Privacy Policy
This Privacy Policy applies to the UCMAS mobile application for iOS and Android devices, along with any related services operated by Optibrain UCMAS (collectively, the "Application"). Optibrain UCMAS is referred to as the "Service Provider". The Service Provider is based in Canada and handles personal information in accordance with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, substantially similar provincial legislation.
Application Purpose and User Structure
The Application is designed as an educational tool to assist UCMAS students in practicing abacus methodologies. Access is limited to users with accounts provisioned by the Service Provider:
-
Student and Centre Users: Students and authorized centre personnel sign in with provisioned usernames and passwords to access practice, progress, and centre updates. Public self-registration is disabled. Authentication data (such as usernames, and session identifiers) is processed through Clerk to secure access to the Application. Student accounts are not required to have an email address.
-
Administrative Users: Administrative access is restricted to a controlled group of authorized personnel with elevated privileges. Administrative users sign in with provisioned email credentials and may use email verification as a second factor. Administrative users manage content, create information posts, and transmit operational push notifications.
Information Collection and Use
To sustain operations and deliver core app features, data collection is limited to the following categories:
-
Authentication Credentials: For all signed-in users, authentication data and session variables are processed through Clerk. Students typically sign in with a provisioned username and password. Administrative users may sign in with email and password, and may complete email verification when required. Practice and progress data generated during signed-in use is stored locally on the device unless otherwise described in this policy.
-
Device Tokens: For users who enable push notifications, the Application collects and stores standard mobile device tokens. These identifiers are stored within the application database using Prisma and are utilized solely to route push notifications.
-
Administrative Operations: Administrative users who publish content or send notifications may have their actions associated with their provisioned Clerk account for operational and security purposes.
-
Technical Network Data: When connecting to servers, technical protocol data such as ephemeral IP addresses is transmitted to facilitate network connectivity. This data is transient and is not retained for tracking or behavioral analysis.
-
Diagnostics and Performance Data: The Application uses Expo EAS Observe to collect limited diagnostics and performance information, such as app startup timing, screen rendering performance, navigation timing, app version, operating system version, platform, and anonymous installation or session identifiers. This information is used only to monitor reliability, diagnose performance regressions, and improve app stability. It is not used for advertising, behavioral profiling, or identifying student users.
-
App Usage Data: The Application uses Expo EAS Insights to collect anonymized app launch and usage metadata, such as platform, app store version, operating system version, update adoption, and an anonymous installation identifier. This data is used to understand release health and app usage trends. It is not used for advertising or behavioral profiling.
Does the Application collect precise real-time location information?
The Application does not request, collect, or monitor precise location-based data from your mobile device.
Third-Party Access and Data Sharing
The Service Provider shares data with infrastructure sub-processors only to the extent necessary to perform baseline technical operations:
-
Authentication Management: User credentials and sessions are authenticated and processed securely via Clerk.
-
Database Infrastructure: Device tokens and provisioned administrative data are stored within infrastructure managed through Prisma.
-
Notification Delivery Networks: Device tokens are passed to platform notification architectures, including Apple Push Notification service (APNs) and Firebase Cloud Messaging via Expo, to deliver push alerts.
-
Diagnostics and Usage Services: Anonymized diagnostics, performance metrics, and app usage metadata may be processed through Expo EAS Observe and Expo EAS Insights to support app reliability, performance monitoring, and release health analysis.
The Service Provider does not engage in behavioral advertising, third-party advertising analytics, or data monetization brokers. Operational diagnostics and usage monitoring described above are used solely to maintain and improve the Application.
What are my opt-out rights?
You may stop the processing of device tokens by disabling notification permissions in your device settings or by deleting the Application.
You may request access to, correction of, or deletion of personal information associated with your provisioned account by contacting the Service Provider at justinbdaludado@gmail.com. Where required by law, you may also withdraw consent for certain processing, subject to legal or contractual restrictions.
Your Rights Under Canadian Privacy Law
If you are located in Canada, you have rights under PIPEDA and applicable provincial privacy laws, including the right to:
- Know what personal information the Service Provider collects, uses, and discloses
- Access personal information held about you, subject to limited exceptions
- Request correction of inaccurate or incomplete personal information
- Withdraw consent to certain processing, where consent is the legal basis and withdrawal is permitted by law
- Challenge the Service Provider's compliance with applicable privacy obligations
To exercise these rights, contact the Service Provider at justinbdaludado@gmail.com. You may also file a complaint with the Office of the Privacy Commissioner of Canada or, where applicable, your provincial privacy regulator if you believe your privacy rights have been violated.
Children's Privacy
Because the Application is designed for UCMAS students practicing abacus exercises, the primary user demographic includes children.
Accounts are provisioned by the Service Provider or authorized centre personnel; children do not self-register through a public sign-up flow. Where a child is under the age at which they can provide meaningful consent under applicable Canadian law (generally under 13, or as required by applicable provincial law such as Quebec's privacy legislation), account provisioning and consent should be obtained from a parent or legal guardian through the UCMAS centre or the Service Provider.
The Application may process a provisioned username or, for administrative users, an email address and session identifiers through Clerk for authentication, and device tokens for push notifications. Parents and guardians retain authority over notification permissions and may revoke them by adjusting device notification preferences, contacting their UCMAS centre, or removing the Application.
Security
The Service Provider implements reasonable technical and administrative controls to protect database entries managed via Prisma and Clerk. However, because no internet transmission or electronic storage medium can be certified as fully infallible, absolute security cannot be guaranteed.
Data Breach Notification
In the event of a verified data breach posing a real risk of significant harm to an individual, the Service Provider will investigate the incident, take reasonable steps to reduce the risk of harm, and provide notifications to affected individuals and to the Office of the Privacy Commissioner of Canada (and any applicable provincial privacy authority) in accordance with PIPEDA and other applicable Canadian requirements.
Changes to This Privacy Policy
This Privacy Policy may be modified periodically to reflect shifting operational or regulatory standards. Material updates will be communicated by refreshing the privacy statement on the respective app distribution stores with a revised effective date.
This Privacy Policy is effective as of June 27, 2026.
Contact Us
For inquiries concerning privacy compliance, data handling, or to execute data rights, please contact the Service Provider via email at justinbdaludado@gmail.com.