Privacy Policy
Last updated: 2026/07/20
Privacy Policy
Last Updated: March 2026
Introduction
This Privacy Policy explains how we collect, use, share, and protect personal information when you use this application ("App"). By using the App, you agree to the practices described in this Policy.
Information We Collect 1. Information You Provide
- Account information: Email address, username, date of birth (age verification only), language preference
- Profile information: Display name, avatar (optional)
- Feedback and support: Messages and attachments you send through the in-app feedback feature
2. Information We Collect Automatically
- Usage data: Questions answered, learning progress, streaks, scores, session duration, features used
- Device information: Device model, operating system version, app version, platform (iOS/Android/Web)
- Push notification tokens: Device tokens for delivering push notifications (stored and processed by Apple APNs / Firebase FCM)
- Log data: IP address, timestamps of login events (retained for 6 months for security purposes)
3. Information from Third-Party Platforms
- Subscription status: RevenueCat provides us with your subscription entitlement status and anonymized purchase history. We do not receive your full payment details.
- Platform identifiers: An anonymous identifier from your Apple ID or Google account used to verify your subscription.
How We Use Your Information
We use collected information to:
- Create and maintain your account
- Deliver the app's features (questions, progress tracking, performance reports, streaks)
- Send push notifications and email digests you have opted into
- Process and verify your subscription
- Detect and prevent fraud and unauthorized access
- Monitor app errors and fix crashes
- Improve our application using aggregated, anonymized analytics
- Comply with legal obligations
We do not use your information for advertising or sell it to data brokers.
Sub-Processors and Third-Party Service Providers
We share personal data with the following service providers who process data on our behalf under contractual obligations to protect your data:
Service Provider Country Data Shared Purpose Subscription management RevenueCat, Inc. USA Anonymous user ID, subscription status, purchase history, app version Subscription and entitlement verification Error monitoring Functional Software, Inc. (Sentry) USA Device type, OS version, app version, error stack traces (no PII by default) Crash reporting and error monitoring Push notifications (Android) Google LLC (Firebase FCM) USA Android device push token Delivering push notifications on Android devices Push notifications (iOS) Apple Inc. (APNs) USA iOS device push token Delivering push notifications on iOS devices App delivery & OTA updates 650 Industries, Inc. (Expo/EAS) USA App bundle, device metadata App distribution and over-the-air updates Application hosting [TO BE SET IN ADMIN PANEL] [TO BE SET IN ADMIN PANEL] All account and usage data stored in our database Hosting and operating the application
All sub-processors are required to process data only on our instructions and in compliance with applicable data protection laws. Where required by law (GDPR, APPI), we have or will enter into Data Processing Agreements (DPAs) with these providers.
In addition, the following companies act as independent data controllers for their own services:
- Apple Inc.: Controls data related to App Store purchases and Apple ID services
- Google LLC: Controls data related to Google Play purchases and Play services
International Data Transfers
Our App is operated primarily from Japan. Our sub-processors (listed above) are located in the United States. When personal data is transferred from the European Economic Area (EEA) or Japan to the United States:
- Transfers from the EEA are protected by Standard Contractual Clauses (SCCs) or other appropriate safeguards under GDPR
- Transfers from Japan are made under measures compliant with APPI Article 24 cross-border transfer requirements
Data Sharing
We do not sell your personal information. We do not share personal information for cross-context behavioral advertising.
We may disclose personal information when:
- You have given explicit consent
- Required by applicable law, court order, or valid legal process
- Necessary to protect life, safety, or property
- As described in the sub-processor table above (service provision)
Data Protection
We implement appropriate technical and organizational security measures including:
- Encryption of data in transit (TLS 1.2+) and at rest
- Access controls and authentication on backend systems
- Regular security assessments
- Principle of least privilege for data access
User Rights
Depending on your location, you may have the right to:
- Access: View your personal data through your in-app profile
- Correction: Update your data in profile settings
- Deletion: Delete your account via Profile → Delete Account. This anonymizes your personal identifiers.
- Data portability: Request a copy of your data in machine-readable format via the in-app feedback feature
- Opt-out of data sale: Toggle available in Profile → Privacy Settings (we do not sell data, but this flag is honored)
- Withdraw consent: For notifications — disable in app or device settings; for email digests — use the unsubscribe link
We will respond to verifiable requests within 30 days (45 days for CCPA). For requests, use the in-app feedback feature or the account deletion flow.
Use of Cookies and Local Storage
Our website uses only strictly necessary cookies (session, CSRF token, and a cookie that stores your analytics consent choice). The mobile app uses secure device storage (iOS Keychain / Android Keystore) for authentication tokens and preferences. See our Cookie Policy for details.
We do not use any advertising or tracking cookies or third-party tracking pixels.
Website Analytics
Our website uses privacy-friendly, cookie-free page view statistics: no IP addresses are stored, visitor identifiers are anonymized and rotate daily (so visits cannot be linked across days), and no data is shared with third parties. Visitors in the EU/EEA, United Kingdom, and Switzerland are only included in these statistics after giving explicit consent via the consent banner. Any visitor can decline or withdraw consent at any time using the "Privacy Settings" link in the website footer.
Data Breach Notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay (within 72 hours where required by GDPR Article 33) and will inform affected users without undue delay, in accordance with GDPR Article 34, the Japanese Act on the Protection of Personal Information (APPI), and other applicable laws.
Children's and Minors' Privacy
This App is open to users of all ages, with protections that scale to a user's age (see the Terms, "Age Requirements and Minors"). We collect date of birth at registration to determine the applicable protections and the digital-consent age for the user's region.
For children below their region's digital-consent age (for example, under 13 in the US under COPPA), we obtain verifiable parental consent before using the child's personal information, collect only what is needed, do not use behavioural tracking or targeted advertising, do not sell or share their data, and do not permit in-app purchases. At registration we collect a guardian email solely to request consent and send the required parental notice. For teens (their region's consent age up to 18) we apply the same data minimisation and no purchases.
Parents and guardians have the right to review the personal information collected from their child, refuse to permit its further use, withdraw consent, and request deletion. If consent is withdrawn or not provided within our grace period, the child's account and personal data are deleted (the immutable consent record is retained as proof of compliance). To exercise these rights, contact us via the in-app feedback feature or the contact form on our website. We comply with COPPA (US), the GDPR child provisions (EU/UK), and Japan's APPI, as applicable.
Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by posting a notice within the App and updating the "Last Updated" date. Continued use of the App after changes constitutes acceptance of the updated Policy.
Contact
For privacy-related questions or requests, please use the in-app feedback feature.
For EU/EEA users, see our Data Processing Information (GDPR) document for additional information. For California residents, see our CCPA Privacy Notice. For Japan residents, see our APPI Compliance Notice.