Privacy Policy
Effective Date: September 24, 2026
At Learnijoy, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, mobile apps, or browser extension.
1. Information We Collect
Personal Data:
Name, email address, phone number, billing information, and login credentials.
Usage Data:
Pages visited, time spent, courses accessed, browser type, and IP address.
Community and Safety Data:
If you use Learn comments, we collect the comment text you submit, your public display alias and avatar colour, your community-guideline consent record, reports you make or receive, accounts you block, and moderation actions. Do not include phone numbers, email addresses, home addresses, or other personal information in a comment.
Push Notification Data:
Push notifications are optional. If you are signed in and choose Enable notifications in our iOS or Android app, and grant the operating-system permission where required, we collect a random app-install identifier, an Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM) registration token, your mobile platform, app version, and the delivery environment needed for iOS. We associate this information with your account only so we can deliver relevant learning and account notifications. On the device, we also create a separate random 32-byte cleanup secret so that this installation can remove its push registration after logout even if the session has already expired. We store only a one-way verifier of that secret on our server, do not use it for analytics or tracking, and never send it to APNs or FCM. On Android, FCM also processes a Firebase Installation ID and limited app, SDK, and device metadata needed to operate the service. We do not use Firebase Analytics or advertising for push notifications.
Cookies and Tracking Technologies:
We use analytics and advertising cookies based on your region and, where the law requires it, your consent. See our Cookie Policy for details and to manage your preferences.
2. How We Use Your Information
- To provide and manage your course subscriptions.
- To improve platform performance and user experience.
- For billing and customer support purposes.
- To send updates, promotions, and learning resources.
- To operate Learn comments, prevent abuse, review reports, enforce our community rules, and protect learners.
- If you enable them, to deliver notifications such as comment replies, class reminders, assignments, and learning updates.
3. Information Sharing
We do not sell or rent your personal data. We may share it with:
- Service providers for technical or customer support.
- Legal authorities if required by law.
- Eligible signed-in learners can see published comments and their public author alias. They do not receive the author's email address or phone number.
- Authorised moderation staff can review comments, reports, and related account information when needed to investigate safety concerns. A reporter's identity is not shown to the reported learner.
- Apple processes the APNs token, a generic notification title and body, and limited routing metadata on iOS. Google processes the equivalent FCM delivery information on Android. Detailed grades, learning status, and inbox text are not sent in provider-visible alerts. Apple and Google provide notification delivery services on our behalf; Learnijoy does not use this information for advertising or cross-app tracking.
- If you use our browser extension, Cloudflare and Google process the text it sends for checking, as described in section 8.
4. Data Security
We implement strong encryption, firewalls, and secure data storage to protect your data.
5. Community Data Retention
Comments remain available until you delete them, we remove them, or your account is deleted, subject to limited retention required for security, legal compliance, and resolving reports. Block preferences remain until you remove the block or delete your account. We may retain a limited moderation record where needed to prevent abuse or meet legal obligations.
6. Your Rights
- Access, update, or delete your personal information.
- Opt-out of promotional communications.
- Delete your own Learn comments.
- Block or unblock another learner in Learn comments.
- Decline notifications or turn them off later in your device settings without losing access to the in-app notification inbox.
7. Push Notification Retention
We do not register a push destination until you enable notifications and, where required, grant the operating-system permission. This in-app choice is required on older Android versions even when Android does not show a separate permission prompt. Your registration is removed when you sign out, when the app detects that notification permission was revoked, when Apple or Google reports that the token is invalid, or when your account is deleted. On logout or an account switch, the app also asks the operating system to remove already delivered Learnijoy alerts so another person using the same device cannot read them. Inactive registrations are deleted after 180 days. If logout cleanup is temporarily offline, the app keeps a random, account-free local cleanup capability for up to 210 days and retries when the connection returns; the server stores only its one-way verifier. Provider-visible generic alerts expire within five minutes. The related in-app notification is retained for up to 90 days, or for 30 days after you read it, whichever occurs first.
8. Browser Extension (LearniTube and LearniGram)
Our Chrome extension turns YouTube and Instagram into study spaces during study hours chosen by a parent. It is meant to be installed by a parent or school for a student in classes 6 to 10. It shows no ads, and we do not sell its data or use it for advertising. Our use of the data it handles complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
What the extension reads:
Only on youtube.com and instagram.com, and only during study time. On YouTube, it reads the titles, channel names, and descriptions of videos on the page or being opened, and the search terms typed. On Instagram, it reads the captions, image descriptions, and the author's username and display name of posts in the feed, from content Instagram has already loaded. It does not read the contents of direct messages, passwords, cookies, or any other website. Outside study time it does nothing on either site.
What is sent for checking, and to whom:
To decide whether a video, post, or search suits study time, the extension sends the text described above, together with the student's class, to Learnijoy's checking service, which runs on Cloudflare Workers. The service passes it to an AI model provider, currently Google's Gemini API, and returns only an allow or block decision. The student's name, the parent PIN, and the Learnijoy connection token are never sent to it. We do not store the checked text. The service keeps only overall request counts and uses the requesting IP address for rate limiting. Google processes the text under its Gemini API terms.
What is stored in the browser:
The settings a parent enters (the student's first name, class, lesson language, subject mix, and study timetable), a salted one-way hash of the parent PIN, recent check results for about an hour, the list of lesson videos watched from our library, and the daily summary shown to the parent. If Chrome Sync is turned on, Chrome may copy the settings, but not the PIN or the connection token, to other browsers signed in to the same Google account. Removing the extension deletes everything it stored in the browser.
Connecting to a Learnijoy account (optional):
A student can connect the extension to their Learnijoy account by typing a one-time code from the Connect LearniTube page. The code expires after 10 minutes and works once. The extension then receives the student's first name, class, subject mix, and study timetable from Learnijoy, and a study-time change made in the extension is saved to the student's Learnijoy planner. The extension keeps a connection token in the browser, which Chrome Sync never copies. Our servers keep only a one-way hash of the token and of the code, with the device label and when it was connected and last used. The token can only read that profile and update the timetable; it cannot sign in or access anything else. A student can disconnect a browser at any time from the Connect LearniTube page. Connection records are deleted with the Learnijoy account; until then, a disconnected browser's record is kept and marked as disconnected.
When the extension is removed:
Chrome opens a Learnijoy page that receives a random installation ID, the student's class, the extension version, and the country the request came from, so that we can record the removal. No name or account information is included. The installation ID is kept for up to 90 days.
9. Contact
For questions, email us at info@learnijoy.com.