General
Welcome to Mr Fero! We're committed to protecting your privacy and being transparent about how we collect, use, and share your information.
This Privacy Policy describes how Mr Fero ("Mr Fero," "we," "us," or "our") collects, uses, and shares your personal information when you use our mobile application and related services (collectively, the "Service"). By using Mr Fero, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy.
Mr Fero is an AI-powered educational platform designed to help students learn through interactive conversations with AI tutors. We use artificial intelligence to provide personalized educational assistance, answer questions about educational content, and help students better understand their study materials.
We collect information you provide (like your email and username), information about your learning activity (like chat messages and book selections), and technical information (like device type). We use this information to provide our AI tutoring service, improve your experience, and keep your account secure. We share some information with AI service providers to answer your questions, but we never sell your personal data.
Who We Are
Mr Fero is an educational technology platform designed for students, teachers, parents, and lifelong learners aged 13 and older. We provide AI-powered tutoring across a wide range of subjects and educational levels. We provide our Service primarily through our Android mobile application, available on the Google Play Store, and through our web dashboard for administrators and moderators.
Scope of This Policy
This Privacy Policy applies to:
- The Mr Fero mobile application for Android
- The Mr Fero website (mrfero.com and subdomains)
- The Mr Fero backend services
- Any other services we offer that link to this Privacy Policy
Age Requirement
Mr Fero is intended for users aged 13 and older. We do not knowingly collect personal information from individuals under 13 years of age. If you are under 13, you may not create an account or use this Service. If you learn that we have collected personal information from someone under 13 without appropriate consent, please contact us at privacy@mrfero.com and we will delete that information promptly.
If you are between 13 and 17, we encourage you to discuss your use of Mr Fero with a parent or guardian. Parents and guardians are welcome to be involved in their children's learning activities and can help manage account settings.
The Mr Fero app is rated for ages 13 and up on the Google Play Store, consistent with this age requirement.
How We Obtain Your Consent
Before you can create an account and use Mr Fero, we require your explicit consent to this Privacy Policy and confirmation of your age eligibility. This consent process is mandatory and works as follows:
For Email and Password Registration:
When you create an account using email and password, you must check two required boxes before the "Create Account" button will work:
- Age Confirmation: "I am 13 years of age or older"
- Privacy Policy Agreement: "I agree to the Privacy Policy"
Both checkboxes must be selected to proceed. If you do not check both boxes, you will not be able to create an account. A link to this Privacy Policy is displayed on the registration screen for you to review before providing consent.
For Google Sign-In (New Users):
If you sign in with Google and do not have an existing Mr Fero account, a consent dialog will appear after Google authentication. This dialog requires you to confirm the same two statements before your account is created:
- That you are 13 years of age or older
- That you agree to this Privacy Policy
Existing users who signed in with Google previously will not see this dialog when logging in; they proceed directly to the app.
Mandatory Nature of Consent:
Your consent to this Privacy Policy and confirmation of age eligibility are foundational requirements for using Mr Fero. Without providing both consents, you cannot create an account or access our Service. This ensures that all users understand and agree to how we handle their personal information and that our Service is used only by age-eligible individuals.
We record your consent at the time of account creation. If you wish to withdraw your consent, you may do so by deleting your account as described in the "Your Data Subject Rights" section below.
Definitions
In this Policy:
- "Personal Data" means information relating to an identified or identifiable person.
- "Service" means the Mr Fero Android application, website, and related services.
- "We," "Us," "Our" means Mr Fero (mrfero.com).
- "You" means the individual using the Service.
- "Processing" means any operation performed on Personal Data (collection, storage, use, disclosure, deletion, etc.).
Information We Collect
We collect information about you in several ways when you use our Service. This section describes the types of information we collect and how we collect it.
