Legal

Privacy Policy

Effective date: 16 July 2026

1. Who we are

Brightmark is a product of Finedrawn Pte. Ltd. (UEN 202614907C), a company incorporated in Singapore.

In this policy, "Brightmark", "we", "us", and "our" refer to Finedrawn Pte. Ltd. operating the Brightmark platform — including the mobile application, website, and any related services.

2. What data we collect

We collect only the information needed to provide Brightmark's features.

Tutor account data

When you register as a tutor, we collect your name, email address, and the details you enter about your students — including their names, subjects taught, lesson rates, schedules, and the WhatsApp contact number you provide for invoicing.

We also store lesson logs, invoice records, and payment status as you record them.

Calendar data (Google user data)

If you connect Google Calendar, we request access to your Google Calendar via OAuth 2.0 and receive an access token and refresh token from Google in return. We use this access to create, update, and delete the lesson events that Brightmark creates on your behalf.

We do not use this access to read, collect, or store the content of calendar events that Brightmark did not create.

Usage data

We collect basic analytics — pages visited, features used, and session metadata — using self-hosted analytics tools (Umami for the website, Aptabase for the app) that run on our own infrastructure. This data is aggregated, not tied to your identity, and is not sent to any external analytics company.

3. How we use your data

  • To provide and operate the Brightmark platform
  • To generate invoices, lesson logs, and payment records on your behalf
  • To sync lessons to Google Calendar when you have enabled that integration
  • To send push notifications for lesson reminders and invoice alerts that you have enabled
  • To improve the product based on aggregated usage patterns
  • To communicate with you about your account, including support and policy updates

We do not sell your personal data. We do not use your data for advertising.

4. Third-party services and data sharing

We do not sell Google user data, and we do not share it for advertising purposes.

We share data — including Google user data where noted below — only with the service providers listed here, and only as necessary for them to provide the services described on our behalf. None of these providers is permitted to use the data for its own independent purposes.

Supabase (database and authentication)

Our database and authentication infrastructure runs on Supabase. Your account credentials and all application data — including Google Calendar OAuth tokens and the lesson event data created through calendar sync — are stored in Supabase's infrastructure, hosted in the Singapore or Asia-Pacific region.

Google Calendar

If you enable Google Calendar sync, we integrate with Google's Calendar API using OAuth 2.0 to create, update, and delete lesson events on your calendar. You can revoke this access at any time from your Google account settings, which immediately stops any further access.

Sentry (error monitoring)

We use Sentry to capture application errors so we can diagnose and fix bugs. By default, Sentry collects technical diagnostic information such as device type, app version, and error stack traces — it does not capture request or response content unless explicitly configured to do so.

Sentry does not receive Google user data as part of its normal operation.

Umami and Aptabase (self-hosted analytics)

Our usage analytics run on Umami and Aptabase, both self-hosted on our own infrastructure rather than a third-party provider's servers. Neither tool requires a user account, and neither receives Google user data.

We will disclose Google user data beyond the providers above only if required by law, regulation, legal process, or an enforceable governmental request, or to protect the rights, property, or safety of Brightmark, our users, or the public.

5. Data protection and security

We take the following measures to protect your data, including Google user data such as OAuth tokens and calendar event data:

  • Data in transit between your device, Brightmark, and our service providers is encrypted using TLS.
  • Data at rest, including OAuth tokens, is encrypted using AES-256 encryption by Supabase, our database provider.
  • Access to production data is restricted to authorised personnel who need it to operate or support the platform, and is never used for any purpose other than providing the service to you.
  • OAuth tokens are used only to perform the calendar actions you have authorised and are never shared with, or made accessible to, anyone other than the service providers listed in Section 4.

6. Data retention

We retain your data for as long as your account is active.

If you delete your account, your personal data — including Google Calendar OAuth tokens and lesson event data — is deleted immediately from our active systems, except where retention is required by law or for legitimate business purposes such as resolving disputes or enforcing agreements.

Deleted data may persist briefly in encrypted backups until those backups are rotated out in the ordinary course of business.

Aggregated, anonymised analytics data may be retained indefinitely.

7. Cookies

Brightmark's website does not use cookies. Our website analytics (Umami) is cookieless. We do not use tracking or advertising cookies.

8. Your rights

Under Singapore's Personal Data Protection Act 2012 (PDPA) and, where applicable, other data protection laws, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Withdraw consent for processing where consent is the legal basis
  • Request deletion of your account and associated data

To exercise any of these rights, contact us at developer@brightmark.app. We will respond within 10 business days.

9. Children

Brightmark is a tool for tutors. Student profiles are created by tutors for their own record-keeping — students do not create accounts and no data is collected directly from minors.

10. Changes to this policy

We may update this policy as the platform evolves. If we make material changes, we will notify you by email or via an in-app notice at least 14 days before the changes take effect. Continued use of Brightmark after that date constitutes acceptance of the updated policy.

11. Contact

Questions about this policy or how we handle your data should be directed to:

Finedrawn Pte. Ltd.

developer@brightmark.app