🌱 Pre-launch preview: GrowthBud™ is getting ready for launch. Some content, features, and app links may still be updated before the official release.

Privacy Policy

This Privacy Notice describes how Brillianaire Group Pte. Ltd. collects, uses, discloses and otherwise processes personal data through the App and the website. It takes effect on 3 July 2026.

  1. Introduction and Scope
    1. Brillianaire Group Pte. Ltd. (the** “Operator”, “we”, “us” หรือ “our”) is committed to protecting your personal data and to handling it in accordance with the Personal Data Protection Act 2012 of Singapore (the “PDPA”**). This Privacy Notice explains how we collect, use, disclose and otherwise process personal data.
    2. Scope. This Privacy Notice applies to personal data that we collect through both:
      1. the Brillianaire application in mobile and/or web form, together with all related software, features and services (the “App”); and
      2. the Brillianaire website, including all pages, forms and content made available on it (the “Website”).
    3. This Privacy Notice is the companion document to, and should be read together with, our Terms of Service (the “Terms”). It corresponds to the “Privacy Policy” referred to in the Terms. Capitalised terms that are used but not defined in this Privacy Notice have the meanings given to them in the Terms, including** “Account”, “Account Holder”, “Biometric Data”, “Emotion Tracker”, “Linked Child”, “Linked Child Profile”, “Marketplace”, “Report”, “Services” และ “Third-Party Business”**.
    4. In this Privacy Notice, “personal data” means data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access, as defined in the PDPA. “you” และ “your” refer to the individual whose personal data we process, including an Account Holder and, where applicable, a Linked Child (through the Account Holder acting as the responsible adult).
    5. If you do not agree with this Privacy Notice, please do not use the App or the Website.
  2. Who We Are and How to Contact Our DPO
    1. The data controller responsible for your personal data is Brillianaire Group Pte. Ltd., a company incorporated in Singapore whose registered office is at [Registered Address].
    2. We have appointed a Data Protection Officer (the “DPO”) who is responsible for overseeing our compliance with the PDPA and with this Privacy Notice.
    3. You may contact our DPO in any of the following ways:
      1. by email to [DPO Email];
      2. by email to [Support Email], marked for the attention of the Data Protection Officer; or
      3. by post to the DPO at [Registered Address].
    4. Questions, requests and complaints relating to your personal data or to this Privacy Notice may be directed to the DPO using the details above.
  3. Personal Data We Collect
    1. Depending on how you use the App and the Website, we may collect and process the following categories of personal data:
      1. Account and registration data: your name, email address, password (stored in encrypted form), contact details and other information you provide when you register for, and maintain, an Account.
      2. Linked children’s data: personal data about a Linked Child that an Account Holder provides or generates, including the child’s name, age or date of birth, Linked Child Profile information, and the child’s emotion-tracking and Report data. This is addressed further in Clause 8.
      3. Emotion-tracking data: emotional, mood and psychological information that you record, monitor or track through the Emotion Tracker in respect of yourself or a Linked Child. We treat this as sensitive personal data (see Clause 9).
      4. Biometric (fingerprint) data: fingerprint scans and fingerprint-derived data processed to generate a Report. This is Biometric Data and is addressed in detail in Clause 7.
      5. Payment data: information relating to your purchases and payments, such as transaction records, billing details and the payment method used. Card and financial account details are collected and processed by our third-party payment processors and are not stored by us in full.
      6. Website and App usage and device data: technical information about your device and how you interact with the App and the Website, including IP address, device type and identifiers, operating system, browser type, app version, log data, pages and features accessed, and dates and times of access.
      7. Cookies and similar data: data collected through cookies, device identifiers, pixels, tags and similar technologies on the App and the Website, as described in Clause 13.
      8. Contact, enquiry and newsletter data: information you provide when you complete a contact or enquiry form on the Website, correspond with us, or sign up for our newsletter, such as your name, email address and the content of your message.
