LEGAL / PRIVACY

Privacy Policy

Working draft for the founding release ยท Updated July 14, 2026

1. Scope and operator

This policy applies to the LogNormal website, founding-reservation process, iOS application, parent and learner accounts, support channels, and authorized tutor or institution access. The service is currently presented under the LogNormal product name. The final legal operator identity and formal notice address will be published before production account processing begins.

2. Data categories

3. Purposes

4. Authority and legal bases

Where applicable law requires a legal basis, processing may depend on performance of a contract, steps requested before a contract, legitimate interests in operating and securing the service, consent, or compliance with law. The basis depends on the data and jurisdiction. A parent or authorized guardian controls a child learner profile unless a different lawful educational arrangement is expressly established.

5. Parent authority and authorized visibility

The intended account architecture allows the parent to create or remove learner profiles, choose courses, grant or revoke tutor, guardian, or school visibility, review sharing, export information, and request deletion. External roles do not automatically own or receive the complete learner record. Their access must be scoped to an authorized purpose.

6. Children

LogNormal is designed for household use that may include children. A parent or guardian must establish and control a child profile unless an institution has a separate lawful basis and agreement. The service should collect only the information needed to provide training, family controls, safety, and authorized reporting. Children should not submit independent Founding reservations or payment information.

7. Sharing and service providers

Data may be disclosed to infrastructure, authentication, payment, email, support, security, diagnostics, and storage providers only as needed to perform their contracted role; to people or organizations a parent authorizes; during a lawful business transaction with appropriate safeguards; or when required by law. A current production processor list will be published before production account processing. LogNormal does not sell learner data or use it for third-party behavioral advertising.

8. Retention

Account and learning records are retained while needed to provide the account and for a limited period needed for recovery, security, dispute resolution, or legal obligations. Founding transaction records may require separate financial retention. Diagnostic events should be retained for the shortest period reasonably needed for reliability and security. Final category-specific schedules will be published before the founding release.

9. Security

LogNormal uses safeguards appropriate to the development phase, including access controls, credential hashing, secure session cookies for private web areas, transport encryption in production, scoped permissions, and minimization. No system is perfectly secure. Suspected vulnerabilities should be reported to security@lognorm.al without including passwords or unnecessary learner data.

10. International processing

The product is intended for more than one region, but the final hosting locations and transfer mechanisms are not yet represented as settled. Before international production processing, LogNormal will document relevant locations and safeguards.

11. Rights and choices

Depending on location, a person may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent, and may complain to a data-protection authority. Parents may also manage product-level permissions. Requests go to privacy@lognorm.al; the deletion guide explains the current deletion route.

12. Changes and contact

Material changes will be dated and communicated when required. Privacy questions: privacy@lognorm.al. Security reports: security@lognorm.al. Legal notices: legal@lognorm.al.