BrainWave by Sazinga

Privacy policy

App: BrainWave (com.sazinga.brainwave) · Developer: Sazinga · Contact: sumit@sazingadigital.com

The short version. Everything your child reads and earns is encrypted on your own devices before it leaves them. Our server stores scrambled data it cannot unlock, because the key is made on your phone and never sent to us. We do not sell anything, show ads, or run analytics on your child's device.

1. What we store

The server storesThe server can never
A random family id (e.g. f_8f2c41d9a7), not linked to a personRead a single word your child reads
Encrypted data it cannot unlockSee their name, answers, points or streak
A push token, so a device can be told "there is something new"Recover your data if you lose your devices — we hold no key
Timestamps and data sizesLink a family to a person, unless you choose to sign in

2. Accounts are optional

BrainWave works fully without an account. There is no registration, no password, and no email required to use it.

You may optionally sign in with Google or Apple, for one purpose: so that a parent who replaces or loses a phone can find their family's data again. If you do, we store an opaque identifier supplied by Google or Apple, and nothing else. We do not store your email address, your name, or your profile picture. We never receive your password.

Signing in does not let us read anything. It tells our server which encrypted bundle belongs to you; it does not provide a key to open it.

2a. Key backup (optional)

Because signing in does not hand back a key, you can also turn on key backup. Your family key is then written to a private folder inside your own Google Drive — the app-data folder, which no other app can see and which does not appear in your Drive listing. We request one permission for this, drive.appdata, and no other.

No copy of that key reaches our servers, which is also why we cannot restore one for you. The trade-off is worth stating plainly: anyone who can open your Google account can open that backup. Your printed recovery sheet remains the way back in that involves no third party at all, and it keeps working whether or not you use key backup.

You can delete the backup at any time from Settings → Key backup. Deleting it does not touch your books or your child's progress.

Key backup in your own cloud

If you switch it on, BrainWave can back up your family key to your own Google Drive or iCloud, in a private per-app area that other apps cannot see and that we cannot access. It is stored in your account, not ours. You can delete it from your Drive or iCloud at any time. This is optional; the printed recovery sheet does the same job with no cloud involved.

3. What we do not do

4. Children

BrainWave is designed to be used by a child under a parent's direction. The content is chosen by the parent. A child's reading progress, answers, scores and name never leave the family's own devices in readable form, and are never sent to any third party or AI service.

We do not knowingly collect personal information from children. There is no chat, no social feature, no user-to-user contact, and no way for a child to share anything outside the family.

5. The honest caveats

A privacy promise that hides its edges is not one. Three things are true:

  1. When a parent uses AI, the lesson text goes to Google. BrainWave calls Gemini with your own API key, directly from your phone — we never see it and never proxy it. Google receives the passage you asked about, under your own Google account and its terms. Every AI feature has a manual path if you would rather nothing left the phone.
  2. Linked images and videos are fetched from wherever they live. If a lesson links to a picture or a YouTube video, the device requests it from that website, and that website sees a request as it would for any web page. Lesson text, quizzes and progress never travel that way.
  3. We can see traffic, not content. Our server knows a family synced 40 KB at 7pm. It cannot know whether that was a storybook or a spelling test.

6. Your AI key

If you add a Gemini API key, it is stored only in your phone's secure storage. It is never synced, never included in a backup or export, and never sent to our server.

7. Deleting your data

In the app: Settings → Delete everything, which removes the local data and asks the server to drop the family's records. Full instructions, including how to request deletion without the app, are on the account deletion page.

Server access logs, which contain IP addresses and are written by the web server rather than the app, are discarded within 14 days. Families with no activity for 24 months are deleted automatically.

8. Where data is held

Encrypted records are stored on servers operated for Sazinga. Because the content is encrypted with keys we do not hold, its location does not give anyone — including us — the ability to read it.

9. Your rights

You can export your data at any time from Settings (a plain, readable file you own), and delete it at any time. For access, correction or deletion requests, email sumit@sazingadigital.com. We respond within 30 days.

Because we deliberately hold no identifying information, a request may need to be accompanied by your Family ID from the recovery sheet, or made from the Google or Apple account you signed in with, so we can tell which records are yours.

10. Changes

If this policy changes in a way that affects what we collect, the app will say so before the change takes effect.

Last updated 3 August 2026 · Delete your account and data