1. Why we process personal data
We process only the data reasonably necessary to:
- register, sign in, identify, secure, and manage parent-managed accounts;
- store learner profiles and multiplication quiz results and synchronize them across devices;
- provide learning statistics such as correct answers, practice count, and best streak;
- respond to inquiries, investigate errors, and process account and data deletion requests; and
- maintain service security and prevent abuse.
Basic learning and quiz features are available without signing in. Guest results and settings are stored on the device. Cloud Firestore stores and synchronizes account-based learning data only after a member signs in.
2. Personal data we process
| Context | Data | Purpose | Retention |
|---|---|---|---|
| Registration and sign-in | Email address, password and other authentication information, Firebase user ID (UID), account creation and recent sign-in information | Create, identify, secure, and manage the account | Until account deletion, subject to Firebase Authentication's actual retention policy |
| Account and aggregate learning statistics | UID, email address, display language, account type, account creation, recent sign-in and recent practice timestamps, quiz and correct-answer totals, best streak | Account management and aggregate learning statistics | Until account deletion |
| Learner profile | Display name or nickname, profile ID, creation and update timestamps | Distinguish learners within one account | Until account deletion or deletion of that learner profile |
| Learning records | Score, question, correct and incorrect counts, streak, difficulty, question types, selected multiplication tables, time limits, response times, question and answer records, correctness, learning language, profile ID and nickname, completion and synchronization timestamps | Save and display results, provide statistics, and synchronize across devices | Until account deletion; older records may be removed under the app's per-profile history limit |
| Customer support | Email address, inquiry and response history, and—if the user chooses to provide them—device model, Android version, app version, error time, and screenshots with personal data obscured | Respond to inquiries, investigate errors, and handle disputes | Three years after the inquiry is closed or for a period required by law |
| Automatically processed by Firebase Authentication | IP address and user-agent information | Security and abuse prevention during registration and authentication | Logged IP addresses may be retained for a few weeks; Firebase's actual retention policy applies |
Passwords are processed by Firebase Authentication for authentication. The Operator does not directly view or store passwords in plaintext.
3. Children and parent or guardian supervision
Children must use NumiPop under the supervision of a parent or legal guardian. Where parental or guardian consent is required under the laws applicable in the user's country or region, the parent or legal guardian must create and manage the account or provide the required consent.
The adult confirmation shown during registration is a user confirmation. It does not electronically verify the person's relationship to a child and is not stored as a separate parental-consent record.
For users in the United States, the Children's Online Privacy Protection Act (COPPA) may require parental notice and verifiable parental consent before an online service directed to children, or one with actual knowledge of a child under 13, collects personal information from that child. For users in the EEA or United Kingdom, the GDPR or UK GDPR may require parental authorization where processing is based on a child's consent, with the applicable age determined by local law. The current registration confirmation is not represented as satisfying those verification requirements. A parent or guardian should create the online account with the adult's own email address, and a child should not enter an email address or other identifying information.
4. Disclosure to third parties
We do not disclose personal data to third parties as a general rule, except with the user's prior consent or where disclosure is authorized or required by law.
5. Service providers
| Provider | Service | Data processed | Retention |
|---|---|---|---|
| Google LLC (Firebase Authentication) | User authentication, account management, security, and abuse prevention | Email address, password and other authentication information, Firebase UID, IP address, and user agent | Until account deletion or the end of the service arrangement, subject to Firebase's actual retention policy |
| Google LLC (Cloud Firestore) | Store account information, learner profiles, and learning data and synchronize them across devices | UID, email address, display language, account and learning statistics, learner nickname and profile ID, and quiz results | Until account deletion or deletion of the relevant information |
The Cloud Firestore database used by NumiPop is stored in the Seoul, Republic of Korea region (asia-northeast3).
