OlympIQ

OlympIQ Privacy Policy

Effective date: July 15, 2026  ·  Last updated: July 28, 2026

1. Introduction and Data Controller

OlympIQ ("OlympIQ," "we," "us," or "our") is a free educational mobile app that helps students practice for the AMC 10, AMC 12, and AIME mathematics competitions. This Privacy Policy explains what information we collect, how and why we use it, how we protect it, how long we keep it, who we share it with, where it is processed, and the choices and rights you have. By creating an account or using OlympIQ, you agree to this Policy.

OlympIQ is operated by Manish Singh from Arizona, United States. For the purposes of the EU/UK GDPR and similar laws, Manish Singh (OlympIQ's operator) is the "controller" (and, under some laws, the "business" or "operator") responsible for your personal data. Contact: olympiqhelp@gmail.com.

2. Scope

This Policy applies to personal data we process through the OlympIQ mobile app and any related web pages we operate. It does not apply to third-party services we link to, or to services operated by others. Where a regional law grants you rights beyond those described generally, the relevant regional section below applies to you.

3. Information We Collect

We collect only what the app needs to work. We do not run ads, we do not sell your data, and we do not use third-party advertising or tracking services.

Account information

Learning and progress data

Questions you attempt, which you answer correctly, experience points (XP), rank, streaks, badges (including hidden achievement badges), bookmarked questions, and mastery-set progress (which sets you have completed and how many times you have reset them).

In-app activity used for achievements

To award certain achievement badges, the app keeps a couple of counters on your own account - for example, how many times you have opened a particular person's profile (including that person's username, used only to label the badge) and how many times you have answered a specific question incorrectly. This information is used only to unlock badges, is stored privately on your own account (readable only by you, not by other users), and is not used for advertising.

Social features

Your friends list and friend requests you send or receive.

Safety reports

If you report another user, we collect the reason you choose and any short note you add (up to 100 characters) so we can review it and keep the community safe. Reports are visible only to us - never to the person you reported.

Notifications

Messages shown to you inside the app.

Automatically collected technical information

To operate and secure the service, Google Firebase processes certain technical data on our behalf, including your IP address, device and app-installation identifiers (such as a Firebase Installation ID), and basic device and operating-system information. We use this to sign you in, connect your device to our database, protect the service from abuse, and diagnose problems. We do not use identifiers to build advertising profiles or to track you across unaffiliated apps and websites.

Information stored on your device

Authentication tokens are stored locally to keep you signed in. This is standard app storage (not web cookies) and is not used for advertising or cross-app tracking. You can clear it by signing out or deleting the app.

Sensitive / special-category data

We do not collect it. We do not collect Social Security or government ID numbers, precise geolocation, biometric or genetic data, health or "consumer health" data, racial or ethnic origin, religious or philosophical beliefs, financial or payment information, phone numbers, or your contacts. We therefore do not process "special categories" of data under the GDPR, "sensitive personal information" under the CPRA, or "sensitive data" under other laws.

Analytics and crash reporting

OlympIQ does not use Firebase Analytics, Firebase Crashlytics, or any third-party analytics, advertising, or crash-reporting services, and does not track you across other apps or websites.

4. Why We Use Your Information

To create and secure your account; save your progress and show your stats, ranks, and badges; power leaderboards and social features (friends); protect the service from abuse (e.g., limiting friend requests per day and validating quiz answers on our servers); and communicate with you about your account (verification and password-reset emails). We do not use your information for advertising or for automated decisions producing legal or similarly significant effects (see Section 19).

5. Legal Bases for Processing (GDPR / UK GDPR / Swiss FADP)

6. Data Protection Principles

We aim to process personal data in line with the principles of lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality (security); and accountability.

7. Information Visible to Other Users

Your email address is never shown to other users.

8. How and Where Your Data Is Stored; Service Providers (Sub-Processors)

We rely on a small number of service providers that process personal data on our behalf, under their data-processing terms:

We do not sell, rent, or trade your personal information, and do not share it with third parties except the service providers above, or where required by law or to protect rights and safety. These providers do not use your OlympIQ data for their own advertising. Data is encrypted in transit using HTTPS/TLS.

9. International Data Transfers

OlympIQ is operated from the United States, and we may process your data in the United States and other countries. If you access OlympIQ from the EEA, the UK, Switzerland, or another region with transfer restrictions, your information may be transferred to and processed in the United States, which may have different data-protection laws than your home country. Where such transfers occur, they are carried out under appropriate safeguards implemented by our providers, such as the Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Agreement/Addendum.

