Privacy Policy

Effective date: August 22, 2026
What changed in this update: we have turned off ad measurement in our mobile apps. No advertising identifier is collected on any platform, and no app events are sent to Meta or TikTok. We also state plainly what our AI provider does and does not do with what you type. Previously: setting up Toorova now ends with creating an account, and we ask your age range during setup, so account data is collected at the start rather than only if you chose to sign up later; we say plainly that we do not create accounts for learners under 13. Also, as of August 18: the AI Tutor uses your own learning record (including which questions you got wrong) to tailor its answers; we describe how parent, guardian, teacher, and school accounts work and exactly what they can see; and we describe how we record your answer to the AI age and permission questions.
Operated by: Newron Robotics, LLC ("Toorova", "we", "us", "our")
Contact: support@newronrobotics.com

Toorova is a gamified app for learning AI and robotics, available on the web, iOS, and Android. This Privacy Policy explains what we collect, why, who we share it with, and the choices you have. By using Toorova, you agree to this policy.

What we collect

  • Account data. Your email address and display name when you create an account, or the email and basic profile your provider returns if you sign in with Google or Apple. Setting up Toorova ends with creating an account, so this is collected at the start rather than later. Two paths do not end that way, and on both of them nothing reaches us until an account exists: a learner who tells us they are under 13 is handed off to an adult and keeps learning on the device, and some earlier installations still run on a local profile. (If you use Sign in with Apple, you may choose Apple's private email-relay address, and we will only ever see that relay address.)
  • Learning progress. Quests completed and passed, quiz scores, XP, levels, streaks and streak freezes, badges, and a mid-lesson "resume" point, stored so your progress saves and syncs across your devices. This includes question-level detail: which questions you answered incorrectly and which answer you chose, together with when a question is next due for review. We keep this because it is what lets the app bring back the exact idea you are shaky on instead of making you repeat a whole lesson.
  • Your setup answers and your plan, the learning goal you picked, your experience level, where learning fits in your life (school, university, work, or on your own), a professional track if you chose one, the AI assistant you said you use at work if you told us, your daily time goal, and the ordered list of learning paths built from those answers. These decide what the app recommends and in what order. They are not a gate on anything.
  • Things you write and save. Optional notes you type on reflection steps are saved to your private journal. Lessons you bookmark and any note you attach to one, and the entries you add to your project portfolio (project title, description, skills, and any link you paste), are saved to your account so they follow you across devices. Where the AI has reviewed a capstone, the text of the most recent review is saved so you can reopen it; the files you attached are not saved.
  • The name you type on a certificate. Used only to render a certificate PDF. It is kept on that device and nowhere else: it is never sent to our servers, never written to your cloud profile, and never included in an AI request. It is erased when you sign out.
  • AI feature inputs. When you use the AI Tutor, interview practice, portfolio drafting, or the optional AI project (capstone) review, the information needed to generate a response is sent to an AI service provider we use (see "AI features" below). For the AI Tutor this now includes your own learning record: which lessons you have passed or finished, how solid each topic is for you, specific questions you recently got wrong and the answer you picked, the lesson and step you are on, and what is due for review. It also includes anything you type and any material you submit for review.
  • Your AI permission answers, the age range you select and, where relevant, the parental-permission answer given before the AI features unlock, recorded with the date, whether the permission came from you or from a linked parent or guardian's own signed-in account, and which account approved it. We keep this as the record of that permission.
  • Parent, guardian, teacher, and school connections. If you join a class or link a parent or guardian, we store that connection, the class you belong to, work assigned to you, and (for teachers and schools) the class you created, its join code, its roster, and the seats on your license. When someone invites a parent, guardian, or student, we collect the email address they type solely to send that one invitation and to record whether it was accepted; typing an address never gives anyone access to that person's account. If you apply for educator or school access, we also collect your organization, your role, your organization's website, how many seats you are asking for, and any note you write in the application.
  • Email preferences. Whether you opted in to marketing/product emails, and the date you did so, kept as a record of your consent.
  • Subscription status. If you buy Premium, we receive your subscription status (active, expired, etc.) from the app store or payment processor so we can unlock features. We never receive your full card details.
  • Usage analytics, only if you say yes. App events (for example, "quest completed") via Google Firebase Analytics, used in aggregate to improve the app. This is off until you turn it on. In the apps, nothing is collected until you answer the question we ask you once, and the answer can be changed at any time in Settings → Share usage data. On toorova.com a notice asks on your first visit; in the EEA, the UK, and Switzerland nothing is collected unless you accept, and everywhere else declining switches it off immediately. We do not attach your account ID to analytics, so this stream is not joined up with your account. See "Cookies and analytics" below.

