Privacy Policy
Last Updated: January 7, 2026
Effective Date: January 7, 2026
Introduction
BrainBatch ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application ("App").
By using BrainBatch, you consent to the data practices described in this policy.
1. Information We Collect
1.1 NECESSARY FOR SERVICE (No Consent Required)
Legal Basis: Legitimate Interest / Contractual Necessity
We cannot provide the quiz service without storing this data:
Core Functionality Data:
- Quiz answers, scores, and performance metrics
- Badge achievements and progress tracking
- User ID (Firebase UID - anonymous or authenticated)
- Session history and streaks
- Notification preferences (if you enable notifications)
- Authentication data (if you sign in with Apple/Google):
- Email address (optional, if provided by Apple)
- Name (optional, if provided by Apple/Google)
- Unique provider ID
This data is essential to:
- Track your quiz progress and scores
- Award badges and calculate streaks
- Remember your notification time preferences
- Sync data across devices (if signed in)
- Provide the core app functionality
1.2 OPTIONAL ANALYTICS (Requires Your Consent)
Legal Basis: Consent (via Google UMP consent form)
App Usage Analytics:
- Screens visited and time spent
- Device model and OS version
- Features used and buttons clicked
- Crash reports and error logs (Firebase Crashlytics)
- App performance metrics
This data helps us:
- Improve app features and user experience
- Fix bugs and crashes
- Understand how users interact with the app
- Optimize app performance
If you decline: Analytics will not be collected, but the app will work normally.
1.3 ADVERTISING DATA (Requires Your Consent)
Legal Basis: Consent (via Google UMP consent form)
We work with Google AdMob to display advertisements. With your consent, AdMob may collect:
- Advertising ID (IDFA/GAID)
- Ad impressions, clicks, and interactions
- Device information and IP address
- Approximate location (for regional targeting)
If you decline: You'll still see ads, but they won't be personalized to your interests (non-personalized ads only).
2. How We Use Your Information
We use collected information to:
- Provide the service: Track quiz progress, scores, streaks, and badges
- Authenticate users: Verify identity for Sign in with Apple/Google (optional)
- Personalize experience: Save your preferences and notification times
- Improve the app: Analyze usage patterns and fix bugs
- Display ads: Show relevant advertisements via Google AdMob
- Send notifications: Remind you of your daily quiz (if enabled)
- Prevent fraud: Detect cheating and abuse
- Comply with law: Respond to legal requests and enforce our Terms
3. Data Storage and Security
3.1 Where We Store Data
- Supabase (PostgreSQL): User stats, quiz sessions, badges, questions (hosted in United States)
- Firebase: Anonymous/authenticated user IDs, analytics, crash reports (Google infrastructure)
- Google AdMob: Ad performance and monetization data
- Your Device (iOS Keychain): Firebase authentication token (persists across app reinstalls)
- Your Device (UserDefaults): Current session progress, local preferences
Data Location: Our servers are located in the United States. By using the App, you consent to the transfer of your data to these locations.
3.2 Security Measures
We implement industry-standard security measures:
- Encrypted data transmission (HTTPS/TLS)
- Secure authentication (Firebase Auth with iOS Keychain)
- Row Level Security (RLS) policies on database
- Regular security audits and updates
- iOS Keychain for secure token storage
However, no method of transmission over the internet is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security. You acknowledge that you provide your information at your own risk.
4. Third-Party Services
4.1 Firebase (Google)
Purpose: Anonymous/authenticated authentication, analytics, crash reporting
Data Collected: Device info, app usage, crash logs, user ID (anonymous or authenticated)
Privacy Policy: https://firebase.google.com/support/privacy
4.2 Supabase
Purpose: Database hosting for questions, user stats, sessions
Data Collected: Quiz answers, scores, badges, session history
Privacy Policy: https://supabase.com/privacy
4.3 Google AdMob
Purpose: Displaying banner and rewarded video advertisements
Data Collected: Advertising ID, ad interactions, device info, approximate location
Privacy Policy: https://policies.google.com/privacy
Your Choices:
- iOS users can limit ad tracking in Settings → Privacy & Security → Tracking
- You can request ad personalization preferences via Google's Ad Settings
4.4 Google User Messaging Platform (UMP)
Purpose: GDPR/CCPA consent management for personalized ads
Data Collected: Consent choices, approximate location (to determine applicable laws)
Privacy Policy: https://policies.google.com/privacy
4.5 Sign in with Apple
Purpose: Optional authenticated account creation
Data Collected: Apple ID, email (optional, user-controlled), name (optional)
Privacy Policy: https://www.apple.com/legal/privacy/
4.6 Google Sign-In (Future)
Purpose: Optional authenticated account creation
Data Collected: Google account ID, email, name
Privacy Policy: https://policies.google.com/privacy
5. Your Rights (GDPR & CCPA)
If you are in the EU/EEA or California, you have the following rights:
5.1 Right to Access
Request a copy of your personal data we hold.
