Privacy notice
Version of 11 October 2026
What changed on 11 October 2026
- A child's own device: a parent can make a short login code so a child signs in on their own phone or tablet without an email address or password.
- Second guardians: another parent or guardian can join a child with an invitation code and the approval of the parent who added the child. The notice now says what each guardian sees and how a link ends.
- Assignments and notifications: parents can set work with a short message to the child, and Purrfect Marks shows notices in the app. Email is sent only if a parent turns it on (it is not switched on yet).
- Learning records: mastery levels per skill, a review schedule, and records of how practice questions are chosen. They only decide which practice question comes next; nothing in Purrfect Marks makes decisions with legal or similar effects.
- Rewards and getting started: points (XP), streaks, badges and weekly goals, private to the child and their guardians, with no leaderboards. Answers to the getting-started questions are kept as preferences and never used to label a child's ability.
- Tools: bookmarks and working notes, including drawings.
- Records of account, guardian and staff actions (an audit log).
- Your rights: download all your or your child's data, and delete a child or your whole account, yourself from Purrfect Marks. Deleted practice is no longer kept even without a name.
- How long we keep each kind of record.
Purrfect Marks is a free practice site for Singapore primary and lower secondary pupils, run by Joshua Koh (JK) as an individual. This notice explains what we collect, why, who can see it, how long we keep it, and the choices parents have. Most of our users are children, so a parent or guardian sets up the account and gives consent.
What we collect
From the parent or guardian: your email address and name, your language choice, your notification settings, and the dates you accepted this notice and the terms. With Google sign-in, Google sends us your name, email address, a Google account identifier and a link to your profile picture. With email sign-in, we get only your email address. If we have no name for you, you may tell us what to call you.
If you sign in with Apple, Apple sends us an Apple account identifier and an email address. Apple does not send us your name. If you choose Apple's “Hide My Email”, the address is a private relay address made by Apple: we do not see your own address, and emails we send you pass through Apple's relay service to reach you.
About each child you add: a first name or nickname, the school level, the date you gave consent, and, if they are set, a picture chosen from Purrfect Marks' own set, the time zone and the child's answers to the short getting-started questions (how they feel about Maths, what they enjoy, how they like to practise). We do not ask for a child's full name, school, photo or contact details.
A child's own device: when a guardian makes a login code, the child's device signs in without an email address, name or password (an anonymous sign-in). We keep a random id for that sign-in, when the code was made and used, and a device name if one is given. Codes are stored only in a scrambled form.
Second guardians: who invited whom (we store the invitation code only in a scrambled form), who asked to join, and when a link was approved or ended.
When someone practises or takes a mock paper or test: the questions shown and why each was chosen, the answers given, marks and scores, time spent, the hints, worked solutions and retries used, and any problem reported about a question. In a paper, each answer is saved as the pupil moves on, before the paper is handed in, and we record when the paper was started, paused and handed in, and whether the time ran out.
Learning records worked out from those answers: the evidence for each skill, a mastery level per skill (such as “Not enough evidence yet”, “Needs practice” or “Proficient”), and when each skill is due for review.
Assignments: the work a guardian sets, its due date, the guardian's optional message to the child (up to 280 characters) and how far the child has got. Notifications shown in Purrfect Marks, and, only if email is turned on, a record of which emails were sent (not their text).
Rewards: points (XP) earned for effort, level, streak days, badges and weekly goals. Tools: bookmarks, and working notes the pupil types or draws next to a question; notes are never marked.
If someone practises or takes a paper without signing in, a random id in a cookie links their answers in that browser. It does not identify anyone. Guests get no learning records, rewards or assignments.
Technical and security records: the IP address in the sign-in log; attempts to use login and invitation codes (to stop guessing); and an audit log of account, guardian, assignment, download and deletion actions and of staff actions on questions and reports (who did what and when; no answers or free text).
Why we use it
To mark answers, run timed papers (keep the clock, and hand the paper in when the time is up), show results and progress to the child and their guardians, and suggest what to practise next.
To choose practice questions and reviews that suit the child, from the child's own answers. This only decides which practice question comes next and when a skill is reviewed. It is never used to make decisions about a child with legal or similar effects, and a guardian or child can always choose a topic instead. Mastery levels are estimates from the evidence so far and are worded with care.
