Privacy Policy
This policy explains how ZiRan collects, uses, discloses, and protects personal data. It also explains your rights, available controls, and how child-managed account flows are handled.
1. Scope and Accountability
This policy applies to our public website, learner experiences, teacher workflows, and account services. We act as the data controller for account and product operations unless a separate school or enterprise agreement defines a different controller/processor relationship.
2. Data We Collect
We collect only the data needed to operate and secure the service.
- Account data: email address, display name, account identifiers, authentication metadata.
- Authorization data: role, membership tier, account mode, consent-state metadata.
- Learning data: review history, progress metrics, game outcomes, and assignment state.
- Profile settings: language preference, display preferences, optional celebration style, optional avatar image.
- Operational and security telemetry: error logs, performance metrics, anti-abuse and audit events.
- Billing metadata: plan and subscription status; payment card data is processed by payment providers and not stored directly by our app.
3. Data We Do Not Intentionally Collect
- We do not require date of birth for standard registration.
- We do not infer exact age for personalization decisions.
- We do not store full payment card numbers in application databases.
4. How We Use Data
- Provide account access, lessons, review scheduling, and game functionality.
- Apply entitlements, membership controls, and account-mode governance.
- Support safety, fraud prevention, and platform abuse detection.
- Maintain reliability, security, diagnostics, and service improvement.
- Deliver operational notices such as account and subscription events.
5. Legal Bases (UK/EU GDPR)
- Contract: deliver the learner/teacher services you request.
- Legitimate interests: secure and improve the platform, prevent misuse.
- Legal obligation: satisfy legal or regulatory duties where applicable.
- Consent: where law requires consent for specific processing.
6. Children, Parent-Managed, and Teacher-Managed Accounts
The service supports multiple account modes. For child-oriented or guardian-managed flows, account state may remain limited until required guardian authorization is completed.
- Direct learner accounts: consent not required by default account mode.
- Teacher-managed student accounts: educational operator workflows may apply.
- Parent-managed child accounts: consent-state controls may limit learner access until consent is granted.
We design these controls to support applicable child privacy requirements, including COPPA considerations and UK/EU children data rules where relevant.
7. Data Sharing and Subprocessors
We share data only as needed to operate the service.
- Identity providers (optional): external login providers selected by the user.
- Payment providers: subscription and payment processing platforms.
- Email and notification providers: transactional email delivery.
- Hosting and monitoring providers: infrastructure, telemetry, and reliability operations.
Vendors process data under contractual terms and security obligations appropriate to their role.
8. International Data Transfers
If data is transferred across jurisdictions, we use appropriate legal mechanisms and safeguards required by applicable law.
9. Retention
We retain data only as long as needed for service delivery, legal obligations, dispute handling, and abuse prevention. Retention windows are applied by data type and may differ for security logs, subscription records, and learning history.
10. Security
- Role-based and policy-based access control in application workflows.
- Encryption and transport security controls for data in transit.
- Operational monitoring, error diagnostics, and incident-response support.
- Least-privilege access practices for administrative operations.
11. Your Rights and Controls
Depending on jurisdiction, you may have rights to:
- Access a copy of personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete account data, subject to legal and security exceptions.
- Restrict or object to certain processing.
- Data portability where legally required.
In-product controls are available through account management pages, including data export and account deletion features where supported.
12. Cookies and Similar Technologies
We use cookies and similar technologies for session management, security, and user experience. See our Cookie Policy for details.
13. Policy Changes
We may update this policy to reflect legal, technical, or product changes. Material updates will be posted on this page with a revised "Last updated" date.
14. Contact and Requests
For privacy requests, consent disputes, or data rights inquiries, use the designated support/privacy channel in your deployment or organization contact process.
If your account is managed by a school, teacher, or guardian, requests may need to be routed through the responsible account manager.