11Y — Privacy Policy

Application: 11Y
Publisher / Data Controller: Yousef Roshdy
Contact: yossefroshdy2006@gmail.com
Effective Date: 9 July 2026
Last Updated: 12 July 2026
Version: 1.4


1. Introduction

This Privacy Policy ("Policy") describes how the 11Y mobile application (the "Application", "we", "us", or "our") collects, uses, stores, discloses, and protects information relating to individuals who use the Application (each a "User" or "you").

The Application is an educational productivity platform that provides study planning, learning tracks, collaborative teams and groups, private and group messaging, cloud file storage, and Artificial Intelligence assistance. Because these features process User data, this Policy exists to explain, in clear and accurate terms, exactly what data is processed and why.

This Policy is a legal and technical document. It is intended to reflect the actual behaviour of the Application. By creating an Account, downloading, accessing, or using the Application, you acknowledge that you have read and understood this Policy and that your Personal Data will be processed as described herein. If you do not agree with this Policy, you should not use the Application.


2. Definitions

For the purposes of this Policy:


3. Scope of this Policy

This Policy covers the collection and Processing of data through the 11Y Application and its associated backend infrastructure (authentication, database, storage, cloud functions, messaging, analytics, crash reporting, advertising, and AI Services).

This Policy does not cover the independent privacy practices of Third-party Services beyond the scope of their integration with the Application, external websites or applications that may be linked from within the Application, or content and services provided by other Users. Third-party Services process data in accordance with their own privacy policies, referenced in Section 7.


4. Data We Collect

We apply the principle of Data Minimization and collect only the data necessary to operate the features described below.

4.1 Identity Data

Collected when you create or use an Account:

When you register or sign in using Google Sign-In, we receive basic profile information (such as name, email address, and profile photograph) from that provider as permitted by the authorization you grant.

To protect your privacy, the Application stores a SHA-256 cryptographic hash of your email address for the "add friend by email" search feature, rather than exposing plaintext email addresses in publicly readable profile records. This is a data-minimization measure.

4.2 Device and Diagnostic Data

Collected automatically to maintain reliability and security:

4.3 User Generated Content (UGC)

Content you create or upload while using the Application, including:

4.4 AI Interaction Data

When you use AI features, we process:

4.5 Usage, Activity, and Application Data

Generated through normal use of the Application:

4.6 Messaging and Notification Data

To deliver push notifications, we process a device messaging token issued by Firebase Cloud Messaging and metadata required to route notifications relevant to you. Users may disable notifications at any time through their device settings.

4.7 Advertising Data

The Application integrates the Google AdMob advertising SDK and displays advertisements. In connection with serving and measuring those advertisements, Google AdMob may collect device identifiers (including the Android advertising identifier), IP address, and related technical signals, as carried out by Google in accordance with its own policies (see Section 7 and Section 18). The Application declares the com.google.android.gms.permission.AD_ID permission for this purpose, and the advertising identifier is disclosed accordingly in our Google Play Data Safety declaration. We do not share your Identity Data or Content with advertisers for targeting purposes.

4.8 Payment Data

The Application does not currently offer in-app purchases or subscriptions and does not collect, process, or store any payment card or billing information. Google Play Billing is planned for a future release; see Section 18.


5. On-Device Processing

Certain features rely on on-device Machine Learning that does not transmit your content to our servers or to third parties for that specific processing:


6. Purposes of Processing

We process data only for the following purposes, each tied to a real feature of the Application:

Purpose Description
Authentication & Authorization Creating and securing your Account and controlling access to your data.
Synchronization Keeping your study data, content, and settings consistent across your sessions and devices.
Cloud Storage Storing and retrieving the Content you upload.
Core Functionality Operating study planning, learning tracks, teams, groups, messaging, and progress features.
AI Processing Generating responses to the requests you submit to AI features.
Notifications Sending reminders and relevant activity notifications.
Diagnostics & Bug Fixing Detecting, diagnosing, and fixing crashes and performance issues.
Security & Fraud Prevention Protecting the Application and its Users against abuse, unauthorized access, and fraud.
Advertising Displaying advertisements that support the Application.
Analytics Understanding aggregate feature usage to improve the Application.
Support & Communication Responding to your requests and enquiries.
Legal Compliance Meeting obligations under applicable laws.