To make practice suit the child from the getting-started answers. They are kept as preferences the child told us, never to label ability or a learning style.
To encourage effort with points, streaks and badges. They are private to the child and their guardians: there are no leaderboards and no comparison between children.
To let guardians set work and follow it, and to tell people in the app when something changes.
To show guardians which hints were opened. Opening a hint never costs marks.
To find and fix faulty questions, and to work out how hard each question is from everyone's answers taken together.
To keep the service secure and working: to stop code guessing and misuse, to keep a record of who changed a link, a question or a setting, and to restore the service from a backup after a failure.
What we do not do
No advertising, no selling or renting of data, and no tracking or advertising cookies.
We do not send children's answers or personal data to any AI model.
No public profiles and no leaderboards: other families never see your child.
Who can see what
The child sees their own practice, results, rewards, notes and assignments.
Every guardian with an active link (the parent who added the child and any approved second guardian) sees the child's progress, results, help used, assignments and rewards, can make login codes for the child's device, and can download the child's data. Guardians see each other's names, never each other's email addresses. For Exam papers, guardians see the marks for each question but not the answers.
Only the parent who added the child can invite or remove a second guardian and delete the child. A second guardian can leave at any time. When a link ends, that person can no longer see the child at once; the record that the link existed is kept.
JK, and reviewers JK appoints, see reports of faulty questions and the audit log, and look at other personal data only to fix a problem or answer a request.
Cookies
We only use cookies the site needs: the sign-in session (also on a child's own device), the guest id for practice without signing in, which child is practising on this device, and the language you chose if it differs from your browser's.
Where the data is kept
In our database at Supabase and on our app servers at Fly.io, both in Singapore. These providers process data for us and may not use it for their own purposes.
Google and, if you use it, Apple run their own sign-in services under their own privacy policies. They send us only the sign-in details listed above.
Email is not switched on yet. When it is, and only for a parent who turns it on, emails are sent by the mail service Resend, which may handle your email address and the email outside Singapore. Emails never include a child's answers or work.
Every night we make a backup copy of the database, so that we can restore the service after a failure. It holds account details, children's records, and practice, paper and learning records, but not sign-in sessions or the sign-in log with IP addresses. An automated job run for us on GitHub's servers, which may be outside Singapore, encrypts the copy as it is made, so no unencrypted copy is saved. The encrypted copy is stored by Cloudflare in the Asia-Pacific region. Only we hold the key to open it, and we keep it offline: Cloudflare and GitHub cannot read the backups.
How long we keep it
Your account, your children's records, practice, learning records, rewards, notes and assignments are kept while the account is open, until you delete them.
Child login codes and guardian invitations: 30 days after they expire (the code that signed in a child's current device is kept while that device stays signed in). Records of code attempts, kept to stop guessing: 2 days.
Notifications: 180 days after they are read, and never more than 365 days. Records of emails sent: 180 days. Records of how practice questions were chosen: 180 days after the practice ends.
Internal processing records: 30 days (90 days if processing failed). Records that a deletion was done: 90 days. The audit log: 2 years.
Encrypted backups are deleted automatically after 30 days, so data we delete is gone from every backup within a further 30 days. If we ever have to restore a backup, we delete again anything that was deleted after that backup was made.
Your rights
Download: in Settings, “Download my data” gives you a file of everything we hold about you and your own practice; on a child's page, “Download data” gives you everything we hold about that child. Answer keys and other people's details are left out.
Correct: you see each child's details on the child's page; to correct your or a child's details, email us.
Delete a child: the parent who added the child can delete them on the child's page. The child's records, practice, learning records, rewards, notes, assignments, notifications and device sign-in are deleted at once. Problems the child reported about questions are kept without who sent them or what they wrote. Deleting a child also withdraws your consent for them.
Delete your account: in Settings, “Delete my account” deletes your account, your own practice and every child you added. If a child also has another guardian, that guardian keeps the child and becomes its main parent instead. Staff accounts are closed by an admin.
We keep a short record that a download or a deletion happened (ids and dates, no names). For anything else, or if a button does not work for you, email us and we will reply within 30 days.
Changes
If we change this notice in a way that matters, we will ask parents to read and accept it again before continuing.
Contact
Questions or requests about personal data: support07.aceit@gmail.com.