10. Data Retention and Deletion

After deletion from active systems, residual copies may persist for a limited period in our providers' backups before being overwritten in the ordinary course of their operations. We keep only the minimum necessary and retain information longer only where required to comply with law, resolve disputes, or enforce agreements.

11. Security

We use reasonable administrative and technical safeguards to protect your information, including authentication, access controls that limit what each account can reach, and encryption in transit (HTTPS/TLS). Passwords are hashed by Google Firebase Authentication; we never store plain-text passwords. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.

12. Data Breach Notification

If we become aware of a breach affecting your personal information, we will investigate promptly and take steps to contain it. Where required by law, we will notify affected individuals and the relevant supervisory authorities within the timeframes those laws require (for example, the GDPR's 72-hour window for notifying regulators). Any notice we provide will describe, to the extent known, what happened, the information involved, and the steps you can take.

13. Your Privacy Rights

Depending on where you live, you may have some or all of these rights: to access/know, correct, delete, and receive a portable copy of your personal data; to restrict or object to processing; to withdraw consent; to opt out of "sale," "sharing," targeted advertising, and certain profiling; to limit use of sensitive data; to non-discrimination for exercising rights; to appeal a decision; and to lodge a complaint with a supervisory authority. Because the app lets you view, edit, and delete your data directly, you can exercise most rights yourself; for anything else - including a portable copy of your data, which we provide on request within the applicable time limit - contact olympiqhelp@gmail.com (see Section 24 for how we verify and respond).

14. EEA, UK, and Switzerland

If you are in the EEA, UK, or Switzerland, you have the rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection (including to processing based on legitimate interests), and the right not to be subject to solely automated decisions producing legal or similarly significant effects. Where processing is based on consent, you may withdraw it at any time without affecting prior processing. You have the right to lodge a complaint with your local Data Protection Authority (in the UK, the Information Commissioner's Office, ico.org.uk). As a small independent operator, we have not appointed an Article 27 EU/UK representative or a Data Protection Officer; you may contact us directly at olympiqhelp@gmail.com.

15. United States - California (CCPA/CPRA)

Notice at collection. We collect the categories in Section 3 for the purposes in Section 4 and retain them as described in Section 10. Categories: Identifiers (email, username, account/user ID, device and app-installation identifiers, IP address) and Internet/electronic network activity (interactions with the app, such as questions attempted and feature usage). We do not collect Social Security numbers, precise geolocation, biometric information, financial/payment information, or "sensitive personal information."

No sale or sharing. We do not sell your personal information and do not share it for cross-context behavioral advertising, and have not in the preceding 12 months. We therefore do not offer a "Do Not Sell or Share" link; where required, we honor opt-out preference signals such as the Global Privacy Control (GPC). We do not offer financial incentives for personal information.

Your rights: to know, access, delete, correct, limit use of sensitive PI (we collect none), opt out of sale/sharing (we do none), and non-discrimination. Use the Profile-screen tools or email olympiqhelp@gmail.com. We verify requests using your account credentials.

16. United States - Other State Privacy Laws

If you reside in a state with a comprehensive privacy law - such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others - you may have rights to confirm/access, correct, delete, and obtain a portable copy of your personal data, and to opt out of the sale of personal data, targeted advertising, and profiling with legal or similarly significant effects. We do not sell data, serve targeted advertising, or conduct such profiling, so those opt-outs do not apply. Where your state provides an appeal right, you may appeal by replying to our response; if denied, you may contact your state Attorney General. We collect no biometric identifiers (relevant to Illinois BIPA) and no consumer-health data (relevant to Washington's My Health My Data Act and Nevada's health-privacy law).

17. United States - Student Privacy (FERPA / SOPIPA)

OlympIQ is a direct-to-consumer service and is not operated under contract with a school, so we do not maintain "education records" under FERPA. Regardless of whether a school is involved, and consistent with SOPIPA and comparable state student-privacy laws, we make these standing commitments about student data: we do not sell student personal information, we do not serve targeted advertising, and we do not build advertising profiles of students. We use practice data only to provide and secure the service. If a school or district ever adopts OlympIQ under a written agreement, we will act as a "school official" / service provider consistent with FERPA and applicable state law. Parents, guardians, and eligible students may request access to or deletion of a student's data at olympiqhelp@gmail.com.

