HARMONAID INC. PRIVACY POLICY
HarmonAId Inc. (the "Company") is committed to maintaining robust privacy protections for its users. Our Privacy Policy ("Privacy Policy") is designed to help you understand how we collect, use and safeguard the information you provide to us and to assist you in making informed decisions when using our Service.
For purposes of this Agreement, "Site" refers to the Company's website, which can be accessed at studentportal.harmonaid.ai or through our mobile application.
"Service" refers to the Company's services accessed via the Site, in which college students can connect with verified peer tutors for academic support.
The terms "we," "us," and "our" refer to the Company.
"You" refers to you, as a user of our Site or our Service.
By accessing our Site or our Service, you accept our Privacy Policy and Terms of Use (found here: https://studentportal.harmonaid.ai/terms), and you consent to our collection, storage, use and disclosure of your Personal Information as described in this Privacy Policy.
IMPORTANT NOTICE:
We may collect and process sensitive personal data, including data derived from AI analysis of communications for matching and safety purposes. You have the right to limit the use of your sensitive personal data. See Section IV (for California residents) and Section V (for Texas residents) for details on exercising this right.
I. INFORMATION WE COLLECT
We collect "Non-Personal Information" and "Personal Information." Non-Personal Information includes information that cannot be used to personally identify you, such as anonymous usage data, general demographic information we may collect, referring/exit pages and URLs, platform types, preferences you submit and preferences that are generated based on the data you submit and number of clicks. Personal Information includes your email, name, university affiliation, phone number, profile information, payment information (processed securely by Stripe, our third-party payment processor), which you submit to us through the registration process at the Site.
1. Information collected via Technology
To activate the Service you do not need to submit any Personal Information other than your email address. To use the Service thereafter, you do need to submit further Personal Information, which may include: your name, university affiliation, phone number, profile photo, academic major, courses of study, tutoring preferences, and payment information. However, in an effort to improve the quality of the Service, we track information provided to us by your browser or by our software application when you view or use the Service, such as the website you came from (known as the "referring URL"), the type of browser you use, the device from which you connected to the Service, the time and date of access, and other information that does not personally identify you. We track this information using cookies, or small text files which include an anonymous unique identifier. Cookies are sent to a user's browser from our servers and are stored on the user's computer hard drive. Sending a cookie to a user's browser enables us to collect Non-Personal information about that user and keep a record of the user's preferences when utilizing our services, both on an individual and aggregate basis.
For example, the Company may use cookies to collect the following information: User preferences for tutoring subjects and schedules, search history within the platform, tutor-student matching interactions, session booking patterns.
The Company may use both persistent and session cookies; persistent cookies remain on your computer after you close your session and until you delete them, while session cookies expire when you close your browser. For example, we store a persistent cookie to remember your login status and matching preferences.
2. Information you provide us by registering for an account
In addition to the information provided automatically by your browser when you visit the Site, to become a subscriber to the Service you will need to create a personal profile. You can create a profile by registering with the Service and entering your email address, and creating a user name and a password. By registering, you are authorizing us to collect, store and use your email address in accordance with this Privacy Policy.
Cookies are small text files that are stored on your device when you visit our Site. We use cookies to help the Site function properly and to understand how visitors interact with our services.
Essential Cookies (Required)
These cookies are necessary for the Site to function and cannot be disabled:
- Authentication cookies — Keep you logged in to your account
- Security cookies — Protect against abuse and unauthorized access (reCAPTCHA)
Analytics Cookies (Optional)
With your consent, we use Firebase/Google Analytics to understand how visitors use our Site. These cookies help us improve our Service by analyzing:
- Which pages are most visited
- How users navigate through the Site
- General usage patterns and trends
Your Cookie Choices
When you first visit our Site, you will see a cookie consent banner asking for your permission to use analytics cookies. You can:
- Accept — Analytics cookies will be enabled
- Decline — Only essential cookies will be used
- Change your preference — Use the "Cookie Preferences" link in the footer at any time
You may also configure your browser to block all cookies, though this may affect Site functionality.
