Sabura

Privacy Policy

How Sabura collects, uses, stores, and shares personal data, including the rights available to people in the EU and EEA.

Effective and last updated: 16 September 2026. This Privacy Policy applies to sabura.app and its classroom tools, accounts, subscriptions, shared boards, AI features, and support forms. Sabura is the data controller for the processing described here. Privacy requests can be sent to support@sabura.app.

1. Personal data we process

Account data: if you register or sign in, we process your Firebase user ID, email address, display name where provided, authentication information, account settings, and plan status.

Classroom and tool data: you may enter student names or codes, lists, scores, groups, lesson content, dashboard settings, board content, votes, uploaded photos or PDF documents, or similar material. Many standalone tools keep data only in your browser. Data is sent to our cloud services when you choose account sync, persistent file upload, saved features, live sharing, or another online feature.

AI data: when you use the AI Teacher Assistant, we process the prompt, selected grade, content type, duration and language, the generated response, account identifier, and usage count. Do not include student names, health data, disability information, or other sensitive personal data in an AI prompt.

Billing data: for a paid subscription, Stripe processes payment and card details. Sabura receives identifiers and records such as Stripe customer and subscription IDs, plan, price, status, renewal or cancellation status, and billing locale. We do not receive or store full card numbers.

Support and technical data: if you contact us, we process your name, email address, message, and related correspondence. Our hosting and security services may also process IP address, request time, URL, browser/device data, and security logs.

Analytics data: Google Analytics and Microsoft Clarity may process cookie or pseudonymous identifiers, approximate location derived from IP address, device/browser information, pages viewed, referral data, interactions, and session or usability information. For visitors detected in the EU/EEA or UK, these services load only after consent. Outside those regions, they load automatically. Form inputs are not intentionally included in analytics, and Clarity input masking remains enabled.

Optional Canva connection: if you connect Canva, we process OAuth access and refresh tokens linked to your Sabura account, and presentation metadata such as design IDs, titles, thumbnails, and page counts. Saved boards retain selected design references, selection times, and window settings. This integration browses and displays existing presentations; it does not create or edit Canva designs or collect your Canva password.

2. Why we use data and our GDPR legal bases

We process account, requested classroom features, cloud saves, sharing, AI generation, and subscription administration because it is necessary to provide the service you request or to take steps before entering a contract (GDPR Article 6(1)(b)). We process essential service logs, fraud and abuse prevention, debugging, and service security for our legitimate interests in operating and protecting Sabura (Article 6(1)(f)), after considering users’ rights. We process records needed for tax, accounting, disputes, and other legal duties under Article 6(1)(c). Where EU/EEA or UK consent rules apply, we use Google Analytics and Microsoft Clarity only after consent. Outside those regions, we use analytics to understand and improve Sabura, subject to applicable local law.

We do not sell personal data, use it for third-party behavioural advertising, or make decisions producing legal or similarly significant effects solely by automated means. Random classroom tools and AI output are aids for teachers, not profiling or automated decisions about students.

We process Canva connection data to provide the presentation browsing and display features you request, using the service-provision basis described above. Connecting Canva is optional. You can disconnect it from the Canva settings drawer in Sabura.

3. Local browser storage and cookies

Sabura uses necessary browser storage for authentication and security, your privacy choice, language or interface preferences, locally saved lists, and tool state. These features cannot always work without that storage. Local-only data remains on your device until you clear it or use the tool’s deletion control.

Google Analytics may set cookies such as _ga and _ga_*. Microsoft Clarity may set cookies such as _clck and _clsk for usage analytics, heatmaps, and session continuity. For visitors detected in the EU/EEA or UK, these services do not load until “Accept analytics” is selected, and “Privacy settings” remains available in the site footer to reject or withdraw consent. Outside those regions, analytics load automatically. If Sabura cannot determine a visitor’s country, it requires consent by default. Advertising storage and ad personalisation remain disabled.

For Canva, Sabura uses a temporary security cookie during authorisation and browser storage to remember that you connected in this browser. These browser records do not contain Canva access or refresh tokens. Displaying a presentation loads content directly from Canva, which receives connection information such as your IP address and browser details and may use cookies or website data for playback and access checks. Private embeds may require a Canva login and permission to use that website data.

4. When classroom data leaves your device

Standalone tools generally work in your browser. If you sign in and save data, dashboard records and file metadata are stored in Google Firebase. Photos and PDF documents that you choose to persist are stored privately in Cloudflare R2 and are retrieved through access-controlled server functions. If you publish or share a dashboard, people with the link may see media opened on that dashboard. Temporary whiteboard-share files are designed to expire after approximately 10 minutes; persistent account-library files remain until you remove them from the library or delete the associated account. Only share the minimum information required and do not make a link public if it contains identifiable student data.

