ENG BM
Edu N App
Loading session…

Privacy

Privacy Policy for Do Easy PBD.

Operator: Code N Gram

Status: official privacy policy for the current app build and related hosted services described here

Last updated: June 21, 2026

This Privacy Policy explains how Do Easy PBD handles information in the current app build, together with the related hosted account, support, sync, update, and billing services described here.

1. Core privacy position

Do Easy PBD is built as an offline-first app.

  • Most teaching records stay on your device unless you choose a hosted, support, or transfer feature.
  • We do not intentionally sell personal data.
  • We do not run advertising SDKs in the current build.
  • We do not intentionally run classroom-behavior analytics SDKs in the current build.

Manual archive export and import remain user-controlled. In the current release build, Local Sync and cloud backup are disabled by release flags. Online Sync may be available only for eligible signed-in accounts, depending on current access state, device eligibility, and server-side service status.

Teaching-record metadata such as classes, forms, attendance, grades, notes, and entitlement state is handled through the app's offline-first local storage plus hosted services when account features are used. Attachment blobs such as photos, screenshots, PDFs, and similar evidence files may use object storage services when sync, backup, or support-upload features are active.

2. Scope

This policy covers:

  • the Do Easy PBD app
  • related Code N Gram pages and flows used for account access, website-backed billing, billing history, password reset, and profile/account management
  • related backend services used to authenticate users, manage account access, process support requests, provide update metadata, and operate sync/storage flows

This policy does not replace the privacy policies of third-party services you choose to use directly, such as Google sign-in or external payment providers.

3. What normally stays local

The following data normally stays on your device unless you choose to export, import, sync, upload, or otherwise transfer it through a feature that sends it to a hosted service:

  • forms you create or install
  • saved records, notes, and related metadata
  • attached images or evidence files
  • classes, groups, and local archive packages
  • local profile photo and personalization data
  • theme, language, and other local app preferences

The app may also access certain device capabilities only when you choose a related feature, such as:

  • camera access for QR scanning, image capture, or similar user-initiated flows
  • selected files or media that you choose to import, export, attach, or upload
  • local-network capabilities that support same-network device discovery or transfer flows when those features are enabled in your build

4. What we may receive when account or hosted features are used

We receive only the data needed to operate account access, sync, support, and related hosted functions.

4.1 Account and sign-in data

If you sign in, we may process:

  • your email address
  • your Supabase account identifier
  • authentication provider information, such as whether you use email/password or Google sign-in
  • your public in-app user ID, if you create or claim one
  • linked-provider state and related account metadata
  • entitlement, account-access, and signed-in device-overview data
  • app-generated device identifiers or labels used for account-linked device management, entitlement refresh, or sync safety checks

4.2 Support and account-access data

If you contact us or use hosted account features, we may process:

  • the contact details you use to reach us
  • your support messages, screenshots, or bug details
  • account-access status, sync eligibility, signed-in device overview state, and related server audit metadata
  • timestamps and audit notes related to account recovery, device review, sync troubleshooting, or support actions
  • account-deletion or account-recovery status metadata when you use those flows

4.3 Purchase, billing, and access records

If you use website-backed billing, billing history, entitlement restoration, or store-linked purchase recording flows related to Edu N App, we may process:

  • selected product, plan, or entitlement identifiers
  • payment or billing status
  • order, purchase, checkout session, or external transaction reference IDs
  • payment timestamps and access-refresh timestamps
  • provider names and limited verification metadata needed to confirm access

We do not intentionally process full payment card numbers or CVV values through the app itself.

4.4 Operational security data

To operate the service safely, we may also process limited technical metadata such as:

  • app version and platform details
  • entitlement-refresh results
  • device-count or device-eligibility state
  • backend error/access logs needed to investigate failures or abuse
  • local or hosted request metadata reasonably needed to troubleshoot authentication, sync, support, billing, or account-integrity issues

4.5 Online Sync reliability telemetry and diagnostics

When Online Sync features are used, we process limited sync-operations telemetry so support can diagnose restore or convergence failures without reading more teaching content than is necessary.

This telemetry may include:

  • push batch size and pull batch size
  • latest pushed and pulled revision numbers
  • pull bootstrap source, such as mutation replay versus canonical entity bootstrap
  • sync failure category, such as access denied, invalid request, or server error
  • pull/apply duration and related timing metadata
  • per-device sync state metadata, such as device label, last seen, last pushed, and last pulled
  • metadata submitted by the app for sync troubleshooting, such as platform, app version, and device identifier or label

Telemetry is used for reliability, support triage, abuse prevention, and service hardening. It is not used for ad profiling or classroom-behavior analytics.

