Pre-launch legal draft

Privacy policy

This page defines the privacy topics the final policy must cover without inventing practices that have not been confirmed.

Not ready for public reliance. Business identity, contact details, platform terms, data practices, payment processor, store terms, and counsel approval must be confirmed before launch.

Information collected

The final policy must list website analytics, support messages, app-account data, purchase information, device information, cookies, and any other data actually collected. It must also identify which data is collected directly and which is received from service providers.

How information is used

Uses must match the implemented product, such as providing study features, maintaining accounts, processing purchases, responding to support, improving reliability, preventing abuse, and meeting legal obligations.

Sharing and service providers

The final policy must name or clearly describe relevant hosting, analytics, authentication, payment, crash-reporting, email, and app-store providers. It must state whether personal information is sold or used for targeted advertising.

Retention, deletion, and choices

Retention periods, account deletion, marketing choices, cookie controls, access requests, and jurisdiction-specific rights must match the final systems and support process.

Children and security

The final policy must state the intended audience, age treatment, reasonable security measures, and a method for reporting privacy or security concerns.