PRIVACY NOTICE
How Ajir Research Labs collects, uses, stores, and protects your personal data and your content on AskNoema.
Last updated: 24 July 2026. This notice takes effect on the date AskNoema is made publicly available and applies to all users of AskNoema.
1. Introduction and Scope
This Privacy Notice explains how Ajir Research Labs (“Ajir”, “we”, “us”, “our”) handles personal data when you use AskNoema and any related websites, applications, and services (together, the “Service”). It describes what we collect, why, the legal bases we rely on, how long we keep it, who we share it with, how we protect it, and the rights and choices available to you. It should be read together with our Terms of Service and our AskNoema AI Policy.
2. Definitions
- Personal data — any information relating to an identified or identifiable natural person.
- Sensitive personal data — data revealing, among other things, health, ethnicity, religious or political beliefs, or sexual orientation, as defined under the Data Protection Act, 2019.
- Processing — any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
- Data controller — the party that determines the purposes and means of processing. For the Service, this is Ajir Research Labs.
- Data processor — a party that processes personal data on the controller’s behalf.
- User content — the media you upload and the prompts, questions, or feedback you submit to AskNoema.
- Child — a person under the age of eighteen (18), consistent with Kenyan law.
3. Who We Are
Ajir Research Labs is the data controller for the personal data described in this notice. We are based in Kenya and are undertaking registration with the Office of the Data Protection Commissioner (ODPC) as a data controller under the Data Protection Act, 2019. For any privacy matter, including exercising your rights, contact privacy@ajirresearch.com.
4. The Law We Follow
AskNoema launches Kenya-first, so our primary framework is the Constitution of Kenya, 2010 (Article 31 — the right to privacy), the Data Protection Act, 2019 (DPA 2019), and the Data Protection (General) Regulations, 2021. We also align our data-governance practices with the Kenya Artificial Intelligence and Other Emerging Technologies Policy, 2026, which reinforces privacy, human oversight, transparency, and enhanced protection of vulnerable groups.
As the Service expands globally, additional protections apply to users in those regions — the EU General Data Protection Regulation (GDPR) and the EU AI Act for users in the EU/EEA, and the California Consumer Privacy Act (CCPA/CPRA) if and when we launch in California. Where obligations differ, we apply the standard most protective of you.
5. Personal Data We Collect
a. Data you provide directly. Account details (such as your email and, if provided, a display name and authentication credentials); the content you upload to the Service; the prompts, questions, and feedback you submit to AskNoema; and any messages you send us for support.
b. Data we collect automatically. Activity and engagement data (items you view, watch time, interactions, in-app search history, and metadata we derive such as item identifiers, timestamps, extracted topics, transcripts, and audio/visual tags); device and connection data (IP address, device type, operating-system version, network information, and session events); and data stored through strictly-necessary cookies and local storage used for session continuity and security.
c. Sensitive data by inference — please read. AskNoema analyses the content you upload and view, and the topics of that content can imply sensitive personal data — for example political opinions, religious beliefs, health, or sexual orientation. This is “sensitive personal data” under the DPA 2019 (s. 44) and a “special category” under the GDPR (Art. 9). We do not ask for such data directly, we do not build sensitive-interest profiles for advertising, and we process it only as necessary to analyse the specific content you have chosen to submit — under the conditions in section 25 of the DPA 2019, and, for EU users, with your explicit consent where the law requires it.
6. How We Use Your Data, and Our Lawful Basis
We process personal data only where the law provides a basis to do so (DPA 2019 s. 30; GDPR Art. 6):
- Account creation and authentication — to provide the Service to you. Basis: performance of a contract.
- Hosting and displaying your uploaded content — to operate the core Service. Basis: performance of a contract.
- Content analysis and veracity assessment (AskNoema’s core function) — Basis: performance of a contract, and our legitimate interest in reducing misinformation.
- Personalisation and recommendations (profiling based on your engagement and topics) — Basis: consent. You can turn personalisation off without losing the core Service; this profiling is not strictly necessary.
- Product-improvement analytics — Basis: legitimate interest, using pseudonymised or aggregated data.
- Safety, moderation, and prevention of illegal use — Basis: legal obligation and legitimate interest in a safe platform.
- Compliance, audit, and security records — Basis: legal obligation.
- Service communications — Basis: contract; any marketing is separate and strictly opt-in.
7. How We Do Not Use Your Data or Your Content
We place firm limits on ourselves. Specifically:
- We do not sell, rent, or license your personal data or your content to advertising networks or data brokers.
- We do not use your uploaded content for marketing or advertising of any kind.
- We do not use your content to create deepfakes, synthetic media, AI-edited imagery, or any manipulated media, and we do not use it to train systems for those purposes.
- AskNoema has no AI media-generation capability by design: it produces only text-based analysis (reasoning summaries and claim annotations) and never generates or edits images, audio, or video. This is a deliberate safeguard against malicious AI use.
- We do not use third-party advertising cookies, device fingerprinting, or cross-app tracking.
8. Your Content: Storage, Control, and Deletion
Like other social platforms, the content you upload remains available in your account until you choose to delete it. You are in control: you can delete individual items or your whole account at any time, and deletion removes the content from the active Service.
After you delete content, residual copies may persist briefly in secure backups before being overwritten in the ordinary course. We may also retain specific content for a limited period where retention is required to comply with the law, to respond to a lawful order, or to preserve evidence in connection with actual or reasonably anticipated legal proceedings, an investigation, or a safety or abuse matter. Once that purpose ends, the content is deleted.