We rely on your consent (for example, for optional profile data and notifications), the performance of our service to you, and our legitimate interests (such as security and reliability) as the bases for Processing.


7. Third-party Service Providers

The Application relies on the following Third-party Services. Each processes data only for the stated purpose. These providers act as our Cloud Infrastructure and processing partners and maintain their own privacy policies.

Service Purpose Data It May Process
Firebase Authentication (Google) Account creation and sign-in Email, UID, authentication credentials
Google Sign-In Federated sign-in Basic Google profile (name, email, photo)
Cloud Firestore (Google) Structured data storage and synchronization Account data, UGC metadata, activity data
Cloud Storage for Firebase (Google) File storage Images, videos, documents, audio, and other uploaded files
Cloud Functions for Firebase (Google) Secure backend logic, including AI request handling Requests routed through backend logic
Firebase Cloud Messaging (Google) Push notifications Device messaging token
Firebase Crashlytics (Google) Crash reporting Crash logs, device and diagnostic data
Firebase Analytics (Google) Usage analytics Aggregated event and device data
Firebase Performance Monitoring (Google) Performance measurement Performance traces, device data
Firebase App Check / Google Play Integrity Abuse and fraud prevention Device integrity attestation tokens
Google AdMob (Google) Advertising SDK (serves advertisements; processes the advertising identifier) Advertising identifier, IP address, ad interaction data (upon production activation)
Google Gemini (Google AI Services) AI response generation Prompts and content you submit to AI features
Google ML Kit (on-device) Text recognition (OCR) and handwriting (digital ink) recognition — see Section 5 Images and ink strokes are processed locally on your Device; recognition models may be downloaded from Google servers

By using the Application you acknowledge that these providers process data in accordance with their respective privacy policies, including Google's applicable Privacy Policy and Terms.


8. Artificial Intelligence Services

The Application offers AI-powered features (such as assistants and study helpers). When you use these features:

AI-generated output may be inaccurate or incomplete and should not be relied upon as professional advice.

8.1 Self-Development, Coaching & Safety

Some AI features (including the self-development coach and related tools) are provided for educational and personal-development purposes only. They are not a medical, psychological, diagnostic, therapeutic, counselling, or emergency service, and they do not provide any medical or mental-health diagnosis or treatment. They are not a substitute for consultation with a qualified professional.

Where your input indicates distress or a possible risk of harm to yourself or others, the assistant is designed to respond supportively and to encourage you to reach out to a trusted person or a qualified professional; it does not provide diagnosis, treatment, or harmful instructions. If you are experiencing a crisis or an emergency, contact your local emergency services or a qualified professional immediately. The Application also displays an in-app notice describing these limitations before you use the self-development features.


9. Cloud Storage and Synchronization

Content you upload is stored using Cloud Storage operated by our Cloud Infrastructure providers. This enables:

Backups may be maintained by our Cloud Infrastructure providers as part of their standard backup operations.


10. How We Share Data

We share data only as necessary to operate the Application:

Data may be disclosed to:


11. Cross-border Data Transfers

The Application relies on global Cloud Infrastructure. Your data may be stored and processed on servers located in countries other than your country of residence, in accordance with the infrastructure of our Third-party Service Providers. Backend processing (including AI request handling) may be performed in Google Cloud regions. Where such Cross-border Data Transfers occur, they are carried out subject to the safeguards maintained by those providers.


12. Security Measures

We take security measures consistent with industry standards to protect Personal Data, including:

While we take these measures, no method of transmission or storage is completely secure.


13. Data Retention

We retain Personal Data and Content for as long as your Account remains active or as needed to provide the Application's features. When data is no longer required for these purposes, or upon a valid deletion request, it is deleted or anonymized. Following deletion, residual copies may persist temporarily within routine backups maintained by our Cloud Infrastructure providers before being overwritten in the ordinary course of their operations. We may retain limited data for longer where required to comply with Applicable Laws, resolve disputes, or enforce our agreements.


14. Account Deletion

The Application provides an in-app option to permanently delete your Account and associated data, in compliance with Google Play's account-deletion requirements.

When you request deletion:

Account deletion may take a reasonable period to complete.