5.2 Right to Deletion (GDPR Article 17)
Request deletion of your personal data.
In-App Deletion: Settings → Delete My Account
- Deletes all data from 7 database tables
- Deletes Firebase authentication account
- Clears local device data
- App exits for clean state
Note: This action is irreversible and will permanently delete your progress, badges, and statistics.
5.3 Right to Rectification
Correct inaccurate data we have about you.
5.4 Right to Restrict Processing
Limit how we use your data.
5.5 Right to Data Portability
Receive your data in a portable format.
5.6 Right to Object
Object to processing of your data for certain purposes.
5.7 Right to Withdraw Consent
Withdraw consent for personalized ads or data processing at any time via Settings → Privacy Options.
To exercise these rights, contact us at: brainbatchapp@gmail.com
Response Time: We will respond within 30 days.
6. Children's Privacy
BrainBatch is not directed to children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe we have collected data from a child, contact us immediately at brainbatchapp@gmail.com and we will delete it promptly.
7. Data Retention
We retain your data for as long as:
- Your account is active
- Needed to provide the service
- Required by law
Anonymous Users: If you delete the app without signing in, your anonymous Firebase UID is cleared from device Keychain, and data becomes inaccessible. Data may remain on servers for up to 90 days for backup purposes.
Authenticated Users: Data persists across app reinstalls via iOS Keychain. To delete permanently, use in-app "Delete My Account" feature or contact us at brainbatchapp@gmail.com.
8. Cookies and Tracking Technologies
The App does not use cookies. However, third-party services (Firebase, AdMob) may use similar tracking technologies:
- iOS Keychain: Secure storage for Firebase authentication token
- Local Storage: UserDefaults for session state and preferences
- Analytics SDKs: Firebase Analytics for usage tracking (with consent)
- Advertising IDs: IDFA for personalized ads (with consent)
You can control tracking via iOS Settings → Privacy & Security → Tracking.
9. International Data Transfers
Your data may be transferred to and stored in countries outside your country of residence, including the United States. These countries may have different data protection laws.
Safeguards: We use standard contractual clauses and ensure third-party processors comply with GDPR requirements.
10. California Privacy Rights (CCPA)
California residents have additional rights:
- Right to Know: What personal information we collect and how it's used
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt out of "sale" of personal information (we do not sell data)
- Non-Discrimination: We will not discriminate for exercising your rights
Do Not Sell My Personal Information: We do not sell personal information. AdMob may share data with third parties for advertising purposes, which may constitute a "sale" under CCPA. You can limit this via iOS Settings → Privacy & Security → Tracking.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted in the App and on our website (https://brainbatch.vercel.app/privacy.html).
Effective Date: Changes are effective on the date specified at the top of this policy.
Notification: For material changes, we will notify you via in-app message or email (if provided).
12. Contact Us
If you have questions about this Privacy Policy or want to exercise your rights:
Email: brainbatchapp@gmail.com
Website: https://brainbatch.vercel.app
For data deletion requests: Use in-app Settings → Delete My Account or email us.
13. Consent
By using BrainBatch, you consent to:
- This Privacy Policy
- Collection and use of information as described herein
- Transfer of data to third-party services (Firebase, Supabase, AdMob)
For EU/EEA users: You will be prompted for explicit consent via Google's User Messaging Platform when you first open the app.
---
Appendix: Data Processing Details
What Data We Collect
| Data Type | Purpose | Legal Basis (GDPR) | Retention Period |
| ----------- | --------- | ------------------- | ------------------ |
| Firebase UID (anonymous or authenticated) | Authentication, progress tracking | Legitimate interest | Until account deletion |
| Email (if using Sign in with Apple/Google) | Account identification | Consent | Until account deletion |
| Quiz answers | Performance tracking, stats | Legitimate interest | Until account deletion |
| Device info | Analytics, bug fixes | Consent | 90 days |
| Advertising ID | Personalized ads | Consent (via UMP) | Per AdMob policy |
| Notification time | Daily reminders | Consent (opt-in) | Until changed/deleted |
| Flagged questions | Content moderation | Legitimate interest | Until resolved |
| Crash logs | Bug fixes, stability | Consent | 90 days |
Data Sharing
We share data with:
- Firebase/Google: Analytics, authentication, advertising
- Supabase: Database hosting
- AdMob partners: Ad networks (with your consent)
We do NOT:
- Sell your personal information
- Share data with social media platforms (except for Sign in with Apple/Google authentication)
- Use your data for purposes other than described here
---
This Privacy Policy was last updated on January 7, 2026.