teamlilit logo

Privacy Policy

Last updated: August 19, 2026

Teamlilit is committed to protecting your privacy. This Privacy Policy explains what we collect, how we use it, who we share it with, and your rights. By using Teamlilit, you agree to this policy.

1. Who We Are

Teamlilit is built and operated by Amar FILALI, trading as Teamlilit, as a sole trader. There is no holding company, parent group or outside investor. For any privacy matter, including requests under this policy, write to support@teamlilit.com.

Roles under the GDPR: for your own account, profile and billing data, Teamlilit is the data controller. For the personal data of the students you add to the platform, you are the controller and Teamlilit acts as your processor on your instructions. A Data Processing Agreement covering that relationship is available on request, and our full trust and sub-processor disclosure is published at teamlilit.com/trust.

2. Information We Collect

Account information: name, email, date of birth, and password (securely hashed). Optional: avatar, bio, timezone, language preference.

Authentication/security: login events (IP, user agent, success/failure), approximate location derived from IP, and active sessions for security.

Educational data: for teachers: classes, schedules, attendance, scores, exercises, submissions, grading, curriculum programs, session notes. For students: enrollment, attendance, scores, submissions, study activity.

Session data: real-time audio/video is transmitted via our video infrastructure and not stored unless recording is enabled by the teacher. We store session metadata (start/end times, join/leave times, duration).

Files/content: uploaded files and metadata (name, type, size, upload date).

Communication data: notification preferences, push subscription details, and the content of notifications we send.

Billing data: payments are handled by Paddle (Merchant of Record). We do not store card/bank details. We store Paddle customer IDs/subscription IDs/transaction IDs needed to manage subscription status.

Device/usage data: IP, user agent, timestamps to secure the service and prevent fraud. We do not use third-party analytics or advertising trackers.

3. How We Use Your Information

We use data to operate the Platform, manage accounts/subscriptions, facilitate live sessions and learning workflows, send transactional emails and notifications, enforce plan limits, secure accounts, respond to support, and improve reliability.

4. Platform Roles (Tutors Are Independent)

Teamlilit provides software tools. Independent tutors/teachers may use Teamlilit to manage their own classes and students. Tutors/teachers are responsible for how they use the Platform and for obtaining any required permissions/consents (especially when teaching minors).

5. Data Sharing and Third Parties

We do not sell, rent or trade your personal data, and we use no advertising or cross-site tracking. Data is shared only with the processors below, each for a single stated purpose. We name our infrastructure provider because data location is material; for the others we state the role, and the complete named list is available on request at support@teamlilit.com and forms part of our Data Processing Agreement. We give notice before that list changes.

DigitalOcean: hosting, the database, object storage and the GPUs our AI generation runs on, in DigitalOcean's European regions, Frankfurt (FRA1) and Amsterdam (AMS3).

Real-time audio and video: self-hosted by us on our own servers in the EU. Live media is not held by any third-party video vendor and is not stored at all unless recording is enabled.

Speech-to-text transcription: one specialist provider converts lesson audio to text, only when a teacher runs an AI wrap-up. See AI Processing below.

Payments: Paddle, as Merchant of Record, for billing, tax and invoicing. Card and bank details go to Paddle and are never stored by us.

Transactional email: one delivery provider, for lesson links, invitations, invoices and password resets.

Product analytics: one provider, loaded only after you accept analytics cookies.

Google and Microsoft: only where you choose to sign in with them or connect a calendar, and only for the features you enable.

6. Google Account Connection (OAuth), Google Sign-In & Google Calendar

Teamlilit offers optional Google integrations. If you choose to connect your Google account, we use Google OAuth to access limited Google user data only to provide the features you explicitly enable.

Google Sign-In (email and basic profile): When you sign in with Google, we may access your email address (userinfo.email) and basic profile information (such as display name and profile picture), if granted. We use this to create and authenticate your Teamlilit account, identify your account and prevent duplicates, and send essential service communications (security notices, account-related emails). We store your email address as an account identifier, your display name and profile image (if provided) for your profile, and authentication metadata needed to maintain the session (e.g., login timestamps). We do not use Google account data for advertising, and we do not sell it.

Google Calendar access (scheduling & sync): If you enable calendar features, Teamlilit may request access to your Google Calendar to support scheduling workflows (for example: syncing lessons, avoiding conflicts, and keeping sessions consistent across your app and calendar). Depending on the feature you enable, Teamlilit may: read calendar events to detect scheduling conflicts and show availability; create calendar events that represent lessons scheduled in Teamlilit; update those events when a lesson is rescheduled or details change; delete or cancel those events when a lesson is canceled (where applicable). We only access calendar data necessary for these scheduling features.

What we store for calendar sync: To keep calendar sync working, we store the minimum necessary information, such as OAuth access/refresh tokens (stored securely and encrypted where applicable), the selected calendar identifier (if needed), and synced event identifiers and basic metadata related to lessons (event ID, start/end time, sync status). We do not store your full calendar history.

Sharing of Google user data: We do not sell Google user data and we do not share it with third parties for advertising. We may share limited data with service providers strictly required to operate the service (e.g., hosting, security, logging) under confidentiality obligations.

