Privacy Policy
Talas — Educational Learning and Quiz Application
Version: 3
Last Updated: August 9, 2026
1. Who We Are and What This Policy Covers
Talas is operated by its developer ("Talas," "we," "us," or "our"). This Privacy Policy explains how Talas processes personal data when you use the mobile application, learner web experience, and related services (collectively, the "Service").
For privacy questions or requests, contact:
- Email: guilius.kanin@gmail.com
- Subject: "Talas Privacy Request"
This policy is a privacy notice. Agreeing to the Terms of Service acknowledges this notice; it is not blanket consent for every possible use of personal data. Where consent is legally required for a specific activity, we will request it separately when appropriate.
2. Personal Data We Process
The data processed depends on the features you use.
2.1 Account and Authentication
- Google account email address, display name, profile photo URL, and Google or Firebase user identifier
- Authentication events, account status, roles, and acceptance records for legal terms
- We use Google Sign-In and do not receive or store your Google password
2.2 Learner and Institution Profile
- Display name and a profile photo you choose to upload
- Learner type, such as Undergrad, Reviewee, Professional, or High School
- Undergrad year level, when applicable
- Selected school, review center, professional organization, or other institution
- For an eligible School Subject Analytics Portal pilot, your choice to connect future activity to a school analytics space, the school that verified the connection, and its effective start and end dates
- Tribe, level, badges, and other profile or achievement information
2.3 Learning and Activity Data
- Quiz and diagnostic attempts, selected answers, correctness, scores, response timing, completion status, and synchronization state
- Subjects, topics, reading activity, downloads, progress, mastery, goals, missions, streaks, XP, rewards, badges, rankings, and usage budgets
- Question flags, feedback, problem reports, and optional comments
- Weekly learning summaries and AI-assisted study insights
- Internal records used to calculate privacy-protected subject and activity summaries for an eligible school analytics space
2.4 Community and Social Data
- Forum threads, replies, votes, follows, reports, and moderation records
- Community notes, reactions, flags, and contribution records
- Follow relationships, Study Circle membership, and related notification preferences
- Public-profile information and activity-status categories
2.5 Multiplayer and Facilitated Sessions
- Room membership, host or participant role, answers, response timing, scores, results, and reconnect state
- Online presence and connection status for features that show availability
- App-switch or similar integrity signals, infraction counts, and facilitator session reports where supported by the selected game mode
Talas does not use a learner's camera, microphone, or screen recording for multiplayer monitoring. Device and network behavior can affect integrity signals, so they require contextual human review.
2.6 Device, Notification, Analytics, and Diagnostic Data
- Device type, operating system, app version, language and feature preferences
- Push-notification tokens and notification interaction events
- App screens and features used, session and performance events, and pseudonymous app or device identifiers used by analytics providers
- Crash reports, error logs, and technical diagnostics, which may contain device details and limited account or event context
2.7 Information We Do Not Ordinarily Collect From Learners
At the date of this policy, Talas does not operate an in-app payment system and does not collect payment-card information. Ordinary learner use does not require precise location, contacts, microphone recordings, or camera recordings. Talas processes a profile image only when you choose a file to upload or use a photo already associated with your Google account.
3. Where Data Comes From
We receive data:
- Directly from you when you sign in, complete your profile, upload a photo, participate in learning or community features, or contact us
- Automatically from the Service when you study, interact, receive notifications, encounter errors, or join multiplayer sessions
- From Google Sign-In and Firebase services used for authentication and infrastructure
- From an authorized school representative when Talas verifies a learner's prospective connection to a school analytics space, or when another institution-supported account, class, or enrollment is involved
- From other users when they follow, reply to, report, invite, or otherwise interact with you
4. Why We Process Data
Depending on the activity and applicable law, Talas processes personal data to:
- Authenticate accounts and provide requested Service features
- Save learning history, calculate server-authoritative results, and synchronize offline activity
- Personalize study progress, recommendations, goals, reminders, and insights
- Operate public profiles, rankings, community, social, and multiplayer features
- Support class, teacher, facilitator, or school experiences that a learner joins
- Produce aggregate subject and activity summaries for an eligible school analytics space a learner chooses to join
- Send service, learning, social, security, and administrative notifications according to available preferences
- Moderate content, investigate reports, prevent cheating and abuse, protect users, and enforce the Terms of Service
- Diagnose failures, measure feature reliability, control operating costs, and improve Talas
- Comply with legal obligations and establish, exercise, or defend legal claims
The applicable legal basis may include providing the Service you request, Talas's legitimate interests in operating and protecting the Service, consent where required, and compliance with legal obligations. We apply the principles of transparency, legitimate purpose, and proportionality.
