Academies Hub Privacy Policy
Last updated: October 5, 2026
Academies Hub ("we", "us", or "our") provides a platform that helps Quran and online education academies manage students, teachers, courses, lectures, payments, and their public web presence. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
It applies to the marketing website at https://acadmieshub.cloud and the Academies Hub application at https://app.acadmieshub.cloud.
Information We Collect
We collect the following categories of information:
- Account information: your name, email address, phone number, and password (stored hashed) when you create an account or are invited to join an academy.
- Sign in with Google: if you choose to sign in with Google, we receive your name, email address and profile picture from Google (see “Google User Data” below).
- Academy data: information academies enter to run their operations, such as student and guardian names and contact details, teacher profiles, courses, lecture schedules, attendance, and progress notes.
- Payment information: when an academy purchases credits, we collect the details needed to verify the payment, such as the transfer reference and the payment receipt the academy uploads. We do not collect or store card numbers.
- Usage data: log and device information such as IP address, browser type, and pages visited, used to keep the service secure and to improve it.
How We Use Information
We use the information we collect to:
- Provide and operate the Academies Hub platform.
- Schedule lectures and send related notifications and reminders.
- Review and confirm credit purchases.
- Respond to support requests.
- Monitor, secure, and improve the service.
- Comply with legal obligations.
Google User Data
Academies Hub uses Google user data in two optional features: Sign in with Google, and the Google Calendar integration that teachers can connect to receive their lessons with a Google Meet link. This section explains exactly what we receive, why, what we store, who it is shared with, and how it is deleted.
Sign in with Google: when you sign in with Google, Google shares your name, email address and profile picture with us (the “email” and “profile” permissions). We use them only to find or create your Academies Hub account, sign you in, and show your name and picture in the app. We keep your name, email address and the link to your profile picture as part of your account. We do not store Google passwords or Google tokens for sign-in.
Google Calendar integration (optional): a teacher can connect their Google account from Settings → Google Calendar. We then ask for the permission “See, create, change, and delete events on Google calendars you own” (calendar.events.owned), together with your email address so we can show which Google account is connected. We use this permission only on your own primary calendar, and only for events that Academies Hub creates: when a lesson is booked for you, we create a calendar event for it with a Google Meet link; when the lesson is rescheduled, we change that event's time; when it is cancelled, we cancel or delete that event. To avoid creating a duplicate after a network error, we look up our own event by a private marker that only our events carry. We do not read, list, analyse or store any of your other calendar events, calendars or settings.
What we store for the Calendar integration: the email address of the connected Google account, the permissions you granted, the OAuth tokens needed to act on your behalf (encrypted at rest with AES-256-GCM), and, on each lesson, the ID of the calendar event we created and its Google Meet link.
Sharing: the lesson's students are added to the calendar event using the email addresses registered for them in Academies Hub, so Google emails them the invitation, updates and cancellation from your calendar, and they can see the event and its Meet link. Inside Academies Hub, the Meet link is shown on the lesson to its participants and to the academy's staff. We do not sell Google user data, do not share it with other third parties, do not use it for advertising, and do not use it to develop, improve or train generalized artificial-intelligence or machine-learning models. We do not allow humans to read it except with your explicit permission, for security purposes, to comply with applicable law, or where access is necessary to operate and debug the integration.
Disconnecting: you can disconnect Google Calendar at any time from Settings in Academies Hub. When you disconnect, we ask Google to revoke our access and delete the stored connection: the tokens, the connected Google email address and the granted permissions. Calendar events that were already created stay on your Google Calendar and on your invitees' calendars, and you can delete them in Google Calendar; the event IDs and Meet links stay on the lessons in Academies Hub as part of the academy's lesson history.
Removing access from your Google Account: you can also remove Academies Hub at https://myaccount.google.com/permissions. Google stops our access straight away. We learn about it the next time Academies Hub needs to renew its access to your calendar, which happens only when a calendar update for one of your lessons is processed; at that point we delete the stored tokens and ask you to reconnect. To delete the connection itself immediately, use Disconnect in Settings.
Academies Hub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
How We Share Information
We do not sell personal information, and we do not use it for third-party advertising. We share information only:
- Within your academy: administrators and staff of an academy can see the data that belongs to that academy, according to their roles.
- With service providers that help us operate the platform (such as hosting, email delivery, and error monitoring), who are bound by confidentiality and may use the data only to provide their services to us.
- When required by law, or to protect the rights, safety, and security of Academies Hub, our users, or others.
Data Retention and Deletion
We retain information for as long as the related account or academy remains active, and as needed to comply with legal obligations. Each academy controls the records of its own students and staff and can edit or remove them from within the platform.
You may request deletion of your personal data by contacting us at acadmieshub@gmail.com. Google Calendar tokens are deleted when you disconnect Google Calendar, or when we next need to renew access after you remove our access from your Google Account (see “Google User Data”).
Security
All traffic to and from the platform is encrypted in transit using HTTPS/TLS. Sensitive credentials, including Google OAuth tokens, are encrypted at rest. Access to academy data is isolated per academy and restricted by role-based permissions.
Children's Privacy
Students enrolled by an academy may be minors. Academies, as the parties who enter and manage student records, are responsible for obtaining any required consent from parents or guardians. Parents and guardians may contact their academy, or contact us directly, to review or request deletion of a student's information.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page, and for material changes we will provide additional notice within the platform.
Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at acadmieshub@gmail.com.
