On this page

Scope and meaning

This policy covers information processed by LogNormal through the app, website, support and privacy correspondence, earlier beta accounts, and TestFlight information Apple makes available to LogNormal. It does not govern Apple’s independent handling of App Store, Apple Account, payment, or TestFlight information.

“Personal information” means information that identifies, relates to, describes, can reasonably be linked with, or could reasonably be linked with a person or household. Aggregated or deidentified information that cannot reasonably be linked back to a person is not treated as personal information where applicable law allows.

The current app

The current prelaunch build reviewed for this policy is an individual learning experience that works primarily on the device. In that reviewed build, new public account creation and account controls, public cloud synchronization, online multiplayer, and camera pairing are not enabled. The paid launch build is still being prepared; this policy must be updated to match its final data behavior before App Store submission.

On a fresh installation without an earlier account session, the app does not upload exercise records or learner-authored mathematical work to LogNormal’s account service. A TestFlight build is subject to the separate Apple data flow described below. The reviewed app contains no advertising, cross-service tracking, product-analytics, or third-party crash-reporting SDK. It does not request access to location, contacts, microphone, photo library, or health data.

Information on the device

The app stores app-generated installation, attempt, and session identifiers; exercises and modes used; checked outcomes, error categories, assistance and timing; session and progress summaries; resume checkpoints; settings; and mathematical work entered where an exercise needs it for restoration. LogNormal uses these records to operate exercises, resume work, preserve progress, and shape later practice.

The app maintains several separate reporting histories. When those histories are updated, learning-event records are pruned to the most recent 2,000 and records older than 365 days; session summaries are limited to 200; dashboard attempt summaries to 500; and failure signatures to 800. These are not global limits on every local record. Canonical attempt and checkpoint files, settings, an optionally enabled local telemetry queue, and some exercise-specific authored work do not currently have equivalent count or time limits. Optional telemetry is off by default and the reviewed implementation does not upload it.

Where “Reset All Progress” is available, it clears the selected learner’s progress and reporting snapshot. It does not clear session summaries, canonical attempt and checkpoint files, settings, the telemetry queue, account credentials, or every exercise-specific record. Removing the app clears its ordinary application container. Credentials retained from an earlier account-enabled version may require account sign-out or deletion separately.

A retained earlier account session

A device that still contains an account session from an earlier beta may connect to LogNormal’s Supabase-hosted account service when the app starts. The connection may send stored authentication tokens, network request information such as IP address and request headers, an app-generated device identifier, the device name, and locally queued learning attempts and resume checkpoints. The app may retrieve account and learner identifiers, learner display name, country or region, coarse age band, account or guardian relationship, parental course controls, and synchronized learning attempts and checkpoints.

The earlier service may also hold an adult account email or display name, household roles, learner relationships and permissions, device-registration state, entitlements, and agreement or consent records. These categories support authentication, authorization, learner governance, device security, capability access, account lifecycle, and privacy requests.

LogNormal uses retained-session information only to authenticate the account, verify service compatibility, register the device and manage or enforce authorized device access, identify authorized learners, apply parental course controls, restore progress, synchronize learning history, and operate the account lifecycle described in this policy. An earlier account may have used Sign in with Apple; Apple handles that sign-in under its own privacy terms.

Account retention and deletion

Account profiles and learning history are retained while an account remains active so that a learner can preserve longitudinal progress across extended interruptions and return later. After seven years without meaningful learner or authenticated-account activity, LogNormal’s current lifecycle begins a twelve-month notice period before dormant-account deletion. The necessity and proportionality of that period for information associated with children remains part of final legal review.

When permanent account deletion is confirmed through an authorized process, access is revoked and deletion from the live account service begins immediately. There is no account-recovery window. Generated export packages expire within 24 hours. Certain minimized records remain temporarily: ended consent or agreement records may remain for up to 90 days; security and completed-deletion records for up to 30 days; and replicated restore-suppression records are scheduled for purge after 14 days. A suppression record that has not yet replicated is retained until replication succeeds.

The current guardian-authorization challenge and grant tables do not yet have a verified time-based purge. Their maximum retention period must be implemented or otherwise established before the guardian-managed account flow is release-qualified. The 90-day statement above must not be read as applying to those records.

