Privacy Policy

Last Updated: 19 July 2026

The Short Version (for students)

The rest of this page says the same things in full detail.

Welcome to WeloScholars, a product operated by Welo Logic PTE. LTD., a company incorporated in Singapore ("we", "our", or "us"). We are committed to protecting your privacy and ensuring you have a positive experience while using our mobile application and backend services (collectively, the "App"). This Privacy Policy complies with the Singapore Personal Data Protection Act 2012 (PDPA) and applicable international privacy standards.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App. Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the App.

1. Information We Collect

We may collect information about you in a variety of ways. The information we may collect via the App includes:

A. Personal Data

B. User-Generated Content

To provide our core educational services, we collect data you deliberately upload:

C. Automatically Collected Data

When you access the App, our servers automatically collect:

D. Subscription & Billing Data

If you purchase a paid plan, we store limited billing metadata: your subscription tier, billing status, and start/renewal dates, together with a transaction identifier returned by the payment platform. We never receive or store your full payment-card details, regardless of where you subscribe:

2. How We Use Your Information

Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you to:

3. How We Share Your Information

We do not sell your personal information. We only share information with third parties in the following situations:

Each of the service providers above processes your data on our behalf under a data-processing agreement. We do not share your personal data with advertisers or data brokers, and we do not sell it.

4. Data Security

We use administrative, technical, and physical security measures to help protect your personal information, including: encryption in transit (TLS/HTTPS) for all data sent between the App and our servers; access to stored data restricted through role-based access controls; token-based (JWT) authentication for your account; audit logging of sensitive operations; and automatic purging of older data on the schedules described below. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse.

5. Data Breach Notification

We maintain a data-breach response plan aligned with Part 6A of the PDPA (sections 26A–26D). If we suspect a breach of security affecting personal data, we will assess it promptly. Where the breach is assessed to be notifiable — because it is likely to result in significant harm to affected individuals, or is of significant scale (500 or more individuals) — we will notify the Personal Data Protection Commission (PDPC) as soon as practicable, and in any event within 3 calendar days of that assessment.

If a breach is likely to result in significant harm to you, we will also notify you directly as soon as practicable, explaining what happened, the data involved, and the steps we are taking and that you can take. Because many of our users are children, if a breach affects a child's personal data we will proactively notify the child's parent or guardian where we hold their contact details, and any notice addressed to a child will use language a child can understand.

6. Data Retention and Deletion

We retain your personal data only as long as necessary for the purposes stated in this policy. If your account is inactive for 12 consecutive months, we automatically and permanently delete the account and all associated data. Specific retention periods:

Because many of our users are children, we practise data minimisation: we collect only what is needed to provide the learning service, and we automatically delete conversational and usage data on the schedules above rather than retaining it indefinitely.

Your Rights: You have the right to access, correct, or delete your personal data at any time. You can export all your data or delete your account directly within the App's account settings page, via Delete Account, or by contacting our Data Protection Officer.

7. Policy for Children

WeloScholars is an educational service used by students, and in line with the PDPC's Advisory Guidelines on Children's Personal Data (2024) we treat every user under 18 as a child and hold their personal data to a higher standard of protection. We collect only the data needed to provide the learning service, we never use a child's data for advertising or to target harmful content, and a child's account and content are never public or searchable.

Students aged 13 to 17 may consent to this policy themselves. To make that consent meaningful, we provide the plain-language summary at the top of this page; if anything is unclear, we encourage you to read this policy with a parent or guardian, and if we have reason to believe a young user does not understand what they are agreeing to, we will ask for a parent or guardian's consent instead. Withdrawing consent is as easy as giving it.

Students under 13 may use the App only through an account created, held, and supervised by a parent or legal guardian, who gives consent on the child's behalf; this policy serves as the notice to that parent or guardian of the purposes for which the child's data is collected, used, and disclosed. We rely on the account holder's confirmation of age and consent at sign-in; we do not independently verify it. Parents or guardians may contact us at any time to review, correct, or delete their child's data, and if we learn that a child under 13 has provided personal data without the required consent, we will delete it promptly.

8. Cross-Border Data Transfers

Your data is stored and processed in the United States by our cloud infrastructure providers (Google Cloud Platform, MongoDB Atlas). Payment data for website purchases is processed by Stripe, Inc., a US company that maintains global payment infrastructure and is certified to the highest payment-industry security standard (PCI DSS Level 1). In accordance with the Transfer Limitation Obligation in section 26 of the PDPA and the Personal Data Protection Regulations 2021, we transfer personal data outside Singapore only where the recipient is bound by legally enforceable obligations — such as our data-processing agreements with each provider — to protect it to a standard comparable to the PDPA.

9. AI-Generated Content

Questions, explanations, and recommendations in this App are generated by artificial intelligence. While we align all content to the syllabus of your selected curriculum — such as the Singapore Ministry of Education (MOE) syllabus, the Indian CBSE curriculum, or Cambridge IGCSE — AI outputs may occasionally contain errors. We recommend verifying important content with your teacher. Users may report incorrect questions using the in-app Report button.

Which features use AI, and what data they use: question generation and the Solve assistant process the materials you upload; the Tutor Companion, practice recommendations, and mastery tracking use your answers, scores, and topic-mastery history to personalise what you see; study notes and vocabulary practice use your selected level and curriculum. We do not use your personal data or uploaded content to train foundation AI models. Where we analyse usage to improve question quality and App performance, we rely on the PDPA's business improvement provisions and use aggregated or pseudonymised data wherever practicable.

10. Singapore PDPA Rights

If you are in Singapore, you have the following rights under the Personal Data Protection Act 2012 (PDPA):

To exercise these rights, contact our Data Protection Officer at the email below. We will respond as soon as reasonably possible, and generally within 30 days; if we need longer, we will let you know in writing within 30 days of your request and tell you when to expect our response.

11. Cookies & Local Storage

We use a small number of browser storage mechanisms (such as localStorage and on-device storage on mobile) that are strictly necessary to keep you signed in, remember your selected education level and preferences, and secure the App. On the web we may also use cookies that are essential to operate the service. If you purchase a subscription on our website, Stripe's checkout and billing-portal pages set cookies that are strictly necessary for payment processing and fraud prevention, under Stripe's own cookie policy. We do not use third-party advertising cookies or cross-site tracking, and we do not use your data for behavioural advertising.

12. Marketing Communications

We may send occasional promotional messages by email or app notification only. We do not make marketing phone calls or send marketing SMS, so Singapore's Do Not Call Registry provisions are not engaged. Marketing is directed at parents and adult account holders — never at children — and every message includes a working opt-out. Service messages (such as receipts, security notices, and reports you request) are sent regardless of your marketing preferences.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Updated" date and, where appropriate, by in-app notification. You are encouraged to review this Privacy Policy periodically.

14. Contact Us & Data Protection Officer

For privacy questions, PDPA requests, or to report a concern, contact our Data Protection Officer:

Welo Logic PTE. LTD.
Data Protection Officer: privacy@weloscholars.com
General support: support@weloscholars.com