Privacy Policy
The short version
- Lessons Left works without an account. Your students, parents, lessons, packages and payments are stored only on your device. We cannot see them.
- The only data that reaches our server is anonymous usage statistics (for example "lesson marked done"), without names, notes or amounts. You can turn them off in Settings.
- No ads, no data sales, no tracking across apps or websites, no advertising identifier (IDFA).
Who is responsible
The controller for the data described in this policy is [[DEVELOPER_NAME]], [[DEVELOPER_ADDRESS]] ("we"). Contact: [[CONTACT_EMAIL]].
For the student and parent records you enter in the app, you, the teacher, are the controller: you decide what to record and whom to send cards to. We never receive these records. Please tell the families you teach that you keep lesson and payment records, and ask for their consent where your local law requires it (for example the GDPR in the EU, APPI in Japan, PIPA in Korea or PIPL in China).
1. Data that stays on your device
Students and payers (names, the name shown on cards, phone numbers, email addresses, preferred channel, notes), lesson packages and plans, schedules, lessons and their status, cancellations and make-up lessons, charges and payments, your payment details and payment QR code image, card settings and app settings are stored only in the app's storage on your device. They are included in your device backups (for example iCloud Backup) if you use them, and in the backup and CSV files you choose to export.
The app keeps up to 14 automatic daily snapshots on the device so you can undo mistakes. Deleting a student deletes all of that student's records from the app; snapshots taken before that still contain them until they drop out of the 14-snapshot window or you delete them in Settings → Backup & export → Automatic snapshots. Settings → Delete all data first saves one safety snapshot so you can undo it; choose “Delete all data and snapshots” to leave nothing on the device. Deleting the app removes all of its data, snapshots included, from the device.
Contacts and photos: the app reads a contact only when you pick one to fill in a phone number or email, and a photo only when you choose a payment QR code image. It saves a card to your photo library only when you tap Save Image. None of this is sent to us.
Notifications (running low, expiring, overdue, lesson reminders) are scheduled locally on your device. No push server is involved.
2. Cards you send to parents
When you share a balance, renewal, bill or receipt card, the app creates an image or text on your device and hands it to the service you choose (Messages, Mail, LINE, KakaoTalk, WhatsApp, WeChat or another app in the share sheet). We do not receive the card. What happens next is governed by that service's privacy policy.
3. Usage statistics (you can turn this off)
To learn which features help and where people get stuck, the app sends anonymous product-usage events to our server, for example: onboarding completed, student added, lesson marked done, lesson rescheduled or cancelled, card shared (template and channel only), payment recorded, Pro screen viewed, purchase completed (product ID only).
Each event carries: the event name and a few technical properties, a random installation ID created by the app, a random session ID, app version and build, iOS version, device model, language and time zone. Amounts are sent only as rough ranges with the currency code.
We never send student or parent names, phone numbers, email addresses, notes, exact amounts, payment details, contacts or any text you type.
Legal basis: our legitimate interest in improving the app (GDPR Art. 6(1)(f)). You can object at any time in Settings by turning off "Share anonymous usage data"; from the next launch the app sends no events at all.
If your device region is in the EU/EEA, the United Kingdom, Switzerland or South Korea, usage statistics are off by default and no installation ID is created until you turn them on in Settings. There the legal basis is your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time with the same switch.
Retention: individual events 90 days, daily totals (counts only) 400 days. Because events are not linked to your identity, we usually cannot find the events of a specific person; they are deleted automatically.
4. Purchases
Lessons Left Pro is sold through the App Store. Apple processes the payment; we never receive your name, Apple ID or payment details. The app checks your purchase on the device with Apple's StoreKit. If usage statistics are on, the "purchase completed" event contains only the product ID.
5. Crash reports
When the app crashes, it can send a crash report to Firebase Crashlytics, a service of Google LLC. A report contains the technical crash details (stack trace), device model, iOS version, app version, free disk space and memory, the time of the crash and a random Crashlytics installation ID. It never contains student or parent names, notes, amounts or other text you type. Purpose: finding and fixing bugs. Legal basis: our legitimate interest in a stable app (GDPR Art. 6(1)(f)). Retention: 90 days.
6. Server logs and IP addresses
Our server (the statistics endpoint and these web pages) runs on Cloudflare. To deliver requests and protect the service against abuse, Cloudflare processes your IP address. We use it only for short-lived rate-limit counters that are deleted after 2 days; we do not store it with the events.
7. Diagnostic logs you choose to send
The app keeps a technical log on your device (no student names or amounts). It is only sent to us if you choose Settings → About → "Export diagnostic logs" and then send the files yourself (for example by email) from the share sheet. We use it only to answer your request and delete it within 90 days after the issue is closed.
8. Service providers
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting of the statistics endpoint (Workers) and database (D1), these web pages | Global network; database region Asia-Pacific (APAC) |
| Google LLC (Firebase Crashlytics) | Crash reports | United States / global |
| Apple Inc. | App distribution, payments, local notifications | According to Apple's privacy policy |
Where data is transferred outside your country (for example from the EU/EEA to the United States), it is protected by the EU Standard Contractual Clauses and the provider's data processing terms. Apart from Firebase Crashlytics, the app contains no third-party SDKs: no third-party analytics and no advertising SDKs (usage statistics go only to our own server). If we add one, we will update this policy first.
9. What we do not collect
Location, your contacts list, your photo library, microphone, camera, health data, the advertising identifier, browsing history. No ads, no data sales, no tracking.
10. Your rights
- Access and portability: export all your data at any time as a backup file or CSV.
- Correction and deletion: edit or delete any record in the app; Settings → Delete all data; or delete the app.
- Objection: turn off usage statistics in Settings.
- You can contact us at [[CONTACT_EMAIL]] and you may complain to your local data protection authority.
Depending on where you live, laws such as the GDPR (EU/EEA and UK), the Personal Information Protection Act of Korea, the Act on the Protection of Personal Information of Japan, the Personal Information Protection Law of China and US state privacy laws give you these rights. We reply within 30 days.
11. Children
Lessons Left is a tool for teachers and is not directed at children. Students do not use the app; their records are entered by the teacher and stay on the teacher's device. We do not knowingly collect personal data from children.
12. Security
All connections to our server use HTTPS. The statistics database stores no names or contact details. On your device, the data is protected by iOS data protection; we recommend a device passcode.
13. Changes
If we add features that change what data is processed (for example iCloud sync or a read-only balance link for parents), we will update this policy before the feature is released and show the changes in the app's release notes.