6. International Data Transfers
NumiPop is operated by a business based in the Republic of Korea. Depending on the Firebase service used, personal data may be processed in the Republic of Korea or the United States. We take reasonable measures to protect personal data in accordance with applicable law.
| Recipient and contact | Location | Data | Purpose | When and how | Retention |
|---|---|---|---|---|---|
| Google LLC (Firebase Authentication) Google privacy contact |
United States | Email address, password and other authentication information, Firebase UID, IP address, and user agent | Registration, sign-in, account management, security, and abuse prevention | Transmitted over an encrypted connection during registration, sign-in, and authentication requests | Until account deletion. Logged IP addresses may be retained for a few weeks, and removal of other authentication information from live and backup systems may take up to 180 days after deletion is initiated |
You can decline the transfer involved in Firebase Authentication by not registering. You may still use basic learning features as a guest, but account-based storage and cross-device synchronization will not be available.
7. Retention and deletion
- Account data: after the current password is verified in the app, deletion begins for the identified Cloud Firestore profile, quiz-result, and account documents and for the Firebase Authentication account.
- Authentication data: after account deletion, complete removal from Google's live and backup systems may take up to 180 days.
- Guest data: stays on the device and may be removed by clearing app data or uninstalling the app. The account deletion flow has no separate option to erase every guest record that is not linked to the account.
- Support records: may be retained for three years after an inquiry is closed or for a period required by law.
- Legal retention: data that must be retained by law will be separated, used only for that purpose, and deleted when the applicable period ends.
8. User and legal guardian rights
Users and legal guardians may request access, correction, deletion, restriction of processing, withdrawal of consent, or account closure, subject to applicable law.
- In the app: Account → Delete account and data
- On the web: Account & Data Deletion
- By email: [email protected]
We may verify the identity or authority of the requester using the minimum information reasonably necessary and will handle the request under the procedures and time limits required by applicable law.
Regional privacy rights
- Republic of Korea: rights are handled under the Personal Information Protection Act.
- EEA and United Kingdom: where the GDPR or UK GDPR applies, a user may also have rights to data portability, to object, and to complain to the competent supervisory authority. Core account processing is used to provide the requested service; security processing is used to protect accounts and prevent abuse; consent is requested where the applicable law requires it.
- United States: where COPPA applies, a parent may review or request deletion of a child's personal information and refuse further collection or use. Additional state privacy rights apply only where the relevant state law covers the Operator and processing.
Official references: EU General Data Protection Regulation, UK ICO guidance on children and the UK GDPR, and U.S. FTC COPPA guidance.
9. Security measures
- Encryption in transit using HTTPS/TLS
- Authentication and access control through Firebase Authentication
- User-scoped access through Firestore Security Rules
- Protection of administrator accounts and least-privilege access
- Reviews of security settings and data processing
10. Cookies, advertising, analytics, and diagnostics
The reviewed app version does not initialize or use Google Analytics or Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring, Google Mobile Ads or AdMob, or another advertising SDK. We also found no code that separately stores device model, operating-system version, app version, advertising ID, or IP address in Cloud Firestore.
The app and this information site do not use cookies or advertising identifiers for personalized advertising. Firebase Authentication does process IP addresses and user-agent information for security and abuse prevention. We will review this policy and the Google Play Data safety information before introducing tools that change these facts.
The Korean account menu includes an optional “Buy image arithmetic cards” link that opens a Naver Smart Store product page after the parent chooses to continue. The app does not append a Firebase UID or registered email address to that URL, includes no in-app billing or subscription SDK, and stores no payment data in Cloud Firestore. Orders and payments made on the external store are governed by that store's privacy and transaction-retention terms.
11. Privacy contact
| Operator | 이지수 (business name: 직선거리) |
|---|---|
| Privacy Officer | 이지수 |
| [email protected] | |
| Business registration number | 263-05-02002 |
12. Complaints and remedies
You may contact us first at [email protected]. Users in the Republic of Korea may also contact the Personal Information Infringement Report Center (118), the Personal Information Dispute Mediation Committee (1833-6972), or the Korean National Police cybercrime reporting system (182). Users elsewhere may contact the data-protection authority available in their country or region.
13. Changes to this policy
We will provide notice through the app or this website before a material revision takes effect and will follow any additional procedure required by applicable law.
Original effective date: July 20, 2026 · Last updated: August 4, 2026