← Back to Home

Privacy Policy

Version: June 30, 2026

This Privacy Policy informs you about what to expect when we collect personal information through the Light application (the "Service"). Please read carefully and use the Service only if you fully agree with the terms presented herein.

1. Who are we?

The Service is independently developed and operated by an Individual Developer. Unlike large-scale corporate platforms, this is an autonomous project. For any questions related to privacy or data deletion, you can contact the developer directly through the application.

2. What do we collect?

We collect the following categories of information:

  1. Information you voluntarily provide:
    • Your display name, email address, and profile photo URL provided by you when creating an account or logging in via social authentication (such as Google Auth).
    • Your mobile phone number if you use the leaderboard feature under the "Friends" tab. To protect your privacy, the phone number is sanitized and encrypted locally on your device in a secure one-way cryptographic hash format (SHA-256) before being sent to our servers. Your raw (plain text) phone number is never sent or stored on our servers.
    • Content created by you for the operation of the app, such as folders, decks, flashcards, and associated study data.
    • Messages, feedback, or support reports you send directly to us.
  2. Access to device features and local data:
    • Phone Contacts (Optional): If you choose to use the "Friends" leaderboard, the application will request permission to access your local address book contacts. The app reads phone numbers strictly locally, sanitizes them, and generates SHA-256 hashes instantly in local memory to match against the registered user database. No name, phone number, or contact list data is ever sent, stored, or shared with our servers or third parties. All match processing occurs strictly on your device.
    • Biometric Authentication (Optional): If you enable biometric lock (Face ID or fingerprint), the application will request device authentication. This authentication is performed directly and securely by your mobile device operating system (Android Keystore / iOS Secure Enclave). The Light app does not access, collect, or store your biometric information under any circumstances. We only receive success or failure confirmation from the system.
    • Local Encryption (Secure Storage): Local security information, such as biometric lock activation and Premium account status, is stored locally in encrypted form via Flutter Secure Storage to protect your physical data against unauthorized extraction.
  3. Automatically collected information:
    • App usage data for software diagnostics and crash prevention (error logs).
    • Device information used to access the Service (make, model, OS version, and mobile ad identifiers generated by official Google and Apple platforms).

3. What is the legal basis for processing?

Under applicable data protection laws, we process your personal data based on the following legal grounds:

4. Sharing Information with Third Parties

As an individual developer, we do not sell or rent your data under any circumstances. Your information is shared with service partners exclusively to enable the Service:

5. How long do we retain your information?

Unless indicated otherwise or required by law, the following retention rules apply:

6. User Rights & Account Deletion

You have the right to request confirmation of processing, access to your collected personal data, correction of inaccurate data, full erasure of stored information, data portability, and revocation of previously granted consent. To request deletion of your account and associated data, please visit our Account Deletion Request Page or use the in-app deletion settings.

7. Data Security and Limitation of Liability

Adequate technical measures are implemented to protect your data, such as encryption and strict cloud security rules. However, due to the decentralized nature and inherent risks of the web environment, the developer (individual) disclaims civil liability arising from third-party malicious intrusions (hackers), security failures on third-party servers (Google/Firebase), or leaks beyond direct technical and financial control.