Privacy Policy
This Privacy Policy explains how Production da Vinci K.K. ("we", "us", "the Company") handles personal data in connection with the Gradigo learning application and website (the "Service"). It supersedes any prior policy for the Service.
We have written this policy to match what the Service actually does. If you find a discrepancy between this text and the Service, please tell us at the contact below.
1. Who is responsible
The data controller is Production da Vinci K.K. (Japan).
- Contact: support@production-davinci.com or our contact page.
- Product: Gradigo (GRE / GMAT / TOEFL / IELTS preparation — vocabulary, quantitative, and verbal practice).
2. Data we collect
We collect only what the Service needs to work. Categories:
| Category | Examples | Source | Required? |
|---|---|---|---|
| Account & identity | Email, display name, profile photo, sign-in provider (Google / Apple / email), account timestamps | You / your sign-in provider | Required to have an account |
| Study profile | Target exams, target score, test date, study goal, preferred language | You | Optional |
| Learning data | Vocabulary / quantitative / verbal practice and review history, progress and mastery, mistakes, bookmarks, streaks, mock-exam results, in-progress exam state (with a device identifier for cross-device sync) | Generated as you study | Created by use |
| Subscription | Your Pro entitlement status and expiry (a cached copy; the authoritative record is held by RevenueCat), free-tier usage counters | Your purchase / RevenueCat | Only if you subscribe |
| Referral | Invite/inviter relationships and your referral code | Referral feature use | Only if you use referrals |
| Analytics & diagnostics | Product-usage events, Core Web Vitals (web), crash and error reports (mobile) — pseudonymous at most, never linked to your email or account id (see §6) | Automatic (consent-gated) | Optional |
| Technical | IP address in server access logs, approximate device/browser info, a device identifier used for exam sync | Automatic | Created by use |
We do not collect: your exact location, advertising identifiers (there is no advertising SDK and no cross-app tracking; the iOS app shows no App Tracking Transparency prompt), payment card numbers (handled by the store or payment processor — see §5), your date of birth, or biometric data. Push-notification tokens are requested on mobile but discarded, never stored or transmitted; all reminders are scheduled locally on your device.
3. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR, where applicable) |
|---|---|
| Provide your account, sync your learning progress and settings across devices | Performance of a contract |
| Provide and manage the Gradigo Pro subscription and free-tier limits | Performance of a contract |
| Keep the Service secure — authentication, breached-password checks, abuse prevention, App Check | Legitimate interests (security); legal obligation where relevant |
| Diagnose crashes and errors, and improve the product | Consent (analytics/crash reporting is opt-in on web, opt-out on mobile) |
| Operate the referral programme | Performance of a contract / your request |
| Communicate with you about the Service (e.g. email verification, support replies) | Performance of a contract; legitimate interests |
4. Third parties who process data, and where
We use the following processors. We do not sell your personal data, and we do not share it for advertising.
| Processor | What it does | Region | Data it receives |
|---|---|---|---|
| Google / Firebase (Google LLC) | Authentication, database, cloud functions, storage, App Check | Firestore, functions and storage run in asia-northeast1 (Tokyo); Firebase Authentication is a global service | Account, learning, subscription-cache, and referral data |
| PostHog | Product analytics | EU | Pseudonymous product-usage events and Web Vitals — never your email or account id (see §6) |
| Sentry (mobile app only) | Crash and error monitoring | EU | Redacted crash/error reports, tagged with a pseudonym at most |
| RevenueCat | Subscription and entitlement management (authoritative record of your Pro status) | United States | Your account identifier and purchase/entitlement records |
| Apple | App Store in-app purchases (iOS); Sign in with Apple | Apple regions | Payment and subscription data for iOS purchases; sign-in token |
| Google Play | Google Play in-app purchases (Android); Google sign-in | Google regions | Payment and subscription data for Android purchases; sign-in token |
| Stripe (via RevenueCat Web Billing) | Web payment processing (currently limited — see Terms) | United States / global | Payment details, only when you buy on the web |
| Vercel | Website hosting and performance measurement (Speed Insights) | Global edge / United States | HTTP access logs (including IP address), request metadata, Core Web Vitals |
| "Have I Been Pwned" (Cloudflare) | Checks at sign-up whether your chosen password appears in known breaches | Global | Only the first five characters of a hash of your password; your password and full hash never leave your device |
Because these processors operate outside Japan (and, for some, outside the EU/UK), your data may be transferred internationally. Where required, such transfers rely on the processor's standard contractual clauses or an equivalent lawful transfer mechanism.
5. Analytics, crash reporting, and your control over them
Analytics and crash reporting are designed to be privacy-preserving:
- We never send your Firebase account id or email to PostHog or Sentry. At most we use an opaque, rotatable pseudonym issued by our server; when that pseudonym service is not active, analytics is fully anonymous (an anonymous device identifier only).
- Before any event is sent, URLs are reduced to route templates (query strings and one-time codes removed), emails and tokens are stripped, and keys that could carry sensitive values are dropped. Text on the page is masked in autocapture.
