1. Introduction
This Privacy Policy (the “Policy”) explains how Matdo Lab LLC (“Matdo”, “we”, “us”, “our”) handles personal information in connection with the Matdo Check application for iPad (the “App”) and the website at matdolab.com (the “Site”).
Matdo Check is designed so that the information it records never reaches us. Much of this Policy therefore describes information that stays under your control rather than information we hold. Sections 5 and 8 to 10 describe how the App handles data on your device; sections 6, 14 and 19 describe the limited categories of personal information we actually receive.
This Policy does not form part of any contract of sale. Downloads and purchases through the App Store are also governed by Apple's applicable terms.
2. Summary
Non-binding summary
- We do not receive, store, or have access to your attendance records. They stay on your iPad.
- The App has no accounts, no analytics, no advertising, and no servers operated by us.
- iCloud Backup is off unless you switch it on, and it writes to your own Apple Account, encrypted.
- Apple processes all purchases. We never see payment details.
- The only personal information we receive is what you send us — a contact-form message or an email.
This summary is provided for clarity in accordance with the transparency principle. It is not a substitute for the full Policy, and in the event of any inconsistency the numbered sections below prevail.
3. Definitions
- Attendee Records
- The data a Center enters into or generates within the App: attendee names; optional telephone numbers, grade and student number; check-in and check-out times; and the audit log of instructor corrections and resets.
- Center
- The tutoring center, school, place of worship, club, camp, or other organisation that installs and operates the App on its own device.
- Device
- The iPad or other Apple device on which the App is installed.
- You
- The reader of this Policy: a Center operating the App, a member of its staff, or a visitor to the Site.
4. Our role and your role
The App is licensed software that runs entirely on your Device. It is not a hosted service. We do not operate a backend, we do not maintain a database of Attendee Records, and we have no technical means of retrieving Attendee Records from a Device.
Accordingly, as between you and us:
- The Center determines which attendees are entered, for what purpose, and for how long records are kept. In the terminology of the EU and UK General Data Protection Regulation, the Center is the controller of Attendee Records.
- We do not act as a processor of Attendee Records, because we never receive them and cannot access them. We supply software; we do not process data on the Center's behalf.
- We are the controller only of the limited personal information we receive as described in section 6 — principally, information you choose to send us. A provider may act as an independent controller for information it collects directly.
The Center remains responsible for meeting its own obligations to attendees and their parents or guardians, including any notice, consent, retention, and access requirements imposed by law, by its franchise or licensing agreements, or by its own policies.
5. Attendee Records: what the App stores, and where
The App stores all Attendee Records in a single database inside the App's private storage area on the Device. There are no user accounts and no cloud service operated by us. With iCloud Backup switched off (section 8) and no purchase in progress (section 7), the Device may remain offline indefinitely and every check-in function continues to work.
The database is protected by the operating system's file protection, so its contents are encrypted at rest and unreadable until the Device has been unlocked at least once after starting up.
Deleting the App from the Device deletes the database and all local backups with it. Copies previously written to iCloud are addressed in sections 8 and 9.
6. Information we receive
We receive no Attendee Records. The categories below describe the limited personal information handled by us or by service providers in connection with the App and Site.
6.1 Messages you send us
If you complete the contact form on the Site, we receive your name, email address, the organisation you enter (optional), your selected area of interest, and the content of your message. If you email us directly, we receive your email address and whatever the message contains.
Contact-form submissions are transmitted to Web3Forms, a third-party form-delivery service, before reaching our mailbox. Web3Forms also receives technical information needed to deliver and protect the form, such as the request's IP address and browser information, and may retain submission or log data under the settings and policies applicable to our account. See sections 14 to 16.
6.2 Reports provided to us by Apple
As an App Store developer we receive sales and download reports from Apple. These are aggregated and do not identify individual customers. We do not receive the names, email addresses, or payment details of purchasers.
6.3 Diagnostic information, if you have enabled it
If the holder of the Device has switched on Apple's Share With App Developers setting at the operating-system level, Apple may make crash logs, usage statistics, and performance diagnostics available to us. You can control this under Privacy & Security, then Analytics & Improvements, in the Device's Settings. We do not intentionally include Attendee Records in diagnostic reports.
6.4 Server logs for the Site
The Site is hosted by GitHub Pages. When you visit it, GitHub — not Matdo — logs and stores your IP address for security purposes and may process other standard request information under its own privacy statement. We do not receive GitHub's visitor logs. See section 14.
