Privacy Policy

Last updated: 25 August 2026

Welcome to Jamb 380 and Above!

Jamb 380 and Above is a product of LiveLesson Software. The advent of Information and Communication Technology has brought about sweeping changes in the way Learning and Information Services are being delivered. The focus now is to automate the whole learning processes from Nursery to Tertiary Education, which LiveLesson Educational Software tends to achieve.

This Privacy Policy explains what information Jamb 380 and Above collects, how we use it, and how we protect it. Your use of the app is also governed by our Terms of Service.

Google User Data

Jamb 380 and Above uses Google Sign-In and the YouTube Data API. This section explains exactly what Google user data we access, why, how we store it, and how you can withdraw access at any time.

What we access

When you sign in with Google, we receive your basic Google profile: your name, email address and profile picture.

If you choose to subscribe to our channel, like a video, or post a comment from inside the app, we request one additional permission, https://www.googleapis.com/auth/youtube.force-ssl. We use it only to carry out those actions on your behalf, and we ask for it only at the moment you first use one of those features. If you never use them, we never ask for it.

How we use it

Your name, email and profile picture identify your account, show who you are in the app, and let us restore your progress and earnings when you sign in again.

The YouTube permission is used solely to perform actions you explicitly request: subscribing to our channel, liking a video, or posting a comment as you. We never subscribe, like, comment or change anything on your YouTube account without you tapping the button that does it. We do not read your watch history, your subscriptions to other channels, your playlists, or any other YouTube data beyond what is needed to perform and confirm the action you asked for.

What we store, and where

Your name, email, profile picture and — if you provide it — your phone number are stored in our Google Cloud Firestore database, alongside your progress, score and earnings.

When you first use a YouTube feature, Google issues us a refresh token so that you do not have to sign in again every time you use the app. That token is held in a server-only database collection that no app user can read, is used only to obtain short-lived access tokens for actions you initiate, is never sent to your device, and is never shared with anyone.

Who we share it with

We do not sell your Google user data, and we do not share it with third parties for advertising or any other purpose. It is not used to train generalised or artificial intelligence models. It is processed only by the services we use to operate the app: Google Firebase (authentication, database, hosting and notifications) and Paystack (payments and payouts, where you use those features).

Advertising

We show advertising from Google AdMob in parts of the app. Our advertising is not based on your Google user data. Ad providers do not receive your Google profile, and they do not receive anything obtained through the YouTube permission.

How long we keep it

We keep your profile for as long as your account exists. We keep your refresh token until you revoke our access or ask us to delete your account, whichever comes first.

Withdrawing access and deleting your data

You can remove our access to your Google account at any time: go to myaccount.google.com/permissions, select Jamb 380 and Above and choose Remove access. This immediately and permanently invalidates the refresh token we hold, and we delete our stored copy the next time we try to use it.

To delete your account and the personal data we hold, email livelessonsoftware@gmail.com from the address you signed up with, and we will delete it within 30 days.

Limited Use

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The security measures we apply to that data are described in How we protect your data below.

How we protect your data

We treat the following as sensitive information and protect it with the measures set out in this section:

Encryption in transit

Every connection between the app, this website and our servers uses HTTPS/TLS, as do our calls to Google's APIs and to our payment provider. Your data is never transmitted over an unencrypted connection.

Encryption at rest

Your data is stored in Google Cloud Firestore and Firebase, where it is encrypted at rest with AES-256 using Google Cloud's default encryption. We operate no servers of our own and keep no copies of your personal data outside that managed infrastructure.

We never handle your password or your card details

Sign-in is performed entirely by Google. We never see, receive or store your Google password. Card payments and payouts are processed by Paystack, a PCI-DSS compliant payment provider; card details are entered on Paystack's systems and are never stored by us.

Access control

Our database denies access by default: there is no rule that grants general read access to personal data. A signed-in user can read and write only their own record. Withdrawal and payment records are readable only by an authenticated administrator and can never be written from a user's device.

The collection that holds YouTube refresh tokens is closed to every client, with a rule that denies all reads and writes. It can be reached only by our server-side Cloud Functions — not by any user of the app, and not by our own administrators through the app.

Protection of your YouTube authorisation

Our OAuth client secret and payment keys are held in Google Cloud Secret Manager and are injected only into the specific server-side functions that need them. They are not contained in the app, in our public source, or on your device. The exchange of your one-time authorisation code for a refresh token happens entirely on the server, so the refresh token itself never reaches a phone. The app receives only short-lived access tokens for the individual action you asked for.

Data minimisation

We request a single Google permission, we request it only at the moment you first use a feature that needs it, and we collect only the information the app needs in order to work. We do not request scopes we do not use.

Administrative access

Administrative functions are restricted to a small number of accounts holding a verified administrator role, granted server-side and verified on every request. Administrator access is used only for support, content moderation and processing payouts, and never to read your YouTube authorisation, which is technically inaccessible to them.

Retention and deletion

We keep your profile only for as long as your account exists, and your refresh token only until you revoke our access or ask us to delete your account. Revoking access at myaccount.google.com/permissions invalidates the token immediately, and our stored copy is deleted. Account deletion requests are completed within 30 days.

If something goes wrong

If we become aware of a breach affecting your personal data, we will act immediately to contain it, and we will notify the users affected and the Nigeria Data Protection Commission without undue delay, and within 72 hours where the law requires it.

Our processors

The only third parties that process your data are Google Firebase (authentication, database, hosting and notifications) and Paystack (payments and payouts). Both maintain their own recognised security certifications, and both are bound to process your data only on our instructions. We share your data with no one else, and we do not sell it.

If you have questions about this Privacy Policy or your data, contact us at livelessonsoftware@gmail.com.

See also our Terms of Service.

← Back to Home