About Kira Ed Sdn. Bhd.
The entity responsible for collecting and processing personal data on this platform.
Kira Maths is operated by Kira Ed Sdn. Bhd. (Company Registration No. 202601024023 / 1686120-T), a company incorporated under the Companies Act 2016 in Malaysia. In this Privacy Policy, "Kira", "Kira Maths", "we", "us", and "our" refer to Kira Ed Sdn. Bhd. "You" refers to any person who accesses or uses the Kira Maths platform, including parents or guardians acting on behalf of a child user.
Scope of This Policy
This Policy applies to all personal data collected through the Kira Maths platform and any related communications.
This Privacy Policy applies to all personal data collected through the Kira Maths web platform at mykira.co, including all features, game modes, account pages, and any communications we send to users.
This Policy governs our data practices in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. Where users access our platform through Google services, Google's own API Services User Data Policy also applies independently.
By creating an account or using Kira Maths, you confirm that you have read, understood, and agreed to this Privacy Policy. If you are a parent or guardian registering on behalf of a child, you are providing consent on that child's behalf by completing the registration process.
Children's Privacy and Parental Responsibility
Kira Maths is designed for children aged 7–12. We apply particular care to how we handle data for younger users.
Kira Maths is designed for use by primary school children aged 7 to 12 (Years 1–6 of the Malaysian KSSR curriculum). We take the privacy of younger users seriously and collect only the data necessary to deliver the platform's learning features.
Parental Responsibility at Registration
Because our platform is used by children, we require that an adult — specifically a parent or legal guardian — is responsible for any account registered for a child under 13. By completing registration with a valid email address, the registered account holder confirms that they are either:
- At least 13 years of age and registering on their own behalf; or
- A parent or legal guardian registering on behalf of a child, in which case they consent to the collection and use of the child's personal data as described in this Policy.
It is the responsibility of the parent or guardian to ensure that their child uses the platform appropriately and that the information provided at registration is accurate.
Data Minimisation
We collect only the data necessary to provide an adaptive, curriculum-aligned learning experience. We do not request information beyond what is required to operate the platform and we do not use children's personal data for purposes other than those described in this Policy.
Parental Access and Deletion
Parents and guardians may at any time request access to, correction of, or deletion of their child's personal data. See Section 11 for how to exercise these rights.
Data We Collect
We collect data you provide directly, data generated through platform use, and limited data received from third-party authentication services.
4.1 Account and Profile Data
| Data Field | Why We Collect It | Required |
|---|---|---|
| First name & Last name | Account identity and display in parent or teacher dashboards | Yes |
| Display name | In-game identity and leaderboard display | Yes |
| Email address | Authentication, account recovery, and platform communications | Yes |
| Year of birth | Age-appropriate difficulty calibration and determining applicable data handling requirements | Yes |
| Gender | Optional demographic analytics to improve the platform | Optional |
| Country & State | Localising content and aligning to the correct national curriculum | Yes |
| School or Institution | Leaderboard context and future school-linked features | Optional |
| Year level (Primary 1–6) | Selecting the correct curriculum band, question difficulty, and skill sequence | Yes |
| Phone number | Optional account recovery | Optional |
4.2 Learning and Performance Data
As you use Kira Maths, we generate and store the following data to power the adaptive learning engine:
- Questions answered, including whether each answer was correct or incorrect;
- Response times per question;
- Per-skill mastery level estimates using Bayesian Knowledge Tracing;
- Skill difficulty ratings and progression data;
- Spaced repetition schedules for skill review;
- Weekly, monthly, yearly, and lifetime cumulative scores;
- Session data including game mode, session duration, and questions attempted;
- Daily energy bar usage and in-game coin balance;
- Engagement streak data.
This data is used exclusively to personalise your learning experience. It is not sold or shared with third parties for commercial purposes.
4.3 Technical and Usage Data
We automatically collect standard technical data when you access the platform, including your IP address, browser type and version, device type, and pages visited. This data is used for platform security, analytics, and improvement purposes only.
4.4 Google Sign-In Data
If you choose to register or log in using Google Sign-In, we receive the following data from Google: your full name, email address, and Google profile identifier. We use this data solely to create and authenticate your Kira Maths account. We do not access any other data from your Google account.
How We Use Your Data
Each use of your data has a defined purpose and a lawful basis under PDPA 2010.
- To provide the adaptive learning service — personalising question difficulty, skill sequencing, and session structure based on your performance history;
- To operate and maintain your account — authentication, profile management, and account security;
- To display leaderboards and progress — your display name and scores may appear on leaderboards where applicable;
- To send service communications — including account confirmation, password reset emails, and updates directly related to the platform;
- To improve the platform — aggregated and anonymised analytics to improve question quality, curriculum alignment, and the overall learning experience;
- To display advertisements — see Section 7 for details on how advertising works on the platform;
- To comply with legal obligations — as required by Malaysian law.
We do not use your personal data for automated profiling for any purpose other than adaptive learning, and we do not use it to enable third-party marketing directed at you.