Canva access and refresh tokens and temporary authorisation state are stored on Sabura’s backend in Cloudflare Durable Objects. Tokens are not included in saved boards or sent to the dashboard frontend. Saved presentation references are stored with board data in Firebase. Presentation files are displayed through Canva’s embed service rather than copied into Sabura’s file library. A shared board may expose presentation references and content to its viewers, subject to Canva’s own access settings.

5. Service providers and recipients

We use Cloudflare for hosting, delivery, security, server-side functions, private R2 file storage, image optimisation, and temporary whiteboard sharing; Google Firebase for authentication and account, dashboard, or file-metadata storage in a European database region; Stripe for checkout, subscriptions, customer billing portal, and fraud prevention; and DeepSeek to generate requested AI content. We also use FormSubmit when you submit the contact form and Google Fonts to deliver website fonts.

With consent, we use Google Analytics for traffic and product analytics and Microsoft Clarity for interaction analytics, heatmaps, and session recordings. These providers process data under their own terms and privacy documentation and may act as processors or separate controllers for specified activities. We may also disclose data where required by law, to protect rights or security, or as part of a business reorganisation subject to appropriate safeguards.

We use Canva to authorise the optional connection, retrieve presentation metadata, and deliver embedded presentations. Canva processes data under its own Privacy Policy. Connecting Canva does not itself publish your designs or change their sharing permissions.

6. International transfers

Some providers or support teams may process data outside the EU/EEA, including in countries that may not provide equivalent protection. Where GDPR requires it, transfers are made using an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful safeguard. You may contact us for information about the safeguard relevant to your data.

7. How long we keep data

Account, persistent photos or PDFs, and other cloud-saved classroom data are generally kept while the account or saved feature remains active. An account-library file is deleted when you use its Remove control, and account files are deleted after an account-deletion request, subject to technical completion and legal exceptions. AI usage records are kept for the applicable monthly usage period and as reasonably needed to prevent abuse and resolve errors. Temporary whiteboard shares expire after approximately 10 minutes. Contact correspondence is kept only as long as needed to answer and document the request. Billing and transaction records are kept for the period required by applicable tax, accounting, anti-fraud, and legal-claims rules. Security logs and provider data are retained for the shortest configured or operationally necessary period. Local browser data remains until you delete it.

Canva retention and removal: we keep connection tokens while the connection is active. Temporary authorisation state is removed after use or expiry, normally within 10 minutes. Disconnecting in Sabura starts token revocation and deletion and removes saved Canva selections from your saved and shared boards, closing their presentation windows. Background checks are designed to detect Canva-side revocation and deleted or disabled Sabura accounts daily and start the same cleanup without a return visit. Failed cleanup is queued for automatic retry; our target is to complete removal within 30 days of disconnection or account deletion. Provider outages can delay completion. Offline browser copies are cleared when the updated application next connects and receives the cleanup notice, or you can clear browser data yourself. A cleanup timestamp may remain with your Sabura account to prevent old selections from returning. Disconnecting does not delete your original designs in Canva or unrelated Sabura account data. Contact support@sabura.app for removal requests or concerns.

8. Your rights in the EU and EEA

Depending on the circumstances, you may request access, correction, deletion, restriction, or portability of your personal data, and may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time through “Privacy settings.” You also have the right to complain to the data protection authority in the EU/EEA country where you live, work, or believe an infringement occurred.

Send requests to support@sabura.app. We may need to verify your identity and normally respond within one month. Some rights have legal limits, for example where records must be kept by law. If a school controls the relevant student data, please contact the school first; we will assist the school where Sabura acts on its instructions.

9. Schools, teachers, and children

Sabura is intended to be operated by teachers, schools, and other authorised adults, not for children to create independent accounts or submit personal information without appropriate school or parental authorisation. A school or teacher that enters student data must have authority and an appropriate legal basis, provide required notices, follow local age-of-consent and education rules, and use data minimisation. Use first names, initials, or non-identifying codes whenever practical.

10. Security

We use HTTPS, access controls, authentication, scoped storage, and service-provider safeguards intended to protect data. No internet service is completely secure. Keep account credentials confidential and contact us promptly if you suspect unauthorised access.

11. Changes and contact

We may update this policy when the service, providers, or legal requirements change. We will change the date above and provide additional notice where a change materially affects your rights. Questions, GDPR requests, and account-deletion requests can be sent to support@sabura.app.

← Back to Home