase a record from a historical backup.
We also delete things automatically once we no longer have a reason to keep them — see How long we keep it below.
How long we keep it
We keep your information while there is a reason to, and then delete it automatically. These are the periods we apply:
- Your student's records — deleted 30 days after you withdraw consent or close your account. Access stops immediately; the 30 days exist only so an accidental withdrawal can be undone.
- Your account, if you stop using it — deactivated after 2 years without signing in, and deleted 1 year after that. Signing in at any point before deletion keeps it active.
- Our records of administrative actions — kept 2 years, then deleted.
You never have to wait for these. You can delete your student's record, or your whole account, yourself and immediately.
One thing we keep for longer, on purpose. When we delete a student's records we keep a short note that consent was given — the date, which version of this notice you agreed to, and that we emailed you about it. It is the evidence that we were allowed to hold the information in the first place, and it deliberately contains nothing identifying your student: no name, no school, no results.
And one limit we want to be straight about. These periods apply to our live service. A copy may persist in an encrypted database backup until that backup expires, and we cannot selectively erase one record from a historical backup.
How we protect it
All traffic is encrypted in transit using HTTPS, and the service instructs browsers never to connect insecurely. Passwords are stored only as bcrypt hashes. Every request for a student's data is checked against a single authorisation gate, so one guardian cannot reach another guardian's student — and a denied request reveals nothing about whether that student exists. Sessions expire after 12 hours. Administrative actions are recorded in an audit log.
No service can promise it will never suffer a breach. If one occurs and affects your information, we will tell you and notify the Office of the Data Protection Commissioner as the law requires.
Children's information
This service exists to hold information about children, so we treat it as the most sensitive thing we handle. In practice that means: an adult holds the account, a student cannot log in, we collect the minimum we can, no child's information is ever shared or advertised against, and you can delete all of it yourself.
If you are not the parent or legal guardian of a student, please do not add them. If you believe someone has added a child they have no authority over, contact us immediately at the address above.
Changes to this notice
If we change how we use information in a way that materially affects you or your student, we will update the date at the top and ask for your consent again where the law requires it. The consent you give is recorded with a version, so we can tell what you agreed to and when.
See also our terms of use.