LEGAL
Terms of servicePrivacy policyRefund policyCookie policy
Questions about any of this?
legal@hileila.com

Privacy policy

Last updated 21 September 2026Gridwork Ltd, Ras Al Khaimah

Leila handles information about children. That raises the bar, so this policy sets out exactly what we collect, why, who else touches it and what you can make us do about it. We hold ourselves to the UAE Personal Data Protection Law and to GDPR children’s-data standards, whichever is stricter in a given case.

01

Who controls your data

Gridwork Ltd (licence 07011194), of Office A, Innovation Business Center, RAK BANK ROC Office, Ground Floor, Al Rifaa, Sheikh Mohammed Bin Zayed Road, Ras Al Khaimah, United Arab Emirates, is the controller of the personal data described in this policy.

Our data protection contact is privacy@hileila.com. Write there for anything in this document and a person will answer.

02

What this covers

This policy covers the Leila website, the Leila apps, and everything we do with the information you or your approved senders give us. It does not cover a school’s own systems, your email provider, or any other site we link to — those have their own policies.

03

What we collect

Account data: your name, email address, mobile number, the city you nominate and the number of children in your household.

Family data: each child’s name, year group, school, classes, activities, allergies and medical notes you choose to record, routines, and who is permitted to collect them.

Connected-source data: the content of messages from school and activity senders you have specifically approved, and entries from calendars you choose to sync.

Payment data: handled by Stripe. We receive a payment reference, the amount, the result and the last four digits of the card. We never see or store the full card number.

Support data: what you write to us, and our replies.

Usage data: device type, browser, approximate location derived from IP address, and which pages and features you use. Analytics are only collected if you accept cookies.

School portal credentials, if you choose to connect one. Only the portals you connect, only the username and password that portal needs, and never a password you use anywhere else. See section 17.

04

What we deliberately do not collect

We do not read mail from senders you have not approved. Approval is per sender and you can revoke it at any time.

We do not ask for or store passwords to third-party sites, with one exception you choose and control: a school portal you explicitly connect. Section 17 sets out exactly what that means, what we hold and how to end it. We will never ask for a password to your email, your bank, or anything else.

We do not buy contact lists, we do not enrich your record from data brokers, and we do not sell personal data to anyone, for any price, ever.

We do not use your family’s content to train third-party AI models. Our model providers are contracted on zero-retention, no-training terms.

05

Why we use it

To run the service you asked for: reading approved messages, preparing forms, drafting replies, keeping each child’s record, briefing the household members you nominate, and telling you what needs a decision.

To take payment, prevent fraud and meet our accounting and tax obligations.

To answer you when you write to us.

To keep the service secure and working, and to improve it. Where we analyse usage to do that, we work from aggregated, de-identified statistics.

06

Our legal bases

Performance of our contract with you, for everything needed to deliver the service and take payment.

Your consent, for each connected source, for analytics and marketing cookies, and for any marketing message. Consent can be withdrawn at any time and withdrawing it is as easy as giving it.

Our legitimate interests, for security, fraud prevention and service improvement — balanced against your rights, and never where those rights come first.

Compliance with a legal obligation, for tax records and for a lawful order from a competent authority.

07

Children’s information

Children do not hold accounts and we do not market to them. Their information is provided by a parent or guardian, is used only to deliver the service to that household, and is never used for advertising, profiling or audience building.

A child’s medical and dietary information is treated as sensitive. Leila will surface it where it is needed — on a consent form, in a brief to a carer — but she will never change it without your explicit approval.

When a parent account is deleted, the children’s records in it are deleted with it.

08

Who else touches it

A short list of processors, each under a written contract and each limited to what they need: Stripe for payments; a cloud provider for hosting, storage and compute; an email and messaging platform for transactional and, where you have opted in, marketing messages; and AI model providers for language processing under zero-retention, no-training terms.

We publish the current list on request to privacy@hileila.com. If we add a processor that materially changes how your data is handled, we will tell you before it starts.