Deletion removes information from the live account service, but deleted information may remain in a provider backup until that backup expires. The provider’s contractual maximum backup lifetime has not yet been verified and must be established before release. If a backup is restored for disaster recovery, the restored account service must remain unavailable to the app until current deletion-suppression records are reapplied and verified.

See Account Deletion for the request process.

Sources and purposes

Information comes directly from an adult or eligible self-managed learner; from activity in the app; from the device and operating system; from an earlier authenticated account session; from Apple when a person uses TestFlight, Sign in with Apple, or an App Store transaction; from a person who contacts LogNormal; and from infrastructure providers that operate the website or account service.

LogNormal uses information only as applicable to provide and secure the requested Services; authenticate accounts and authorized devices; create and govern learner profiles; preserve, synchronize, and display learning progress; restore work; administer subscriptions and entitlements; answer support and privacy requests; diagnose defects; prevent abuse; enforce agreements; comply with law; and protect users, LogNormal, and the Services.

Learning records may be used to choose or adapt later practice for that learner. LogNormal does not use them to make decisions producing legal or similarly significant effects, and the reviewed implementation does not use them for advertising or cross-service tracking.

Website and email

The website is hosted by Vercel. When a browser requests a page, Vercel may process the IP address, approximate city or country derived from the IP address, requested URL, request time, browser and device headers, and infrastructure security or diagnostic information. LogNormal has not added advertising pixels, product analytics, or marketing cookies. Vercel determines infrastructure-level retention under the applicable project configuration and its service terms. Read the Vercel Privacy Notice.

The adult question and launch-notification forms are not enabled. They do not submit or store entries. You can email contact@lognorm.al directly. Correspondence is handled through the receiving Proton Mail mailbox; include only the information needed for your request.

Support correspondence is retained for 12 months after resolution, then deleted unless an active dispute or legal obligation requires longer. Provider logs, backups, and separately retained legal or privacy-request records are not covered by this correspondence period.

Existing launch-email links use a separate confirmation and unsubscribe service backed by Supabase. Brevo delivers those emails and may process open and click events. Public signup remains disabled while email-provider tracking and retention settings are being verified. Unconfirmed requests are removed after seven days; confirmed addresses remain until withdrawal or list closure, after which a keyed suppression hash and minimal consent history are retained for two years.

The website does not process payment cards, App Store purchases, or subscription transactions.

TestFlight and Apple

If a development build is delivered through TestFlight, Apple automatically collects and may make beta-testing data available to Apple and LogNormal. Depending on how the tester was invited and what occurs, this can include the tester’s name or email, installation and session activity, crash and performance information, build and device identifiers, hardware and operating-system details, networking information, and information about use of the beta app. Optional feedback may include comments and screenshots a participant chooses to send.

LogNormal uses beta-testing data to diagnose and improve the development build. Participants should not include unnecessary personal information about a child in TestFlight feedback or screenshots. LogNormal has not yet adopted its own maximum retention period for TestFlight data and feedback; that period must be established before release. Apple separately handles TestFlight data under its TestFlight Terms and Privacy Policy.

Service providers and location

Vercel processes website delivery and infrastructure security data. Supabase hosts the earlier account service; the exact production project region and applicable data locations must be reverified before release. Apple processes App Store distribution and Apple services a person chooses, including TestFlight or Sign in with Apple.

Each provider handles information under its applicable terms and privacy notice. See the notices from Vercel, Supabase, and Apple. Information may therefore be processed in the United States and other places where those providers operate. Before public launch, LogNormal must verify the applicable provider agreements, subprocessors, locations, transfer safeguards, retention, and protections for information associated with minors. This policy does not claim that unfinished verification is complete.

Children and families

LogNormal is mathematics software intended for a broad audience of learners from age 5 through adult. It is not offered in Apple’s Kids Category, but that designation does not determine whether a children’s privacy law applies and does not remove obligations concerning children’s information. Founding Families correspondence and App Store purchases for minors are handled by adults.

On a fresh installation without a retained account session, the reviewed app does not upload exercise records or learner-authored mathematical work to LogNormal’s account service. Information associated with an earlier beta account may relate to a minor, including a learner display name, coarse age band, country or region, account relationships, and learning progress.