- Session recording and replay are switched off. On the web, your IP address is configured to be discarded by PostHog. Sentry is configured not to attach your IP, cookies, or request bodies.
- There is no advertising, and no tracking across other companies' apps or websites.
On the web, analytics is off until you accept it in the consent banner; you can choose "Essential only" to keep it off. On mobile, analytics is on by default and you can turn it off at any time in Settings → Privacy. Turning it off stops sending to PostHog and removes your identifier from crash reports.
6. How long we keep data
- Your account and learning data are kept for as long as your account is active, and are deleted when you delete your account (see §8).
- Database backups are retained for operational recovery: daily backups for 7 days and weekly backups for 8 weeks; point-in-time recovery covers a rolling 7-day window. Backups age out on this schedule.
- A data-export archive you request is a one-time download that expires quickly: the download link is valid for 15 minutes, and the archive file itself is deleted within 24 hours (fully unrecoverable within about 8 days).
- Processors (PostHog, Sentry, RevenueCat, Vercel) retain data according to their own configured retention; we minimise what they receive as described in §4 and §6.
7. Your rights and how to exercise them
You can exercise the following rights over your personal data. Where the GDPR, UK GDPR, or similar laws apply, these include access, rectification, erasure, portability, restriction, and objection.
- Export (portability / access): from the web app, Settings → Data & Privacy → Download my data produces a machine-readable JSON archive of your data. For your security this requires a recent sign-in and is limited to once every 30 days. (Mobile export is planned; you can request an export by contacting us in the meantime.)
- Delete (erasure): from Settings on either the web or mobile app, choose Delete account. After re-authentication, this immediately and permanently deletes the data we hold in Firebase (your profile, learning history, progress, referral records, and any export archives).
- Sign out of all devices: available from Settings; this revokes all active sessions.
- Correction: you can edit your profile in-app, or contact us.
Please note: deleting your account removes the data we hold, but does not automatically delete records held by external processors. Your subscription record at RevenueCat, and any pseudonymous analytics/crash data at PostHog or Sentry, are governed by those processors' retention; contact us and we will make a deletion request to them on your behalf. To stop future analytics collection entirely, turn analytics off (§6) before deleting.
To make any request or ask a question, use support@production-davinci.com or our contact page. We aim to respond within 30 days.
8. Security
We protect your data with owner-scoped database access rules (you can only read and write your own records), enforced email verification, a minimum 12-character password with a breached-password check at sign-up, App Check to limit abuse of our backend, and encryption in transit. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your information.
9. Children
The Service is intended for people preparing for graduate and English-proficiency admissions tests and is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us data, contact us and we will delete it. Where local law sets a higher age of digital consent, a minor should use the Service only with the consent of a parent or guardian.
10. External-transmission disclosure (Japan)
In accordance with the external-transmission rules of Japan's Telecommunications Business Act (電気通信事業法の外部送信規律), we disclose that the Service may transmit certain information from your device to the following recipients:
- PostHog (EU) — pseudonymous product-usage information, to measure and improve the Service. Sent only after you consent (web) or unless you have turned analytics off (mobile).
- Sentry (EU) — crash and error information from the mobile app, to detect and fix defects. Not sent if you turn analytics off.
- Google / Firebase, Vercel — information necessary to operate the Service (authentication, data storage, hosting, and access logs).
You can stop analytics/crash transmission at any time as described in §6. Transmissions necessary to provide the Service (for example, saving your progress) cannot be turned off while you use the Service.
11. EU/UK and California users
EU / UK (GDPR): the legal bases for our processing are set out in §3. You have the rights described in §8, and the right to lodge a complaint with your local supervisory authority. We have not appointed an Article 27 representative or a Data Protection Officer; direct any GDPR request to the contact in §1.
California (CCPA/CPRA): we do not sell or "share" (as those terms are defined) your personal information, and we do not use it for cross-context behavioural advertising. You may exercise your rights to know, delete, and correct using §8.
12. Security incidents
If we become aware of a security incident affecting your personal data, we will act promptly and, where required by law, notify affected users and the relevant authorities. To report a suspected vulnerability or incident, contact support@production-davinci.com.
13. Changes to this policy
We may update this policy. When we do, we will change the version and effective date below. For material changes that affect your rights or how we use your data, we will provide a more prominent notice (for example, in the app or by email) and, where the law requires it, ask for your consent again. The change history is listed below.
Change history
- 1.1 (July 31, 2026): Android in-app purchases are now offered, so the Google Play processor entry records that Google Play receives payment and subscription data for Android purchases.
- 1.0 (July 11, 2026): First version hosted on gradigo.online. Aligns the policy with the actual Service: names all processors (Firebase, PostHog EU, Sentry EU, RevenueCat, Vercel, Apple/Google, Stripe, HIBP) and their regions, documents pseudonymous/anonymous analytics, retention and backups, and self-service export/deletion.