Privacy policy (placeholder)

This page describes how the product actually handles data. It is a placeholder, not a legally reviewed privacy policy.

What we collect

  • Account: email address, a hashed password, and role (student / parent / teacher / admin).
  • Profile: display name (a nickname is encouraged), interface language, and level.
  • Learning data: lesson progress, answers, mistake records, review schedule, mastery scores, and study time.
  • Security logs: successful and failed sign-ins. IP addresses are stored only as a salted hash.

What we do not collect

  • Students are never required to give a real name.
  • No date of birth, home address, identity document number, school name, or photograph.
  • No third-party advertising or analytics trackers of any kind.
  • No cross-site tracking cookies. Only a session cookie and a language preference cookie are set.

Who can see learning data

  • The student themselves.
  • A parent whose link has been verified with a code and is in the "active" state.
  • Teachers and admins, within their teaching and content responsibilities. Such access is recorded in the audit log.
  • Children’s data is never sold or shared with third parties.

Retention and deletion

Account deletion is a soft delete: the account stops working immediately, learning data is retained briefly so an accidental deletion can be undone, and is then removed permanently. The exact retention period must be decided before launch.

What is not finished

This build has no mail transport configured. Email verification and password reset are modelled in the schema but cannot actually send mail. Both must be completed before launch, and Singapore’s Personal Data Protection Act (PDPA) together with requirements for handling minors’ data must be reviewed by a qualified professional.

This page is placeholder content for a demonstration build. The product makes no claim of compliance with the law of any jurisdiction.

Privacy Ā· LionLearn SG