Noomix · Privacy

Noomix Privacy Policy

Last updated: May 26, 2026

This policy describes how Kitusoft ("we", "us") collects, uses, and protects the information processed when you use the Noomix mobile application ("the App"). It is written to comply with the EU General Data Protection Regulation (GDPR), Ecuador's Organic Law for the Protection of Personal Data (LOPDP, 2021), Brazil's Lei Geral de Proteção de Dados (LGPD), the California Consumer Privacy Act (CCPA/CPRA), the U.S. Children's Online Privacy Protection Act (COPPA), and the data-disclosure requirements of Google Play Data Safety and Apple App Store App Privacy.

1. Data controller

Kitusoft (Cesar J. Santacruz), based in Quito, Ecuador. Privacy contact: soporte@kitusoft.com.

We are not required to appoint a Data Protection Officer under GDPR Article 37, but we receive and resolve rights requests through that same address.

2. Quick summary

  • You can use Noomix without creating an account (local mode). In that case your data stays on your device.
  • If you choose to create an account, we sync your profile, study decks, and session history through Google Firebase so you don't lose them.
  • We do not sell your information. We do not use ads or behavioral trackers today.
  • The camera is only activated to scan QR codes for shared decks. We do not take photos and do not record audio.
  • You can delete your account and your data at any time from inside the App or by emailing us.

3. Data we process

3.1 Local mode (no account)

All information stays in your device's storage and never leaves it:

  • The display name, gender, and avatar you choose during onboarding.
  • Your study decks (titles, questions, answers, settings).
  • Your session history (XP, streak, level, decks played).
  • Your preferences (light/dark theme, sounds, haptics, selected mascot).

We have no way to read this data unless you enable cloud sync.

3.2 If you create an account or sign in

We process the following data in Firebase Authentication and Cloud Firestore (services provided by Google LLC):

| Category | Specific data | Source | |---|---|---| | Account identification | Email address, unique identifier (UID) | You or Google Sign-In | | Public in-App profile | Display name, username, profile photo URL, gender | You | | Credentials | Password (stored encrypted by Firebase, never in plain text and we never see it) | You | | Google identity (if you use Google Sign-In) | Name, profile photo, email, Google ID | Google OAuth | | Learning content | Decks, questions, correct answers, explanations | You | | Social | List of friend UIDs, list of UIDs you share decks with | You | | Study activity | Sessions played, per-question results, duration, XP, streak, level | Generated by the App during play | | Share codes | 8-character alphanumeric codes that link to a deck | Generated by the App |

3.3 Operating-system permissions

  • Camera — activated only when you tap "Scan code". The image is processed on-device to decode a QR code and then discarded. We do not upload or store the image.
  • Network — required to sync with the cloud if you have an account.
  • Audio — the App plays feedback sounds (correct, wrong, level-up). It does not use the microphone.
  • Storage — to save your decks locally and to export/import files when you ask for it.

4. Why we process this data, and on what legal basis

| Purpose | Data | Legal basis (GDPR Art. 6) | |---|---|---| | Create and maintain your account, authenticate you | Email, password, UID, Google data | Performance of contract (Art. 6(1)(b)) | | Sync your decks and progress across devices | Learning content, study activity | Performance of contract (Art. 6(1)(b)) | | Make social features work (sharing decks, viewing friends' public profile) | Public profile, friend list, share codes | Performance of contract (Art. 6(1)(b)) | | Respond to support requests | Email, message | Legitimate interest (Art. 6(1)(f)) | | Comply with legal obligations (respond to authorities) | Any of the above | Legal obligation (Art. 6(1)(c)) | | Prevent abuse, fraud, and Terms violations | Identifiers, activity | Legitimate interest (Art. 6(1)(f)) |

5. Who has access to your data

  • Us (Kitusoft) — only authorized personnel, only when necessary for support or maintenance.
  • Google LLC (Firebase and Google Sign-In) — as a processor. Hosts the database and authentication. Google Firebase is certified under the EU Standard Contractual Clauses (SCCs) and participates in the EU-U.S. Data Privacy Framework.
  • People you choose to share decks with — they will see the shared decks and your public in-App profile.