3. AI-Powered Matching and Chat Analysis
HarmonAId uses artificial intelligence to improve tutor-student matching and service quality. This includes:
- Analysis of in-platform conversations between tutors and students to calculate compatibility scores and matching effectiveness
- Evaluation of communication patterns, response times, professionalism, and engagement quality
- Detection of inappropriate behavior, potential safety concerns, or attempts to circumvent the platform
- Continuous improvement of our matching algorithms based on aggregated, anonymized interaction data
User Consent and Control:
When you begin using our in-platform messaging features, you will be presented with a clear opt-in consent request to allow AI analysis of your conversations. This consent is optional, and you may decline while still using basic chat functionality. However, declining AI analysis means you will not receive match compatibility scores or benefit from our enhanced matching features.
If you consent to AI analysis, you can revoke this consent at any time through your Account Settings. Upon revocation, we will stop analyzing new conversations, though previously analyzed data may be retained in anonymized, aggregated form for platform improvement purposes.
Privacy Protections:
- All chat messages are encrypted in transit and at rest
- AI analysis is fully automated—no human employees read your private conversations unless required for safety, legal, or security purposes
- Your conversation data is never sold to third parties or used for advertising
- We do not analyze protected characteristics such as race, ethnicity, religion, disability status, sexual orientation, or gender identity
- Our AI systems are designed to evaluate communication quality, professionalism, and compatibility—not personal characteristics
We comply with applicable US federal and state data protection regulations, including CCPA, CPRA, and TDPSA, in all aspects of our AI-powered features.
4. Eligibility and Age Requirements
Our Service is intended exclusively for college and university students who are at least 18 years of age. By using our Service, you represent and warrant that you are at least 18 years old and are enrolled in or affiliated with a college or university.
We do not knowingly collect personal information from individuals under the age of 18. If we become aware that a user under 18 has provided us with personal information, we will take steps to delete such information. If you believe we have collected information from someone under 18, please contact us immediately at privacy@harmonaid.ai.
II. HOW WE USE AND SHARE INFORMATION
Personal Information:
Except as otherwise stated in this Privacy Policy, we do not sell, trade, rent or otherwise share for marketing purposes your Personal Information with third parties without your consent. We do share Personal Information with vendors who are performing services for the Company, such as the servers for our email communications who are provided access to user's email address for purposes of sending emails from us. Those vendors use your Personal Information only at our direction and in accordance with our Privacy Policy.
In general, the Personal Information you provide to us is used to help us communicate with you. For example, we use Personal Information to contact users in response to questions, solicit feedback from users, provide technical support, and inform users about promotional offers.
We may share Personal Information with outside parties if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to meet any applicable legal process or enforceable governmental request; to enforce applicable Terms of Service, including investigation of potential violations; address fraud, security or technical concerns; or to protect against harm to the rights, property, or safety of our users or the public as required or permitted by law.
Non-Personal Information:
In general, we use Non-Personal Information to help us improve the Service and customize the user experience. We also aggregate Non-Personal Information in order to track trends and analyze use patterns on the Site. This Privacy Policy does not limit in any way our use or disclosure of Non-Personal Information and we reserve the right to use and disclose such Non-Personal Information to our partners, advertisers and other third parties at our discretion.
In the event we undergo a business transaction such as a merger, acquisition by another company, or sale of all or a portion of our assets, your Personal Information may be among the assets transferred. You acknowledge and consent that such transfers may occur and are permitted by this Privacy Policy, and that any acquirer of our assets may continue to process your Personal Information as set forth in this Privacy Policy. If our information practices change at any time in the future, we will post the policy changes to the Site so that you may opt out of the new information practices. We suggest that you check the Site periodically if you are concerned about how your information is used.
III. HOW WE PROTECT INFORMATION
We implement security measures designed to protect your information from unauthorized access. Your account is protected by your account password and we urge you to take steps to keep your personal information safe by not disclosing your password and by logging out of your account after each use. We further protect your information from potential security breaches by implementing certain technological security measures including encryption, firewalls and secure socket layer technology. However, these measures do not guarantee that your information will not be accessed, disclosed, altered or destroyed by breach of such firewalls and secure server software. By using our Service, you acknowledge that you understand and agree to assume these risks.