5. Information Visible to Other People
Talas includes social and institution-supported features. Depending on the feature:
- Other signed-in learners may see your public-profile display name, selected profile photo, level, XP, tribe, quiz and accuracy summaries, featured badges, follower and following counts, and broad activity-status category.
- Leaderboards and multiplayer rooms may show your display name, score, ranking, progress, or result to eligible participants.
- Forum posts, replies, community notes, reactions, and follow relationships may be visible to signed-in learners, a selected tribe, moderators, or administrators.
- Question-report categories and limited reporter information may be visible in learner quality-review features; full report details are restricted to authorized reviewers.
- Some institution-supported features outside the School Subject Analytics Portal may make enrollment, participation, or learning-performance information available to authorized teachers, facilitators, school administrators, or Talas administrators. The feature should explain its visibility before you join it.
Selecting an institution in your profile does not by itself verify enrollment. Do not include private or sensitive information in a display name, public profile, forum post, reply, note, or multiplayer room.
5.1 School Subject Analytics Portal
The initial real-learner pilot of the School Subject Analytics Portal is for adults enrolled in tertiary education. It does not include senior-high-school learners or other minors. Any future use involving minors requires a separate consent and privacy design before it is offered.
An eligible learner chooses whether to connect future Talas activity to a school analytics space. The connection must be verified and has effective start and end dates. Activity from before the effective start date is not transferred into the school's analytics, and selecting a school in a profile does not create this connection.
Schools receive aggregate summaries only. Through this portal, a school does not receive learner names, email addresses, Talas or Firebase user identifiers, individual attempts, individual scores, learner drill-downs, rosters, or student-level exports. Talas still processes learner-level account, membership, and activity data internally to verify eligibility and calculate those summaries.
Talas suppresses a group's analytics when the group has fewer learners than the configured minimum threshold. The exact threshold may be adjusted as the pilot is evaluated; a suppressed result does not reveal the underlying learner-level data to the school.
6. AI-Assisted Processing
Talas uses Google AI services to help create or review educational content and to generate some study insights.
For a weekly learner insight, Talas may send a bounded summary of recent learning metrics—such as quizzes completed, accuracy, XP, and streak days—to the AI service. The prompt does not include the learner's name, email address, or Talas user identifier. The resulting insight is stored with that learner's account.
AI output is advisory educational content. It does not make legal or similarly significant decisions about a learner and should not be treated as an official academic or professional determination.
7. When We Disclose Data
We do not sell personal data. We disclose data only as reasonably needed:
- To other users, teachers, facilitators, moderators, and institution administrators through the visibility rules described above; School Subject Analytics Portal disclosures to schools are limited to the aggregate, threshold-protected summaries described in Section 5.1
- To Google and Firebase services that provide authentication, databases, file storage, cloud functions, hosting, notifications, analytics, crash reporting, and AI processing
- To people who help operate or secure Talas and are authorized to handle the relevant information
- When required by law, legal process, or a valid government request
- To investigate abuse, protect rights or safety, prevent fraud, or address a security incident
- In connection with a reorganization or transfer of the Service, subject to appropriate notice and safeguards
We do not authorize service providers to use personal data for their own unrelated purposes.