    2. You do not have to provide the personal data we request. However, if you do not provide personal data that is necessary for a particular purpose, we may be unable to provide the relevant part of the Services to you (for example, we cannot generate a Report without the relevant Biometric Data and consent).
  4. How We Collect Personal Data
    1. We collect personal data through both the App and the Website, including in the following ways:
      1. Directly from you when you register for an Account, create or manage a Linked Child Profile, use the Emotion Tracker, request a Report, make a payment, complete a contact or enquiry form on the Website, sign up for our newsletter, or otherwise communicate with us.
      2. Automatically when you use the App or browse the Website, through cookies, device identifiers, analytics tools and server logs, which collect usage and device data as described in Clause 13.
      3. From third parties who provide services to us, such as our payment processors and analytics providers, to the extent described in this Privacy Notice.
    2. Where an Account Holder provides personal data about a Linked Child or any other individual, the Account Holder confirms that they are authorised to provide that personal data and to consent to its processing in accordance with this Privacy Notice and the Terms.
  5. Purposes for Which We Collect, Use and Disclose Personal Data
    1. We collect, use and disclose personal data only for purposes that a reasonable person would consider appropriate in the circumstances and that have been notified to you, including:
      1. to create, administer, secure and support your Account and any Linked Child Profile;
      2. to provide and operate the Services, including the Emotion Tracker, Courses, the Marketplace directory and the generation of Reports;
      3. to collect and process fingerprint scans, with your explicit consent, solely to perform the analysis required to generate a Report (see Clause 7);
      4. to process payments and administer purchases, subscriptions and Fees;
      5. to respond to your enquiries, contact-form submissions and support requests, and to communicate with you about the Services;
      6. to operate, maintain, personalise, analyse and improve the App and the Website, including through usage analytics;
      7. to send you our newsletter and direct marketing about our own products and services where you have consented or where otherwise permitted under the PDPA, subject to your right to opt out (see Clause 14);
      8. to protect the security and integrity of the App and the Website and to detect, prevent and address fraud, misuse and technical issues; and
        1. to comply with applicable law, regulatory requirements and lawful requests, and to establish, exercise or defend legal claims.
    2. We will not use or disclose your personal data for a new purpose that is materially different from those set out above without first notifying you and, where required by the PDPA, obtaining your consent.
  6. Consent and Withdrawal of Consent
    1. We collect, use and disclose personal data with your consent, or as otherwise permitted or required under the PDPA (including where an exception applies, such as deemed consent or the legitimate interests provisions).
    2. Where consent is given by an Account Holder on behalf of a Linked Child, it is given in accordance with Clause 8. Explicit consent is obtained separately in respect of Biometric Data in accordance with Clause 7.
    3. Withdrawal of consent. You may withdraw your consent to our continued collection, use or disclosure of your personal data (or, where applicable, that of a Linked Child for whom you are responsible) at any time by giving us reasonable notice, using the contact details in Clause 2 or Clause 19.
    4. On receiving your withdrawal of consent, we will inform you of the likely consequences of withdrawal. Withdrawing consent may mean that we are unable to continue providing some or all of the Services to you or to a Linked Child. Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal, and we may continue to retain and process personal data where we are legally permitted or required to do so.
  7. Biometric (Fingerprint) Data
    1. Certain Reports are generated on the basis of the analysis of fingerprint scans, which constitute Biometric Data and are a category of personal data requiring particular protection under the PDPA.
    2. Purpose. We collect and process fingerprint scans solely to perform the analysis required to generate the Report that you (or, in respect of a Linked Child, the Account Holder) have requested. We will not use fingerprint scans for any other purpose without obtaining your further consent.
    3. Separate explicit consent. We will collect, use and process fingerprint scans only where explicit consent has been given, separately from acceptance of the Terms and separately from any other consent:
      1. by the Account Holder in respect of the Account Holder’s own Biometric Data; and
      2. by the Account Holder, on behalf of and as the responsible adult for a Linked Child, in respect of that child’s Biometric Data, including where the child is under 13.
    4. Deletion of fingerprint scans after analysis. Once the analysis required to generate a Report has been completed, the fingerprint scans are deleted. We do not retain fingerprint scans after the analysis is complete.
