teache

Privacy Policy

This Privacy Policy explains how teache collects, uses, discloses and protects your personal data, and the rights you have over it under the Data Protection Act, 2012 (Act 843) of the Republic of Ghana.

Last updated: 22 August 2026

1. Who we are

teache ("teache", "we", "us" or "our") is a curriculum planning and assessment suite for Ghanaian teachers, covering schemes of work, lesson notes, records of work, tests, exams and marking schemes. The Service is operated by Utopia UGX Group Ltd, a private company limited by shares incorporated in Ghana (ORC registration number CS257921125). For the purposes of Act 843, Utopia UGX Group Ltd is the data controller responsible for the personal data described in this Policy, except where we act as a data processor on a teacher's behalf as described in Section 5.

This Policy applies to your use of the teache website and application at teache.app and all related services (together, the "Service"). By creating an account or using the Service, you acknowledge that you have read and understood this Policy. It should be read together with our Terms of Service.

2. Definitions

The following terms have the meanings given to them in Act 843:

  • Personal data means data about an individual who can be identified from that data, or from that data and other information in our possession.
  • Processing means any operation performed on personal data, including collecting, storing, using, disclosing or erasing it.
  • Data subject means the individual to whom personal data relates.
  • Data controller means the person who determines the purpose and manner in which personal data is processed.
  • Data processor means a person who processes personal data on behalf of a data controller.

3. Personal data we collect

We collect the following categories of personal data.

3.1 Information you provide to us.

  • Account and sign-in data: your first and last name, email address, a one-way hash of your password (we cannot read the original password), and the school, classes and subjects you set up. If you sign in with Google, Google provides the name, email address and account identifier needed to authenticate you.
  • Content you create: the topics, answers, notes, photos and documents you enter or upload to generate lesson notes, schemes of work, records of work, tests, exams and marking schemes, together with the documents produced from them.
  • Learner information: any personal data about your learners, such as names or class records, that you choose to include in the content you create (see Section 5).
  • Payment and receipt data: the pack and credits, amount, currency, status, dates, payment channel, teache and provider transaction identifiers, receipt number, and a snapshot of the customer name and email printed on the receipt. We also record refunds, chargebacks and payment-recovery events. Payment instrument details, such as mobile-money or card numbers, are collected and processed directly by Paystack and are not stored by us.
  • Communications: the content of messages you send us by email or through the Service, including support requests and feedback.
  • How you found us:if you answer the optional one-question card shown in your dashboard, the channel you choose from a fixed list, and, only if you choose “somewhere else”, the short free-text note you type, up to 120 characters. The question is skippable, is never part of signing up, and is asked only once. We record the fact that you were asked so we do not ask you again.

3.2 Information we collect automatically. When you use the Service, our application, security edge and self-hosted analytics collect limited technical and usage data. This can include IP address, browser and device type, request time, requested route, security and error events, referring site, coarse country and the pages and features used. Analytics excludes URL fragments, and excludes every URL search parameter except five campaign tags. See Section 12 for the cookies and analytics details.

4. How we use your data and our lawful basis

We process your personal data only where Act 843 permits it. The table below sets out our purposes and the corresponding lawful basis.

  • To create and administer your account and provide the Service, including generating and saving your documents. Basis: performance of our contract with you.
  • To process credit purchases and keep accounting and tax records. Basis: performance of our contract and compliance with a legal obligation.
  • To secure the Service, prevent fraud and abuse, and maintain and improve how teache works. Basis: our legitimate interests in running a safe, reliable service.
  • To respond to your messages and provide support. Basis: performance of our contract and our legitimate interests.
  • To understand which channels bring teachers to teache, using the five campaign tags described in Section 12 and your optional answer to the “how did you find us” card, so we know where to keep putting our effort. Basis: our legitimate interests in growing the Service sustainably. The card is optional and skippable, and skipping it changes nothing about your account or what the Service does for you.
  • To send you optional product updates or marketing, where you have asked to receive them. Basis: your consent, which you may withdraw at any time.

We do not sell your personal data, and we do not use the content you create to advertise to you.

5. Learners' and children's personal data

The Service is intended for use by teachers, who must be adults. The content you create may contain personal data about your learners, including children. Where it does, you remain responsible for that data as its controller, and we process it only on your instructions in order to provide the Service to you.

You should include learner personal data only where it is necessary for your planning, should not include more than is needed, and should use initials or generic references in place of full identifying details wherever your planning allows. You are responsible for having the appropriate authority to process your learners' data through the Service.

6. Automated processing and artificial intelligence

The Service uses artificial intelligence to generate documents and guided questions. To do this, the content you enter is transmitted to our AI processor, Anthropic PBC (the provider of the Claude models), which processes it on our behalf and under contract. We transmit only the data needed to produce your document. Under the commercial API terms and configuration we use, Anthropic does not use our API inputs or outputs to train its models unless we expressly opt in; we do not opt in. Anthropic ordinarily deletes API inputs and outputs from its systems within 30 days, subject to any longer period required for safety enforcement, law, or a different written agreement.

This processing assists you in preparing documents that you review, edit and approve. It does not produce legal effects concerning you or similarly significantly affect you within the meaning of Act 843, and you remain in control of the documents you generate.

7. Storage, service providers and disclosure

The live application and database run on a contracted Hetzner virtual private server. Cloudflare provides DNS, traffic delivery and edge security. Nightly database backups are encrypted before they are uploaded to Amazon Web Services S3 in its eu-central-1 region, so AWS stores the encrypted backup object rather than a readable database. We operate our own Umami analytics instance on managed infrastructure.

