Privacy

Privacy policy

How Tdriss handles the data needed to operate its web and mobile clients.

Last updated:9 September 2026
Primary storage
Supabase

Authentication, database, and file storage use Supabase.

Payments
Chargily

Required transaction data is sent when you choose to buy.

Support
Authenticated tickets

Support messages are tied to your account to prevent impersonation.

Identity verification
Didit

Didit processes the document and, when required, biometric data after your consent.

Data we collect
  • Account and profile data.
  • Purchase, entitlement, and progress records.
  • Chat, support messages, and files you submit.
  • Security and operational logs needed to prevent abuse and diagnose failures.
How we use it
  • Authentication and delivery of purchased content.
  • Payment, settlement, and refund processing.
  • Content moderation and fraud prevention.
  • Support and service reliability.
Processing and sharing

We do not sell personal data. We share only what is necessary with Supabase, Chargily, and infrastructure providers to deliver the service or meet a legal obligation.

Identity verification and separated learning environments

After your consent, Didit acts as the verification processor for your identity card and may process biometric data required by the selected workflow. Tdriss uses the approved result to assign a male or female learning environment and guide each user to the environment appropriate for them.

  • Tdriss does not store the document image, document number, face image, or raw Didit payload.
  • We retain the verification status, document-workflow kind, verified gender, consent time, and decision time.
  • Separated learning environments rely only on the identity-card workflow; birth certificates are not accepted for this decision.
Didit’s verification privacy notice also applies and is linked before verification starts.
Data retention

Financial and security records are retained as required for operational and legal obligations.

Your choices and security
  • Request access to or correction of your data.
  • Report unauthorized access promptly.
  • Never share your password or session token.