Last updated: July 14, 2026
This Privacy Policy describes how Megalearn AB ("Megalearn", "we", "us", or "our") collects, uses, and handles your information when you use MegalearnAI (the "Service"), accessible at megalearn.ai and related applications.
Megalearn AB, Sweden, is the controller of the personal data described in this policy. You can contact us at [email protected].
MegalearnAI is designed for families. A parent or guardian creates and manages the family team. Children join through a parent-created invite code and use a child account or child profile managed by the parent or guardian.
Parents and guardians are responsible for deciding whether a child may use the Service. Where consent is required for a child's personal data, the parent or guardian provides or authorizes that consent. Parents can contact us to access, correct, or delete a child's data.
When a parent signs in using Google or Apple authentication, Firebase Authentication stores account information provided by the authentication provider, such as name, email address, provider identifier, and authentication identifiers. In our application database, parents may also provide a nickname, color preference, and team name.
Child accounts are created through parent-managed invite codes. For child accounts and profiles, we may store:
Journal entries waiting for review, rejected entries, and their source drawings are stored in the submitting member's private journal and are not shown to other family team members through the Service. If an entry passes review, a separate approved version and, where applicable, a reviewed copy of its drawing preview may be shared with active members of that family team.
Through normal use of the Service, we store family team data such as:
Paid subscriptions are handled through Apple App Store subscriptions. Apple processes and retains payment-instrument and billing details. We do not receive or store payment-card, bank-account, or other payment-instrument details. We may receive or store subscription status, entitlement status for a family team, the signed app marketing version, product identifiers, transaction identifiers, and purchase or expiry timestamps needed to provide access to paid features.
Before a purchase, our backend creates a random subscription identifier for the family team and the app includes it in the StoreKit purchase. We first verify Apple's signed app transaction, including the App Store environment and app marketing version. We use the random identifier to confirm that Apple's signed purchase transaction belongs to the intended family team, then check current subscription status with Apple before granting access. Signed server notifications and periodic status checks are used to keep renewal, expiry, refund, and revocation state current.
We do not retain raw signed app or purchase transactions or raw signed notifications. Product and transaction identifiers, purchase details, random subscription-identifier mappings, and notification-processing records are stored in server-only records. Because paid access applies to a family team, active team members may see only whether the team has an active entitlement, its provider and product, and limited expiry and update information. Transaction identifiers and Apple payment-instrument or billing details are not included in that shared entitlement status.
Our infrastructure providers may process technical information needed to deliver and secure the Service, such as authentication identifiers, IP addresses, device or browser information, logs, and security signals. We also store limited abuse-prevention records, such as an account identifier or hashed request identifier, a request count, and a reset time. We use this information for operations, App Check, security, abuse prevention, and troubleshooting.
We use information to:
We rely on different legal bases depending on the purpose of processing:
MegalearnAI uses Google Gemini AI to provide educational chats, tutor guidance, missions, content generation, journal guidance, journal safety review, and issue-report investigation.
Chat messages, journal text, submitted drawing preview images, and issue reports may be sent to AI services when needed to provide these features or review content for safety. These requests use authenticated application or server components and may be subject to App Check, membership checks, content or file-size limits, and request limits. We ask users not to submit real names, addresses, phone numbers, email addresses, school details, passwords, or other sensitive personal information in chats, journals, drawings, or issue reports.
We do not send nickname or profile display-name submissions to Gemini to approve or moderate the name.
We use the following third-party services to operate MegalearnAI:
These providers may process data in countries outside Sweden or the EU/EEA. Where personal data is transferred outside the EU/EEA, we rely on the safeguards made available by our providers, such as adequacy decisions, Standard Contractual Clauses, or equivalent transfer mechanisms.
Your data is stored on Google Firebase infrastructure. We implement reasonable technical safeguards, including server-side access rules, authenticated and App Check-protected Cloud Functions, request limits, and restricted file uploads, to protect your data. Private journal content is separated from the approved version shared with a family team. When a drawing preview is approved, the review service creates a content-addressed copy that cannot be overwritten by a client; access is provided through a short-lived link after membership and approval checks.
However, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security. In the event of a data breach, we will investigate, take corrective action, and notify affected users or the Swedish Authority for Privacy Protection (IMY) when required by law.
MegalearnAI is currently in beta testing. During this period:
You should not store sensitive or irreplaceable information in the Service.
We design MegalearnAI to collect as little child personal data as practical for the Service. We use nicknames instead of real names in the app, avoid behavioral advertising and third-party analytics, and give parents control over child accounts and profiles.
Child profiles are visible to family team members through nicknames, activity, progress, journal entries that pass review, and other team features. Journal content that is waiting for review or rejected is not shared with other team members through the Service. Parents should help children avoid entering personal information in free-text areas or drawings.
Parents and guardians can contact us to:
If a parent or guardian believes their child has provided personal information beyond what is needed for the Service, please contact us at [email protected] and we will review and delete it where appropriate.
Depending on where you live and the legal basis for processing, you may have rights to:
You can delete your own account in the app. Parents can also delete managed child accounts or contact us for help. To exercise rights, contact [email protected].
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), or with another competent data protection authority in your country.
We retain account, team, and learning data while the account or family team is active. Rejected journal entries and their associated files are scheduled for deletion after 14 days. Users can delete journal entries, and member, team, and account deletion flows remove associated private journal data, approved journal versions, source drawings, and approved preview copies from active storage where applicable.
Invite codes expire and are removed when they are used, replaced, expire, or the related pending member or team is deleted. Issue reports and related investigation records are retained while reasonably needed to investigate, resolve, audit, or defend the reported issue. Rate-limit windows generally last minutes or a day, although limited security records may remain longer where reasonably needed to investigate abuse or an incident.
Apple notification-processing records are retained for 30 days. Deleting the app, a Megalearn account, or a family team does not cancel billing with Apple. If an individual account is deleted but its family team continues, the shared subscription entitlement and its private subscription record remain with that team. When the family team is deleted, we remove the active entitlement, private transaction state, ownership claim, and family-team subscription-identifier mappings.
After a family team is deleted, we retain one narrow server-only deletion record indefinitely. It contains only the random subscription identifier and the deletion date and, if Apple later contacts us about it, the last notification date. It does not contain a name, email address, Megalearn account or team identifier, Apple transaction identifier, or payment details. We keep it only to safely discard delayed Apple notifications and prevent a deleted subscription identifier from being attached to another family.
Other information may be retained after account deletion where needed for security, issue handling, legal obligations, accounting, backup integrity, or disputes. This can include issue reports and limited security records, but not Apple payment-instrument or billing details. Apple may independently retain its transaction and billing records. Beta data may be reset or deleted earlier as described above.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Megalearn AB
Sweden