The approved launch design requires a learner under 13—or otherwise below the applicable jurisdictional threshold—to use a guardian-managed profile. Before LogNormal collects, uses, or discloses personal information online from or about that learner through the app, account service, TestFlight, website, or another provider acting for LogNormal—including profile or progress records and device, network, or online identifiers—the design requires direct notice and verified guardian authorization, except only for a specific activity that qualified counsel has documented may lawfully occur without prior authorization and only within that exception’s purpose and limits. The design does not give that learner independent email/password or Apple credentials or ask the learner for payment details. Teen self-management is available only where a versioned jurisdiction rule permits it; unresolved eligibility fails closed. The public launch is not release-qualified until the signed release flow, enabled territories, direct guardian notice, authorization, withdrawal, access, and deletion behavior are verified together.

LogNormal asks a parent or guardian to send correspondence concerning a child and not to include information unnecessary for the request. Once the verified privacy channel is published, an authorized parent or guardian may ask to review, correct, export, stop further collection of, or delete a child’s information. If LogNormal learns that a child submitted personal information outside an authorized process, LogNormal will review and delete it where required.

Read the dedicated Children & Family Privacy notice for the planned family-account data categories, guardian controls, and the implementation work that remains before launch.

Disclosure; no sale or targeted advertising

LogNormal discloses information to service providers only for the operational purposes described above; to Apple when a person chooses an Apple service or an App Store transaction requires it; to an account holder or guardian only when the account relationship authorizes access; and to professional advisers bound by appropriate duties when reasonably necessary.

LogNormal may also disclose information when reasonably necessary to comply with law or legal process, protect a person or the Services, investigate fraud or abuse, establish or defend legal claims, or complete a financing, merger, acquisition, reorganization, or sale of assets subject to appropriate confidentiality and successor obligations.

LogNormal does not sell personal information through the reviewed app or website, share it for cross-context behavioral advertising, use it for targeted advertising, or exchange it for a financial incentive. They contain no advertising network or cross-service tracking technology. Final release statements must also be checked against company operations and provider agreements, not only repository code.

Privacy rights and choices

Depending on where a person lives and subject to lawful exceptions, they may have the right to know or access personal information; obtain a portable copy; correct inaccurate information; delete information; withdraw consent or stop future collection; object to or restrict certain processing; opt out of sale, sharing, targeted advertising, or qualifying profiling; and appeal a denied request. A person will not receive discriminatory treatment for exercising a privacy right.

LogNormal does not currently sell or share information for targeted advertising, so an opt-out preference signal such as Global Privacy Control does not change the website’s behavior. If those practices ever change, LogNormal must update its notices and honor legally required preference signals before the change begins.

An authorized agent may submit a request where law permits. LogNormal may verify identity, account relationship, residence, or guardian authority using information proportionate to the request, and will not ask for a password or authentication token. If a request is denied, the response will explain any appeal method required by applicable law. A requester may also contact the competent privacy or consumer-protection regulator.

The receiving inbox is available, but the identity-verification and privacy-request workflow is not yet release-qualified. See Contact for the current way to reach LogNormal. Access, correction, export, deletion, guardian, and appeal procedures must be tested before release.

contact@lognorm.al

International use

Launch territories have not yet been finalized. If LogNormal offers account services in a jurisdiction that requires a particular legal basis, local representative, privacy officer, transfer safeguard, child-consent rule, or complaint process, that requirement must be in place before the territory is enabled.

Where applicable, LogNormal expects to process information as necessary to perform its contract with the account holder, based on consent for processing that requires consent, to comply with legal obligations, and for legitimate interests such as security, support, and improving a requested service where those interests are not overridden by a person’s rights. This paragraph is not a claim that every territory-specific launch requirement has been completed.

Security

The reviewed app writes its canonical attempt-and-checkpoint file using iOS data protection available after first device unlock and stores retained account credentials using iOS Keychain services. The current implementation uses more than one Keychain storage path with different accessibility settings. The release security and disclosure review must verify the final behavior rather than treating every credential store as identical.

No storage or transmission method can be guaranteed completely secure. If you believe an earlier account or correspondence has been compromised, review the Support page for current channel status.

Changes and contact

We may update this policy when the product, providers, law, or data practices change. The effective date identifies the current version. Material changes will receive notice or consent when required, and prior versions should be retained so the applicable disclosure can be reconstructed.

The receiving inbox is available below. Approved public operator details, correspondence handling, and any required territory-specific representative must be completed before the corresponding release.

LogNormal LLC
Wyoming, United States
9370 Nineveh Road, Nineveh, IN 46164, United States

contact@lognorm.al