Mathweave

Mathweave

Privacy policy

Effective 3 September 2026. This policy covers personal data handled by Mathweave. You can read what we collect about you and your child, our reasons for using it, the suppliers that handle it and your choices. A parent holds the account and controls the child profile. We follow Singapore's Personal Data Protection Act 2012.

Who we are

Mathweave is operated by Mathweave Pte Ltd, UEN 202638377E. This policy covers the website, lesson films, parent account, child profile, free trial and paid practice plan. An account belongs to a parent or legal guardian. A child does not have a separate account. Our Data Protection Officer can be contacted at hello@mathweave.com.

A note for your child

Your parent makes your profile and can see everything in it. We keep the name your parent chose, your level, the picture you picked from our set and your practice answers. We use them to show what to work on next and to show your parent how you are getting on. We do not ask for your birthday, school, photograph, home address, email address or phone number. We do not sell your information or use it for advertising. Ask your parent if you want to see, correct or delete what we hold about you.

What we collect about you, the parent

We collect the email address used to sign in. If you choose Google sign in, Google gives us its account identifier, your email address and whether it has verified that address. Security records include session identifiers, IP addresses, browser information, times, a random device identifier and a protected value for the device and network. We record what permission you gave, the policy version, the time, the sign in method and the recorded verification level. For a paid plan, we keep Stripe references for the customer, child, plan, subscription, payment status and events. We also keep your messages and requests. We do not receive or store your full card number.

Mobile verification for the free trial

We may ask you to verify a Singapore mobile number before granting a free trial. When verification is requested, Twilio sends a code to the number through WhatsApp or text message. You type the code back to us. We use the full number only for that request and do not write it to our database or logs. We store a keyed one-way hash and the last four digits. The hash lets us recognise a number that has already received a trial but cannot be changed back into the number. The last four digits let us show a masked number in your account. The number is not used for sign in or marketing. Email hello@mathweave.com to ask about or remove this record. We keep the hash while the one-trial offer operates, because deleting it would allow another trial. We delete it within 90 days after that offer ends.

What we collect about your child

We collect only what practice needs: the display name chosen by the parent, school level, a picture from our set, the question type and exact question version, whether the answer was right, whether it matched a common mistake, the answer time, the time taken and progress measures worked out from those answers. We do not ask a child for a date of birth, school, photograph, home address, email address or phone number. A first name or nickname is enough for the display name.

What we do with it

We use personal data to open and secure the account, send a sign in code, complete Google sign in, verify a mobile number for the trial when requested, record parent permission, run practice, save answers, work out progress, suggest revision, show the parent the child's record, start and end the trial, take payment, manage the plan, send service messages, prevent misuse, investigate faults, answer requests, keep legal records and handle disputes. We do not sell personal data. We do not use a child's data for advertising or advertising profiles and do not pass it to data brokers. A new use needs fresh permission where the law requires it.

Your permission, and taking it back

We ask for parent or guardian permission before a child profile stores data. The permission screen is separate and nothing is ticked in advance. We keep the wording, time and account used to give permission. Singapore guidance requires parent or guardian consent for a child under 13. We use the same parent-controlled process for every child profile. You can withdraw permission from the account page. We show the result before you confirm. Withdrawal deletes child profiles and practice records, except records still needed for a legal or business purpose. It does not cancel a paid plan. Cancel the plan separately under Manage billing.

Who else handles it

We give each supplier only what it needs. Amazon Web Services hosts the Mathweave server, database and encrypted backups. Stripe runs checkout, payment and subscriptions. It collects card and billing details on its own page. Google provides optional sign in. Resend sends sign in codes and service email. Twilio sends a mobile verification code when verification is requested. Professional advisers receive what they need to advise us. Authorities receive what the law requires. A genuine buyer or successor may receive account records under confidentiality and data-protection duties. Some suppliers also decide how to use some data for security, fraud prevention, compliance or platform operations. Their own privacy terms apply to those uses. We remain responsible for the personal data under our control.

Where it is kept

The Mathweave server, database and backups are in the Amazon Web Services Singapore region. Stripe uses entities in Singapore and Ireland and transfers data to the United States and other countries used by its affiliates and subprocessors. Resend stores customer data in the United States. When mobile verification is requested, Twilio processes the Verify service in its default United States region and may use delivery providers in other countries. Stripe, Resend and Twilio may therefore process data outside Singapore under their service and data-protection terms. For an overseas transfer under our control, we use written safeguards that require protection comparable to the Singapore PDPA.