1. Information You Provide to Us
We collect information that you voluntarily provide when creating an account and using our Service:
Account Information:
- Email Address: Required for creating your account, logging in, and sending important notifications about your account
- Username: A unique identifier you choose for your account (3-32 characters)
- Password: Used to secure your account. We never store your password in plain text; it is encrypted using industry-standard cryptographic hashing
- Consent Records: We store records of your consent to this Privacy Policy and your confirmation that you are 13 years of age or older, as provided during account creation
Google Sign-In Information:
If you choose to sign in with Google, we receive:
- Your Google email address
- Email verification status
- Google account identifier (used to link your Google account to Mr Fero)
- Your display name (used temporarily to suggest a username; we don't store your Google profile picture)
Learning Content:
- Chat Messages: The questions you ask and conversations you have with our AI tutor
- Voice Input: When you use the microphone feature, we record and transcribe your audio to text. Audio recordings are processed through AI services but are not permanently stored
- Photo Submissions: When you take or upload photos of questions using the camera feature, we process these images to extract text. Original images are processed but not permanently stored in our databases
- Study Materials: Information about which books and educational materials you're studying
Account Management Information:
- Activation codes you redeem for credits
- Email verification codes and password reset requests
- Account deletion requests submitted through our web form
2. Information We Collect Automatically
When you use Mr Fero, we automatically collect certain technical information:
Usage Information:
- Learning Activity: Which books you open, when you start chat sessions, your learning progress, and which AI models you prefer to use
- Chat Sessions: When you start and end study sessions, duration of sessions, and which books you were studying
- Credit Usage: How many credits you use for AI interactions and your credit balance
- Feature Usage: Which features you use (text chat, voice input, photo submissions) and how frequently
Device and Technical Information:
- Device Type: Android device model and operating system version (used for compatibility and troubleshooting)
- App Version: Which version of the Mr Fero app you're using
- Network Information: Your Internet Protocol (IP) address (used for security, preventing abuse, and rate limiting)
- Network Status: Whether your device is online or offline (helps optimize app behavior)
- Push Notification Tokens: Device tokens needed to send you notifications about your account or learning activity
AI Model Information:
- AI model preferences and usage patterns
- Token usage statistics (how much AI processing your questions require)
- Cost and credit deduction information for AI interactions
We do not collect advertising IDs, track your location, monitor your activity across other apps, use third-party analytics or advertising SDKs, or collect any information from you when you're not using Mr Fero.
3. Information from Third-Party Services
Google OAuth:
If you sign in with Google, Google provides us with the information described in Section 1 (Google Sign-In Information) above. Google's use of your information is governed by Google's Privacy Policy.
AI Gateway and Third-Party AI Providers:
Mr Fero's core educational functionality relies on artificial intelligence to answer your questions and provide tutoring. To deliver this service, we use OpenRouter as an AI gateway that acts as a proxy to connect our Service to third-party AI model providers.
How the AI Gateway Works
When you interact with our AI tutor (by typing a question, using voice input, or uploading a photo), here's what happens:
- You submit content: Your question, along with any voice recordings (transcribed to text) or images (processed for text extraction), is sent to our backend server
- We prepare the request: Our server assembles a complete AI request that includes:
- Your question or prompt
- Relevant educational content from the book you're studying (retrieved from our database)
- Recent conversation history to provide context for follow-up questions
- System instructions that guide the AI to act as an educational tutor
- Transmission to OpenRouter: This complete request is transmitted over an encrypted HTTPS connection to OpenRouter's API
- Routing to AI providers: OpenRouter forwards your request to the selected AI model provider, which may include:
- OpenAI (for GPT models)
- Anthropic (for Claude models)
- Google (for Gemini models)
- Other leading AI providers
- Response generation: The AI provider processes your request and generates an educational response
- Return path: The response travels back through OpenRouter to our server, then to your app
What We Store vs. What Gets Transmitted
Data We Store:
- Chat History: Your questions and the AI's responses are stored in our database to maintain conversation continuity and allow you to review your learning history. This data is associated with your account and the book you're studying
- Session Information: We store metadata about your chat sessions, including timestamps, which book you were studying, and which AI model you used
- Usage Logs: We log AI model usage for credit accounting and cost tracking (including token counts and costs)
Data Transmitted to OpenRouter and AI Providers:
- Your questions and prompts (text, transcribed audio, or text extracted from images)
- Educational context from the book you're studying (to help the AI provide accurate, curriculum-specific answers)
- Recent conversation history (so the AI can understand follow-up questions)
- System prompts and instructions (that define the AI's role as an educational tutor)
Pass-Through Processing: OpenRouter acts as a gateway and does not permanently store your prompts or AI responses according to their privacy policy. The data passes through OpenRouter to reach the AI provider, generates a response, and returns to Mr Fero.
