Trust and Data Protection
Last updated: August 19, 2026
This page answers the questions tutors and schools ask before they trust a platform with their students' data: who we are, where the infrastructure runs, what happens to recordings, which providers process your lessons, and how you get everything back out again. It is written to be specific rather than reassuring. Where something is not in place yet, it says so.
1. Who is behind Teamlilit
Teamlilit is built and operated by Amar FILALI, trading as Teamlilit, as a sole trader. There is no holding company, no parent group and no outside investors. You are dealing directly with the person who writes the software.
For any legal, privacy or contractual matter, write to support@teamlilit.com and it reaches the operator directly, not a ticket queue.
Sales are handled by Paddle.com Market Ltd as Merchant of Record. Paddle is the seller on your invoice and the counterparty for payment and tax purposes, which is why its name rather than ours appears on your card statement.
On data protection roles: for your own account and billing data, Teamlilit is the data controller. For the student data you put into the platform, you are the controller and Teamlilit is your processor, acting on your instructions. The Data Processing Agreement section below covers how to put that in writing.
2. Where the infrastructure runs
Teamlilit runs on DigitalOcean. The application servers, the database, the cache, object storage and the live video infrastructure are all hosted there, in DigitalOcean's European regions: Frankfurt (FRA1) and Amsterdam (AMS3).
The real-time audio and video layer is self-hosted on our own servers rather than bought as a managed service. Your lesson media travels through servers we control and operate, so there is no third-party video vendor holding it, replaying it or retaining it.
One caveat we would rather state than bury: DigitalOcean is a United States company. Pinning storage and compute to an EU region means your data physically resides in Europe, which is what GDPR data-location residency asks for, and it is the reason we chose those regions. It does not, on its own, place the data beyond the reach of the US CLOUD Act, under which a US-incorporated provider can in principle be compelled to produce data it holds anywhere in the world. If your institution requires a fully EU-sovereign provider with no US parent company, Teamlilit does not meet that bar today, and we would rather tell you now than after you have migrated.
3. Which providers can touch your data
We name our infrastructure provider below, because where your data physically sits is the part that matters most. For the remaining processors we describe the role rather than the vendor. The complete named list is available on request at support@teamlilit.com and forms part of the Data Processing Agreement, and we give notice before it changes.
DigitalOcean: hosting, the database, object storage and the GPUs our AI generation runs on, all in EU regions.
Real-time audio and video: none. We self-host this layer, so no third-party video vendor appears on this list at all.
Speech-to-text transcription: one specialist provider turns lesson audio into text, and only when you choose to run an AI wrap-up. The section on AI below sets out exactly what is sent, what comes back and what is deleted.
Payments: handled by Paddle as Merchant of Record, covering billing, sales tax and invoicing. Card and bank details go to Paddle and are never stored by us.
Transactional email: one delivery provider sends lesson links, invitations, invoices and password resets.
Product analytics: one provider, loaded only after you accept analytics cookies. There are no advertising trackers anywhere on the platform and we do not share data with ad networks.
Google and Microsoft: only if you choose to sign in with them or connect a calendar. You can disconnect either at any time from your settings, and revoke access from your Google or Microsoft account as well.
4. What happens during a live session
Audio and video are transported live through our EU self-hosted media servers and are not written to disk unless a teacher starts a recording. Session metadata such as start and end time, who joined and how long they stayed is stored, because attendance, billing and reporting are built on it.
Only a teacher can start a recording. While one is running, every participant sees a recording indicator for as long as it lasts. There is no silent recording and no hidden mode: a student is never recorded without that indicator being visible on their screen.
5. What happens to recordings
A recording belongs to the teacher who made it. It is stored in our EU object storage on a private bucket, is never public-readable, and is reachable only from that teacher's account. Other tutors cannot open it, including other staff members inside the same Academy team.
You can download or delete any recording yourself at any time. Deleting removes the underlying file from storage, not merely the entry from a list.
6. How long recordings are kept
Retention follows your plan. Solo does not include session recording at all. Pro keeps recordings for 30 days. Academy keeps them for 90 days. An unlimited recording retention add-on is available on the plans that include recording, and it removes the time limit entirely.
Expiry is enforced automatically by a scheduled cleanup job rather than by hand. When a recording passes the end of its retention window, the file is deleted from storage. If you add the unlimited retention extension before a recording expires, it is re-checked against your new entitlement and kept rather than deleted.
Treat retention as a ceiling and not as a promise to hold something for you that long. If a recording matters, download it well before the window closes.
7. How AI processes your lessons
Two steps, and only when you run an AI wrap-up. Nothing is processed unless you ask for it.
Transcription: the lesson audio is turned into text by our transcription provider. As soon as that succeeds the audio file is deleted from our storage, with a storage lifecycle rule behind it as a backstop so nothing survives a failed cleanup. We keep the transcript, not the audio, and the transcript lives in your account where you can read and delete it.
Generation: the transcript, now plain text, is processed by open-weight models running on GPUs inside our own EU cloud infrastructure, one drafting the wrap-up and a second critiquing that draft before you see it. No third-party AI vendor receives your transcript at this stage.
We run open-weight models on our own infrastructure rather than calling a commercial model API on purpose. Commercial APIs route your data to the vendor's own servers, frequently outside the EU, which would quietly weaken the residency position described above.