    5. Retention of the Report. The Report generated from the analysis is retained on the relevant user’s profile so that it remains available to the Account Holder, until the Report is deleted in accordance with Clause 15, on account closure, or upon your request.
    6. In-house analysis. The analysis of fingerprint scans to generate a Report is carried out in-house by us. We do not send fingerprint scans to any third-party analyser for this purpose.
    7. Handling. We handle all Biometric Data in accordance with the PDPA, including by applying reasonable security arrangements to protect it, limiting its use to the purpose described in this Clause 7, and honouring rights of access, correction and withdrawal of consent in accordance with Clause 18. Withdrawal of consent to the processing of Biometric Data may prevent the generation of a Report but will not, of itself, delete a Report already generated except as provided in Clause 15 or on request.
  8. Children’s Personal Data and Parental/Guardian Consent
    1. The App allows an Account Holder to link a child to their Account and to create a Linked Child Profile. A Linked Child may be under 13 years of age. The Emotion Tracker and Reports may be used by an Account Holder in respect of a Linked Child.
    2. Explicit parental/guardian consent. By linking a child and creating a Linked Child Profile, the Account Holder confirms that they are the parent or legal guardian of that child, or are otherwise lawfully authorised to act on the child’s behalf, and gives explicit consent, as the responsible adult, to the collection, use and disclosure of the child’s personal data (including any Biometric Data) for the purposes described in this Privacy Notice and the Terms. Where the child is under 13, this explicit consent is required before any personal data of the child is processed.
    3. Consent in respect of a Linked Child is required specifically and separately in respect of any Biometric Data, in accordance with Clause 7.
    4. Parental access and deletion rights. The Account Holder responsible for a Linked Child may, at any time, request access to, or correction of, the child’s personal data, withdraw consent in respect of the child, and request deletion of the Linked Child Profile and associated data, by contacting our DPO using the details in Clause 2. Withdrawal of consent or a deletion request may result in the deletion of the relevant Linked Child Profile and may affect the availability of the Services for that child.
    5. If you believe that a child’s personal data has been provided to us without appropriate parental or guardian consent, please contact our DPO and we will take steps to delete that personal data.
  9. Emotion-Tracking and Other Sensitive Data
    1. The Emotion Tracker enables you to record, monitor and track emotional, mood and psychological information in respect of yourself and any Linked Child. We regard this emotion-tracking and psychological information as sensitive personal data and afford it heightened protection.
    2. We collect, use and disclose emotion-tracking data only for the purposes described in Clause 5, only with consent (including, in the case of a Linked Child, the explicit consent of the responsible adult), and subject to reasonable security arrangements appropriate to the sensitivity of the data.
    3. We do not use emotion-tracking data or Reports to provide medical, psychological or other professional advice, and such data is not disclosed to Third-Party Businesses or used for the direct marketing of third parties.
  10. Disclosure to Third Parties and Data Intermediaries
    1. We do not sell your personal data. We disclose personal data only as described in this Privacy Notice, with your consent, or as otherwise permitted or required under the PDPA.
    2. We may disclose personal data to the following categories of third parties, some of which act as our data intermediaries (processing personal data on our behalf and on our instructions):
      1. payment processors, to process payments and administer purchases and subscriptions;
      2. cloud hosting and storage providers, to host and store the App, the Website and associated data;
      3. analytics providers, to help us understand and improve how the App and the Website are used; and
      4. email and notification providers, to send service communications, our newsletter and other messages.
    3. Where a third party acts as our data intermediary, we require it by written contract to process personal data only for the purposes we specify, to protect the personal data with reasonable security arrangements, and to comply with the applicable requirements of the PDPA.
    4. We may also disclose personal data where required to do so by law or regulation, to a court, regulator or law enforcement authority, or where necessary to establish, exercise or defend legal claims, or to protect the rights, property or safety of the Operator, our users or others.
