Privacy policy
App: BrainWave (com.sazinga.brainwave) ·
Developer: Sazinga · Contact:
sumit@sazingadigital.com
The short version. A parent signs in with Google and writes the lessons. A child never gets an account — no email, no password, no birth date, no photo. The lessons you write and your child’s answers and points are stored in plain text on a server we operate, so we can read them. We do not sell or share them, we show no advertising anywhere in the app, and we run no analytics or tracking on any screen a child sees.
This changed, and we would rather say so. An earlier version of BrainWave was end-to-end encrypted: the server held ciphertext and genuinely could not read it. Running lessons, tasks and rewards across two parents and several devices meant moving to accounts on a server we operate, so we can now read the lesson text you write and your children’s progress. If you used the earlier version, that is a real change in what we can see, and this policy replaces the one that described it.
1. Who has an account
Parents do. Children do not. You sign in with Google. Your child is a name you add inside your household — they sign in to nothing, and we hold no credential for them.
A child’s tablet joins your household by scanning a QR code you show it from the parent app. That pairs the device to the child you chose; it does not create an account.
2. What we store
| What | Why |
|---|---|
| Your account — your Google account identifier, email address, name and profile picture, when you last signed in, and which notifications you want | To sign you in, to show who is signed in, and to let you invite a co-parent by email address |
| Your household — its name, its members, and any outstanding co-parent invitations | So both parents see the same children, lessons and approvals |
| Each child — the display name you choose, a colour, and the cartoon face they build from preset shapes | To tell your children apart, on your screen and theirs. No photograph, no date of birth, no contact details |
| What you write — subjects, lesson text, quizzes, questions, answers and explanations | To deliver them to your child’s device. Stored in plain text |
| What your child does — quiz attempts and the answers they chose, scores, tasks marked done, points earned and spent, rewards, redemptions and goals | To show you their progress and to run the points system you set up |
| Your AI key, if you add one — encrypted at rest with AES-256-GCM | So the optional AI drafting features can run under your own provider account |
| A push token per device | To tell a parent something needs approving, and a child that it was. Delivered through Firebase Cloud Messaging (Google) |
3. What we never do
- No advertising anywhere in the app, and no advertising identifiers.
- No third-party analytics or tracking SDKs — in particular, nothing at all on a child-facing screen.
- No selling or sharing of personal data with anyone.
- No profiling of children, and nothing used to train any AI model.
- No payment details — there is nothing to pay for.
- No access to location, contacts, microphone or address book.
4. Artificial intelligence
The AI features are optional, and they run on your own API key from a provider you choose — Google Gemini, Groq, OpenRouter, Cerebras or Anthropic. You can write every lesson and every question yourself and never add a key at all.
When you do use them, our server calls that provider with your key. Two things are worth being exact about:
- What is sent: the lesson text and the instruction you typed, so a draft or a set of questions can be written. The provider receives it under your own account and its terms.
- What we never send: your children’s names, their answers, their scores, their points, or anything else about them. No part of a child’s record is ever read into a prompt. AI is used for authoring, by a parent, on a parent’s own screen — so the one way a child’s name could reach a provider is if you typed it into the box yourself. It never decides anything either: every draft is shown to you and saved only when you accept it.
5. Children
BrainWave is used by a child under a parent’s direction, on a device the parent pairs. The parent chooses every lesson and approves what a child earns.
We do not knowingly collect personal information directly from children. A child cannot enter an email address, cannot sign in, and cannot reach anyone outside the household: there is no chat, no social feature, no user-to-user contact, no public profile, and no way to share anything out of the app. The child-facing screens carry no advertising, no analytics and no third-party content.
The only personal information about a child on our server is what a parent typed in — a display name — and the record of the work they did in the app.
6. Linked images and videos
If a lesson you write links to a picture or a YouTube video, the device fetches it from that website when the lesson is opened, and that website sees the request as it would for any web page. Nothing about your child is attached to it. A lesson that links to nothing external makes no such request.
7. Deleting your data
In the parent app: More → Delete account. You confirm by typing your own email address, and it happens immediately — there is no waiting period.
That deletes your account, your AI keys, your push tokens, and every household where you are the only parent — including that household’s children, their lessons and their points. A household you share with a co-parent stays with them; only your membership is removed.
You can also delete a single child, or a whole household, from inside the app without closing your account.
If you no longer have the app, the account deletion page explains how to ask us by email.
8. How long we keep things
Your content stays until you delete it or close your account. There is no automatic expiry and no hidden copy kept afterwards.
Web server access logs — the request line, status and IP address, written by the web server rather than by the app — are rotated and discarded within 14 days. Application logs record the method, path, status and timing of a request, never its contents, your credentials or your AI keys.
9. Where data is held
On a server operated for Sazinga, in a PostgreSQL database, with the whole site served over HTTPS. Backups are kept for a short period so the service can be restored after a failure, and they are covered by your deletion request.
10. Your rights
You can see everything we hold about your household inside the app, correct it there, and delete it there. For any access, correction or deletion request you would rather make directly, email sumit@sazingadigital.com from the address on your account and we will respond within 30 days.
11. Changes
If this policy changes in a way that affects what we collect or who can read it, the app will say so before the change takes effect. The move away from the earlier end-to-end encrypted version is described at the top of this page rather than quietly dropped.
Last updated 18 August 2026 · Delete your account and data