LEGAL / PRIVACY
Privacy Policy
Working draft for the founding release ยท Updated July 14, 2026
1. Scope and operator
This policy applies to the LogNormal website, founding-reservation process, iOS application, parent and learner accounts, support channels, and authorized tutor or institution access. The service is currently presented under the LogNormal product name. The final legal operator identity and formal notice address will be published before production account processing begins.
2. Data categories
- Account data: names, email addresses, roles, household relationships, authentication and account status.
- Learner profile data: profile name or identifier, selected courses, starting coordinate, preferences, and parent-controlled permissions.
- Mathematical activity: exercises shown, learner decisions, steps, repairs, accuracy, timing, consistency, and progress derived from that activity.
- Device and reliability data: app version, operating-system version, device class, crash or diagnostic events, and security signals when enabled.
- Founding and payment records: tier, commitment amount, reservation state, notices, cancellation state, gift or OpenSeat status, and payment-provider tokens or status. LogNormal does not need the complete payment-card number.
- Communications: support, privacy, security, legal, pilot, and Founder communications.
- Website data: ordinary server logs and security events. LogNormal does not currently promise a particular analytics vendor or advertising profile.
3. Purposes
- Provide mathematical training, progress evidence, family controls, and authorized sharing.
- Operate accounts, synchronize state where enabled, secure the service, diagnose faults, and prevent abuse.
- Manage conditional Founding reservations, notices, gifts, OpenSeat commitments, and related support.
- Improve exercises, accessibility, performance, and product reliability using appropriately limited evidence.
- Meet legal obligations and enforce the applicable terms.
4. Authority and legal bases
Where applicable law requires a legal basis, processing may depend on performance of a contract, steps requested before a contract, legitimate interests in operating and securing the service, consent, or compliance with law. The basis depends on the data and jurisdiction. A parent or authorized guardian controls a child learner profile unless a different lawful educational arrangement is expressly established.
5. Parent authority and authorized visibility
The intended account architecture allows the parent to create or remove learner profiles, choose courses, grant or revoke tutor, guardian, or school visibility, review sharing, export information, and request deletion. External roles do not automatically own or receive the complete learner record. Their access must be scoped to an authorized purpose.
6. Children
LogNormal is designed for household use that may include children. A parent or guardian must establish and control a child profile unless an institution has a separate lawful basis and agreement. The service should collect only the information needed to provide training, family controls, safety, and authorized reporting. Children should not submit independent Founding reservations or payment information.
7. Sharing and service providers
Data may be disclosed to infrastructure, authentication, payment, email, support, security, diagnostics, and storage providers only as needed to perform their contracted role; to people or organizations a parent authorizes; during a lawful business transaction with appropriate safeguards; or when required by law. A current production processor list will be published before production account processing. LogNormal does not sell learner data or use it for third-party behavioral advertising.
8. Retention
Account and learning records are retained while needed to provide the account and for a limited period needed for recovery, security, dispute resolution, or legal obligations. Founding transaction records may require separate financial retention. Diagnostic events should be retained for the shortest period reasonably needed for reliability and security. Final category-specific schedules will be published before the founding release.
9. Security
LogNormal uses safeguards appropriate to the development phase, including access controls, credential hashing, secure session cookies for private web areas, transport encryption in production, scoped permissions, and minimization. No system is perfectly secure. Suspected vulnerabilities should be reported to security@lognorm.al without including passwords or unnecessary learner data.
10. International processing
The product is intended for more than one region, but the final hosting locations and transfer mechanisms are not yet represented as settled. Before international production processing, LogNormal will document relevant locations and safeguards.
11. Rights and choices
Depending on location, a person may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent, and may complain to a data-protection authority. Parents may also manage product-level permissions. Requests go to privacy@lognorm.al; the deletion guide explains the current deletion route.
12. Changes and contact
Material changes will be dated and communicated when required. Privacy questions: privacy@lognorm.al. Security reports: security@lognorm.al. Legal notices: legal@lognorm.al.