    5. We may disclose personal data in connection with a corporate transaction, such as a merger, acquisition, reorganisation or sale of assets, subject to appropriate safeguards and the requirements of the PDPA.
  11. Marketplace and Third-Party Links
    1. The Marketplace is a country-segmented directory through which Third-Party Businesses (enrolled education-related businesses) advertise and link out to their own websites. No products or services are sold, and no transactions are processed, on or through the App.
    2. Independent controllers. Each Third-Party Business is an independent data controller in respect of any personal data it collects from you through its own website or otherwise. We do not share your personal data with Third-Party Businesses; the Marketplace directory merely displays listings and links out to their websites.
    3. When you follow a link from the Marketplace, or any other third-party link on the App or the Website, you leave our platform and access a third-party website that we do not operate or control. We are not responsible for the data protection or privacy practices of any third-party website, and you should review the relevant third party’s own privacy policy.
  12. Transfers of Personal Data Outside Singapore
    1. Your personal data may be stored and processed in Singapore and, in connection with the services provided by our data intermediaries and other third parties (such as cloud hosting, storage and analytics providers), may be transferred to, stored in, or processed in countries outside Singapore.
    2. Transfer Limitation safeguards. Where we transfer personal data outside Singapore, we will comply with the Transfer Limitation Obligation under the PDPA. In particular, we will take appropriate steps to ensure that the recipient is bound by legally enforceable obligations to provide to the transferred personal data a standard of protection that is comparable to that under the PDPA, for example by:
      1. entering into contractual clauses requiring the recipient to protect the personal data to a comparable standard; or
      2. transferring the personal data to a recipient in a jurisdiction, or under a certification or binding scheme, that provides a comparable standard of protection.
    3. You may contact our DPO using the details in Clause 2 for more information about the safeguards we apply to overseas transfers of personal data.
  13. Cookies, Device Identifiers and Tracking Technologies
    1. We and our service providers use cookies and similar technologies on both the App and the Website to operate them, to remember your preferences, to keep you signed in, to measure and analyse usage, and to improve the Services. These technologies include:
      1. session cookies, which are temporary and are deleted when you close your browser or the App;
      2. persistent cookies, which remain on your device for a set period or until you delete them;
      3. third-party cookies, set by our service providers, such as analytics providers;
      4. device identifiers, such as mobile advertising identifiers and other identifiers associated with your device;
      5. pixels and tags, small tracking technologies used to understand engagement with content and communications; and
      6. analytics SDKs, software components integrated into the App that collect usage and device data.
    2. App-based tracking consent. Tracking technologies used within the App, including analytics SDKs and device identifiers, are enabled on the basis of your consent, which we obtain at account registration and/or through an in-app consent prompt. You may manage or withdraw your consent to App-based tracking at any time through the App’s privacy or settings menu and through your device operating-system settings (for example, by resetting or limiting the advertising or device identifier), or by contacting our DPO using the details in Clause 2. Disabling certain App tracking technologies may affect the functionality of the App.
    3. Website cookie consent. Where required, the Website presents a cookie consent mechanism that allows you to accept or reject non-essential cookies. Essential cookies that are necessary for the App and the Website to function may not be capable of being disabled.
    4. Your controls. You can manage or disable cookies through your browser settings, and you can manage device identifiers and tracking through the settings on your device. Disabling certain cookies or identifiers may affect the functionality of the App or the Website.
  14. Direct Marketing and Your Choices
    1. Where you have consented, or where otherwise permitted under the PDPA and applicable law, we may send you our own direct marketing communications about our products, services and offers, including our newsletter.
    2. Opt-out. You may opt out of receiving direct marketing communications from us at any time, at no cost, by using the unsubscribe mechanism in the relevant message or by contacting us using the details in Clause 2 or Clause 19. We will give effect to your opt-out within the time required by law.
    3. We conduct our marketing in accordance with the PDPA, including its provisions on consent and unsubscribe, and, in respect of telephone numbers, the Do Not Call provisions of the PDPA. We do not sell your personal data, and we do not disclose your personal data to third parties for their own direct marketing purposes.