How long we keep it

A sign in code is valid for 10 minutes and its expired record goes within another 24 hours. A session can refresh for up to 30 days. Its revoked or expired record goes within another 7 days. Short rate-limit counters last up to 48 hours, security and misuse records up to 120 days, and a settled temporary Stripe event claim up to 10 days. A child profile and practice record stay until you delete the profile, withdraw permission or close the account. If an account has no paid plan and nobody signs in for 24 months, we email the parent and delete its parent and child data 30 days later unless the parent signs in. After account closure, other live account data is deleted within 30 days. Encrypted backups expire within 35 days. We keep consent, parent-verification and terms-acceptance evidence for 6 years after account closure or withdrawal. We keep billing, invoice and accounting records for 5 years from the end of the financial year of the transaction. We keep an ordinary support message for 2 years after the case closes and a privacy request or legal dispute record for 6 years. Resend keeps active email and log data for 30 days and backups for 7 days, and deletes remaining customer data within 90 days after our Resend account ends. Twilio marks the full number in a verification as personal data with a maximum 30 day life. Stripe and, if you choose optional Google sign in, Google keep data they control under their own notices and legal duties.

Cookies

We use three first-party necessary cookies. The session cookie holds a signed reference, not child data, and lasts up to 30 days. The device cookie, mw_did, holds a signed random anti-abuse device identifier for rate limiting and misuse detection. It lasts up to 400 days, the maximum imposed by the browser. The Google OAuth state cookie protects one optional Google sign in attempt and is deleted when used or after 10 minutes. We use no advertising or analytics cookies. Blocking necessary cookies stops sign in and security checks from working.

How we protect it

We use one-time sign in codes instead of stored passwords. Session cookies are secure and HTTP-only and can be revoked on the server. We limit repeated requests. A child's record is available only through the parent account that owns it. Stripe receives card details on its hosted payment page, not through Mathweave. Backups are encrypted. No online service can promise perfect security. Keep your email and Google accounts secure and email hello@mathweave.com promptly if you suspect misuse.

Messages from Mathweave

Mathweave never sends a sign-in link, never asks anyone to sign in from a link, never asks for a password because we have none, and never asks for card details by message. A six-digit code is the whole sign-in or verification message, and you only ever type it on mathweave.com; anyone asking for more is not us, so report it to hello@mathweave.com.

Seeing it, correcting it, exporting it and deleting it

The account page lets you export the complete record we hold for a child and delete a child profile or withdraw permission. The export includes the profile, attempts, progress and permission record. For anything else, email hello@mathweave.com from the address on the account. You may ask for access to parent or child data under your control, information about its use or disclosure in the preceding year, a correction, an export, deletion or account closure. We may verify your identity to protect the child. We respond as soon as reasonably possible. If an access or correction request takes longer than 30 calendar days, we write within those 30 days with the expected date. Legal exceptions may apply. We give the reason where the law allows and send a required correction to recent recipients.

The emails we send you

We send service emails needed for the account or plan. These include sign in codes, the free-trial reminder, payment receipts, cancellation messages and security notices. They cannot be turned off while the related account or plan is open. We do not send marketing email. We do not use the verified mobile number for marketing. An address given only for notice of a new school level is kept for that notice and can be removed by emailing hello@mathweave.com.

If something goes wrong

We contain and assess a suspected personal-data breach and fix its cause. We notify the Personal Data Protection Commission when the law requires it. After deciding that a breach is notifiable, we notify the Commission as soon as practicable and within 3 calendar days. Where a breach is likely to cause significant harm, we also tell the affected people as soon as practicable. We use plain language and contact the parent when a breach concerns a child profile.

Changes to this policy

We update this policy when the service, our suppliers or the law changes. The current effective date appears at the top. We email you before a material change to the handling of your family's personal data takes effect. We ask for fresh permission where the law requires it.

How to contact us, and how to complain

Contact the Data Protection Officer of Mathweave Pte Ltd, UEN 202638377E, at hello@mathweave.com. Use this address to ask a question, exercise a data right, close an account, remove a mobile-number record or make a complaint. We investigate and respond. You may also raise a data-protection concern with Singapore's Personal Data Protection Commission.

Our terms and conditions set out the plan, the free trial, the price and how to cancel.