Skip to main content
Zoora

Privacy Policy

Last updated: 26 July 2026

This policy explains what data Zoora collects, how it is used, and what choices you have. It is written to be short and readable.

01Who this policy covers

This policy covers the zoora.ir website and the Zoora service — both the marketing pages and the parts that work once you have signed in.

  • You need no account to browse the website and read the marketing pages.
  • Organizations start by filling in the get-started form.
  • The Students, Teachers, and Managers of an Organization get their accounts from that Organization; there is no personal sign-up on Zoora.

02Who controls your data

Zoora is a multi-Organization system. Every User, Class, and record belongs to one Organization, and the answer here depends on the role in which you deal with us.

  • If you have visited the Zoora website, filled in the get-started form, or are an Organization's billing contact, Zoora itself controls that data.
  • If you are a Student, Teacher, or Manager of an Organization, that Organization controls your data; Zoora processes it only on the Organization's instruction.

That is why requests to access, correct, or delete coursework data go to your Organization rather than to Zoora. The Organization decides what is recorded, how long it stays, and when it is removed. If such a request reaches us directly, we will point you to your Organization and will not alter the data without that Organization's instruction.

03What data we collect

Data reaches Zoora along several routes. We list each group separately so that it is clear what is recorded and where it came from.

From the get-started form

  • Your name.
  • Your phone number.
  • The name of the Organization you are asking on behalf of.
  • An optional note, if you wrote one.
  • The plan you clicked on before the form opened.
  • A hidden anti-bot field that human users never fill in and that serves only to block automated submissions.

The accounts your Organization creates

  • Your name and username.
  • Your password, which is stored as a hash, never in readable form.
  • Your role in the Organization and the permissions that role grants.
  • Any extra profile field the Organization's Manager has defined. Which fields are asked for is the Organization's decision, not Zoora's.

What you create in the service

  • Classes and Class enrolments.
  • Quizzes and the answers given to them.
  • Chat messages and Q&A messages.
  • Polls.
  • Files you upload.
  • Whiteboard content.
  • Attendance and grades.

Recordings of Live Sessions

  • The host of a Class can record the session; when they do, video, audio, and any shared screen are recorded.
  • The recording file is kept in Zoora's storage, in that Organization's own area, separate from other Organizations'.

Technical records

  • For sensitive actions we keep a record of who did the action and when, together with the IP address and the browser user-agent of the device.
  • When quiz answers are finally submitted, a snapshot of your device is recorded: the device type (mobile, tablet, or computer), the operating system, the browser, and the raw browser user-agent. Only the Teacher sees this, and it is stripped out of the Student-facing views.
  • If the Organization turns on location checking for a quiz, your browser is asked for your location when the quiz starts, and the approximate coordinates and their accuracy are recorded. If you refuse, the refusal itself is recorded rather than your location. This is used only to show which Students sat close to one another, and only the Teacher sees it.
  • In quizzes where the Organization has turned on leaving-the-page monitoring, the number of times you left the quiz window and the total time away are recorded. Your browser reports these counts, they are not conclusive proof of cheating, and only the Teacher sees them.

Payments

  • Zoora keeps invoices and payment records.
  • Payment happens on the online payment gateway and your bank card details are entered on the gateway's own pages; those details never reach Zoora.

The notification channels you link yourself

Your Zoora account has no phone number and no email address. If you also want notifications outside the app, you link a channel to your account yourself, and we keep only that address as a notification destination:

  • A phone number, for SMS notifications. The number is confirmed with a one-time code.
  • Your chat id on Telegram or Bale, if you connect the notification bot to your account.
  • A device token, for notifications on your phone or in your browser. A separate token is recorded for each device.

Linking any of these is optional and you can unlink it at any time. Until you link one, notifications appear only inside the app itself.

04What is stored in your browser

Zoora sets no tracking or advertising cookies, and has no behavioural analytics or cross-site tracking. The only cookie we set is functional: it remembers whether you left the app's sidebar open or collapsed. Beyond that, a few values are kept in your own browser's storage so the app can work:

  • Your sign-in token, so that you do not sign in again every time you open a page.
  • Draft answers to a quiz in progress, so that refreshing the page does not lose your answers.
  • The language and the light or dark theme you chose.
  • For platform administrators, the list of recently visited Organizations.
  • The fact that you dismissed the install-the-app prompt, so that it is not shown again.

These values stay on your own device, and clearing your browser's storage deletes them. Signing out clears the sign-in token.