We use the following service providers and recipients where needed to provide teache. We give each only the data needed for its role:

  • Hetzner, AWS and Cloudflare for hosting, encrypted backup storage, network delivery and security.
  • Anthropic to generate the documents and guided questions you request.
  • Paystack to process payments, confirm their status, and support refunds, chargebacks and payment recovery.
  • Google when you choose Google sign-in, and Brevo to deliver transactional account and service emails.
  • Tally when you choose to submit our linked support or feature-request forms. The information you enter there is sent directly to Tally for us to review.
  • Where required by law, to comply with a legal obligation, court order or lawful request from a competent authority.
  • To protect rights and safety, where necessary to prevent or address fraud, security issues, or harm to any person.
  • In a business transfer, if teache is involved in a merger, acquisition or sale of assets, in which case we will notify you and this Policy will continue to apply.

We do not sell or rent your personal data.

8. International transfer of data

The providers above may process data outside Ghana, including in the European Economic Area, the United States and other countries from which their services are delivered. This means that using teache can involve an international transfer. We minimise the data sent, use encrypted and authenticated connections, review each provider's location, role, contractual terms and security commitments, and require protection appropriate to the data and consistent with Act 843. We maintain an inventory of these transfers and reassess it when a provider or its role changes.

9. Data retention

We retain your personal data for as long as your account is active and as long as needed to provide the Service. If you ask to delete your account, any payment still awaiting final reconciliation must first be resolved so that money or credits are not lost. We then delete the account, its teaching content and ordinary account records, except for the limited financial records described below.

Your answer to the “how did you find us” card, including any free-text note, is stored on your teacher profile and is deleted with your account. It is part of the copy you receive if you ask for access to your data, and you can ask us to erase it on its own at any time without deleting your account. Only the people who run teache can read the free-text note, and it is read by hand rather than fed into any automated profiling.

We keep financial and transaction records for at least six years to meet Ghana tax-record duties and to account for purchases, refunds and chargebacks. When an account is deleted, payments on which money moved are copied to an account-detached financial record without the customer's name or email. Transaction references, receipt numbers, provider identifiers and stable integrity hashes remain pseudonymous personal data during their retention period. When the six-year period ends, we remove those identifiers and retain only non-identifying accounting totals, unless a tax proceeding, investigation, refund, dispute or other legal hold requires the relevant record for longer.

For payment recovery and audit, we keep a bounded dead-letter record when an authentic Paystack event cannot safely be applied. A full, HMAC-verified webhook body is kept only in exceptional cases: when the event cannot be parsed, when a reversal has no stable identity, or when a dispute event is not recognised. These bodies are access-restricted, may contain additional information supplied by Paystack, and are removed with the event's pseudonymous identifiers after six years unless a legal hold applies.

Encrypted database backups follow a rolling 30-day expiry. Information deleted or de-identified in the live database may therefore remain in an inaccessible encrypted backup for up to 30 additional days. If a backup is restored, deletion, de-identification and cleanup controls must be reapplied before the restored system is allowed to serve users.

10. Security

We take reasonable technical and organisational measures to protect your personal data against loss, unauthorised access, alteration and disclosure, as required by Act 843. These include encryption of data in transit, restricting access to authorised personnel, and using reputable providers for payment and infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect your data and to notify you and the Data Protection Commission of any breach where the law requires.

11. Your rights

As a data subject under Act 843, you have the following rights in respect of your personal data:

  • Access: to ask whether we hold personal data about you and to request a copy of it.
  • Correction: to ask us to correct data that is inaccurate, misleading, out of date or incomplete.
  • Deletion: to ask us to delete or destroy your personal data where there is no lawful basis for us to keep it.
  • Objection: to object to the processing of your data for a particular purpose, including direct marketing.
  • Withdrawal of consent: to withdraw any consent you have given, at any time, without affecting processing carried out before withdrawal.

To exercise any of these rights, email us at [email protected]. We will respond within the period required by law. We may need to verify your identity before acting on your request.

12. Cookies and analytics

We use only the cookies necessary to operate the Service, such as keeping you signed in and keeping the Service secure. These essential cookies are required for the Service to function.

For analytics we use a self-hosted Umami instance. It does not set an analytics cookie or track you across other websites. It records the page path, visit time, referring site, browser and device type, and coarse country so we can understand and improve use of the Service.

The page path is recorded without its fragment, and without its search parameters, with one exception. We keep five campaign tags, and only these five: utm_source, utm_medium, utm_campaign, utm_content and utm_term. They tell us which link brought you here, so we can see which of our own posts, guides or videos are worth continuing. Every other search parameter is removed in your browser before anything is sent, so single-use values carried in a link, such as an email verification or password reset token, never reach Umami at all.

We do not send your name, email or document content to Umami. If you answer the optional “how did you find us” card, only the channel you picked is sent, recorded as a fixed code such as colleague. If you instead typed a free-text note, that note is never sent to Umami: it stays in our own database, and we read it by hand. We treat linkable technical data as personal data while it is processed. Because we do not use non-essential or advertising cookies, we do not display a cookie-consent banner.

13. Marketing communications

We will only send you marketing communications where you have asked us to. You can opt out at any time using the unsubscribe link in our emails or by contacting us. We will still send you essential service messages, such as security and account notices, which are not marketing.

14. Complaints and the Data Protection Commission

If you have a concern about how we handle your personal data, please contact us first at [email protected] so we can try to resolve it. You also have the right to lodge a complaint with the Data Protection Commission of Ghana, the authority responsible for enforcing Act 843.

15. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or the law. When we do, we will revise the "Last updated" date above and, where the changes are significant, take reasonable steps to notify you.

16. Contact us

For any question about this Policy or your personal data, contact the controller:

Utopia UGX Group Ltd
ORC registration number CS257921125
HNO. 54 Dome Pillar 2, Near Ghana Atomic Energy Commission, Yam Street, Accra, Ga East, Greater Accra, Ghana
[email protected]
055 206 8939