VERIFICATION AND SECURITY
Phone and Email Verification: We collect phone numbers and email addresses to verify your identity and secure your account. Verification codes are sent via:
- Email OTP for email verification
- SMS OTP for phone verification (processed by Twilio)
We store verified contact information in encrypted form and use it for:
- Account authentication
- Security alerts
- Session notifications (with your consent)
COMMUNICATIONS
Text Message Notifications: With your consent, we send SMS notifications about:
- Upcoming tutoring sessions
- Session confirmations and changes
- Payment confirmations
- Time-sensitive security alerts
You control your notification preferences in Account Settings. Reply STOP to opt-out of non-essential messages. Transactional messages (security alerts, payment confirmations) cannot be disabled as they are essential to the Service. Standard message and data rates may apply. Message frequency depends on your platform activity.
IV. RIGHTS FOR CALIFORNIA RESIDENTS (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Where there is any conflict between this section and other portions of this Privacy Policy regarding California-specific rights, this section shall control.
4.1 Right to Know
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which the information was collected, the business or commercial purpose for collecting the information, and the categories of third parties with whom we share the information.
4.2 Right to Delete
You have the right to request deletion of your personal information that we have collected, subject to certain exceptions permitted by law (such as compliance with legal obligations, completing transactions, detecting security incidents, and exercising free speech).
4.3 Right to Correct
You have the right to request that we correct inaccurate personal information that we maintain about you, taking into account the nature of the personal information and the purposes for which we process it. You may submit a correction request through your Account Settings or by contacting us at privacy@harmonaid.ai.
4.4 Right to Data Portability
You have the right to request a copy of your personal information in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity.
4.5 Right to Limit Use of Sensitive Personal Information
You have the right to limit the use and disclosure of your sensitive personal information to purposes necessary to perform the services you request. HarmonAId collects the following categories that may constitute sensitive personal information under the CPRA:
- Account log-in credentials (email and password)
- AI-derived inferences about communication quality and compatibility (when you consent to AI analysis)
To limit the use of your sensitive personal information, you may: (a) revoke consent to AI analysis of your conversations in Account Settings; (b) contact us at privacy@harmonaid.ai to request limitations on other sensitive data processing; or (c) use the "Limit the Use of My Sensitive Personal Information" link, which will be available on our Site.
4.6 Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you services, charge you different prices, provide a different quality of service, or suggest that you will receive a different level of service for exercising your rights.
4.7 Right to Opt-Out of Sale or Sharing
HarmonAId does not sell your personal information and does not share your personal information for cross-context behavioral advertising. Should this practice ever change, we will provide a conspicuous "Do Not Sell or Share My Personal Information" link on our Site and notify you in advance.
4.8 Authorized Agent
You may designate an authorized agent to submit requests on your behalf. To do so, provide us with written authorization signed by you, or a power of attorney. We may verify your identity before processing a request submitted by an authorized agent. Submit authorized agent requests to privacy@harmonaid.ai.
4.9 Categories of Personal Information Collected
The following table describes the categories of personal information we collect, the sources, purposes, and third parties with whom each category is shared. This disclosure covers the preceding 12 months.