    We never measure learners under 18. The choice is offered only to people who have told us they are 18 or older. Under 13, 13 to 17, "prefer not to say", and "we do not know yet" all leave analytics off, are never asked to turn it on, and if the account later tells us it belongs to a minor, an answer given earlier is withdrawn automatically.
  • Crash and error reports. Technical crash diagnostics via Firebase Crashlytics on our iOS and Android apps. Crashlytics does not support the web, so on toorova.com an unexpected error is instead reported to Firebase Analytics as an app_error event containing the type of the error (for example, "FormatException"), a short label for where it happened, and the top line of the technical stack trace inside our own code. The error's message is deliberately left out, because an error message often quotes the value that caused it. At most ten of these are sent per page load. They are diagnostics, not content: we do not send the text of your reflections, your AI conversations, or your answers in them.
  • Identifiers, a random per-installation Firebase instance ID and similar IDs attached to analytics and crash data, used for analytics and stability.
  • Security and abuse-prevention records. Counters that limit how often one account can call an expensive feature, and a server-only audit trail of the actions that change who can see whose data: a class created or archived, a class joined or left, a student removed, an invitation sent or accepted, a parent link accepted or revoked, a sponsored seat issued or handed back, and an AI age or permission answer recorded. Each entry holds the account IDs involved, the class or relationship it concerns, and the time. It never holds an invitation token or an email address. It exists so that "who gave this adult access to this child's account, and when" has an answer, and it is deleted automatically after 400 days. Nobody using the app can read it.

    Before an AI request or a sensitive action runs, your device also proves it is a real installation of Toorova rather than a script. On the web this is Google reCAPTCHA Enterprise, on Android Google Play Integrity, and on iOS Apple App Attest (with DeviceCheck as a fallback). Those checks send device and browser signals to Google or Apple.
  • Ad measurement: none. We do not collect an advertising identifier on any platform, and we do not send app events to any advertising platform. There is no Google Advertising ID collection on Android, no IDFA collection and no App Tracking Transparency prompt on iOS, and nothing is reported to Meta or TikTok about installs, account creation, subscription screens, or purchases.

    To be exact about what is in the app rather than only about what we do: our mobile apps still contain the Meta and TikTok measurement kits (SDKs), because we may advertise Toorova again in the future. They are switched off. They are never started, they are never given an identifier or an event, and the Android advertising permissions they would otherwise add have been stripped out of the app. Nothing reaches those companies from your device.

    We turned this off because Toorova is used in schools and by children. If we ever switch it back on, we will update this page and the store privacy labels before that version ships.

We do not collect your location, contacts, or microphone. If you attach an image, file, code sample, or project material for AI review, we process it for that requested feature; depending on how the feature is configured, it may be transmitted to our AI provider and may be retained temporarily by us or our providers for security, debugging, abuse prevention, legal compliance, or service operation. We do not sell your personal information, we do not share it for advertising, and we do not show third-party ads inside Toorova. We do not track you across other apps or websites.

How we use your information

  • To provide, operate, personalize, and improve the Service and your learning experience.
  • To save and sync your progress across devices, and to generate certificates.
  • To generate AI responses and project feedback that you request.
  • To manage your account, process subscriptions, and unlock Premium features.
  • To send you account/transactional emails and, with your consent, product and marketing emails.
  • To maintain security, prevent abuse and fraud, debug, and comply with law.

For users in the EEA/UK, our legal bases are: performance of our contract with you (to run the Service), your consent (e.g. marketing email, usage analytics, and the AI features), our legitimate interests (to secure and improve the Service), and legal obligation.

AI features

The AI Tutor and our other AI features are powered by third-party AI service providers, currently including OpenAI, and possibly other providers in the future. When you use an AI feature, the information needed to generate a response is sent to OpenAI or another AI service provider we use. Depending on the feature and the app's architecture, this information may be processed through Toorova's app, our backend infrastructure, or our service providers in order to generate a response.

