Ooks — Privacy Policy
Who we are
Ooks is a spelling- and dictation-practice app for Singapore primary-school children (English and Chinese). A guardian photographs a weekly spelling list, the app extracts the words, and the child studies them with a spaced-repetition scheduler that aims for strong recall by the test date.
This service is operated by the provider of Ooks ("Ooks", "we", "us"), based in Singapore. For any privacy question or request, contact us at privacy@ooks.ai.
We are the data controller for the personal data described in this policy.
A note on how Ooks is structured
Ooks uses two kinds of accounts:
- Guardian account — a normal account created with an email address. The guardian sets up and manages everything.
- Child account — created by the guardian for each child. A child signs in with a username and password only — never a real email address or phone number. Behind the scenes we generate an internal, non-personal login identifier (e.g.
username@ooks.internal); it is never shown and contains no real personal information.
Some users may try Ooks on the web without registering. In that case we create a temporary anonymous account so the trial can save progress. It holds no name, email, or phone number.
The guardian provides consent on behalf of the child. By creating a child profile, the guardian confirms they are the parent or legal guardian and consent to the processing described here.
What we collect
We practise data minimisation — we collect only what is needed to run the study app. We do not ask for a child's real name, date of birth, photo, or contact details.
| Data | Why we collect it | Where it is stored |
|---|---|---|
| Guardian email address | To create and secure the guardian account, and for password recovery | Cloud (authentication) |
| Guardian display name (optional) | To personalise the account | Cloud database |
| Child username & password | So the child can sign in | Cloud (authentication) |
| Child nickname / display name | To show whose study session is running (chosen by the guardian — need not be a real name) | Cloud database |
| Child grade level (P1–P6) | To tune the study scheduler | Cloud database |
| School / class label (optional) | To suggest relevant shared word lists from the same school | Cloud database |
| Language setting (English / Chinese) | To pick the correct text-to-speech voice | Cloud database |
| Deck names, spelling words, definitions, example sentences | The study content itself | Cloud database + on-device |
| Spelling-list photo | Read once by AI to extract the words; kept privately so you can re-check the original | Private cloud storage |
| Study progress (scheduler state, due dates, pass/fail per word) | To schedule reviews and show progress | Cloud database + on-device |
| Study-session records & typed answers (text) | To grade answers and show history | Cloud database + on-device |
| Push notification token | To send study reminders (only if you enable them) | Cloud database |
| Crash and error diagnostics | To find and fix bugs (contains no names, emails, or answers — only an internal ID) | Error-reporting service |
What we never collect
A child's real name · date of birth · photo of the child · home address · phone number · precise location · biometric data · advertising identifiers · behavioural-tracking data. We run no advertising SDKs and do no behavioural ad tracking.
How we use data
We use the data above only to:
- Provide the study app — extract words from photos, schedule reviews, grade answers, play audio, and sync your data across your devices.
- Send study reminders, only if you turn on notifications.
- Keep the service secure (authentication, rate-limiting, abuse prevention).
- Fix bugs and improve the app using crash diagnostics and aggregate, non-identifying usage statistics.
We do not sell personal data, and we do not use it for advertising.
The spelling-list photo (our most sensitive surface)
When you photograph a spelling list:
- The photo is uploaded to private cloud storage, readable only by your account.
- Our server sends it to an AI vision service to read out the word list. Only the extracted text returns — no analysis of who is in the photo.
- The photo is kept with the resulting deck so you can re-check the original against the extracted words. It stays private to you and is never shared with other families or added to any shared library.
- When you delete the deck (or the child profile), the photo is deleted. If you start a scan but never save a deck, the photo is automatically purged within about one hour.
Only the word-list text can ever be shared (see "Sharing", below) — never the photo.
Voice answers (a planned feature, not yet live)
A future version may let a child speak an answer. If and when we ship it: audio will be sent for transcription only, never saved to any device or server, and only the result (correct/incorrect) will be stored. We will ask for separate consent before enabling it.