09

Where it lives and where it goes

Data is stored in the region you are served from. Where a processor necessarily operates across borders, we rely on recognised safeguards — standard contractual clauses, or an adequacy decision — and we keep a record of which applies to whom.

We will not move your data to a jurisdiction with materially weaker protection without telling you first.

10

How it is protected

Encrypted in transit and at rest. Access limited to the staff who need it for a specific task, granted individually, logged, and reviewed.

School portal credentials are held under a second layer of encryption with a key that is not in the database, so a copy of the database alone does not yield them. They are decrypted only at the moment a task you approved runs, they are never written to a log, an error report or a backup in readable form, and they are never sent to an AI model.

Multi-factor authentication on every internal system that can reach customer data. Separate credentials for production. No copying live family data into a test environment.

If a breach occurs that is likely to result in a risk to you, we will notify you and the UAE Data Office without undue delay, and tell you what happened, what we did and what you should do.

11

How long we keep it

Account and family data: for as long as your account is open, then 30 days after you close it, then deleted.

Message content: the summary is kept while the account is open; the original message is kept for 12 months unless you delete it sooner.

Payment and tax records: 5 years, because we are required to keep them.

Support correspondence: 2 years.

Backups are overwritten on a rolling cycle and a deletion propagates to them within 35 days.

12

Your rights

You have the right to be informed, to access, to correct, to delete, to restrict processing, to object, to data portability, and to withdraw consent.

Most of these you can exercise yourself: you can export everything Leila knows about your family, or delete the account and its whole history, from inside the product without asking us.

For anything else, write to privacy@hileila.com. We respond within 30 days and will tell you promptly if a request will take longer and why. We will not charge you for a reasonable request.

We will ask you to verify your identity before acting on a request about family data. That is a protection for you, not an obstacle.

13

Automated processing

Leila summarises, classifies and drafts automatically. She does not make decisions that have a legal or similarly significant effect on you — the approval boundary in the terms means anything consequential waits for a human.

If you think she has got something wrong about your family, tell us and we will correct it and, where we can, fix the cause.

14

Marketing

We will only email or message you about things you did not ask for if you have opted in, and every such message carries a one-click unsubscribe that works.

Transactional messages — a receipt, a security alert, a notice about a change to these terms — are not marketing and you cannot opt out of them while you hold an account.

15

Cookies

Our use of cookies and similar technologies, and the choices you have, are set out in the cookie policy.

16

Complaints

Write to privacy@hileila.com first and give us a chance to fix it. If you are not satisfied you have the right to complain to the UAE Data Office, or to the supervisory authority where you live.

17

School portals

You can connect a school portal — Seesaw, a GEMS portal, ClassDojo and others — so that Leila can read what the school posts there and prepare things you would otherwise fill in by hand. This is optional. Everything else in Leila works without it.

To do that we need the username and password you use for that portal, and we store them. We said in an earlier version of this policy that we never would. We changed that deliberately rather than quietly, because the alternative was a copilot that cannot see the place most school information now lives.

What we hold: the username and password for each portal you connect, and a session cookie while a task is running. What we do with them: sign in to that portal, read what is there, and fill in forms you have approved. What we never do: use them anywhere other than the portal you connected them for, share them with anyone, or send them to an AI model. The model that reads a page never receives the credential that opened it.

Nothing is submitted without you. Leila prepares the form, shows you every value she intends to enter, and waits. A submission or a payment is irreversible in a way an email is not, so these wait for a separate confirmation from you even when you have approved similar things before.

You can disconnect a portal at any time from Settings, which deletes the credential immediately rather than marking it inactive. Deleting your account deletes them with everything else. If you change the password at the school’s own site, ours stops working and Leila will tell you rather than retrying and locking you out.

Please change the password if you stop trusting us with it, and please do not give us a password you use for anything else. We will tell you if we ever detect that a portal credential has been accessed in a way we did not expect.

18

Changes to this policy

If we change this policy in a way that materially affects you, we will email you before the change takes effect. The date at the top is always the version you are reading, and we keep previous versions on request.

This page is written to be read. If anything here is unclear, ask and a person will answer.
Write to us
Leila