  • Some AI features may store the result so you can revisit it (for example, a saved capstone review). Other AI interactions, and any files you submit, may be retained temporarily by us or our providers for security, debugging, abuse prevention, legal compliance, or service operation.
  • What you type is not used to train AI models. Not by us, and not by our provider. OpenAI's published API data usage policies state that data sent to the OpenAI API is not used to train or improve OpenAI models unless the customer explicitly opts in to share it. We have not opted in. Those same policies state that OpenAI generates abuse-monitoring logs of API use and retains them for up to 30 days, unless a longer period is required by law or is reasonably necessary to protect their services or a third party from harm, after which they are deleted. Those terms are OpenAI's and can change; we hold any AI provider we use to this standard and will say so here if it ever changes.
  • What is not sent to the AI provider. Your email address, your display name, and your Toorova account ID are not part of what we send. Our servers use your account ID to look up your own record, and then send only what is in that record. What the provider receives is the lesson text, your message, the earlier turns of that conversation, and your learning record. Nothing in it names you. For a project review it also receives the material you attach and the file name you gave it, so if you would rather not share your name, keep it out of the file name.
  • The AI Tutor sees your learning record, and only yours. To answer usefully it is given a summary of how you are doing. Lessons passed, how solid each topic is, questions you recently got wrong along with the answer you chose, where you are in the course, and what is due for review. This is assembled on our servers from your own account and is sent to our AI provider with your question. It can never include another learner's record. It is not shown to your parent, guardian, or teacher: question-level detail is deliberately kept out of what adults connected to your account can see.
  • Please do not enter sensitive personal information, confidential information, or private information about yourself or others into the AI features.
  • The AI features are a learning aid and may be inaccurate, incomplete, or out of date. You should verify important details, and you should not rely on them as a substitute for a qualified teacher, professional advisor, engineer, doctor, lawyer, or safety expert.

Age and permission. Toorova is intended for users 13 and older, and the AI features are not available to users under 13. Before the AI features unlock we ask you to select your age range and, if you are under 18, to confirm you have permission from your parent or legal guardian. Where a parent or guardian is already linked to the account, that permission must come from their own signed-in account rather than a box ticked on the learner's device, and it stops applying if the link is later removed. This decision is recorded and enforced on our servers, so it cannot be changed from the app by editing data on the device. We should be straightforward about the limit of this: the age range itself is self-declared. We do not ask for a date of birth, identity document, or payment card to verify it.

Parents, guardians, teachers, and schools

A learner can choose to connect their account to a parent or guardian, or join a class run by a teacher or school. Nothing is connected without the learner accepting an invitation, and a learner or parent can end the connection at any time, after which access stops.

What a connected parent, guardian, or teacher can see: the learner's display name, whether they have been active recently and how consistently, XP, level, streak, badges, their daily goal, which lessons they have finished and which they have passed, how many of the hands-on exercises in their recent lessons they completed out of how many those lessons set, the course they are on, and the plain-language titles of what they have been working on. The purpose is to answer "is this person learning, and are they stuck?"

What they cannot see: individual questions and answers, which option was chosen, reflections written in the learner's private journal, and AI Tutor conversations. This is a deliberate boundary enforced by our database rules, not just by the design of the screens.

Teachers and schools additionally have records tied to running a class, the class and its join code, its roster, assigned work, and the seats used on a license. If a teacher invites a parent or a student, we collect the email address entered in order to send that invitation. If you are a teacher or parent using Toorova to oversee a learner, remember that the learner's information is theirs; please use it only for supporting their learning.

Email communications

We send transactional emails about your account, for example sign-up confirmations, password resets, and important service notices. With your opt-in consent (an unchecked box you tick at sign-up), we may also send product updates, new course announcements, and learning tips. Marketing email is entirely optional: every marketing email includes an unsubscribe link, and opting out never affects essential account or transactional emails. We may use a third-party email service provider to help us send these transactional and marketing emails. We do not sell your email address or share it for anyone else's marketing. To opt out at any time, use the unsubscribe link or email support@newronrobotics.com (postal: 828 E Edgehill Rd, Salt Lake City, UT 84103).

How and where data is stored

Your account and progress are stored using Google Firebase (Authentication and Cloud Firestore). Security rules enforce that only you can read your own account, apart from the limited summary a parent, guardian, or teacher you are connected to may see, which is described in "Parents, guardians, teachers, and schools" above. The same rules keep parts of your record out of your own app's hands as well: your XP, streak, passed quests, roles, and your recorded AI age and permission answer are written only by our servers, so they cannot be edited from a device. When you use an AI feature, the information needed to generate a response is processed through Toorova's app and/or our backend infrastructure and sent to our AI service provider(s) to generate a response. Our providers may process and store data on servers in the United States and other countries.

Cookies and analytics

We use no advertising cookies and no cross-site tracking cookies. What we do use falls into two groups.

  • Essential storage. Signing in stores your session so the site knows it is you on the next page. The site also remembers your light or dark theme choice, your language, and your answer to the analytics question below. This is how the site works at all, so there is nothing to switch off, and none of it is shared with anyone.
  • Analytics, only with your permission. If you accept, Google Analytics sets its usual _ga cookies to count visits. If you have not accepted, they are not set, and if you decline after accepting, we switch Google's own kill switch on and delete those cookies rather than merely hiding the notice.