Your control, revocation, and deletion: You can disconnect Google integrations at any time from your Teamlilit account settings. You can also revoke Teamlilit's access from your Google Account settings (Security → Third-party access). When you disconnect Google: we stop accessing your Google data going forward; we invalidate and/or delete stored OAuth tokens and calendar identifiers within 30 days; events previously created in your Google Calendar may remain in your calendar unless you delete them. If you delete your Teamlilit account, we delete associated Google connection data as part of account deletion, subject to legal and compliance obligations.

Teamlilit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Session Recording

Teachers may enable session recording. When active, participants are notified by a visible recording indicator that stays on screen for as long as the recording runs. There is no silent recording. Recordings are stored on private, non-public storage in the EU and are accessible only to the teacher who created them, including as against other staff members in the same Academy team. The teacher is responsible for obtaining any consent required before recording.

Recordings are retained according to plan: 30 days on Pro and 90 days on Academy, unless an unlimited retention extension is active. Solo does not include recording. Expiry is enforced by an automated cleanup job that deletes the underlying file from storage. Teachers can download or delete a recording themselves at any time.

8. AI Processing

The AI wrap-up is optional and runs only when a teacher starts it. Nothing is processed by AI otherwise.

When it runs, lesson audio is sent to our transcription provider and returned as text. The audio file is deleted from our storage as soon as transcription succeeds, with a storage lifecycle rule as a backstop. We retain the transcript, not the audio. The transcript is then processed by open-weight models running on GPUs within our own EU infrastructure to draft a summary, session notes and suggested exercises; no third-party AI vendor receives the transcript.

We do not use lessons, transcripts, recordings, notes or student records to train AI models, and we do not sell, licence or share them for that purpose. Audio is sent for transcription under API terms that do not permit training on submitted data.

Transcripts are stored in the teacher's account and can be deleted there. Because a transcript may contain student names spoken aloud, teachers should treat it as student personal data and apply their own retention practice to it.

AI output is always a draft. Nothing generated by AI reaches a student until the teacher has reviewed, edited and sent it, and each wrap-up records that approval.

9. Children's Privacy

Teamlilit is intended for users aged 13+. Users under 18 require parent/guardian consent. If a teacher enrolls minors, the teacher represents they have obtained required parental/institutional consent. If we learn we collected data from a child under 13 without appropriate consent, we will delete it promptly.

10. Data Retention

We retain data while your account is active. If you cancel, we retain data for 90 days for reactivation; after that, it may be deleted. If you request deletion, we delete within 30 days, subject to legal obligations such as retaining billing records for tax purposes.

Session recordings follow their own, shorter schedule: 30 days on Pro and 90 days on Academy, unless an unlimited retention extension is active. Lesson audio captured for an AI wrap-up is deleted as soon as it has been transcribed and is never retained as a stored recording.

11. Your Rights

Depending on jurisdiction: access, correction, deletion, portability, and withdrawing consent where applicable. Contact support@teamlilit.com and we respond within 30 days.

12. Security

We use industry-standard measures (password hashing, HTTPS/TLS, session management, role-based access, secure reset/verification tokens). No system is 100% secure.

13. Cookies and Local Storage

We use essential cookies and local storage for authentication, security, and your preferences (such as theme and language). When enabled, we also use a privacy-focused product analytics tool (PostHog) to understand and improve how the product is used, and our payment provider (Paddle) may set cookies during checkout. Analytics cookies are only set after you accept them, and you can change your choice at any time. We do not use advertising cookies and we do not sell your data. For full details and how to control cookies, see our Cookies Policy.

14. International Transfers

Our infrastructure is located in the European Union, in DigitalOcean's Frankfurt and Amsterdam regions. Some sub-processors are incorporated outside the EU and may process data in other jurisdictions under appropriate safeguards, including Standard Contractual Clauses. Paddle may process data in multiple jurisdictions in order to handle global payments.

We would rather state one limitation than leave it implied: DigitalOcean is a United States company. Placing storage and compute in an EU region means your data physically resides in Europe, which is what data-location residency requires, but it does not by itself put that data beyond the reach of the US CLOUD Act, under which a US-incorporated provider may in principle be compelled to produce data it holds anywhere. If your organisation requires a provider with no US parent company, Teamlilit does not meet that requirement today.

15. Changes

We may update this policy and will notify you of material changes at least 30 days before they take effect.

16. Data Processing Agreement

If you process student personal data through Teamlilit, you may need a written processing agreement. We provide a GDPR Article 28 Data Processing Agreement on request: email support@teamlilit.com and we will send it for signature. It reflects the roles described in Who We Are, incorporates the sub-processor list in this policy, and commits us to giving notice before that list changes. Schools and institutions can request completion of a security questionnaire at the same address.

17. Contact

Privacy questions: support@teamlilit.com

If you have any questions about this Privacy Policy, please contact us.

Email us at support@teamlilit.com

Seamless learning

Start free trial

14-day free trial · No credit card required · Cancel anytime

Teamlilit