AI Provider Data Practices: The AI model providers (OpenAI, Anthropic, Google, etc.) process your requests to generate responses. According to their respective privacy policies, these providers do not use data submitted through their APIs to train their models or for purposes other than providing the requested AI inference.
Your Consent and Responsibilities
By using Mr Fero's AI tutoring features, you consent to:
- The transmission of your questions, educational context, and conversation history to OpenRouter and downstream AI providers
- The processing of your content by third-party AI services to generate educational responses
- Our storage of your chat history and learning activity on our servers
Third-Party Privacy Policies:
While we carefully select our AI gateway and provider partners, we do not control their data practices. We encourage you to review the privacy policies of these third-party services:
- OpenRouter: openrouter.ai/privacy
- OpenAI: openai.com/privacy (API Data Usage Policy)
- Anthropic: anthropic.com/privacy (Commercial Privacy Policy)
- Google: policies.google.com/privacy (Cloud Privacy Notice)
Data Security in Transit
All data transmitted between your device, our servers, OpenRouter, and AI providers is encrypted using industry-standard TLS/HTTPS protocols. This ensures that your questions and conversations are protected during transmission.
What Information is NOT Sent to AI Providers
We do not send the following information to OpenRouter or AI providers:
- Your password or authentication credentials
- Your email address or username
- Your credit balance or payment information
- Your IP address or device information
- Any personal data unrelated to the specific educational question you're asking
How We Process Your Information
We use the information we collect about you for the purposes described below. The legal basis for processing your information varies depending on the purpose and applicable law.
1. To Provide and Maintain Our Service
We process your information to deliver the core functionality of Mr Fero:
- AI Tutoring: Processing your questions, voice input, and photo submissions through AI models to provide educational responses and explanations
- Conversation Context: Maintaining chat history during your study sessions so the AI tutor can provide contextual, relevant answers to follow-up questions
- Learning Materials: Providing access to educational books and retrieving relevant content from our database to help answer your questions accurately
- Account Management: Creating and maintaining your account, allowing you to log in, and syncing your preferences across sessions
- Credit System: Tracking your credit balance, processing credit usage for AI interactions, and managing activation codes
- Model Selection: Remembering your preferred AI model and applying your choices to future conversations
2. To Personalize Your Experience
We use your information to tailor Mr Fero to your learning needs:
- Learning Progress: Tracking which books you're studying and your conversation history to provide continuity in your learning
- AI Model Preferences: Remembering which AI models you prefer to use for different types of questions
- Session Management: Maintaining your active study sessions so you can pick up where you left off
- Language Preferences: Applying your language choice (English or Arabic) across the app interface
3. To Communicate with You
We use your contact information to send you important messages:
- Account Notifications: Sending email verification codes, password reset links, and account security alerts
- Service Updates: Notifying you about changes to our Service, new features, or important policy updates
- Push Notifications: Sending app notifications about your learning activity (if you've enabled notifications on your device)
- Support: Responding to your questions and providing customer support
We do not send marketing emails or promotional content. All communications are related to your account or the operation of our Service.
