SiguanAI

Privacy Policy

Effective 2026-05-27

This Policy explains how Siguan AI (operated by Siguan Media Information Technology Pte. Ltd., “Siguan AI”, “we”) collects, uses and protects personal data you and your child generate while using our website (siguanai.com), our AEIS AI products (aeis.ai, en.aeis.ai, psle.siguanai.com, olevel.siguanai.com, alevel.siguanai.com), the AEIS Helper mobile application (Android; iOS to follow), and related services (together, the “Services”).

We process data in line with Singapore’s Personal Data Protection Act (PDPA); for users in the EU/EEA and the UK we treat the equivalent obligations under GDPR / UK GDPR as the floor (lawful basis, data subject rights, breach notification). Mainland-China users on aeis.ai are additionally covered by the Personal Information Protection Law (PIPL).

1. What we collect

1.1 Data you provide

  • Account data: email, name (optional), password (stored as a bcrypt hash — we cannot view the plaintext).
  • Phone number (optional, used for SMS verification and account-recovery flows).
  • WeChat account info (only if you sign in with WeChat): WeChat openid, unionid, nickname, avatar URL. We do not collect your WeChat friends list, chat history, or the phone number bound to your WeChat account.
  • Family and child profile: family name, child nickname, birth year, current grade, target grade, daily learning goal.
  • Payment data: handled by Antom (Ant International Pte. Ltd., the cross-border payment gateway operated by the Ant Group). We retain only transaction metadata (order ID, amount, currency, status). Full card numbers, CVV, and third-party wallet credentials never touch our servers.
  • Children’s learning data: composition text, answers, mistake history, mock-exam scores, AI tutoring conversations. Should an oral / speaking feature be added in the future, we will request the microphone permission separately and disclose this collection before recording starts. Learning data is used strictly for personalized tutoring and is not used to train public AI models.
  • Communication content: anything you send through email or in-app feedback.

1.2 Automatically collected

  • Device and browser metadata (model, OS, screen size, app version);
  • Access logs: IP address and User-Agent are SHA-256 hashed before being written to audit logs — no reversible plaintext is retained;
  • Usage analytics — the siguanai.com website uses Plausible Analytics (no cookies, no personal identifiers, no cross-site tracking); the AEIS Helper mobile app uses internal event telemetry (page views + key interactions), no third-party advertising SDKs, no Google Advertising ID collection;
  • Attribution: UTM parameters (utm_source / utm_medium / utm_campaign / utm_content) and HTTP referer, so we can understand where users discover us.

2. Children’s data

Our Services target minors aged 7–18. Registration and management are done by a parent or guardian. We apply additional safeguards:

  • All learning data is owned by the parent account; the child has no independent account;
  • The parent may at any time request export or deletion of the child’s full data record by emailing [email protected];
  • Children’s data is not used for marketing or shared with third parties for commercial purposes;
  • When data informs model improvement, only de-identified, aggregated signals are used — never the raw record of an identifiable child.

3. How we use the data

  • To provide the Service: marking, explanations, weekly parent reports, customer support;
  • To improve the product: aggregated, de-identified analysis of common mistakes to refine the question bank and AI prompts;
  • Account notices: subscription status, product updates, security alerts (you cannot opt out — these are transactional);
  • Marketing: only after your explicit opt-in, and every marketing email has a one-click unsubscribe.

4. Legal basis (EU/EEA & UK)

For users protected by GDPR / UK GDPR, we rely on these legal bases depending on the activity:

  • Contract — providing the Service you subscribed to (account management, marking, parent reports);
  • Consent — marketing emails (one-click unsubscribe in every message);
  • Legitimate interest — fraud prevention, aggregated analytics, security;
  • Legal obligation — tax records, lawful authority requests.

5. How data is shared

We do not sell user data. Limited sharing happens in these scenarios only:

  • Infrastructure providers — AWS (database, object storage), Cloudflare (CDN, DNS), Resend (transactional email) — strictly to provide the Service, under signed data-processing agreements;
  • AI inference — Anthropic Claude models accessed via AWS Bedrock. Only the question / answer text needed for a given marking or explanation call is sent; account identifiers such as email or name are never included. AWS Bedrock processes inference logs under its service terms and does not use customer inputs to train its foundation models;
  • Payment processor Antom (Ant International Pte. Ltd.) for overseas card / PayNow / Alipay payments. See Antom’s privacy notice at antom.com/privacy-policy;
  • WeChat Open Platform — when you sign in with WeChat, we request openid/unionid and basic profile (nickname, avatar) only; the exchange is governed by Tencent’s privacy policy;
  • Legal requirement — response to court orders, regulator requests, or to prevent unlawful activity.

6. Storage, retention & cross-border

  • Primary storage is in the AWS Singapore region (ap-southeast-1). AI inference may run on Bedrock endpoints in the AWS US region (us-east-1); transfers are governed by Standard Contractual Clauses or equivalent safeguards;
  • Active accounts: data is kept while the account is in use;
  • Closed accounts: data is deleted within 30 days, except where longer retention is required by law (e.g. tax records — kept up to 7 years under local requirements);
  • Unpaid trial accounts: archived after 90 days of inactivity, then retained for a further 365 days for recovery before permanent deletion.

7. Your rights

Wherever you are, you may exercise the following rights. Users in the EU/EEA, UK, California or Singapore have these rights as a matter of law:

  • Access — request the data we hold about you;
  • Rectification — correct inaccurate data;
  • Export / portability — download your child’s learning record as JSON / CSV;
  • Erasure — close the account and delete all related data;
  • Restriction — pause specific processing activities;
  • Withdraw consent — unsubscribe from marketing or disable optional features at any time;
  • Object — object to processing based on legitimate interest;
  • Lodge a complaint — with your local supervisory authority (e.g. PDPC in Singapore, the ICO in the UK, your national DPA in the EU).

Send any request to [email protected] — we respond within 30 days.

8. Security

  • TLS 1.3 encryption in transit, end to end;
  • Passwords hashed with bcrypt;
  • Database encryption at rest, MFA-protected admin access;
  • Sensitive operations (export, delete) require dual confirmation and trigger an email alert.

9. Updates

We give at least 30 days’ notice by email and in-site banner for material changes. Continued use after the effective date constitutes acceptance.

10. Contact

Data controller: Siguan Media Information Technology Pte. Ltd. (Singapore)
Privacy email: [email protected]