7. Purchases and subscriptions
All purchases and subscriptions are processed by Apple through the App Store under Apple's own terms and privacy policy. Payment details are never shown to us and never pass through the App.
To determine whether a licence is active, the App queries Apple's on-device App Store service. That query is not reported to us and carries no Attendee Records.
8. Optional iCloud Backup
The App offers a daily copy of its database to iCloud, so that a lost, damaged, or replaced Device does not take the Center's roster and attendance history with it. This feature is off unless a member of staff switches it on in Settings, under Data.
When it is enabled, the operating system uploads the copy to the Center's own Apple Account, into the App's private iCloud container, which no other application can read. It is not sent to us, and we have no access to it.
Each copy is encrypted before it leaves the Device, using authenticated encryption. The encryption key is held by the Center's instructor PIN and by the recovery code shown when that PIN is set. We hold no copy of either secret. In consequence:
- Reinstalling the App, on this or any other Device, cannot open a backup without the PIN or the recovery code.
- If both the PIN and the recovery code are lost, those backups cannot be opened by anyone, including us.
The most recent seven copies are retained automatically, together with up to five copies that staff have named. Switching the feature off stops new copies being made; it does not delete copies already stored. To remove those, delete the App's iCloud data from the Device's Settings, under your Apple Account then iCloud.
9. Device-level iCloud backup
Separately from section 8, if the Device backs itself up to iCloud, the App's database is included in that device backup under the Center's own Apple Account. This is a function of the operating system rather than of the App. It is managed in the Device's Settings, under your Apple Account, then iCloud, then Backups.
10. Access controls within the App
The check-in screen is intended to be visible at a counter and displays attendee names during search and confirmation. Every other function — the roster, records, history, and corrections — is behind the instructor PIN, and the Settings area is additionally behind Face ID, Touch ID, or the Device passcode. Instructor screens relock automatically after two minutes without interaction.
The Center is responsible for choosing a PIN that is not easily guessed, for limiting who knows it, and for keeping the Device itself protected by a passcode.
11. Children's information
Centers using the App commonly record the names of children. Because those records remain on the Center's own Device and, if backup is enabled, within the Center's own Apple Account, we do not collect, receive, or process personal information from or about children, and we have no ability to access it.
The App is not directed at children as its users and does not request any information from a child. An attendee checking in types only a name that a member of Center staff has already enrolled. The App contains no advertising, no analytics, no social features, and no mechanism by which a child could transmit information to us or to any third party.
Responsibility for obtaining any notice or consent required before a child's details are entered — whether under the Children's Online Privacy Protection Act, education-records legislation, applicable data protection law, or a franchise agreement — rests with the Center.
12. How we use information
The limited information described in section 6 is used only as follows:
- Messages you send us — to respond to your enquiry and to provide support.
- Apple's aggregated reports — to understand sales volumes and to run our business.
- Diagnostic reports, where enabled — to identify and fix defects in the App.
- Site request logs — GitHub processes these to host, secure, and maintain GitHub Pages; we do not receive its visitor logs.
We do not use any of this information for advertising, for profiling, or for automated decision-making that produces legal or similarly significant effects. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
13. Legal bases for processing (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under Article 6 of the GDPR and UK GDPR:
- Messages you send us — our legitimate interests in responding to enquiries and supporting customers, and, where your message concerns a purchase or prospective purchase, the performance of a contract or steps taken at your request.
- Diagnostic reports — where those reports constitute personal information, our legitimate interests in maintaining the App's security, reliability, and performance. Apple makes them available only if the Device holder has enabled sharing with app developers.
- Site request logs — GitHub determines its own legal bases for the visitor information it processes as the independent provider of GitHub Pages. See GitHub's privacy statement in section 14.
14. Disclosure of information
We do not sell personal information or disclose it for advertising purposes. Personal information may be handled by the following providers or recipients in the circumstances described:
- Web3Forms — receives and delivers contact-form submissions to us and performs abuse prevention. It processes the form fields and technical information described in section 6.1. Web3Forms describes its practices in its privacy and GDPR information.
- GitHub, Inc. — hosts the Site through GitHub Pages and records visitor IP addresses for security, as described in section 6.4 and the GitHub Privacy Statement.
- Apple Inc. — distributes the App and processes all purchases. Apple acts as an independent controller in respect of your relationship with the App Store, under its own privacy policy.
- Legal requirements — where disclosure is required by law, court order, or a lawful request from a public authority, or is necessary to establish, exercise, or defend legal claims.