How the choice is made. On your first visit a notice asks. Decline is the same size and the same weight as Accept, side by side, with nothing pre-selected. In the EEA, the UK, and Switzerland we treat ignoring the notice as a refusal, so analytics stays off until you accept; elsewhere it runs until you decline, and declining takes effect at once. We work out which rule applies from your browser's own time-zone setting, deliberately erring toward the stricter one. No third party is contacted to look you up, and we do not use your IP address to place you.

Changing your mind. On the website, use the Cookies & analytics link in the footer of any page, including this one. In the iOS and Android apps, use Settings → Share usage data. The setting is per browser and per device, so it is not carried across by signing in.

Who we share data with

We share data only with the service providers that help us run Toorova:

  • Google Firebase / Google Cloud. Authentication, database, hosting, serverless functions, analytics, and crash reporting.
  • OpenAI (and any other AI service provider we may use), to generate the AI responses and reviews you request from the inputs you provide.
  • Apple, Google, Stripe, and RevenueCat, to process premium subscription payments and report your subscription status to us. We never receive your full card details.
  • An email service provider (currently Resend), to help us send account/transactional emails such as password resets and invitations and, with your consent, product/marketing emails.
  • A form-handling provider (currently Formspree), used by the contact and inquiry forms on our website and by the support and inquiry forms inside the Toorova app, to deliver what you type to our support inbox. If you fill in one of those forms, Formspree receives the details you entered there, which may include your name, email address, organization, role, how many learners you are asking about, and your message. In the app's support form your email address is filled in from the account you are signed into, and you can change it before sending. Formspree never receives your learning progress.
  • Google reCAPTCHA Enterprise, Google Play Integrity, and Apple App Attest, the checks described under "Security and abuse-prevention records" above, which confirm a request came from a genuine copy of Toorova.
  • jsDelivr, a public code-delivery network, and Google's own content network (gstatic.com). Used only by the website. jsDelivr serves the Python runtime for the in-browser Code Playground, and Google's network serves the graphics engine and fallback fonts the web app is drawn with. They receive your IP address, your browser's details, and the fact that you loaded that file. They receive no account data, and the code you write in the Playground never leaves your browser: it runs in a sandbox on your own device and is not sent to us or to anyone else.

Separately from these providers, and only where you have chosen it, some of your learning information is visible to a parent or guardian you have linked, or a teacher whose class you have joined. See "Parents, guardians, teachers, and schools" above for exactly what they can and cannot see.

We do not sell your personal information, we do not share it for advertising, and we do not show third-party ads inside Toorova. Your data is not used to train AI models, by us or by our AI provider. See "AI features" above for what our provider does with what you send it.

Payments

Toorova offers optional premium subscriptions. Payment is handled entirely by the relevant store or processor, the Apple App Store, Google Play, or Stripe (on the web), and we do not receive or store your full card details. Subscription status is reported to us via RevenueCat, our subscription-management provider, so we can unlock Premium on your account. Price, billing cycle, auto-renewal, and cancellation terms are presented at the time of purchase.

Your choices and rights

  • Edit your display name at any time (Profile).
  • Opt out of marketing email via the unsubscribe link in any such email.
  • Manage who is connected to your account. You can see the parents, guardians, and classes linked to your account and remove any of them, which immediately stops their access to your progress. You can also change or withdraw your AI permission answer, with one exception: once an account has told us it belongs to someone under 13, that answer cannot be taken back from the app. Only a parent or guardian linked to the account, or our support team, can change it. That is deliberate, because an age gate you can simply re-take until it lets you through is not a gate.
  • Delete your account and data, you can delete your account in the app (Settings → Delete account), request deletion at toorova.com/account-deletion, or contact support@newronrobotics.com. This removes your account and associated data. A short, specific list of records survives deletion, and "Data retention" below sets it out in full rather than leaving it to a general exception; beyond that, we retain information only where we must for legal, security, fraud-prevention, billing, dispute-resolution, or compliance reasons. If you have a paid subscription, cancel it through the relevant store or billing provider, deleting your account does not cancel billing.
  • Depending on where you live (for example, the EEA or UK under GDPR, or California under the CCPA/CPRA), you may have the right to access, correct, export, delete, or restrict processing of your data, to object to certain processing, and to not be discriminated against for exercising these rights. To exercise them, contact support@newronrobotics.com. You may also have the right to lodge a complaint with your local data-protection authority.
  • Turn usage analytics on or off at any time, Settings → Share usage data in the apps, or the Cookies & analytics link in the footer of any page on our website. It is off until you turn it on, and it is never available to learners under 18. Crash reporting on the iOS and Android apps is not covered by that switch; it can be limited through your device or platform settings where available, and you can contact support@newronrobotics.com with any privacy request.
  • Ad measurement: there is nothing to opt out of. We do not read your advertising identifier on any platform and we do not send app events to any advertising platform.

