1. Overview
1001463290 ONTARIO INC. ("Guardian," "we," "us," or "our") operates Guardian: Curriculum Review (the "App") and this support and legal website. Guardian helps parents and guardians review school materials, including textbook information, worksheets, syllabi, and public district or curriculum sources.
Guardian is designed for parents and guardians. It is not intended for children to use on their own, and we do not knowingly collect personal information directly from children. Parents should avoid entering a child’s full legal name or other unnecessary identifying information.
2. Information we collect
Account and authentication information
This may include your Sign in with Apple identifier, email address if Apple shares it, Guardian account and session identifiers, and an encrypted Apple credential used only to revoke Apple access when you delete an Apple-authenticated account.
Family profile and review preferences
You may choose to provide grade level, general school or district context, learning priorities, and review preferences. Selected preferences may reveal sensitive interests or opinions about religion or worldview, political or social issues, race or identity, gender identity or sexual orientation, and sexual content.
School materials and source information
This may include images, OCR text, pasted text, syllabus files, worksheet text, textbook identifiers, ISBNs, related source notes, and the general location or school/district context used to find public curriculum sources.
Results and follow-through
This may include review results, processing status, parent decisions, conversation completion, school-message drafts, sent confirmations, response notes, school events, reminders, and other Guardian case information you choose to save.
Purchases, support, and technical information
We collect purchase and subscription information needed to verify App Store entitlements, renewals, refunds, restore requests, and subscription analytics. We also process support codes, privacy export and deletion request metadata, and basic technical information needed to operate, secure, debug, and improve Guardian.
App usage events
Guardian records limited first-party events such as first open, app open, onboarding progress, material added, paywall view, purchase, restore, and report unlock. These events include a random Guardian installation identifier plus app version, build number, operating-system version, platform, and broad device class. The random identifier and queued deliveries may be stored on your device. When transmitted to Guardian’s service, the identifier is stored server-side only as a keyed hash. Event payloads do not contain uploaded school material, child names, family review preferences, school names, report contents, AI prompts, findings, source text, case contents, response notes, or school-message drafts.
Website access information
This public website is designed without optional analytics, advertising scripts, or marketing cookies. Our hosting and content-delivery provider may process standard technical request information, such as IP address, browser or device information, requested page, and timestamps, to deliver, secure, and troubleshoot the website.
3. How we use information
- Provide curriculum, worksheet, syllabus, textbook, and district-source review features.
- Generate evidence-backed findings, source references, parent conversation guides, and school-message drafts.
- Authenticate accounts, maintain sessions, restore access, and connect purchases to the correct Guardian account.
- Process subscriptions, introductory offers, purchase restores, refunds, and entitlement status.
- Provide privacy exports, support-code workflows, account deletion, and customer support.
- Protect Guardian from misuse, troubleshoot issues, measure core app reliability and funnel performance, comply with legal obligations, and enforce our terms.
4. AI processing, public sources, and service providers
Guardian may send the school material and context you choose to review to service providers that help operate the App, including AI processing, hosting, database, email, Apple, subscription, attribution, and public-source lookup providers. Current categories of providers include Apple services, RevenueCat for subscription handling and analytics, AppsFlyer for mobile attribution when authorized, and Cloudflare or another hosting/content-delivery provider for this website.
Guardian may use public data sources such as Google Books, Open Library, Internet Archive, ERIC, and public district or curriculum pages to identify and review materials. Those services may receive technical request data when Guardian requests public-source information.
We require providers that process personal information on our behalf to protect it in a manner consistent with this policy and applicable law, or to provide equivalent protection. Their own terms and privacy policies may also apply when they operate as independent services.
School material, child profile details, report contents, findings, Guardian cases, response notes, and school-message drafts are not sent to AppsFlyer, RevenueCat, Meta, or advertising partners.
5. Analytics, tracking, advertising, and sale of data
Guardian uses the limited first-party app events described above to understand core funnel performance and service reliability. These events are not used to build advertising profiles from school material or family review content.
Guardian does not sell your personal information. If you affirmatively allow tracking through Apple’s permission prompt, Guardian may activate AppsFlyer and Meta App Events to measure which campaigns—including Reddit, Facebook, and Instagram campaigns—lead to selected in-app events. Those services may then use Apple’s advertising identifier and a Guardian installation identifier. RevenueCat may share subscription lifecycle and revenue events with AppsFlyer without school or child content.
If tracking permission is denied, restricted, or not yet decided, Guardian does not start AppsFlyer, does not send Meta app events, and does not link the Guardian installation identifier to those providers. Guardian may use Apple’s privacy-preserving aggregate attribution frameworks where available. Core curriculum-review features work without tracking permission.
6. Retention, export, and deletion
We keep information only as long as needed to provide Guardian, maintain subscriptions and account history, respond to support and privacy requests, protect the service, and meet legal obligations. Different operational records use different configured windows. For example, first-party analytics events are generally retained for up to 90 days; authentication challenges, one-time privacy export links, support codes, audit metadata, and App Store reconciliation records use their own limited windows.
When the same Guardian installation later sends a first-party event while signed in or requests a privacy export, events created before sign-in may be connected to that account so the export includes them.
Signed-in parents can request a one-time privacy export or account deletion in Guardian Settings. For an Apple-authenticated account, Guardian first asks Apple to revoke the stored credential and does not report deletion complete if revocation fails. Completed deletion removes the Guardian backend account, saved profile, entitlement metadata, review history, Guardian cases, action history, school events, reminders, saved drafts, support cases, sessions, recovery hash, encrypted Apple credential, account-linked first-party analytics and audit records, and pseudonymous first-party events matching the current installation where Guardian can identify them.
The deleting device also clears Guardian’s local analytics identifier, queued first-party deliveries, one-time analytics markers, and pending AppsFlyer event and attribution-snapshot state. A fresh random identifier may be created if Guardian is used again after deletion. Pseudonymous events from a different installation that were never connected to the account may remain until the analytics retention window expires. Apple, AppsFlyer, Meta, RevenueCat, and other providers may retain information already processed under their own policies.
To honor a completed deletion if a first-party analytics delivery was already in transit or is retried, Guardian may retain only a one-way installation hash in a deletion-suppression list for no longer than the analytics retention window, generally 90 days. The hash is used only to discard those late deliveries and does not contain the raw installation identifier.
Deleting Guardian account data does not cancel an App Store subscription. Subscriptions are managed separately through Apple.
7. Your choices
- You choose which materials to scan, upload, paste, or review and which profile details and review preferences to save.
- You may use Sign in with Apple where available to manage account access.
- You may request a one-time privacy export or delete your Guardian account in the App’s Settings.
- You may manage App Store subscriptions through your Apple account subscription settings.
- You may allow, decline, or later change app tracking permission through iOS Settings.
- You may contact us with a privacy question using the information below.
8. Security and international processing
We use reasonable technical and organizational measures designed to protect information, including hashed account identifiers, encrypted Apple revocation credentials, short-lived support and privacy-export codes, and restricted support diagnostics. No method of transmission or storage is completely secure.
Information may be processed in Canada, the United States, or other countries where Guardian’s service providers operate. Privacy and data-protection laws in those locations may differ from the laws where you live.
9. Changes and contact
We may update this policy as Guardian changes. The effective date above reflects the current version. Material changes may also be communicated in the App or on this page.
For privacy questions or support, use Guardian’s in-app support flow or email louismurad21@gmail.com.