Sync telemetry is designed to avoid storing full teaching-record payload content in diagnostics tables where possible. Teaching content may still exist in the product data stores required for sync and storage features when those features are active for your account.

4.6 Attachment, backup, and support-upload data

When Online Sync, support evidence uploads, or other hosted file-transfer features are active, we may process:

  • attachment object metadata such as object key, hash, size, MIME type, and upload/download state
  • signed upload or download requests needed to transfer attachment blobs securely
  • the attachment file bytes themselves when you choose a feature that uploads or restores those files through a hosted flow
  • evidence images or similar support attachments you choose to upload for a problem report

Structured teaching metadata and attachment blobs are handled separately. Hosted account and sync metadata are coordinated through backend services, while uploaded object storage may be handled through Cloudflare R2 or a similar storage provider configured for the service.

5. What we do not intentionally collect by default

In the current build, we do not intentionally collect:

  • advertising identifiers for marketing profiling
  • payment card numbers or CVV values through the app
  • classroom-behavior analytics for advertising or user-profiling purposes

6. Exports, imports, local network transfers, and backups

For user-controlled transfer outside hosted account features, the current supported data-transfer path is manual archive export/import.

  • when you export files, they are stored wherever you choose to save them
  • when you import files, the app reads the file you selected locally
  • you are responsible for the security of exported files and the storage locations you choose
  • if a same-network device transfer feature is enabled in a later release, that flow is intended to move data directly between your devices rather than through our hosted sync servers

Cloud backup and Local Sync are currently disabled in the release build even if related code or documentation references still exist. If those features are enabled in a later release, this policy should be updated with the relevant operational details before or with that rollout.

7. How we use information

We use information to:

  • authenticate your account
  • refresh account access and device status correctly
  • operate account-linked sync, update, billing, and related recovery flows
  • support account, device, and troubleshooting workflows
  • process user-initiated support evidence uploads and account-management requests
  • confirm purchases, billing state, or entitlement state where those flows are part of the service
  • protect the service and comply with legal obligations

8. When we share or disclose information

We do not intentionally sell personal data. We may disclose information:

  • to service providers that help us operate authentication, cloud storage, support, website billing, account management, or related infrastructure
  • when you intentionally use a third-party sign-in or payment flow
  • when required for security, fraud prevention, abuse investigation, legal compliance, or to enforce our terms
  • in connection with a business reorganization, acquisition, or asset transfer, subject to applicable law

9. Service providers and third parties

Current service providers in or around the app include:

  • Supabase, for authentication, account records, sync-access/device flows, and related hosted functions
  • Google, if you choose Google sign-in through the supported auth flow
  • Cloudflare, for website, Worker, and object-storage infrastructure used by sync, support-upload, update-distribution, backup, or similar file-transfer features when enabled
  • payment or billing providers used by the Edu N App website or related hosted purchase flows, when you choose those flows

10. Storage, security, and international processing

We use reasonable safeguards appropriate to the service, including:

  • encrypted transport where supported
  • secure handling of auth and account tokens through the app and hosted services
  • restricted handling of account-access adjustments and support-side recovery actions
  • auditability around account and sync support actions

Our service providers may process or store information in jurisdictions outside your own. Where that happens, processing follows the provider and service setup chosen for the app at the time.

No service can guarantee absolute security. You are also responsible for protecting the devices and exported files you control.

11. Retention and deletion

  • local app data stays on your device until you delete it
  • account and sync-access records may be retained while your account exists or as needed for support, fraud prevention, security, or legal compliance
  • support communications may be retained as needed to resolve account or sync questions
  • sync telemetry and diagnostics records are retained for operational troubleshooting, security review, and service reliability analysis, then reduced or removed according to operational retention policy
  • if you request account deletion through supported flows, current cloud-backup objects may be deleted promptly while some account records may enter a pending-deletion or recovery window before final removal
  • some information may be retained longer where needed for fraud prevention, abuse handling, security review, financial recordkeeping, or legal compliance

12. Your choices

Depending on your location and applicable law, you may be able to:

  • access account data we hold about you
  • correct inaccurate account data
  • export local data from the app
  • delete local data from your device
  • request account deletion where supported

If your app account can be deleted, Google Play may also require a web-based account-deletion resource in addition to any in-app deletion flow.

13. Children

The app is intended for teachers and educational record workflows. It is not directed to children to create accounts on their own.

14. Changes

We may update this policy as the product changes. If sync behavior, storage scope, billing flows, support flows, or distribution channels change later, this policy should be updated before or with the relevant rollout.