4. To Ensure Security and Prevent Abuse
We process certain information to keep Mr Fero safe and secure:
- Authentication: Verifying your identity when you log in and protecting your account from unauthorized access
- Rate Limiting: Using your IP address to prevent automated abuse, spam, and excessive requests
- Fraud Prevention: Detecting and preventing fraudulent account creation, credit manipulation, and abuse of activation codes
- Security Monitoring: Identifying unusual patterns that might indicate security threats or unauthorized access
- Audit Logging: Recording administrative actions (by admins and moderators) for accountability and security purposes
5. To Improve and Develop Our Service
We analyze usage patterns to make Mr Fero better:
- Service Performance: Understanding how users interact with different features to identify bugs and improve reliability
- Feature Development: Analyzing which features are most valuable to students to guide our development priorities
- AI Quality: Evaluating AI model performance and accuracy to select the best models for educational purposes
- Cost Optimization: Monitoring token usage and costs to provide the most efficient AI tutoring service
- User Experience: Identifying friction points in the learning experience and making improvements
6. To Provide Administrative Tools
For users with moderator or administrator roles:
- Moderator Dashboard: Providing moderators with tools to manage activation codes and monitor their assigned budget usage
- Administrator Panel: Giving administrators access to manage users, books, AI models, and system settings
- Usage Analytics: Providing insights into platform usage, credit distribution, and user activity for administrators
- Content Management: Allowing authorized users to upload educational books and manage learning materials
7. To Comply with Legal Obligations
In limited circumstances, we may process your information to:
- Respond to legal requests from law enforcement or government authorities where required by law
- Enforce our Terms of Service and protect the rights, property, or safety of Mr Fero, our users, or others
- Comply with applicable privacy laws and regulations, including children's privacy protections
- Process account deletion requests and fulfill your data subject rights
We process your information based on: (1) your consent when you create an account and use our Service, (2) our need to perform our contract with you to provide educational services, (3) our legitimate interests in improving and securing our Service, and (4) compliance with legal obligations where applicable.
Your Data Subject Rights
You have certain rights regarding your personal information. This section explains what rights you have and how to exercise them.
1. Right to Access Your Information
You have the right to access the personal information we hold about you.
In the App: You can view most of your information directly in the Mr Fero app, including your account details (email, credits balance), learning history, and chat sessions. Go to the Account section in the app to see your profile information.
Request a Copy: If you want a comprehensive copy of all your data, you can request a data export by contacting us at privacy@mrfero.com. We will provide your data in a structured, commonly used format within 30 days of your request.
2. Right to Delete Your Account
You have the right to delete your account and all associated personal information at any time. When you delete your account, we permanently remove:
- Your email address, username, and password
- All chat messages and conversation history
- Your learning progress and session data
- Credit balance and transaction history
- All account preferences and settings
Account deletion is permanent and cannot be undone. Once deleted, you will not be able to recover your account, chat history, or any other data.
You have two options to delete your account:
Option 1: Delete from the App
If you are signed in and your account uses email and password authentication, you can delete your account from the app:
- Open the Mr Fero app on your Android device
- Go to Account (account settings)
- Tap Delete My Account
- Confirm by entering your account password in the dialog shown
- Your session ends and we begin account erasure on our servers
Google Sign-In only: If you registered only with Google and have not set a password, in-app deletion may not be available until you set a password, or you may use Option 2 below.
When deletion succeeds in the app, we remove your chat messages, diagnostic logs, credits history, tokens, and device tokens, and anonymize your profile (email and username are replaced with non-identifying placeholders). Some technical records may persist for a limited period as described under Data Retention below.
Option 2: Request Online (Without Signing In)
If you do not have the app installed, cannot sign in, or prefer to submit a request in writing, use our web form. The same form may be used for access, correction, portability, or deletion requests:
- Visit https://api.mrfero.com/delete-account
- Enter the email address and username associated with your Mr Fero account
- Describe your request in the message field (for example, delete my account, export my data, or correct my email)
- Submit the form
We will verify your identity using the information provided and respond within thirty (30) days (one calendar month), unless applicable law allows or requires a longer period, in which case we will notify you. Deletion requests are routed to accounts@mrfero.com for processing.
You may also email privacy@mrfero.com (general privacy rights) or dataexport@mrfero.com (data export / portability).
3. Right to Correct Your Information
You have the right to update or correct inaccurate information.
Username or Email Address Errors: To update your username or correct an email address error (such as a typo made during registration), contact us at support@mrfero.com with:
- Your account email address (or the incorrect one if you cannot log in)
- Your username
- The correction you need
We will verify your identity and process your request within 30 days.
Changing to a Different Email: If you have a verified account but wish to use a different email address, you will need to delete your current account and create a new one with the desired email address. Note that your chat history and credits cannot be transferred to the new account.
Password: Use the "Forgot Password" feature on the login screen to reset your password at any time.
4. Right to Data Portability
You have the right to receive a copy of your personal information in a structured, machine-readable format, and to transfer that data to another service.