05How we use data

We use data only for the things the service cannot work without:

  • Running and maintaining the service and keeping it secure.
  • Creating Classes and quizzes, and recording and grading coursework and grades.
  • Delivering notifications to you.
  • Issuing invoices and taking payment.
  • Investigating abuse and security incidents with the help of the records kept for sensitive actions.
  • Answering the messages you send to our contact addresses.
  • Improving the stability and quality of the service.

We do not sell your data, and we do not use it to build an advertising profile or to show targeted ads.

06AI-assisted grading

If your Organization's plan includes it and a Teacher starts AI grading for a quiz, we send the question text, its model answer, and the text of the Student's descriptive answer to an external AI processing service. That service may be located outside Iran.

  • The Student's name, username, and id are not sent; what is sent is the question text, its model answer, and the Student's answer text.
  • The Teacher chooses whether the result is recorded only as a suggested grade or applied directly as the grade. Either way, the AI's short explanation stays on the answer.
  • The final grade is always the Teacher's; a Teacher's manual grade takes precedence over the AI suggestion and is not overwritten by it.
  • Until a Teacher starts AI grading, no answer is sent for processing.

If your Organization does not want answers sent to an external service, it simply does not use AI-assisted grading; every other part of the system works without it.

07Who we share data with

We share data only with the service providers Zoora needs to work, and only for that work:

  • Service hosting and file storage.
  • Delivering live audio and video in Classes.
  • The online payment gateway.
  • The service that delivers notifications to phones and browsers.
  • The SMS provider, only if you have linked a phone number for notifications yourself.
  • Telegram or Bale, only if you have connected the notification bot to your account yourself. In that case the text of the notification passes through that messenger.
  • The AI processing service described in the AI-assisted grading section.

We also hand data to a competent legal authority, to the extent the law requires it of us. We do not share your data with advertisers.

08Where data is processed

Zoora is built and hosted for the Iranian market.

There are two exceptions: the AI processing described above may happen outside Iran, and some of the service providers whose categories are named in the previous section may also process data outside Iran.

09How we protect data

Data is protected in several layers:

  • Reaching an Organization's data always requires authentication.
  • Each Organization's data is kept separate from every other Organization's data.
  • What a User sees is limited to the permissions of their role.
  • Traffic between the browser and the service is encrypted in transit.
  • Sensitive actions leave an auditable record behind them.

Even so, no system is completely secure and we cannot guarantee absolute security. Keeping your password and sign-in details safe is up to you and your Organization.

10How long we keep data

For as long as your Organization is active, its data stays available to it. If an Organization is suspended, its data remains but is no longer reachable. When an Organization is deleted outright, its records are removed from the database and its stored files — including Live Session recordings and uploaded files — are purged from storage by a background job.

There is one exception: some plans set a retention period for Live Session recordings, and recordings older than that period are deleted automatically. The period is part of your Organization's plan and is stated in the plan's description.

We keep some financial and security records for as long as the law requires. Apart from the case above, when coursework data is deleted is your Organization's choice; taking a backup of the data before the account is closed is the Organization's own responsibility.

11Your rights and how to use them

You can ask what data is held about you, ask for incorrect data to be corrected, and request that your data be deleted.

  • If you belong to an Organization, send the request to that Organization; the decision is theirs.
  • If you contacted us through the website, or you are an Organization's billing contact, write to privacy@zoora.ir.

Before we act on a request, we ask for enough information to establish who you are, so that one person's data does not reach someone else.

12Children and Students under 18

Accounts are created by Organizations, not by Students. A Student cannot sign up on Zoora on their own.

Where a user is under 18, the Organization confirms by creating the account that it has the legal authority to do so and has obtained the consent required — including parental or guardian consent, to the extent the law requires it — to create the account, to record sessions that user appears in, and to process their coursework.

Zoora does not knowingly collect data from children directly, outside the framework of an Organization. A parent or legal guardian with a concern should contact the Organization first, and may also write to privacy@zoora.ir if needed.

13Changes to this policy

Every time this policy changes, the update date at the top of this page is refreshed.

If a change is significant, we tell Organizations through the service itself. Continuing to use Zoora after a change means the new version applies to you.

14Language

This policy is published in Persian and English.

This English text is a translation provided for convenience. If it conflicts with the Persian version, the Persian version governs.

15Contact us

You can write to us with any question about this policy:

  • Privacy questions and requests about data: privacy@zoora.ir
  • Anything else: support@zoora.ir