8. Storage, Security, and International Processing
Talas primarily uses Firebase and Google Cloud services. Data may be processed in data centers outside the Philippines, subject to provider safeguards and applicable data-protection requirements.
We use reasonable administrative, technical, and organizational safeguards, including access controls and encryption provided by our cloud services in transit and at rest. Locally cached data is isolated by the operating system's application sandbox, but the sandbox is not described as independent application-level encryption.
No system is completely secure. You should protect your Google account and device, use available security controls, and report suspected unauthorized access.
9. Retention and Account Deletion
We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including providing learning history, maintaining community conversations, securing the Service, resolving disputes, and meeting legal obligations.
In general:
- Active account and learning data is retained while the account remains in use or while needed to provide the Service.
- Transient presence, cache, notification, rate-limit, and operational records are removed or rotated according to their operational purpose.
- Analytics, crash, security, and audit records follow configured retention periods appropriate to their purpose and provider.
- When account deletion completes, Talas deletes the authentication account and sweeps user-scoped learning, profile, social, enrollment, and operational records.
- Authored forum or community content may be anonymized rather than erased so that shared conversations and moderation history remain understandable.
- Limited information may remain temporarily in protected backups or be kept where necessary for security, fraud prevention, legal compliance, or legal claims.
Account deletion can be started from the Profile screen. Because deletion is permanent once completed, Talas may require recent authentication before processing it.
10. Your Privacy Rights
Subject to applicable law, you may have the right to:
- Be informed about the processing of your personal data
- Access personal data Talas holds about you
- Correct inaccurate or incomplete information
- Object to or request restriction of certain processing
- Request erasure or blocking of data
- Request a portable copy of eligible data
- Withdraw consent for processing that relies on consent, without affecting earlier lawful processing
- Seek damages or file a complaint with the National Privacy Commission
Some information can be reviewed or changed directly in the Service. For other requests, email guilius.kanin@gmail.com with the subject "Talas Privacy Request." We may need to verify your identity and clarify the scope of the request before acting.
11. Children's Privacy
Talas is not intended for children under 13. Users aged 13 to 17 should use Talas only with the permission and supervision of a parent or legal guardian.
Talas does not currently collect a date of birth or use identity-document age verification. Learner-type selections, including "High School," are used to tailor the learning experience and are not treated as verified proof of age.
The School Subject Analytics Portal pilot is not available to users under 18, including senior-high-school learners. This pilot boundary does not change the eligibility rules for other Talas features described above.
Parents and guardians should review Talas's public-profile, community, multiplayer, and institution-sharing features with a minor. A parent or legal guardian may contact us to ask about, correct, restrict, or delete a minor's personal data. If we learn that personal data was collected from a child under 13 who was not eligible to use Talas, we will take appropriate steps to restrict the account and delete the data.
12. Third-Party Services
Key service providers include:
| Service | Purpose | Privacy information |
|---|---|---|
| Google Sign-In and Firebase Authentication | Account login | Google Privacy Policy |
| Cloud Firestore, Realtime Database, Cloud Functions, Cloud Storage, and Hosting | Service infrastructure and data storage | Firebase Privacy and Security |
| Firebase Cloud Messaging | Push notifications | Firebase Privacy and Security |
| Google Analytics for Firebase | Product analytics | Firebase Privacy and Security |
| Firebase Crashlytics | Crash and diagnostic reporting | Firebase Privacy and Security |
| Google AI services, including Gemini | Educational content support and bounded learner insights | Google Privacy Policy |
External sites and services have their own privacy practices. Review their notices before providing information directly to them.
13. Changes to This Policy
We may update this policy to reflect changes in Talas, law, security practices, or service providers. We will update the date above and may provide an in-app notice. Material changes may be presented together with a new Terms version or another appropriate acknowledgment or consent flow.
14. Contact and Complaints
For privacy questions, requests, or concerns:
- Email: guilius.kanin@gmail.com
- Subject: "Talas Privacy Request"
You may also contact or file a complaint with the National Privacy Commission.