- Business transfer — in connection with a merger, acquisition, or sale of assets, in which case we will take reasonable steps to ensure the recipient honours this Policy.
No Attendee Records are disclosed to any of the above, because we do not hold them.
15. International transfers
We are established in the United States. The service providers named in section 14 may process information in the United States and other countries described in their notices. If you contact us from outside the United States, the information in your message will be transferred to and processed in the United States, where data protection law may differ from that of your own jurisdiction. Where applicable law requires a transfer mechanism for processing for which we are responsible, we will use one permitted by that law.
Attendee Records are not transferred internationally by us, because they are not transferred to us at all. Where iCloud Backup is enabled, storage locations are determined by Apple under the Center's own Apple Account.
16. Retention
- Attendee Records — retained on the Device for as long as the Center chooses. We hold none and therefore retain none. Deleting the App deletes the database and its local backups; copies in iCloud persist until deleted as described in section 8.
- Correspondence — retained for as long as reasonably necessary to handle your enquiry, provide support, maintain appropriate business records, and establish or defend legal claims, and then deleted or anonymised.
- Provider-held information — diagnostic reports, contact-form delivery data, and Site request logs are retained under the settings and retention practices of Apple, Web3Forms, and GitHub respectively. The provider notices linked in section 14 contain further details.
17. Security
The App applies operating-system file protection to its database, requires a six-digit instructor PIN stored only as a slow, salted hash, enforces an escalating lockout after failed attempts, gates the Settings area behind device-owner authentication, and encrypts every copy written to iCloud with authenticated encryption, as described in section 8.
For information we ourselves hold, we apply measures appropriate to its limited nature and volume, including access controls on our mailbox.
No method of storage or transmission is completely secure. The security of Attendee Records depends substantially on measures within the Center's control — the Device passcode, who is told the instructor PIN, and where the recovery code is kept.
18. Your rights
18.1 EEA and UK
Subject to the conditions and exemptions in applicable law, you have the right to request access to the personal information we hold about you; to have it corrected or erased; to restrict or object to its processing; to receive it in a portable form; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your supervisory authority, and in the United Kingdom with the Information Commissioner's Office.
18.2 California
Subject to the conditions and exemptions in the California Consumer Privacy Act as amended, California residents have the right to know what personal information we have collected, used, and disclosed; to request its deletion or correction; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
We do not sell or share personal information as those terms are defined in that Act, and we do not use or disclose sensitive personal information for purposes requiring a right to limit.
18.3 Other jurisdictions
Residents of other US states with comprehensive privacy legislation have comparable rights of access, correction, deletion, portability, and opt-out. We honour such requests on the same basis as those described above.
18.4 Exercising your rights
Write to us at the address in section 21. We will verify your request by reference to the email address from which you contact us, and respond within the period required by applicable law. You may use an authorised agent where the law permits.
Please note the practical limit: the only personal information we hold about you is your correspondence with us. We cannot provide, correct, or delete Attendee Records, because we do not have them. A request concerning attendance records should be directed to the Center that operates the App. If you are unsure which Center that is, we will help you identify the right recipient where we can.
19. The Site
The Site is a static website. Matdo sets no cookies, runs no analytics, and embeds no advertising technology, third-party trackers, or social widgets. Fonts and other assets are served from the Site itself.
The two exceptions are described above: standard server logging by our host (section 6.4), and delivery of contact-form submissions by Web3Forms (section 6.1). Matdo does not use either to profile visitors.
20. Changes to this Policy
We may amend this Policy from time to time. The current version is always published at this address, with its effective date and version number shown at the top. Where a change materially affects your rights, we will take reasonable steps to bring it to your attention. The corresponding text shown inside the App is updated to match in the next release.
Changes apply from the effective date shown above. If a change requires your consent under applicable law, we will request it separately.
21. Contact and complaints
The controller responsible for personal information received directly by Matdo, as described in sections 6.1 and 6.3, is Matdo Lab LLC. Apple and GitHub act as independent controllers for the processing described in this Policy under their respective privacy notices.
- matdo@matdolab.com
- Location
- West Lafayette, Indiana, United States
We aim to resolve any concern directly. If you are in the EEA or the UK and remain dissatisfied, you may complain to your national supervisory authority; if you are in the United Kingdom, that is the Information Commissioner's Office.
End of Policy · Version 2.0 · Effective 27 August 2026 · Matdo Lab LLC