| Category | Examples | Source | Business Purpose | Third Parties |
|---|---|---|---|---|
| Identifiers | Name, email, phone number, university affiliation, profile photo | Directly from you (registration) | Account creation, identity verification, communications | Service providers (Twilio for SMS verification) |
| Commercial Information | Transaction records, payment status, last four digits of card | Stripe (payment processor) | Processing payments, transaction history | Stripe Inc. (PCI-DSS Level 1 compliant) |
| Internet/Electronic Activity | Browsing history on our Site, search history, cookies, device info, referring URLs | Automatically via cookies and browser | Improving Service, analytics, user experience | Analytics service providers |
| Education Information | Academic major, courses of study, university enrollment (self-reported) | Directly from you | Tutor-student matching, platform functionality | Not shared with third parties |
| Professional Information | Tutoring subjects, availability, session history, ratings | Directly from you and platform activity | Matching, quality assurance, platform operation | Displayed to other users as part of tutor profiles |
| Inferences / AI-Derived Data | Compatibility scores, communication quality metrics, matching preferences | AI analysis of platform interactions (with your consent) | Tutor-student matching optimization | Not shared with third parties |
| Geolocation Data | General location derived from IP address | Automatically collected | Service optimization, security | Not shared with third parties |
4.10 Data Retention Periods
In compliance with CPRA requirements, the following table sets out the retention period for each category of personal information we collect:
| Data Category | Retention Period |
|---|---|
| Account Information | Duration of active account + 30 days after deletion request |
| Transaction Records | 7 years (tax and legal compliance) |
| Communication Logs (in-platform) | Duration of active account; anonymized upon deletion |
| AI-Derived Matching Data | Anonymized and aggregated upon consent revocation or account deletion |
| Cookies (Session) | Expire when browser is closed |
| Cookies (Persistent) | Up to 12 months, or until manually deleted |
| Verification Data (OTP codes) | Deleted immediately after verification |
| Anonymized/Aggregated Data | Retained indefinitely for analytics and platform improvement |
4.11 California "Shine the Light" (Civil Code § 1798.83)
Under California Civil Code Section 1798.83, California residents who provide personal information in obtaining products or services for personal, family, or household use are entitled to request information about personal information shared with third parties for those third parties' direct marketing purposes. HarmonAId does not share personal information with third parties for their direct marketing purposes. If this practice changes in the future, we will update this section and provide you with an opt-out mechanism.
4.12 Do Not Track and Global Privacy Control
California law requires us to disclose how we respond to Do Not Track (DNT) signals. We do not currently respond to DNT signals, as there is no uniform industry standard for DNT.
However, we do recognize and honor Global Privacy Control (GPC) signals from your browser. When we detect a GPC signal, we treat it as a valid opt-out request under the CCPA/CPRA, specifically as a request to opt out of the sale of personal information and sharing for cross-context behavioral advertising. Since we do not currently sell personal information or share it for cross-context behavioral advertising, the GPC signal serves as an additional safeguard for your privacy preferences.
4.13 Financial Incentives
We do not offer financial incentives or price or service differences in exchange for the retention or sale of personal information. Should we ever offer such a program, we will provide you with clear notice and obtain your opt-in consent prior to enrollment, and you will have the right to withdraw at any time.
4.14 How to Exercise Your California Rights
To exercise any of the rights described in this section, you may:
- Email us at: privacy@harmonaid.ai
- Adjust your preferences in your Account Settings on the Site
- Write to us at: HarmonAId Inc., 131 Continental Dr Suite 305, Newark, DE 19713
Verification Process: When you submit a request, we will verify your identity by matching at least two pieces of personal information you provide against information we have on file. For requests to access specific pieces of personal information, we may require additional verification. We will respond to verifiable requests within 45 days of receipt. If we need additional time (up to an additional 45 days), we will inform you of the reason and the extension period in writing.
Request Metrics: In compliance with CCPA regulations, we will compile and publish annual metrics on the number of requests to know, delete, correct, and opt-out that we receive, as well as our median response time and the number of requests denied.
V. RIGHTS FOR TEXAS RESIDENTS (TDPSA)
If you are a Texas resident, you have the following rights under the Texas Data Privacy and Security Act (TDPSA):
- Right to Confirm: You have the right to confirm whether we are processing your personal data.
- Right to Access: You have the right to access the personal data we have collected about you.
- Right to Correct: You have the right to correct inaccuracies in your personal data.
- Right to Delete: You have the right to request deletion of your personal data, subject to certain legal exceptions.
- Right to Data Portability: You have the right to obtain a copy of your personal data in a portable, readily usable format.
- Right to Opt-Out: You have the right to opt out of:
- The sale of your personal data (we do not sell personal data)
- Targeted advertising (we do not engage in targeted advertising)
- Profiling in furtherance of decisions that produce legal or similarly significant effects (our AI matching does not produce such effects)
To exercise your TDPSA rights, contact us at privacy@harmonaid.ai. We will respond to your request within 45 days. You will not be discriminated against for exercising these rights.
Right to Appeal: If we deny your request, you have the right to appeal our decision by contacting us at privacy@harmonaid.ai within a reasonable time after receiving our denial. We will respond to your appeal within 60 days.
