Privacy Policy
Last Updated: September 17, 2026
⚠️ Important Notice
LACO AI provides AI-powered information services covering schools, businesses, and student academic records. Full sensitive-data features (including student grades) are currently available exclusively to La Consolacion College Bacolod (LCCB). Businesses may sign up for general document analysis under a separate tier described below. This platform is provided "as-is" and is under active development.
1. Introduction
Welcome to LACO AI ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered platform for school, business, and academic-record information services.
This project is developed under the Apache License 2.0. We are committed to protecting your privacy and handling your data responsibly.
2. Platform Scope
LACO AI operates under two distinct scopes:
- Academic (La Consolacion College Bacolod only): Full access to sensitive student data, including grades, is available exclusively to LCCB. Other schools or institutions seeking full system access must contact us directly to negotiate a separate agreement.
- Business: Businesses may sign up for general PDF document analysis under the Free Trial, Pro, or Enterprise tier (see Section 3.5). This tier is not intended for sensitive or confidential data.
2.1 Account Approval Process
- Student and Teacher (LCCB academic) accounts are subject to admin review before activation. Your account will remain under review until an administrator approves it.
- Business accounts (Free Trial, Pro, Enterprise) do not require admin approval to sign up and access the platform. However, payments submitted for Pro or Enterprise plans are still reviewed by an administrator (see Section 8).
3. Information We Collect
3.1 Account Information
- Email address (used as unique identifier)
- Full name
- Password (encrypted using industry-standard hashing)
- User role (Admin, Teacher, or Student)
- Year level (for students)
- Profile picture (optional)
- Account creation date and timestamps
- Account status (active/inactive)
- Email verification status
3.2 Usage Data
- PDF file uploads (name, size, file path)
- Chat conversations with AI (prompts and responses)
- Selected PDF documents for chat context
- Search queries within PDF lists
- API request logs and response times
- User activity timestamps
- Profile updates and password changes
- File deletion activities
3.3 Technical Data
- IP address (for rate limiting and security)
- Browser type and version
- Device information
- JWT authentication tokens (stored in cookies)
- Local storage data (email for session recovery)
- Request headers and origin validation
3.4 Academic Data (LCCB Only)
- Student grades and related academic records
- Admin users have access to user management features
- Admin activity logs (user creation, status updates, deletions)
- API usage logs accessible by admins
3.5 Business Accounts
- Free Trial: 2 PDF uploads, 10,000 API requests, 10MB per upload, 1 month free
- Pro (₱799/month): 250 PDF uploads/month, 1,000,000 API requests/month, 100MB per upload
- Enterprise (₱1,999/year): 10,000 PDF uploads/year, 5,000,000 API requests/year, 500MB per upload
- Business PDF uploads under all tiers are treated as Public Documents and should not contain sensitive information (see Section 6)
4. How We Use Your Information
We use collected information for:
- User authentication via JWT tokens and email verification
- Role-based access control (Admin, Teacher, Student)
- Processing PDF documents with OpenAI (gpt-4o-mini) for information retrieval and chat
- Generating AI-powered responses to user questions, including academic records for LCCB students
- Storing and managing profile pictures
- Enabling search and filtering of uploaded PDFs
- Admin features: user management, API logs, and system monitoring
- Rate limiting to prevent spam and abuse (1 request per second per IP)
- CSRF protection and origin validation
- Enforcing Free Trial, Pro, and Enterprise tier limits for business accounts
- Reviewing and processing business plan payments, refund requests, and resubmissions
- Debugging and system performance monitoring
5. Data Storage and Security
- User data stored in Supabase PostgreSQL database with row-level security
- Sensitive data and document summaries are encrypted at rest
- Profile pictures stored in Supabase public storage buckets
- PDF files stored in Supabase storage buckets
- Passwords encrypted using industry-standard hashing
- Payment account numbers are encrypted at rest and only decrypted for authorized admin review
- JWT tokens with secret key encryption for session management
- API endpoints protected with JWT authentication and rate limiting
- CSRF protection via origin header validation
- Rate limiting: 1 request per second per IP address to prevent spam
- Old profile pictures automatically deleted when updating
- We implement reasonable security measures but cannot guarantee absolute security
- HTTPS encryption for all data transmission
6. Public Documents and Sensitive Data Warning
Business and general users: PDF documents uploaded outside the LCCB academic scope are treated as Public Documents. Do not upload documents containing passwords, credentials, or other sensitive information into Public Documents.
Web-link conversion: The feature that converts a web link into a PDF is available only for Public Documents. Do not submit links that expose private, restricted, password-protected, or confidential content.
La Consolacion College Bacolod is not responsible for any damages, losses, or consequences resulting from sensitive data uploaded into Public Documents by businesses or general users.
7. Third-Party Services
We use the following third-party services:
- Supabase: PostgreSQL database, authentication, and file storage services
- OpenAI (gpt-4o-mini): AI-powered chat responses and document analysis
- Render: Python API hosting for backend services
- Vercel/GitHub Pages: Next.js application deployment
- Next.js: React framework for the web application
These services have their own privacy policies and terms of service. We are not responsible for their data handling practices, security measures, or service availability.