We do not sell your information. We do not disclose it to data brokers or ad networks.

6. International transfers

Your data is stored on Google Firebase servers. The primary region we use is southamerica-east1 (São Paulo, Brazil). Google may replicate data to other regions for redundancy. These international transfers happen under the safeguards of the EU-U.S. Data Privacy Framework, the European Commission's Standard Contractual Clauses, and equivalent provisions applicable under LGPD and LOPDP.

7. How long we keep your data

  • Account data and cloud content: while your account is active. If you ask us to delete your account, or you delete it yourself from the App, we erase all content linked to your UID within 30 days.
  • Local-mode data: until you uninstall the App or clear its storage.
  • Support records (emails): up to 24 months, for ticket traceability.
  • Data required for legal obligations: for as long as applicable law requires.

8. Your rights

Wherever you live, we guarantee the following rights over your personal data:

  • Access — know what data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure ("right to be forgotten") — ask us to delete your information.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interest.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Withdraw consent — when processing is based on consent, without affecting prior processing.
  • No automated decisions — Noomix does not make automated decisions with legal effects about you.
  • Lodge a complaint — with your local data-protection authority (in Ecuador, the Superintendencia de Protección de Datos Personales; in the EU, your national authority; in Brazil, the ANPD; in California, the Attorney General or the CPPA).

How to exercise them: email soporte@kitusoft.com from the address tied to your account. We respond within the statutory deadlines (30 days for GDPR, 15 days for Ecuador's LOPDP, 45 days for CCPA).

To delete your account and all your data, there is a direct route with no need to email us: see the Delete your Noomix account page.

For California residents: you have the additional CCPA/CPRA rights, including the right to know what personal information we collect, to delete it, to correct it, to opt out of "sale" or "sharing" of information (we do neither), and not to receive discriminatory treatment for exercising these rights.

9. Security

  • All communications between the App and our servers go over HTTPS/TLS.
  • Passwords are stored encrypted by Firebase Authentication; we never have access to your plain-text password.
  • Firestore security rules restrict data access: only you can read and write your account data and the data of people you explicitly share content with.
  • We follow industry best practices, but no system is 100% impenetrable. If a security breach affecting your data ever happens, we will notify you as required by law (within 72 hours to relevant authorities under GDPR).

10. Children

Noomix is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe your child has provided us information, email soporte@kitusoft.com and we will delete it.

If the user is between 13 and 18 (or the applicable digital-consent age in their country: 16 in the EU by default, 14 in Ecuador), we recommend that parents or legal guardians review this policy and supervise use of the App.

11. Ads and analytics in the future

Today, Noomix does not display ads and does not use behavioral analytics. However, we reserve the right to introduce, in the future, third-party services for:

  • Personalized or non-personalized advertising (for example, Google AdMob).
  • Usage analytics and app metrics (for example, Google Analytics for Firebase, Firebase Crashlytics).
  • Install attribution.

If we do, we will update this policy before activating those services, identify which providers we use and what data they receive, and offer the consent mechanisms required by applicable law (for example, consent forms for EU users under ePrivacy/GDPR before any advertising identifier, and Apple's App Tracking Transparency prompt on iOS).

12. Cookies and similar technologies

Noomix is a native application and does not use cookies. We use operating-system local storage (SharedPreferences on Android, UserDefaults on iOS) to save your preferences. This storage is not accessible to other apps or websites.

13. Third-party links

The App may contain links to external sites (e.g., kitusoft.com, support email). We are not responsible for how those sites process your data. Read their privacy policies separately.

14. Changes to this policy

We may update this policy to reflect changes in the App, the law, or our practices. When we do:

  • We will change the "Last updated" date at the top.
  • If the change is material (for example, starting to show ads or changing processing purposes), we will notify you inside the App or by email before the change takes effect.
  • Continued use of the App after notice means you accept the new version.

15. Contact

Questions, rights requests, incident reports?

Kitusoft Quito, Ecuador Email: soporte@kitusoft.com Website: kitusoft.com