Privacy Policy
Durmah Learning Pte Ltd, registered in Singapore, operates this independent service and is responsible for the personal data it collects. It is not part of a university. Contact us at admin@durmah.ai about your data or privacy rights.
Individual study support and model training
Your study material is for your learning. Durmah's product rule is to process permitted material for the individual student's requested study assistance and the necessary service operations described in our privacy policy. That permission does not include using the material to train or fine-tune AI models, build shared model-improvement datasets, or provide another student's answers.
Generating a response from your prompt and permitted material is called inference. It is different from training or fine-tuning a model. The AI may use its existing knowledge and authorised reference sources to help explain your material; it is not limited to repeating your document. Another student's private work must not supply your answer.
This requirement applies to Durmah and its AI providers. Before release, provider contracts and settings must be reviewed for this restricted use of student inputs, outputs and derived content. These reviews are incomplete, so external AI and new academic uploads remain paused. No training is different from no storage or no operational access. Read our privacy policy and current availability.
The restricted-use requirement covers study files, notes, prompts, responses, summaries and derived representations such as embeddings. They must not become a shared training, fine-tuning or model-evaluation collection. A request for help does not authorise that secondary use. Necessary storage, access control, security, support and legal obligations are distinct service operations; they must be proportionate and disclosed, and do not create an unrestricted “service improvement” permission.
Data Categories
1. Institutional Pack Data
Institution and module context whose source rights and currency must be checked. Public availability alone is not a licence for reuse; institutional content is withheld from AI pending review.
2. Student Uploaded Data
Materials you upload or generate in your account (for example permitted notes, files, prompts and independent practice drafts). These are separated from other student accounts, subject to the processing and operational access described here.
This can include essays, assignment briefs, draft answers, lecture notes, uploaded documents, Mark My Paper submissions, AI feedback history, module choices, YAAG/calendar data, planner data, saved study materials, and profile or university verification details.
Independent study records and contact preferences
The independent writing editor keeps its text in the current browser page's memory until you download it or explicitly request AI assistance. It is not automatically saved or submitted to an AI provider. Closing or reloading the page can lose undownloaded text.
For signed-in users, we store task declarations, the relevant policy version, expiry and revocation status, and content-free activity events such as permission decisions and provider-request attempts. These records identify your account and may include short task labels and course references; keep academic content and sensitive information out of those labels. You can export these records and request deletion through account privacy controls.
Optional product and research email preferences are separate, default to off and can be withdrawn in the independent workspace. Acceptance of a social-media connection is not treated as marketing consent. Promotional trial reminders and referral emails are paused.
External AI and new academic uploads remain paused while processing arrangements are reviewed. The current database region is Singapore. The provider inventory, review limitations and feature status are described on Service transparency. We have not verified a universal zero-retention or no-training commitment for all providers, or a single fixed retention period for every existing data category.
External processing and sign-in
Signing in with Google provides account identity information to Durmah. University email verification checks address ownership, not institutional approval. We do not ask for your university password.
Hosting, storage, authentication, email delivery, payment and AI providers process data needed for the services you use. AI features send relevant prompts, uploaded content or extracts to the provider used by that feature. Account privacy does not mean that content stays only on your device or that no provider can access it.
Processing may take place outside the UK. Do not assume UK-only storage, zero provider retention or that an upload is suitable for confidential or restricted university material. Contact us before sharing material that has specific processing or location requirements.
How Academic Data Is Used
Existing essays, drafts, notes, files and study records support saved-work access and necessary account administration. Older features include Mark My Paper, revision, module planning and lecture support; naming those features does not mean that new uploads or AI processing are currently available. Reopening them requires the relevant release reviews.
Academic work is intended to be private to its owner and authorised operations. Account and storage access controls enforce that separation. Student-uploaded academic data is not used to create shared university packs or global legal resources.
Visibility and Account-Based Access
Copyright permission, an instruction to use a feature, and a lawful basis for processing personal data are different questions. An upload declaration does not establish all three. Durmah remains responsible for its own data-protection obligations and provider arrangements. Our responsible-study explanation distinguishes private learning from external processing.
Personal academic material is tied to your own account. Access controls and database access controls are used so student-owned records are separated by account. Admin access is limited to operational support, safety, billing, security, and lawful business needs.
Wellbeing & Support: what we do and do not do
Information about your mental health is special-category personal data under Article 9 of the UK GDPR, and we treat it differently from your academic data. This section explains exactly how.
Durmah is not monitored, and cannot get help for you
No one at Durmah reads, reviews or monitors your wellbeing conversations. Durmah does not raise alerts, does not notify your university, your tutor or your emergency contacts, and cannot contact emergency services on your behalf. Durmah is a student support and navigation service. It is not a healthcare provider, a counselling service, a crisis service or a therapist, and it must not be relied on as one. If you need urgent help, use the services listed on the Wellbeing & Support page — they are staffed by real people.
The wellbeing AI conversation is not enabled
Durmah has not enabled the optional wellbeing AI conversation while its lawful basis, Article 9 condition and related data-protection controls remain under formal review. The endpoint is unavailable and the member page does not send wellbeing text to an AI provider.
The urgent-help contacts, support directory, short resets, workload triage and message-building guidance work without an AI feature. Text entered into those local tools is not sent to Durmah or an AI provider.
Durmah no longer offers a mood check-in or wellbeing score, and does not store mood ratings, stress ratings or wellbeing trend data.
What we do record
When the urgent-support information is shown, we record a single content-free counter noting that it was shown and on which part of the product. That record contains no user identifier, no message text and no indication of what was said. It exists so we can tell how often the support routes are being surfaced. It cannot be used to identify you or to follow anything up, and nobody reviews it for that purpose.
Lawful basis
Special-category processing requires both an Article 6 lawful basis and an Article 9 condition. Not storing the information does not remove that requirement. Durmah will not enable an optional wellbeing AI feature unless those grounds and the required controls have been formally established and described here first.
Security Posture
- Account-based access controls
- Row-level security isolation between users
- Encrypted storage and encrypted data transmission
Data Use Limits
- Data is not sold.
- Student uploads are not reused to build Institutional Packs.
- Processing supports service delivery, necessary administration, billing, support and security.
Student Control and Deletion Requests
The ICO guide to individual rights explains the rights and their conditions. These rights are separate from copyright ownership in your study materials.
Where UK data-protection law applies, you may have rights to access and correct personal data, request erasure or restriction, object to processing and obtain portable data where the relevant conditions apply. A deletion request is not a promise that every record can immediately be erased. You can raise concerns with us or complain to the ICO; other local rights may also apply.
You can request deletion of uploaded personal study data, workspace study data, or account-related app data from your account privacy page or by contacting admin@durmah.ai.
Deletion requests are reviewed before execution so Durmah can avoid deleting the wrong records, shared academic resources, or another student's data. Where records are clearly owned by your account, Durmah can delete or reset them through an owner-scoped workflow. Ambiguous account records may require manual review.
Subscription Cancellation Versus Data Deletion
Cancelling or stopping a subscription does not automatically delete your study workspace. This helps prevent accidental loss of essays, drafts, notes, planning data, or feedback history. If you stop using Durmah.ai and want personal study data deleted, submit a deletion request.
Records That May Be Retained
Minimal audit, legal, security, billing, fraud-prevention, or operational records may be retained where necessary. Durmah does not promise instant deletion, but requests are handled through a reviewed process.