Third-Party Services
We engage the following third-party processors who may handle personal data on our behalf.
| Service | Provider | Purpose | Data Processed |
|---|---|---|---|
| Database & Auth | Supabase, Inc. | Stores all account, profile, and learning data; manages authentication sessions | All account and performance data (hosted in Singapore — see Section 8) |
| Google Sign-In | Google LLC | Optional OAuth authentication | Name, email address, Google profile identifier |
| Google AdSense | Google LLC | Serves advertisements to support platform operations (see Section 7) | IP address, device and browser information, cookie data where applicable |
We do not sell personal data to any third party. We do not share individual user data with advertisers for the purpose of targeted profiling.
Advertising
Advertising helps us cover the costs of running the platform and is what makes Kira Maths free to use.
Kira Maths uses Google AdSense to display advertisements on the platform. Advertising revenue contributes to the costs of operating, maintaining, and improving the platform.
How Ads Work
Advertisements may appear within the platform. We are committed to keeping the advertising experience non-invasive. Most advertisements are displayed passively and do not interrupt learning. Some advertisements are optional and rewarded — a user may choose to watch a short advertisement to receive additional in-game energy. These are always the user's choice and are never required to access core learning features.
Google AdSense and Cookies
Google AdSense may use cookies and similar technologies to serve advertisements. Google may use data about your visits to this and other websites to show you relevant advertisements. You can learn more at policies.google.com/technologies/ads. You may adjust your advertising preferences through your Google Account or at google.com/settings/ads.
Cross-Border Data Transfers
Some of our service providers store and process data on servers located outside Malaysia.
Kira Maths is operated from Malaysia. However, some third-party services we use process and store data on servers located outside Malaysia. By using Kira Maths, you consent to these transfers.
- Supabase — all account and learning data is stored on Amazon Web Services (AWS) infrastructure in Singapore (ap-southeast-1), within the Southeast Asian region;
- Google — authentication and advertising data is processed by Google on its global infrastructure, including servers in the United States.
We take reasonable steps to ensure that these service providers maintain data protection standards consistent with the requirements of PDPA 2010 and applicable international standards.
Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes described in this Policy, or as required by law.
| Data Type | Retention Period |
|---|---|
| Account profile data (name, email, year of birth, etc.) | Retained while the account is active. Deleted within 30 days of a verified account deletion request. |
| Learning and performance data | Retained for the lifetime of the account. Deleted within 30 days of a verified account deletion request. |
| Anonymised analytics data | Retained indefinitely in aggregated, non-identifiable form. Not subject to deletion requests. |
| Legal and compliance records | Retained for 7 years as required under Malaysian law, regardless of account status. |
Security
We implement appropriate technical and organisational measures to protect your personal data.
- All data transmitted between your browser and our servers is encrypted using TLS (HTTPS);
- Passwords are managed through Supabase Auth using industry-standard cryptographic hashing. We do not store passwords in plain text or in any recoverable form;
- The adaptive learning engine runs server-side, and sensitive service credentials are never exposed to the browser;
- Administrative access to the platform and database is restricted to authorised personnel only.
No method of electronic transmission or storage is 100% secure. While we take all reasonable precautions, we cannot guarantee the absolute security of your data. In the event of a data breach that affects your rights, we will notify affected users in accordance with our obligations under PDPA 2010.
Your Rights Under PDPA 2010
Malaysian law gives you specific rights regarding the personal data we hold about you.
Right of Access
You may request a copy of the personal data we hold about you or your child. We will respond to access requests within 21 days.
Right of Correction
You may request that inaccurate or incomplete personal data be corrected. Most profile data can be updated directly from your account settings. For data that cannot be updated directly, contact dpo@mykira.co.
Right to Withdraw Consent
You may withdraw consent to the processing of your personal data at any time by deleting your account or contacting us. Withdrawal does not affect the lawfulness of any processing carried out before withdrawal, and may limit or prevent your access to the platform.
Right to Request Deletion
You may request deletion of your account and associated personal data at any time. We will fulfil verified deletion requests within 30 days, subject to our legal retention obligations in Section 9.
Right to Prevent Direct Marketing
You may opt out of any marketing communications at any time by clicking "Unsubscribe" in any email from us, or by contacting hello@mykira.co.
To exercise any of the above rights, contact us at dpo@mykira.co. We may request verification of your identity before processing a request.
Changes to This Policy
We may update this Policy from time to time. We will notify you of material changes.
We may update this Privacy Policy to reflect changes in our practices, the platform, or applicable legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this document and, where the changes materially affect your rights, post a notice within the platform or notify you by email.
Your continued use of Kira Maths after the effective date of an updated Policy constitutes your acceptance of the changes. We encourage you to review this Policy periodically.
Contact Us
For any questions, concerns, or data requests, reach us through the appropriate channel below.
Kira Ed Sdn. Bhd. · 202601024023 (1686120-T)
Business Address: T2, L19, BO-1-D, KL Eco City, 59200 Kuala Lumpur, Federal Territory of Kuala Lumpur
Response time: We aim to respond to all enquiries within 5 business days.