8. Are lessons or student recordings used to train AI
No. Your lessons, transcripts, recordings, notes and student records are never used to train AI models, neither ours nor a provider's. We do not sell, licence or share them for that purpose, and there is no setting or future plan under which that quietly becomes true.
The only material that leaves our infrastructure is the lesson audio sent for transcription, and it goes under API terms that do not permit training on submitted data. It is deleted from our storage immediately after it has been transcribed. The generation step never leaves our own infrastructure at all, because it runs on open-weight models on our own GPUs.
The AI also never acts on its own. Every wrap-up is a draft: nothing reaches a student until you have read it, edited what you want to change and sent it yourself, and each wrap-up records that you approved it.
9. What happens if Teamlilit shuts down
A fair question to ask of a product run by a small team, and the honest answer is a commitment rather than a guarantee of survival.
If Teamlilit ever winds down, we commit to giving at least 90 days' notice by email to every active account before the service stops; to keeping the full data export working for that entire period; to billing nothing beyond the shutdown date and refunding prepaid time; and to never transferring your data or your students' data to a third party as a business asset without telling you first and giving you time to export and delete.
In the meantime the export described below already works, and it works without our involvement. Do not wait for a shutdown notice to find out whether your data comes out cleanly. Run it once this week.
10. Getting your data out
Everything in your account is exportable, by you, without asking us and without a fee.
Full account export: one request from your account settings returns a single JSON document containing your profile, preferences, students, lessons, invoices, session notes and AI wrap-ups. It stays available even after you have requested deletion and are inside the grace period, because that is precisely the moment you need it most.
Students as CSV: your student list exports to CSV, filtered however you have it filtered on screen, and it contains every matching record rather than only the page you are looking at.
Everything else in its original form: invoices as PDFs, recordings as ordinary video files, and uploaded teaching materials exactly as you uploaded them.
One limitation, stated rather than hidden: each collection inside the JSON export is capped at 5,000 records, so that a very large account cannot ask the system for an unbounded document that times out. If any collection reaches that cap, the export names it in an explicit truncated list, so you never receive a silently shortened file and assume it is complete. If you are near that size, write to support and we will produce a complete export for you.
11. How hard is it to migrate away
Deliberately easy, because a product that retains customers by making departure painful is not one worth paying for.
Students arrive and leave as CSV, so the same file that imports into Teamlilit imports into most other tools. Curriculum programs import as JSON or CSV. Invoices are standard PDFs. Recordings are ordinary video files. There is no proprietary container to unpick, no export fee and no retention call to sit through first.
What no format carries across is the structure that connects those pieces: which lesson produced which note, which invoice covers which sessions, which student sat in which group. The JSON export preserves those relationships in full, so they can be reconstructed, but no competitor imports that format directly today. That is a property of the market rather than a lock we built, and it is true of every platform in this category.
12. Uptime
Academy plans carry a 99.9% uptime SLA.
The platform runs on dedicated DigitalOcean servers with a managed database, and releases are deployed as rolling updates, so shipping a new version does not require a maintenance window or take the service down.
We do not yet publish a public status page with historical uptime figures, so we will not quote you a past number here that you cannot verify. Until that page exists, incident notices go out by email to the accounts affected, and you can ask support for the incident history covering any period you care about, including before you sign up.
13. Data Processing Agreement
Teamlilit offers a GDPR Article 28 Data Processing Agreement. Request one at support@teamlilit.com and we will send it to you for signature.
It records the roles set out at the top of this page: for your students' personal data you are the controller and Teamlilit is the processor acting on your instructions, while for your own account and billing data Teamlilit is the controller. It incorporates the sub-processor list published above and commits us to giving notice before that list changes.
If you are a school or an institution with a procurement process, ask at the same address and we will complete your security questionnaire. We are not certified to ISO 27001 or SOC 2 today, and if your procurement rules require either of those, we do not meet that requirement yet.
14. Who owns the teaching material you upload
You do, without qualification. Lesson materials, exercises, whiteboard exports, session notes, uploaded files and recordings remain yours. Teamlilit claims no ownership of any of it.
The only rights you grant us are the ones needed to run the service on your behalf: storing your files, transmitting them to the students you share them with, generating previews and thumbnails, and keeping backups. That licence exists so the platform can function, not so that we can reuse your work. We do not put your teaching content in marketing, do not show it to other tutors and do not train models on it.
The AI wrap-ups, summaries and exercises generated from your lessons are yours as well. When you delete your account, that licence ends with it.
15. Security practices
Passwords are hashed and never stored in a readable form. All traffic runs over HTTPS and TLS. Access is role-based, so a student account cannot reach teacher data or another student's records. Active sessions can be reviewed and revoked from your settings, and login attempts are recorded with IP address and device so that anything unfamiliar is visible to you.
No system is perfectly secure, and any provider claiming otherwise is selling something. If you believe you have found a vulnerability, report it to support@teamlilit.com and we will respond. We will not pursue anyone who reports a genuine issue in good faith.
If a question about trust, security or data protection is not answered here, ask it. Write to support@teamlilit.com and you will get a direct answer, including when the answer is that we do not do that yet.
Email us at support@teamlilit.com