8. Payments and Refunds
- Business accounts on the Pro or Enterprise plan submit payment details, including an account/payment method identifier, for manual admin verification
- Submitted account numbers are encrypted before being stored; only administrators can review them for verification purposes
- Each payment is assigned a status: pending (awaiting review), success (approved and plan activated), declined (rejected, with a reason), refund_requested (awaiting refund review), or refunded (refund processed)
- You will receive an email notification when you submit a payment, resubmit updated payment details, request a refund, and when an admin approves, declines, or refunds your payment
- Only one pending payment is allowed per account at a time; you must wait for a decision, or resubmit details if requested, before submitting again
- Requesting a refund re-encrypts the submitted account number and marks the payment as refund_requested pending admin processing
- Declined payments may include a reason from the admin explaining why verification failed
9. Data Retention
- Account data: Retained until you request deletion by contacting the admin (see Section 10)
- Profile pictures: Stored until replaced or account deleted
- PDF files: Stored in database and storage bucket until manually deleted via context menu
- Chat history: Stored indefinitely in your account until manually cleared
- Payment records: Retained for accounting and dispute-resolution purposes, with account numbers encrypted
- API logs: Retained for debugging, research, and admin monitoring purposes
- Authentication tokens: JWT tokens expire based on configured session duration
- Rate limit data: Stored temporarily in memory; old entries auto-cleaned
- OTP verification codes: Used for password reset and verification, short-lived
10. Account Security, Password Recovery, and Deletion
- You retain full control over your own account password
- Password recovery is self-service via OTP (One-Time Password) sent to your registered email, through
/auth/forgot-password - Admins cannot recover or reset your password on your behalf — recovery is only possible through your own email via OTP
- Account deletion is not self-service. To delete your account and wipe all associated data, you must contact the admin email directly
11. Your Rights
You have the right to:
- Access your personal data through your profile settings
- Update your name and profile picture
- Recover your password via OTP at
/auth/forgot-password - View your uploaded PDFs and chat history
- Delete individual PDFs via right-click context menu
- Request correction of inaccurate account data
- Request full account and data deletion by contacting the admin email
- Be informed of data breaches affecting your information
12. User Roles and Permissions
12.1 Students and Teachers (LCCB)
- Accounts require admin review and approval before activation
- Can upload and manage their own PDF documents
- Can chat with AI about their PDFs and their own academic records
- Can search and filter their PDF library
- Can update their profile and recover their password via OTP
- Students under 13 require Guardian or Parent supervision
12.2 Administrators
- Full access to user management features
- Review and approve student/teacher account registrations
- Can create, update, and manage user accounts (cannot reset user passwords — recovery is OTP-only)
- Handle account deletion requests received via admin email
- Review, approve, decline, or refund business payments
- Can view and manage API usage logs
- Can assign teacher roles to users
- Can monitor system health and performance
12.3 Business Accounts
- Sign-up does not require admin approval
- Free Trial: 2 PDF uploads, 10,000 API requests, 10MB per upload limit, 1 month free trial
- Pro tier (₱799/month): 250 PDF uploads/month, 1,000,000 API requests/month, 100MB per upload — payment requires admin verification
- Enterprise tier (₱1,999/year): 10,000 PDF uploads/year, 5,000,000 API requests/year, 500MB per upload — payment requires admin verification
- All business tiers use Public Documents and must not upload sensitive or password-containing PDFs; web-link conversion is also limited to Public Documents
13. Children's Privacy
Users under 13 years of age are not permitted to sign up or use LACO AI without direct parental supervision and consent.
- A parent or legal guardian must provide consent before a child under 13 creates an account or uses the Service
- A parent or legal guardian is solely responsible for supervising their child's use of the Service, including AI interactions and PDF uploads
- We do not knowingly collect data from children under 13 without verified parental consent
- If we become aware that a child under 13 has registered without parental consent, we will take steps to disable the account and delete associated data
- Parents or guardians may contact the admin email to review, request deletion of, or ask questions about their child's data
14. No Illegal Activities
This platform is strictly for lawful use. We:
- Do not engage in any illegal activities
- Do not support or facilitate illegal content or actions
- Reserve the right to terminate accounts engaged in illegal activities
- Will cooperate with law enforcement if required by law
15. Changes to This Privacy Policy
We may update this Privacy Policy at any time. Changes will be posted on this page with an updated revision date.
16. Contact Information
For questions about this Privacy Policy, account deletion requests, or negotiating full-system access for other schools, please contact the admin.
Project Owner: cordyStackX
License: Apache License 2.0
GitHub: github.com/cordyStackX/lccb_ai_2
Disclaimer
Use at your own risk. We provide no warranties beyond what is stated in this policy and are not liable for damages arising from sensitive data uploaded into Public Documents. Your data is processed by third-party services including OpenAI.