Effective date: 26 July 2026 Last updated: 26 July 2026
One Percent ("One Percent", "we", "us") provides a mobile and web application that generates short daily learning curricula using artificial intelligence. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
One Percent is operated from Singapore. If you have any question about this policy or how your data is handled, contact us at [email protected].
| Data | When | Why |
|---|---|---|
| Email address | If you sign up or sign in | Authenticate you, send one-time sign-in codes, recover your account |
| Name | Optional, during profile setup | Personalise greetings in the app |
| Gender | Optional, during profile setup | Product analytics and content relevance |
| Learning topics you type | Whenever you create a curriculum | Generate your curriculum (see §4 — AI processing) |
| Support messages | If you contact support | Respond to your request |
| Data | Purpose |
|---|---|
| Anonymous user identifier | Persist your progress before you create an account |
| Curricula, lessons and lesson progress | Deliver the core service and resume where you left off |
| Streaks, completion counts and minutes learned | Show your progress and streak features |
| Saved topics | Populate your Library |
| Reminder time, timezone, notification preferences | Send the daily reminders you asked for |
| Push notification token | Deliver push notifications |
| Subscription status, plan, renewal date, store identifiers | Provide paid features and restore purchases |
| Data | Purpose |
|---|---|
| Product analytics events (e.g. curriculum generated, lesson completed, streak milestone, trial started) | Understand which features work and improve the product |
| Diagnostic and crash data | Detect, diagnose and fix faults |
| IP address (transiently) | Security, abuse prevention and rate limiting |
We do not collect precise geolocation, contacts, photos, health data, or advertising identifiers.
Where the UK or EU GDPR applies to you, we rely on the following bases:
| Purpose | Legal basis |
|---|---|
| Providing the service you requested | Performance of a contract (Art. 6(1)(b)) |
| Sending one-time sign-in codes | Performance of a contract (Art. 6(1)(b)) |
| Push notifications and reminders | Consent (Art. 6(1)(a)) — withdrawable in Settings or your OS |
| Product analytics and service improvement | Legitimate interests (Art. 6(1)(f)) |
| Security, abuse prevention, rate limiting | Legitimate interests (Art. 6(1)(f)) |
| Billing and fraud prevention for paid plans | Performance of a contract / legal obligation |
| Optional profile fields (name, gender) | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interests, we have assessed that our interest in operating and improving a functioning product does not override your rights, in part because analytics data is limited to product events rather than content.
Generating a curriculum requires sending the topic text you enter to a third-party AI model provider, which returns generated lesson content. You should avoid entering sensitive personal information in the topic field.
We share personal data only with service providers acting on our instructions. This list is current as of the "Last updated" date and changes as our providers change — in particular, the AI model provider(s) may be substituted or added to.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| AI model provider(s) — currently Anthropic, PBC | AI curriculum and lesson generation | Topic text you enter |
| Railway | Application hosting and database | All service data |
| PostHog | Product analytics | Pseudonymous user id, product events |
| Sentry | Error and crash monitoring | Diagnostic data, pseudonymous user id |
| Resend | Transactional email (sign-in codes, support) | Email address, message content |
| Expo | Push notification delivery | Push token, notification content |
| RevenueCat | Subscription management | Pseudonymous user id, purchase records |
| Apple | App distribution and payment processing | Purchase and billing data (held by Apple) |
| Google / Apple | Optional social sign-in | Identifier and email from the provider |
We may also disclose data where required by law, to enforce our terms, or in connection with a merger or acquisition (in which case we will notify you).
We do not sell personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.
We are based in Singapore and our providers process data in other countries, including the United States and the European Union. Where personal data is transferred out of the UK/EEA we rely on the European Commission's Standard Contractual Clauses or an applicable adequacy decision. Where personal data is transferred out of Singapore, we take reasonable steps to ensure the recipient provides a standard of protection comparable to the PDPA.
| Data | Retention |
|---|---|
| Account and learning data | While your account is active |
| Anonymous accounts with no activity | Automatically deleted after 30 days of inactivity |
| Deleted accounts | Soft-deleted immediately, then permanently purged after 30 days |
| One-time sign-in codes | The code expires within minutes; the record, including the email it was sent to, is deleted within 7 days |
| AI usage and cost records | Retained for billing and capacity planning, but de-identified when your account is deleted — the record survives with no link to you |
| Analytics events | Retained no longer than necessary for the purposes in §2.3, in line with our analytics provider's configured retention period |
| Records required for tax, accounting or legal defence | As required by law |
When an account is deleted, deletion cascades through the database: your profile, every curriculum, day and lesson, your saved topics, your notification history, your sign-in sessions and any linked Google/Apple identities are all removed.
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to our processing of your personal data, and to withdraw consent at any time.
We will not discriminate against you for exercising these rights. If you are in the UK/EEA you may lodge a complaint with your supervisory authority. If you are in Singapore you may lodge a complaint with the Personal Data Protection Commission (PDPC).
If you are in Singapore, we handle your personal data in accordance with the Personal Data Protection Act 2012 ("PDPA"):
Our Data Protection Officer can be reached at [email protected].
One Percent is not directed to children under 13 (or under 16 where local law sets a higher age), and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact [email protected] and we will delete it.
We maintain technical and organisational measures appropriate to the risk, including:
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant regulator where required by law and within the applicable deadlines.
We will update this policy as the product changes. Material changes will be notified in-app or by email before they take effect, and the "Last updated" date above will always reflect the current version.
One Percent Singapore [email protected]