Children

Toorova is intended for users 13 and older. We ask for your age range during setup, and our sign-up does not create an account for a learner who tells us they are under 13. Instead we say that an adult sets the account up, and the learner can carry on with the lessons on that device, where their plan and what they finish stay on the device and reach no server of ours until an adult creates an account.

Here is exactly what our servers refuse for an account that has said it is under 13, so there is no doubt about which parts are enforced and which are policy:

  • The AI features never unlock. Not by the learner, and not by a parent or guardian either. This is checked on our servers on every AI request, not only in the app.
  • The learner cannot link a parent or guardian by themselves. For an under-13 learner the link has to run through their school: a teacher we have approved, whose class the learner is actually on, invites the parent by email, and the parent signs in as that address and accepts. The consenting gesture belongs to an adult from beginning to end.
  • The under-13 answer cannot be taken back from the app, including by deleting the account and starting again. Only a linked parent or guardian, or our support team, can change it. We keep a small server-side marker to make that stick; see "Data retention".

If you are under 18, you may use the AI features only with permission from your parent or legal guardian. Where a parent or guardian is linked to the account, that permission must be given from their own signed-in account, a box ticked on the learner's device is refused, and it stops applying if the link is removed. Where no parent or guardian is linked, a 13 to 17 learner confirms permission themselves, and we record that it was self-confirmed rather than given by an adult, because the difference matters and we should not pretend otherwise. As noted above, the age range is self-declared: we do not ask for a date of birth, an identity document, or a payment card, so none of this is age verification.

Usage analytics are never collected from anyone under 18. See "What we collect".

A parent or guardian who is linked to a learner's account can see that learner's progress as described in "Parents, guardians, teachers, and schools", can see and change the learner's AI age and permission state, can withdraw AI permission, and can end the link at any time. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, a parent or guardian may contact support@newronrobotics.com and we will remove it.

International users

We are based in the United States and process data there and in other countries where our providers operate. Where required, we rely on appropriate safeguards (such as the EU Standard Contractual Clauses used by our providers) for international transfers. By using the Service, you understand your information may be processed in the United States.

Security

We use industry-standard measures, including provider-side encryption in transit and at rest, and per-user access rules, to protect your data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Data retention

We keep your account and progress until you delete your account. Deleting it removes your profile, your learning progress, your question-level record and review schedule, your reflections, saved lessons and notes, your portfolio, your saved AI reviews, your subscription record, and the mapping to our payment processor. It also removes you from any class rosters and parent or guardian dashboards, and ends outstanding invitations you sent. Your files are never stored in the first place, so there are none to delete.

What deliberately survives, and why. We would rather be exact than reassuring, so this is the complete list:

  • The audit trail described under "What we collect", the record of who was granted access to whose account. It holds account IDs, not names or email addresses, and it is deleted automatically 400 days after the event. Deleting an account is not a way to erase the record that an adult was once given access to a child's.
  • The under-13 marker, if the account ever declared itself under 13. It contains the age band and the date it was set, and nothing else, no name, no email, no progress. It survives on purpose: without it, deleting the account and creating a new one would clear the answer and reopen the age gate.
  • One-time markers recording that this account already claimed its sign-up bonus and already imported any device-only progress, so neither can be claimed again, and a counter recording how often account deletion itself was called. Each is a few numbers under an account ID that no longer belongs to anyone.
  • Educator and school licenses. If you held educator or school access, your role, your organization's website, and the note you wrote are deleted, and the license is closed so it can issue nothing further. The license record itself is kept, along with your organization's name and the number of seats requested, because it is the account of how many sponsored seats were issued and to whom they were charged.

Backups and provider logs may persist for a limited period in line with our providers' retention practices, and we may retain limited information where required by law.

Changes to this policy

We will update this page when the policy changes and note the new effective date above. For material changes, we will provide notice in the app where appropriate. Your continued use of the Service after an update takes effect means you accept the revised policy.

Contact

Questions or requests: support@newronrobotics.com
Newron Robotics, LLC · 828 E Edgehill Rd, Salt Lake City, UT 84103, USA.