Mathly

Privacy Policy

Effective date: August 24, 2026 · Applies to the Mathly mobile application for iOS and Android (com.balkanbit.mathly)

1. Who we are

The Mathly application (“the App”) is published by “Pazaruvai Umno” EOOD (“ПАЗАРУВАЙ УМНО” ЕООД), a company registered in the Republic of Bulgaria with Unified Identification Code (UIC/ЕИК) 206373314, with registered address at Sofia 1343, Lyulin 2, bl. 235, vh. V, et. 2, ap. 81, Republic of Bulgaria (“we”, “us”, “our”). We are the Data Controller under the EU General Data Protection Regulation (GDPR) and the Bulgarian Law on Personal Data Protection (PDPA). The App is developed and operated through the BalkanBit venture studio.

Questions about this policy or your data: manol@balkanbit.app.

2. What the App does with your problem photos

Mathly reads a math or science problem from a photo you capture with your camera or select from your photo library, then returns a step-by-step solution. Photos are handled as minimally as possible:

  • A photo is sent over an encrypted HTTPS connection to our solving service only when you explicitly scan a problem.
  • Our service passes the image to our AI provider, OpenAI, which reads and solves the problem — the same third-party AI service disclosed inside the App before your first submission. We keep no copy of the photo once your solution is returned. OpenAI holds it briefly for abuse monitoring — up to 30 days — and then deletes it. Only the resulting text solution comes back to your device.
  • The solution and the problem are then stored locally on your device so you can find them in History. You can remove all of it at any time in Settings → Delete all my data.
  • Photos are never used to identify you, sold, shared for advertising, or used to train AI models.

Please do not photograph documents containing personal information about you or others — the App only needs the problem itself.

3. Categories of data we process

  • Problem photos and typed problems — processed transiently as described in Section 2.
  • Solutions, chats, and onboarding answers — your solved problems, follow-up conversations, subjects, level, goal, and explanation-style preferences are stored only on your device. They are removed when you delete your data in the App or uninstall the App. We keep no server-side copy of your history.
  • Preferences sent with a request — your level and explanation style accompany a scan so the answer is pitched correctly. They are used to produce the response and are not stored against any profile.
  • Anonymous app identifier — a random identifier generated by our subscription provider (RevenueCat) to associate your subscription with your device and to enforce fair-use limits. It is not linked to your name, email, or any account — the App has no user accounts.
  • Purchase data — if you subscribe, Apple or Google processes the payment. We and our processor RevenueCat receive the anonymous identifier, product purchased, subscription status, device platform, and locale. We never receive your payment card details.

We do notcollect your name, email address, phone number, contacts, or location. The App contains no advertising and no third-party analytics SDKs, and it does not track you across other companies’ apps or websites.

4. Lawful bases for processing

  • Performance of a contract (Art. 6(1)(b) GDPR) — to read and solve the problems you submit and to manage your subscription and purchases.
  • Consent (Art. 6(1)(a) GDPR) — for access to your camera and photo library. You grant this through the operating system prompts and each scan is started only by your explicit action. You may withdraw consent at any time in your device settings.
  • Legitimate interest (Art. 6(1)(f) GDPR) — to prevent fraud and abuse of the solving service and to keep the service secure.
  • Legal obligation (Art. 6(1)(c) GDPR) — to keep transaction records required by tax and accounting law.

5. Service providers

We use a small number of processors, each bound by data processing agreements and receiving only what is necessary:

  • OpenAI — our AI inference provider: processes the problem photo or text to produce a solution. Your content is not used to train their models. It is retained only for abuse monitoring, for up to 30 days, and then deleted.
  • Cloud hosting provider — hosts our solving API.
  • RevenueCat, Inc. — subscription management (anonymous identifier, purchase and entitlement data).
  • Apple App Store / Google Play — payment processing under their own privacy policies.

Where a provider processes data outside the European Economic Area, transfers are protected by the European Commission’s Standard Contractual Clauses or an adequacy decision (including the EU–US Data Privacy Framework where applicable).

6. Retention

  • Photos and problems — we keep no copy once your solution is returned. Our AI provider retains them for abuse monitoring for up to 30 days, then deletes them.
  • Solutions, chats, and answers on your device — kept until you delete them in the App or uninstall the App.
  • Purchase records — kept for the duration of your subscription and thereafter up to 10 years where required by Bulgarian tax and accounting law.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy in a portable format;
  • rectify inaccurate data and restrict or object to processing;
  • withdraw consent at any time, without affecting prior processing;
  • erasure (“right to be forgotten”), subject to legal retention duties.

Because we hold no account data about you, most data lives only on your device: choosing Settings → Delete all my data or uninstalling the App removes it. For anything else — including deletion of purchase records associated with your anonymous identifier — email manol@balkanbit.app and we will respond within one month.

8. Children

Mathly is a study tool suitable for general audiences and asks for no personal information from any user, including children. We do not knowingly collect personal data from children, and the App contains no advertising and no cross-app tracking. Under the Bulgarian PDPA, consent of a person under 14 is valid only if given by a parent or guardian; if we learn we have processed a child’s data without valid consent, we will delete it immediately.

9. Security

All data in transit is encrypted with HTTPS/TLS. Problem images are processed transiently and are not written to long-term storage. Requests are authorized per device, and data on your device is protected by your device’s operating system sandbox.

10. Complaints

You have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP):

  • Address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
  • Fax: +359 2 915 3525
  • Email (qualified electronic signature required): kzld@cpdp.bg
  • Web: https://www.cpdp.bg

11. Changes to this policy

We may update this policy as the App evolves. Material changes will be announced in the App before they take effect, and the effective date above will always reflect the current version.