18. Other Countries

OlympIQ is a small, independent, U.S.-based project. If a data-protection law of another country or region applies to you - such as Canada's PIPEDA and Quebec Law 25, Brazil's LGPD, Australia's Privacy Act, or others - and grants you rights beyond those described above, contact olympiqhelp@gmail.com and we will honor the rights we are legally required to provide, and cooperate with the relevant authority as required. If a mandatory local requirement conflicts with this Policy, that requirement governs for residents of that jurisdiction.

19. Automated Decision-Making

XP, ranks, streaks, and badges are generated automatically from your practice activity. These are routine gameplay features and do not produce legal or similarly significant effects about you. We do not profile you for advertising and do not use solely automated decision-making of the kind restricted by GDPR Article 22.

20. Marketing and Electronic Communications

We send only transactional messages (email verification, password reset, and account or security notices). We do not send marketing emails. If we ever introduce optional marketing communications, we will obtain any consent required by laws such as the U.S. CAN-SPAM Act, Canada's CASL, and the UK's PECR, and provide an unsubscribe mechanism.

21. Cookies and Similar Technologies

The mobile app does not use web cookies; it stores only essential authentication tokens on your device to keep you signed in. Any web pages we operate use only storage that is strictly necessary to provide the service you request; we do not use advertising or analytics cookies. Because we use only strictly necessary storage, no consent banner is required under the EU ePrivacy Directive / UK PECR. You can clear local data by signing out or deleting the app.

22. Third-Party Links and Services

Our data-processing service providers are listed in Section 8. Separately, the app may include links to other sites (e.g., the Mathematical Association of America, Art of Problem Solving, Creative Commons). We do not control those sites and are not responsible for their content or privacy practices; their own policies apply.

23. Children's Privacy

OlympIQ is intended for users who are at least 13 years old. We ask for your date of birth when you create an account and do not allow accounts for anyone under 13. We do not knowingly collect personal information from children under 13. If you are between 13 and the age of digital consent in your region (which can be up to 16 in parts of the EEA), please use OlympIQ only with the involvement of a parent or guardian.

Consistent with the U.S. Children's Online Privacy Protection Act (COPPA) and the GDPR's provisions on children, we minimize what we collect from and display about younger users. If you believe a child under 13 has created an account or provided personal information, contact olympiqhelp@gmail.com and we will delete the account and its data promptly. A parent or guardian may review, request deletion of, or refuse further collection of their child's information by contacting us.

24. How to Exercise Your Rights; Verification; Authorized Agents; Appeals

Most rights can be exercised directly from the Profile screen (change username, email, or password; delete your account and all associated data). For other requests, email olympiqhelp@gmail.com. Verification: to protect your data, we verify requests using your account credentials (e.g., signing in and confirming from your account email). Authorized agents: you may use an authorized agent where the law permits; we may require proof of authorization and verification of your identity. Timing: we respond within the timeframe required by law (for example, generally within 45 days under U.S. state laws, extendable as permitted, and within one month under the GDPR). Appeals: where the law provides an appeal right, reply to our response to appeal; you may also complain to your data-protection authority or attorney general. We will not discriminate against you for exercising your rights.

25. "Do Not Track" and Opt-Out Preference Signals

Because we do not track users across other websites or apps and do not sell or share personal information, there is nothing for a browser "Do Not Track" signal to change. Where required by law, we honor recognized opt-out preference signals such as the Global Privacy Control (GPC) as they apply to any sale/sharing (of which we do none).

26. Competition Content

Practice problems are past AMC and AIME competition problems, used under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 (CC BY-NC-SA 4.0) license and credited to the Mathematical Association of America (MAA). This is licensed educational content and is not related to the collection of your personal information.

27. Governing Law and Your Local Rights

This Policy and any dispute relating to it or your use of OlympIQ are governed by the laws of the State of Arizona and the United States, without regard to conflict-of-laws principles. Nothing in this Policy waives or overrides any mandatory consumer-protection or data-protection right you have under the laws of your own country, state, or province of residence, which continue to apply to the extent required.

28. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app. Your continued use of OlympIQ after changes take effect means you accept the updated Policy.

29. Contact Us; Controller and Representatives

OlympIQ is operated by Manish Singh from Arizona, United States; the operator, Manish Singh, is the data controller. Email: olympiqhelp@gmail.com. As a small independent operator, we have not appointed a Data Protection Officer or an EU/UK Article 27 representative; please direct all privacy inquiries and rights requests to the address above, and we will handle them in accordance with applicable law.