What may remain: Content that you contributed to shared spaces (such as messages within a team, group, or chat with other Users) may be retained so that other Users' conversations remain coherent; once your Account is deleted, such Content is no longer attributable to an identifiable Account. In addition, residual copies may persist temporarily in backups as described in Section 13.

To delete your Account, use the in-app deletion option, or contact us at yossefroshdy2006@gmail.com.


15. Your Rights

Subject to, and where required by, Applicable Laws, you have the right to:

To exercise these rights, contact yossefroshdy2006@gmail.com. We will respond within the period required by Applicable Laws.

Depending on your jurisdiction, you may have additional rights under the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA), as described in Section 22.


16. Children's Privacy

The Application is not directed to children under the age of 13 (or the minimum digital age required by applicable law). We do not knowingly collect Personal Data from children under that age. If you believe a child has provided us with Personal Data, please contact us at yossefroshdy2006@gmail.com, and we will take steps to delete such data.


17. Logs and Diagnostics

We process the following operational records to keep the Application reliable and secure:

These records are used for reliability, security, and troubleshooting, and are retained only as long as reasonably necessary.


18. Advertising and Payments

Advertising. The Application integrates the Google AdMob advertising SDK and displays advertisements (banner, native, interstitial, and rewarded formats). Google may collect and process device identifiers — including the Android advertising identifier — IP address, and related technical data in order to serve, cap, and measure advertisements, as described in Google's own policies. We do not share your Identity Data or Content with advertisers for the purpose of targeting. Personalized advertising, where enabled, is subject to applicable consent requirements, and you can reset or delete your advertising identifier at any time from your device settings.

Payments. Purchases and subscriptions are not currently available in the Application, and no in-app billing system is presently active. Google Play Billing will be integrated in a future release, before the public production release, to offer paid features. Payment card details are never stored by the Application. When billing is enabled, all payments will be processed exclusively through Google Play Billing; payment card data will be handled by Google and not stored by us, purchases will be verified through Google Play, and refunds will be governed by Google Play's policies. Applicable taxes may apply depending on the user's jurisdiction. This Policy and the Data Safety disclosure will be updated before any paid feature is enabled.


19. User Responsibilities, Content Moderation & Reporting

By using the Application, you agree that you will:

19.1 Prohibited Content and Conduct

The Application includes features that allow Users to interact and share User Generated Content (UGC) — including private, group, and team messages, images, videos, documents, audio, and files. You must not create, upload, share, or transmit Content that:

19.2 Reporting and Blocking Tools

To help keep the community safe, the Application provides in-app tools that let you:

Reports are received by our authorized moderation team and reviewed. To report Content or a User, use the report option in the app, or contact us at yossefroshdy2006@gmail.com.

19.3 Moderation and Enforcement

We reserve the right, but are not obligated, to review, moderate, restrict, or remove any Content, and to warn, suspend, or permanently terminate the Account of any User who violates this Policy or our terms — with or without notice, and at our sole discretion — in order to protect Users and comply with Applicable Laws. We aim to act on valid reports of clearly objectionable Content within a reasonable time.

19.4 Zero Tolerance for Child Sexual Abuse & Exploitation (CSAE)

We have a zero-tolerance policy toward child sexual abuse and exploitation material (CSAE/CSAM). Such Content is strictly prohibited. Where we become aware of such Content, we will remove it, terminate the responsible Account, and report it to the relevant authorities as required by Applicable Laws.

19.5 AI Features — Acceptable Use

The Application offers Artificial Intelligence features. You must not attempt to use these features to generate content that is prohibited under Section 19.1. AI safety filters are applied to reduce harmful outputs, and you may report an AI-generated response you believe is inappropriate. AI-generated output may be inaccurate and should not be relied upon as professional advice.


20. Changes to this Policy

We may update this Policy from time to time to reflect changes in the Application, legal requirements, or our practices. When we do, we will revise the "Last Updated" date and, where appropriate, the version number. Material changes will be communicated through the Application or other reasonable means. Your continued use of the Application after an update constitutes acceptance of the revised Policy.


21. Contact Us

For any questions, requests, or concerns regarding this Policy or your Personal Data, or to exercise your rights, privacy requests may be submitted to:

We will make reasonable efforts to respond promptly.


22. Compliance

This Policy is designed to be consistent with, and the Application's data practices are intended to comply with:

This Policy is intended to reflect the actual data practices of the Application.