One Percent

One Percent — Privacy Policy

Effective date: 26 July 2026 Last updated: 26 July 2026

One Percent ("One Percent", "we", "us") provides a mobile and web application that generates short daily learning curricula using artificial intelligence. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

One Percent is operated from Singapore. If you have any question about this policy or how your data is handled, contact us at [email protected].


1. Summary


2. Data we collect

2.1 Data you provide

Data When Why
Email addressIf you sign up or sign inAuthenticate you, send one-time sign-in codes, recover your account
NameOptional, during profile setupPersonalise greetings in the app
GenderOptional, during profile setupProduct analytics and content relevance
Learning topics you typeWhenever you create a curriculumGenerate your curriculum (see §4 — AI processing)
Support messagesIf you contact supportRespond to your request

2.2 Data generated by your use

Data Purpose
Anonymous user identifierPersist your progress before you create an account
Curricula, lessons and lesson progressDeliver the core service and resume where you left off
Streaks, completion counts and minutes learnedShow your progress and streak features
Saved topicsPopulate your Library
Reminder time, timezone, notification preferencesSend the daily reminders you asked for
Push notification tokenDeliver push notifications
Subscription status, plan, renewal date, store identifiersProvide paid features and restore purchases

2.3 Data collected automatically

Data Purpose
Product analytics events (e.g. curriculum generated, lesson completed, streak milestone, trial started)Understand which features work and improve the product
Diagnostic and crash dataDetect, diagnose and fix faults
IP address (transiently)Security, abuse prevention and rate limiting

We do not collect precise geolocation, contacts, photos, health data, or advertising identifiers.


3. Legal bases (UK/EU GDPR)

Where the UK or EU GDPR applies to you, we rely on the following bases:

Purpose Legal basis
Providing the service you requestedPerformance of a contract (Art. 6(1)(b))
Sending one-time sign-in codesPerformance of a contract (Art. 6(1)(b))
Push notifications and remindersConsent (Art. 6(1)(a)) — withdrawable in Settings or your OS
Product analytics and service improvementLegitimate interests (Art. 6(1)(f))
Security, abuse prevention, rate limitingLegitimate interests (Art. 6(1)(f))
Billing and fraud prevention for paid plansPerformance of a contract / legal obligation
Optional profile fields (name, gender)Consent (Art. 6(1)(a))

Where we rely on legitimate interests, we have assessed that our interest in operating and improving a functioning product does not override your rights, in part because analytics data is limited to product events rather than content.


4. Artificial intelligence processing

Generating a curriculum requires sending the topic text you enter to a third-party AI model provider, which returns generated lesson content. You should avoid entering sensitive personal information in the topic field.


5. Sub-processors and disclosure

We share personal data only with service providers acting on our instructions. This list is current as of the "Last updated" date and changes as our providers change — in particular, the AI model provider(s) may be substituted or added to.

Sub-processor Purpose Data involved
AI model provider(s) — currently Anthropic, PBCAI curriculum and lesson generationTopic text you enter
RailwayApplication hosting and databaseAll service data
PostHogProduct analyticsPseudonymous user id, product events
SentryError and crash monitoringDiagnostic data, pseudonymous user id
ResendTransactional email (sign-in codes, support)Email address, message content
ExpoPush notification deliveryPush token, notification content
RevenueCatSubscription managementPseudonymous user id, purchase records
AppleApp distribution and payment processingPurchase and billing data (held by Apple)
Google / AppleOptional social sign-inIdentifier and email from the provider

We may also disclose data where required by law, to enforce our terms, or in connection with a merger or acquisition (in which case we will notify you).

We do not sell personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.


6. International transfers

We are based in Singapore and our providers process data in other countries, including the United States and the European Union. Where personal data is transferred out of the UK/EEA we rely on the European Commission's Standard Contractual Clauses or an applicable adequacy decision. Where personal data is transferred out of Singapore, we take reasonable steps to ensure the recipient provides a standard of protection comparable to the PDPA.


7. Retention

Data Retention
Account and learning dataWhile your account is active
Anonymous accounts with no activityAutomatically deleted after 30 days of inactivity
Deleted accountsSoft-deleted immediately, then permanently purged after 30 days
One-time sign-in codesThe code expires within minutes; the record, including the email it was sent to, is deleted within 7 days
AI usage and cost recordsRetained for billing and capacity planning, but de-identified when your account is deleted — the record survives with no link to you
Analytics eventsRetained no longer than necessary for the purposes in §2.3, in line with our analytics provider's configured retention period
Records required for tax, accounting or legal defenceAs required by law

When an account is deleted, deletion cascades through the database: your profile, every curriculum, day and lesson, your saved topics, your notification history, your sign-in sessions and any linked Google/Apple identities are all removed.


8. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to our processing of your personal data, and to withdraw consent at any time.

We will not discriminate against you for exercising these rights. If you are in the UK/EEA you may lodge a complaint with your supervisory authority. If you are in Singapore you may lodge a complaint with the Personal Data Protection Commission (PDPC).


9. Singapore (PDPA)

If you are in Singapore, we handle your personal data in accordance with the Personal Data Protection Act 2012 ("PDPA"):

Our Data Protection Officer can be reached at [email protected].


10. Children

One Percent is not directed to children under 13 (or under 16 where local law sets a higher age), and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact [email protected] and we will delete it.


11. Security

We maintain technical and organisational measures appropriate to the risk, including:

No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant regulator where required by law and within the applicable deadlines.


12. Changes

We will update this policy as the product changes. Material changes will be notified in-app or by email before they take effect, and the "Last updated" date above will always reflect the current version.


13. Contact

One Percent Singapore [email protected]