  15. Retention of Personal Data
    1. We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required or permitted by law.
    2. Deletion after account closure. When you close your Account, we will delete or anonymise the personal data associated with your Account and any Linked Child Profile promptly, and in any event within approximately 30 to 90 days of account closure, except where we are required or permitted by law to retain it for a longer period (for example, to comply with legal, accounting, tax or regulatory obligations, or to establish, exercise or defend legal claims).
    3. Fingerprint scans. Fingerprint scans are deleted after the analysis required to generate a Report has been completed, in accordance with Clause 7. Reports are retained on the relevant profile until deleted in accordance with Clause 7.5.
    4. Where personal data is retained beyond the periods described above for legal reasons, we will retain it only for as long as the relevant legal purpose requires and will protect it in accordance with this Privacy Notice.
  16. Protection and Security of Personal Data
    1. We make reasonable security arrangements to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks.
    2. These arrangements include technical measures (such as encryption of passwords, access controls and secure hosting) and organisational measures (such as staff confidentiality obligations and limiting access to personal data to those who need it). Sensitive personal data, including Biometric Data and emotion-tracking data, is afforded heightened protection appropriate to its sensitivity.
    3. While we take reasonable steps to protect personal data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your Account credentials confidential.
  17. Data Breach Notification
    1. We maintain procedures to detect, assess and respond to data breaches involving personal data.
    2. In the event of a data breach that results, or is likely to result, in significant harm to affected individuals, or that is of a significant scale, we will notify the Personal Data Protection Commission (the “PDPC”), and the affected individuals where required, in accordance with the data breach notification obligations under the PDPA and within the timeframes prescribed by law.
  18. Your Rights
    1. Subject to the PDPA, you have the following rights in respect of your personal data (and, where applicable, that of a Linked Child for whom you are responsible):
      1. Access. You may request access to personal data about you that is in our possession or under our control, and information about the ways in which that personal data has been or may have been used or disclosed within the preceding year.
      2. Correction. You may request that we correct an error or omission in personal data about you that is in our possession or under our control.
      3. Withdrawal of consent. You may withdraw any consent you have given for the collection, use or disclosure of your personal data, in accordance with Clause 6.
      4. Complaints. You may raise a complaint about our handling of your personal data with our DPO.
    2. How to exercise your rights. To exercise any of these rights, please contact our DPO using the details in Clause 2. We may need to verify your identity before responding, and, in the case of a request relating to a Linked Child, confirm that you are the responsible Account Holder. We will respond to your request within the time required by the PDPA. We may charge a reasonable fee for an access request, and will inform you of any such fee in advance.
    3. In limited circumstances, we may be entitled or required under the PDPA to refuse an access or correction request in whole or in part. Where we do so, we will inform you of our reasons to the extent required by law.
  19. How to Contact Us and Escalation to the PDPC
    1. If you have any questions, requests or complaints about this Privacy Notice or about how we handle your personal data, please contact our DPO:
      1. by email to [DPO Email];
      2. by email to [Support Email], marked for the attention of the Data Protection Officer; or
      3. by post to the DPO at [Registered Address].
    2. We take all complaints seriously and will investigate and respond to your complaint as soon as reasonably practicable.
    3. Escalation to the PDPC. If you are not satisfied with our response, or believe that we have not handled your personal data in accordance with the PDPA, you have the right to lodge a complaint with the Personal Data Protection Commission of Singapore (the PDPC). Information about how to contact the PDPC and lodge a complaint is available on the PDPC’s website.
  20. Changes to This Privacy Notice
    1. We may update this Privacy Notice from time to time to reflect changes in our practices, the Services, or applicable law.
    2. Where we make changes, we will update the effective date at the top of this Privacy Notice and make the updated version available through the App and the Website. Where a change is material, we will take reasonable steps to bring it to your attention and, where required by the PDPA, obtain your consent.
    3. Your continued use of the App or the Website after an updated Privacy Notice takes effect indicates that you have read and understood the update, to the extent permitted by law.
thไทย