VI. EDUCATIONAL RECORDS AND FERPA
HarmonAId provides a peer-to-peer tutoring marketplace and does not act as an educational institution or "school official" as defined under the Family Educational Rights and Privacy Act (FERPA). We do not access, collect, or maintain student education records from educational institutions.
Any information provided to HarmonAId is provided directly by users themselves (students and tutors) and is not obtained from educational institutions' official records. Students retain full control over what information they share on the platform.
If you have questions about how your educational institution handles your education records, please contact your institution's registrar or privacy office directly.
VII. PAYMENT PROCESSING
We use Stripe, Inc. as our third-party payment processor to process payments made through our Service. We do not directly collect or store credit card information. Payment information is collected and processed by Stripe in accordance with their privacy policy and security standards, including PCI-DSS Level 1 compliance.
We may receive limited payment-related information from Stripe, such as transaction confirmation, payment status, and the last four digits of credit card numbers for display purposes, but we do not have access to full credit card numbers or other sensitive payment credentials. For more information about how Stripe handles your payment information, please visit: https://stripe.com/privacy.
VIII. DETAILED COOKIE POLICY
Types of Cookies We Use:
- Essential Cookies: Required for the operation of our Service, including authentication and security features. These cookies cannot be disabled without affecting Service functionality.
- Functional Cookies: Remember your preferences and settings to provide enhanced functionality, such as keeping you logged in and remembering your tutoring subject preferences.
- Analytics Cookies: Help us understand how users interact with our Service by collecting anonymous usage data to improve platform performance.
- Advertising Cookies: We do not currently use advertising cookies or third-party advertising networks.
Managing Cookies:
You can control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of our Service. Most browsers allow you to refuse cookies or delete cookies already stored on your device. Consult your browser's help documentation for specific instructions.
Global Privacy Control (GPC):
We recognize Global Privacy Control (GPC) signals from your browser. If you enable GPC, we will treat it as a valid request to opt out of the sale of personal data and targeted advertising (though we do not currently engage in these activities).
IX. LINKS TO OTHER WEBSITES
As part of the Service, we may provide links to or compatibility with other websites or applications. However, we are not responsible for the privacy practices employed by those websites or the information or content they contain. This Privacy Policy applies solely to information collected by us through the Site and the Service. Therefore, this Privacy Policy does not apply to your use of a third party website accessed by selecting a link on our Site or via our Service. To the extent that you access or use the Service through or on another website or application, then the privacy policy of that other website or application will apply to your access or use of that site or application. We encourage our users to read the privacy statements of other websites before proceeding to use them.
X. DATA RETENTION
We retain your personal information for as long as your account is active or as needed to provide you with our Service. If you wish to delete your account or request that we no longer use your information, please contact us at privacy@harmonaid.ai. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Anonymized and aggregated data may be retained indefinitely for analytics and platform improvement purposes. For specific retention periods by data category, see Section 4.10 above.
Data Protection Assessments:
We conduct regular data protection assessments to evaluate risks associated with our data processing activities, particularly our AI-powered matching features, to ensure appropriate safeguards are in place.
XI. CHANGES TO OUR PRIVACY POLICY
The Company reserves the right to change this policy and our Terms of Service at any time. We will notify you of significant changes to our Privacy Policy by sending a notice to the primary email address specified in your account or by placing a prominent notice on our site. Significant changes will go into effect 30 days following such notification. Non-material changes or clarifications will take effect immediately. You should periodically check the Site and this privacy page for updates.
XII. CONTACT US
If you have any questions regarding this Privacy Policy or the practices of this Site, please contact us:
By email: privacy@harmonaid.ai
By mail: HarmonAId Inc., 131 Continental Dr Suite 305, Newark, DE 19713
XIII. GOVERNING LAW
This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Delaware and the United States, without regard to its conflict of law provisions. You agree that any dispute arising from or relating to the subject matter of this Privacy Policy shall be governed by the exclusive jurisdiction and venue of the state and federal courts in Delaware.
Last Updated: This Privacy Policy was last updated on February 8, 2026.