Sharing word lists with other families
Ooks lets you share a word list so classmates can study the same words. When you share a deck:
- Only the words and study content are shared — word, definition, pinyin, example sentence, language, and the week/title.
- No child names, no guardian name, no email, and no photo are shared. The identity of who created or enrolled in a deck is not exposed.
- A shared deck is reachable only by its share code — a short code randomly generated when the deck is created: a 6-digit number (e.g.
123-459) for decks created now, or a 3-word phrase (e.g.brave-tiger-koala) for decks created before this change. There is no public browse or search — the code is the key. - Each child's study progress is private and is never shared, even on a shared deck.
Sharing is your choice. You can keep a deck private, and you can stop sharing at any time from the deck settings.
Third parties who process data for us
We use a small number of service providers ("data intermediaries" under the PDPA), each only for the function listed:
| Provider | Role | What it receives |
|---|---|---|
| Cloud infrastructure provider | Cloud database, authentication, file storage | Account data, study data, the private scan photo |
| API / edge provider | API layer that holds our keys and brokers AI calls | Requests passing through; no long-term storage of your content |
| AI vision service | Reads the spelling-list photo to extract words | The photo and extracted text only — no account identifiers |
| Text-to-speech service | Generates the audio that reads words aloud | The word text only |
| Push-notification service | Delivers push reminders | A device push token only |
| Error-reporting service | Crash/error diagnostics | Technical error data with an internal ID — no names or answers |
We never include a guardian email, child nickname, or any identifier in the AI or text-to-speech requests — those calls carry only the word or image.
Our AI provider states that data sent through its API is not used to train its models under the terms we use.
Where data is stored
Your data is stored on cloud infrastructure that may be located outside Singapore. Where data is transferred abroad, we take steps so it receives a standard of protection comparable to the PDPA. Ooks also works offline: a copy of your study data lives on your device so the app functions without a connection.
How long we keep data
| Data | Retained |
|---|---|
| Account, child profiles, decks, study progress | Until you delete them, or you close the account |
| Scan photo | Until the deck is deleted (abandoned scans purged within ~1 hour) |
| Study-session history & typed answers | Up to 12 months, then anonymised (de-linked from any child) |
| Shared word lists you contributed | Remain in the shared library after account deletion (they contain no personal data); the creator link is removed |
| Crash diagnostics | Per the error-reporting provider's standard retention |
Your rights and choices
Under the PDPA you may:
- Access the personal data we hold about you and your children.
- Correct inaccurate data.
- Delete an individual card, a deck, a child profile (which removes that child's study records), or your entire account. See how to delete your account and data. Account deletion is a hard delete completed within 24 hours.
- Withdraw consent — for example, turn off notifications, stop sharing a deck, or close the account.
To exercise any right, use the in-app controls or email privacy@ooks.ai.
Children's data
Ooks is designed to be used by children under the direction of a guardian. We treat children's data with heightened care: no real name, no date of birth, no photo of the child, no location, no advertising. The guardian creates and controls the child's profile and can delete it at any time. We align our handling with international norms for children's data (COPPA, GDPR Article 8) in addition to the PDPA.
Security
- Database-level access controls (Row Level Security) so each account sees only its own data.
- All traffic encrypted in transit (HTTPS/TLS).
- AI and text-to-speech keys held server-side only — never shipped in the app.
- Per-user rate limits to contain abuse of a compromised session.
- Diagnostics logs carry internal IDs only — no emails, nicknames, or answers.
No system is perfectly secure, but we follow these practices to protect your data. In the event of a significant data breach, we will notify the PDPC and affected users as required under the PDPA.
Changes to this policy
We may update this policy as the app evolves. We will post the new version here and update the "Last updated" date; significant changes will be notified in-app.
Contact
Ooks — Singapore
Email: privacy@ooks.ai
If you are not satisfied with our response, you may contact Singapore's Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.