Skip to content

Privacy

Tik Boom Privacy Notice

This notice explains how Tik Boom handles accounts, account-holder phone records, learning data, purchases, the account’s devices, notifications, and support requests.

1. Scope of this notice

This notice covers the Tik Boom app and related support requests made through herov.net/tikboom.

2. Account and sign-in

The app uses Firebase Authentication for sign-in and account access.

On Android, sign-in methods are Google and email. On Apple devices, Google, Apple, and email are available.

Sign-in services may process account identifiers, account data, diagnostics, or usage data under their provider disclosures. Tik Boom does not operate its own analytics system, and a provider disclosure does not mean the app stores every category in its own database.

3. Learning data and phone record

Tik Boom stores learning and progress data locally on the device.

Tik Boom does not send learning or progress data to a cloud database or Tik Boom API.

After sign-in, the app shows a screen for the adult account holder’s mobile number, with its country code. Tapping “Next” without a number continues without saving anything, and the screen appears again the next time the app opens until a number is saved. The number can be viewed, changed, or removed in Parent Settings.

If a number is entered, it is stored in a private record scoped to that account identifier in Cloud Firestore, with the country code, the number, and when it was added and updated. The Tik Boom server reads the number and keeps a copy with the account’s email and creation date, to show it to the Tik Boom team for managing the customer record and contacting the account holder about the account and the service; it deletes this copy within about 15 minutes after the number is removed, and with the account as described in section 7.

Neither the app nor the Tik Boom server sends an SMS or verification code to the number, and the number is stored as unverified; any verification of the number takes place outside the app.

4. Subscription and payment

Subscriptions are purchased through the App Store on Apple devices and Google Play on Android devices. The purchase sheet of the store used is authoritative for price, billing, renewal, and cancellation terms.

To verify a Google Play subscription and update its status, the app sends the account identifier and purchase token to the Tik Boom server over an encrypted connection. The server retains an encrypted purchase token and limited verification records to check the purchase and prevent its use by another account. Tik Boom does not receive full card details.

On Apple devices, after a purchase or a restore of purchases, and when the app opens while the subscription is active in the App Store, the app sends the App Store transaction information signed by Apple, with the account’s sign-in token, to the Tik Boom server over an encrypted connection. The server verifies Apple’s signature and then binds the subscription to that account.

For each account, the server keeps one subscription record in Cloud Firestore: the purchase store, plan, status, expiry date, time of the last update, and a hash of the purchase reference. The app reads this record on any device signed in to the same account, Apple or Android, and opens the subscription there. App Store subscription-status notifications from Apple and Google Play purchase verification keep the record up to date.

This page and the support email do not ask you to enter card details.

Apple or Google may retain purchase and account records they manage under their own terms and retention policies.

5. How data is used

Data is used for sign-in and account access, local learning-progress storage, customer-record and phone management, complimentary memberships, subscription verification and access on the account’s devices, showing the account’s devices for support and service, sending news and offers notifications to devices that allow them, and support or privacy requests.

Tik Boom does not use a standalone product analytics or advertising service, sell data, use data for advertising, or track users. Sign-in and database providers may process limited operational and diagnostic data under their own disclosures.

The app downloads offer settings and banner images from the Tik Boom server; these requests carry only the app version, language, and platform. It also sends anonymous daily counts to the Tik Boom server, such as how often the subscription screen or a banner was shown or a plan was chosen, with no account, device, or advertising identifier, used only to improve the subscription screen.

Separately from these requests and counts, the app sends a device report to the Tik Boom server, linked to the account, after sign-in and when the app opens, at most once every 24 hours unless something in it has changed. The report contains: the platform, app version, and build number; the device maker, model, codename, and type (phone or tablet); the operating system version and API level; the screen resolution, memory size, processor name, and graphics processor name; the app language, device language, region setting, and time zone; the install source (App Store, TestFlight, Google Play, or other); and the notification permission status. The report is used only to show the account’s devices to the Tik Boom team for support and service. It contains no advertising or device identifiers, location, contacts, or list of installed apps. The server keeps one record for each of the account’s device models, with when it was first and last seen.

With the device’s permission only, the app receives news and offers notifications written by the Tik Boom team. On iPhone and on Android 13 and later, the app asks through the system’s notification permission request, once per installation; on earlier Android versions the system notification setting applies. When notifications are allowed and the “News & offers” switch in Parent Settings is on, the device joins one Firebase Cloud Messaging topic for its platform and the app language, and the Tik Boom server sends each notification to that topic without storing the device’s notification token or a list of devices. The device has no notification token before permission is given. Notifications can be turned off at any time with the switch or in the system settings; turning the switch off removes the device from the topic and deletes its notification token, and deleting the account does the same on that device. A notification image, if any, is downloaded from herov.net without any identifier.

  • Sign-in and account access.
  • Local storage of learning and progress data on the device.
  • Management of the adult account holder’s phone record and complimentary memberships linked to the account.
  • Verification of the subscription through the App Store or Google Play, and access to it on every device signed in to the same account.
  • Showing the account’s devices to the Tik Boom team for support and service.
  • Sending news and offers notifications to devices that allow them.
  • Receipt of support and privacy requests through the published support email.

6. Service providers

Tik Boom uses Firebase Authentication for sign-in, Cloud Firestore for the phone record, complimentary memberships, and the subscription record, Google sign-in on Android and Google or Apple sign-in on Apple devices, the App Store or Google Play for purchases, Firebase Cloud Messaging for notifications, the Tik Boom server to verify App Store and Google Play purchases and private trial codes, to receive App Store subscription-status notifications from Apple, linked to the account by an anonymous token, to receive device reports, and to send notifications, and Gmail for support messages.

Account, phone-record, purchase, and support-message processing is also subject to each provider’s terms and privacy policies.

7. Retention and deletion

Parent Settings includes an in-app account-deletion path. It deletes the account-scoped complimentary-membership record first, then the phone record, Firebase identity, and local app data.

The account’s subscription record in Cloud Firestore, its device records, and the Tik Boom server’s copy of the mobile number are deleted with the account: at once for an account that signs in with email, and within a day for an account that signs in with Apple or Google.

Learning and progress data remain local to the device until they are removed through account deletion or by removing the app and its data.

If a mobile number is added, its record remains linked to the account identifier until it is changed or removed in Parent Settings, or the account is deleted.

Tik Boom may retain limited records to verify purchases, prevent duplicate trial-code redemption, or meet legal duties; in-app account deletion does not automatically cancel store subscriptions or erase those records. To request deletion of associated account data outside the app, use the account-deletion page or support email. When handling the request, we explain what must be retained, why, and for how long, and delete data no longer needed for a legitimate purpose.

Apple or Google may retain independently controlled information under their own obligations and service terms.

8. Privacy requests

A privacy question or request can be sent to the support email published below.

9. Security

These paths rely on account and purchase provider controls plus app configuration, but no digital service is completely secure.

Do not email passwords, verification codes, or complete payment details.

10. Website data and necessary cookies

The herov.net/tikboom website uses cookies that are necessary for the session and request protection. These cookies are not used for advertising or tracking.

Website operations may process request information needed for security and delivery, such as IP address, browser type, URL, and request time in logs.

Support messages are delivered through Gmail, whose email processing and retention controls also apply.

11. Contact

Use the support email published on this page for questions and requests.

Requests and questions

herovikd@gmail.com