9. Acceptable Use and Prohibited Content
The Service may not be used to upload, store, or distribute illegal content. Prohibited content includes, without limitation, child sexual abuse material; non-consensual intimate imagery; pornographic or sexually explicit material; content depicting graphic violence or gore; content that incites violence, terrorism, or hatred; and any other material unlawful under Kenyan law, including the Computer Misuse and Cybercrimes Act, 2018, the Sexual Offences Act, 2006, and the Films, Stage Plays and Publications Act.
Uploading prohibited content may result in immediate removal of the content, suspension or permanent banning of your account, and, where the law requires, preservation of the content and reporting or disclosure to the relevant authorities. As an intermediary, we cooperate with lawful takedown orders and investigations in line with the Computer Misuse and Cybercrimes Act, 2018. Detailed community and acceptable-use rules are set out in our Terms of Service.
10. AI Processing, Automated Decisions, and AI Transparency
AskNoema is context-locked to the item you are viewing. When you activate it, the relevant content and your prompt are processed by our reasoning system and, where applicable, by third-party AI model providers as service providers, solely to generate your requested analysis. These are transient processing calls, not data-sharing partnerships: we do not sell or hand over your data to those providers for their own purposes, and your content is not used by us to build advertising or sensitive-interest profiles.
You are always interacting with an AI system, not a human expert. We state this in line with our transparency principle and, for EU users, the EU AI Act (Art. 50).
Automated decisions. AskNoema’s assessments (such as claim annotations and veracity signals) are decision-support, not final decisions about you. No decision producing legal or similarly significant effects on you is made solely by automated means without a human-review pathway. You may contest any assessment and request human review (see section 14). This reflects your right under the DPA 2019 (s. 35) and the GDPR (Art. 22).
11. Cookies and Similar Technologies
We use only first-party, strictly-necessary cookies and local storage for session continuity, security, and remembering your preferences. These are essential to operate the Service and are exempt from consent requirements, though we inform you of their use here. We do not use analytics, advertising, or tracking cookies from third parties.
12. How Long We Keep Your Data
We keep personal data only as long as necessary for the purposes described, in line with the storage-limitation principle (DPA 2019 s. 25; GDPR Art. 5). In practice:
- Uploaded content and AI interaction history — kept until you delete them or close your account (see section 8), subject to limited legal-hold retention.
- Account data — kept for the life of your account and a short period after closure.
- Pseudonymised analytics — retained in aggregate form only.
- Safety, moderation, compliance, and audit records — retained for as long as applicable law requires.
13. Sharing and International Transfers
We do not sell your personal data. We share it only with categories of service providers who process it on our behalf under written data-processing agreements, and only to the extent necessary. These categories are: cloud hosting and infrastructure providers; third-party AI providers (AI companies) engaged to power content analysis; and security, error-telemetry, and support tools (whose logs use session identifiers, not full personal content).
Some providers are located outside Kenya. We transfer personal data abroad only where we can demonstrate an appropriate legal basis under the DPA 2019 (ss. 48–49) — such as adequacy or appropriate contractual safeguards — and, for sensitive personal data, on the basis of your explicit consent in addition to those safeguards. For EU users, transfers rely on GDPR Chapter V mechanisms.
14. Your Rights
Under the DPA 2019 (s. 26) you have the right to be informed; to access your data; to have inaccurate data corrected; to have your data erased (subject to lawful retention); to object to processing based on legitimate interest; to data portability; and not to be subject to a decision based solely on automated processing. EU users have equivalent rights under the GDPR, and California users under the CCPA/CPRA when applicable.
Response times we honour:
- Kenya: access requests within 7 days; correction and erasure within 14 days (Data Protection (General) Regulations, 2021).
- EU/EEA: within one month, extendable by two months for complex requests (GDPR Art. 12).
- California (when applicable): within 45 days (CCPA).
To exercise any right, email privacy@ajirresearch.com. We will not discriminate against you for exercising your rights.
15. Security
We use technical and organisational measures designed to protect your data, including encryption in transit and at rest, access controls limited to authorised personnel, and regular security reviews. No system is perfectly secure, but we work to protect your data and to detect, contain, and remediate incidents promptly.
16. Data-Breach Notification
If a personal-data breach occurs, we will notify the ODPC within 72 hours of becoming aware where the law requires (DPA 2019 s. 43), and affected users without undue delay where the breach is likely to result in high risk to their rights. EU users are additionally covered by the GDPR (Arts. 33–34).
17. Law-Enforcement and Legal Disclosure
We may disclose personal data where we are legally required to do so — for example, in response to a valid court order, warrant, or lawful request from a competent authority — or where disclosure is necessary to protect the rights, safety, or property of users, the public, or Ajir Research Labs. We assess each request for validity and disclose only what is legally required.
18. Complaints
If you have a concern, please contact us first at privacy@ajirresearch.com. You also have the right to complain to a regulator: in Kenya, the Office of the Data Protection Commissioner (ODPC); in the EU/EEA, your local Data Protection Authority.
19. Changes to This Notice
We may update this notice, for example to reflect new laws, regulators’ guidance, or features. When we do, we will revise the “Last updated” date and, for material changes, notify users before the changes take effect.
20. Contact
For any question about this notice or our data practices, contact our privacy team at privacy@ajirresearch.com.