To request a copy of your data, email dataexport@mrfero.com with your account email address. We will provide your data in JSON format, which includes:
- Account information (email, username, creation date)
- Chat history and messages
- Learning activity and session logs
- Credit transaction history
- Account preferences and settings
We will fulfill data portability requests within 30 days.
5. Right to Restrict or Object to Processing
You have the right to restrict or object to certain types of processing of your personal information.
If you wish to restrict how we process your information or object to specific processing activities, please contact us at privacy@mrfero.com with details of your request. We will review your request and respond within 30 days.
Note that restricting certain processing may limit your ability to use some features of Mr Fero. For example, restricting processing of chat messages would prevent the AI tutor from functioning.
6. Right to Withdraw Consent
Where we process your information based on your consent, you have the right to withdraw that consent at any time.
Foundational Consent:
Your initial consent provided during account creation (agreeing to this Privacy Policy and confirming you are 13 years or older) is foundational to our service agreement and forms the legal basis for creating and maintaining your account. Because this consent is required to use Mr Fero, withdrawing this foundational consent means you can no longer maintain an account with us. To withdraw your foundational consent, you must delete your account as described in Section 2 ("Right to Delete Your Account") above. Account deletion permanently removes all your data and ends our processing of your personal information.
Feature-Specific Consent:
For optional features that require separate consent (such as push notifications), you can withdraw consent for those specific features without deleting your entire account:
- Push Notifications: Turn off notifications in your device settings for the Mr Fero app
- Specific Processing Activities: Email privacy@mrfero.com to withdraw consent for specific optional processing activities
Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
7. Right to Lodge a Complaint
If you believe we have not handled your personal information properly, you have the right to lodge a complaint with a data protection authority in your country.
However, we encourage you to contact us first at privacy@mrfero.com so we can try to resolve any concerns directly.
To exercise any of these rights, you can:
- View your account information in the app (Account section)
- Delete your account from the app (if you have a password-protected account)
- Submit a request through our web form at https://api.mrfero.com/delete-account (for deletion, correction, access, or export requests)
- Email us at privacy@mrfero.com or support@mrfero.com (for any data subject right)
We will respond to all requests within 30 days. We may need to verify your identity before processing your request to protect your privacy and security.
How We Share Your Information
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We share information only as described below.
Service Providers and Sub-Processors
We use trusted third parties to operate Mr Fero. They process data on our behalf under contractual obligations appropriate to their role:
- OpenRouter (openrouter.ai/privacy) — routes AI inference requests to model providers
- AI model providers (e.g., OpenAI, Anthropic, Google via OpenRouter) — generate educational responses to your prompts
- Google — Sign-In token verification when you use Google authentication
- Email delivery services — deliver transactional emails (verification, password reset, account notices)
- Hosting and infrastructure providers — operate our servers, secure databases, and caching systems
A current list of sub-processors may be requested at privacy@mrfero.com.
Legal and Safety Disclosures
We may disclose information if we believe in good faith that disclosure is necessary to comply with law, respond to lawful requests, protect the rights and safety of Mr Fero, our users, or others, or prevent fraud or abuse.
Data Retention
We retain personal information only as long as necessary for the purposes in this Policy, unless a longer period is required by law.
- Active accounts: Account, chat messages, and learning data are kept while your account is active.
- Chat diagnostic logs: Server-side diagnostic logs (which may include prompts and model metadata) are retained for up to ninety (90) days by default, then deleted by an automated job.
- Rate-limiting data: Temporary rate-limiting records expire automatically after short windows (minutes to hours).
- Email verification tokens: Hashed codes expire within fifteen (15) minutes.
- Refresh tokens: Valid for up to thirty (30) days unless revoked.
- Deleted accounts: After account deletion, identifiable data is removed or anonymized; residual technical logs may persist until the next retention cycle (up to 90 days).
Information Security
We implement reasonable technical and organizational measures, including:
- Encryption in transit: HTTPS/TLS between your device, our servers, OpenRouter, and other providers
- Password protection: Passwords stored using cryptographic hashing; tokens stored as cryptographic hashes server-side
- Device storage: Authentication tokens on Android stored in encrypted secure storage
- Access controls: Role-based access to administrative systems
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
Data Storage Location
Your personal information is stored on secure servers located in Germany, within the European Union. This ensures full compliance with the General Data Protection Regulation (GDPR) and European data protection standards.
We use professional cloud hosting and infrastructure services that meet industry security standards and comply with applicable data protection regulations. Our infrastructure providers are carefully selected based on their compliance with data protection laws and security best practices.
Security Measures
We implement multiple layers of security to protect your data:
- Data in transit: All data transmissions are encrypted using TLS/HTTPS protocols
- Secure authentication: Multi-factor authentication options and secure access controls
- Regular security updates: Continuous monitoring and timely application of security patches
- Automated backup systems: Regular backups to prevent data loss
- Industry-standard database security: Database encryption and access logging
Data Residency
Your data remains within the European Union and is not transferred to third countries for storage purposes, unless necessary for specific service functionality (such as Google Sign-In authentication or AI inference processing as described in the "AI Gateway" section). Any such transfers are conducted with appropriate safeguards in accordance with GDPR requirements.
International Data Transfers
Your personal data is primarily stored and processed within the European Union (Germany). However, certain service providers and features may involve data transfers to other countries:
- AI Processing: When you use our AI tutoring features, your questions are transmitted to AI providers through OpenRouter. These providers may process data in the United States or other jurisdictions. As described in the "AI Gateway" section, these providers have committed not to use API data for training or purposes other than providing the requested inference.
- Google Sign-In: If you use Google authentication, your sign-in process involves Google's services, which may process data internationally according to Google's privacy policy.
- Email Services: Transactional emails (verification codes, password resets) may be processed by email service providers that operate internationally.
When we transfer personal information internationally, we rely on appropriate safeguards where required by law, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions recognizing equivalent data protection standards
- Your explicit consent through use of specific features that require international data transfer
- Contractual obligations with service providers to protect your data
Your core account data, chat history, and learning records remain stored within the European Union at all times.
Cookies and Similar Technologies
The Mr Fero Android application does not use browser cookies for tracking or advertising.
Our administrator web dashboard may use essential cookies for language and theme preferences (for example, fero_admin_lang, fero_admin_theme). These are not used for cross-site tracking.
We do not use third-party advertising or analytics cookies on student-facing services.
Requests Without a Logged-In Account
If you cannot access the app or are not signed in, you may still exercise certain rights by submitting a request through our web form at https://api.mrfero.com/delete-account or by emailing us.
The form collects your account email, username, and an optional message describing your request (deletion, access, correction, or export).
We will verify your identity using the information you provide and respond within thirty (30) days (one calendar month). If we need more time where permitted by law, we will inform you of the reason and extension period.
- Privacy & general rights: privacy@mrfero.com
- Data export / portability: dataexport@mrfero.com
- Account deletion operations: accounts@mrfero.com
- Support: support@mrfero.com
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the revised policy at https://api.mrfero.com/privacy and update the "Last Updated" date. For material changes, we may notify you through the app or by email where appropriate. Continued use of Mr Fero after the effective date constitutes acceptance of the updated Policy.
Content Safety and Moderation
We are committed to providing a safe and appropriate educational environment for all users:
AI Content Moderation:
- Educational Focus: Our AI tutors are specifically instructed to provide educational content appropriate for students and to avoid inappropriate topics
- Content Filtering: We configure our AI systems to filter responses that may contain inappropriate content, including violence, explicit material, or other content not suitable for educational purposes
- Safe Learning Environment: The AI is designed to maintain a respectful, educational tone and to redirect inappropriate questions to educational topics
- No Social Features: Mr Fero does not include social networking features, public chat rooms, or direct messaging between users
While we implement technical measures and AI instructions to filter inappropriate content, no automated system is perfect. AI responses are generated in real-time and may occasionally produce unexpected outputs. We continuously work to improve our content safety measures. If you encounter inappropriate content, please report it immediately to safety@mrfero.com.
Safety and Privacy Contact
If you have safety concerns, encounter inappropriate content, or have questions about privacy practices, please contact us at:
- Privacy Inquiries: privacy@mrfero.com
- Safety Concerns: safety@mrfero.com
- General Support: support@mrfero.com