Privacy Policy
What we collect, where it goes, and your rights under Malaysian PDPA.
Last Updated · June 2026
Cigu is a lesson-planning app for Malaysian school teachers. It helps you generate a Rancangan Pengajaran Harian (RPH) and supporting teaching materials. This policy explains what personal data Cigu collects, how it is used, who we share it with, and the rights you have under the Personal Data Protection Act 2010 (Malaysia).
Cigu is operated by Learnest Lab Sdn Bhd ("we", "us"), the data controller for the personal data described below.
1 ·What We Collect
When you use Cigu, we collect:
- Account information — your email address, used to sign you in. If you sign in with Apple or Google, we receive your email and display name from them.
- Teacher profile — the details you choose to add to your profile: your name, school name, teaching grade (gred DG), and the subjects and levels you teach.
- Lesson-plan inputs — what you type or select to generate an RPH: the subject, the level or year, the topic, the lesson duration, and any free-text instruction or prompt you provide.
- Your generated content — the RPHs Cigu produces for you, plus any teaching materials generated from them (quizzes / kuiz, slides / slaid, and mind maps / peta minda), along with any reflections or classes you create in the app.
- Usage and diagnostic data — anonymous product-analytics events (for example, that an RPH was generated) and crash reports. These help us fix problems and improve the app.
Cigu does not collect receipts, identity-card numbers, income figures, payment-card details, or any tax information. We do not ask for, and have no use for, your students' personal data — please do not enter student names, IC numbers, or other student personal details into lesson-plan prompts.
2 ·How We Use Your Data
- To provide the app's core feature — generating an RPH and teaching materials from the inputs you give us.
- To save your RPHs and materials to your account so you can open them again from any device you sign in on.
- To pre-fill the generator with your profile (for example, your usual subjects and levels) so you type less.
- To fix crashes and understand which features are used, so we can improve the app.
- To send you the sign-in email you request (the magic link).
We do NOT sell your data. We do NOT share it with third parties for advertising or marketing. We do NOT use your lesson-plan content to train our own models.
3 ·Where Data Is Stored
- Your account, profile, RPHs, and generated materials are stored on our secure cloud database (Neon Postgres) and are tied to your account — not stored only on your device. This is what lets your work follow you across devices.
- Our backend service runs on Vercel.
- Crash reports and anonymous product analytics are stored with the providers named in Section 4.
- On your device, Cigu keeps only your sign-in session (held in the device's secure storage) and a local cache of your own content for speed.
Cigu does not use Firebase.
4 ·Third-Party Services We Use
To run Cigu, we share limited data with the providers below. Each one is named so you know exactly who sees what. These providers process data on our behalf and are not permitted to use it for their own purposes.
- Google Gemini (Google LLC). Our primary AI provider. When you generate an RPH or teaching material, the inputs you provide (subject, level, topic, duration, and your free-text instruction), together with the relevant Malaysian curriculum (DSKP) reference text, are sent to Google's Gemini API to produce the draft. Under the Gemini API terms, Google does not use this input to train its models.
- Anthropic Claude (Anthropic PBC). Our fallback AI provider. If Gemini is unavailable, the same inputs are sent to Anthropic's Claude API instead, for the same purpose. Anthropic does not use API inputs to train its models.
- OpenAI (OpenAI, L.P.). Used only to convert curriculum reference text and topics into search embeddings so Cigu can find the most relevant DSKP material for your lesson. Short pieces of text (such as your topic) are sent to OpenAI's embedding API for this purpose. OpenAI does not use API inputs to train its models.
- Resend. Sends the sign-in (magic-link) email to your email address. Resend receives your email address and the message content.
- Sentry. Collects crash and error reports so we can fix bugs. To help us trace a crash to your session, a report may include your account ID and email along with device diagnostic information.
- PostHog. Records anonymous product-analytics events (such as "an RPH was generated") to help us understand and improve how the app is used. These events do not include your lesson-plan content.
- Apple Sign-In. If you sign in with Apple, Apple receives your sign-in request and returns your email (or a private relay email, if you choose) and your name.
- Google Sign-In. If you sign in with Google, Google receives your sign-in request and returns your email and name.
5 ·Data Transferred Outside Malaysia
Some of these services are hosted outside Malaysia. By using Cigu, you consent to the following cross-border transfers of your personal data:
- Google (via the Gemini API and Google Sign-In) — your lesson-plan inputs and sign-in data are processed on servers that may be located in the United States.
- Anthropic (via the Claude API) — your lesson-plan inputs are processed on servers that may be located in the United States, when the fallback provider is used.
- OpenAI (via the embeddings API) — short pieces of text are processed on servers that may be located in the United States.
- Neon and Vercel — store and serve your account data and our backend on servers that may be located outside Malaysia.
- Resend, Sentry, and PostHog — process your email, crash reports, and analytics events on servers that may be located outside Malaysia.
- Apple Sign-In — involves servers that may be located outside Malaysia.
6 ·Your Rights Under PDPA
Under the Personal Data Protection Act 2010 (Malaysia), you have the right to:
- Access your data. View your profile, RPHs, and materials in the app at any time.
- Correct your data. Edit your profile in-app, and regenerate or delete any RPH or material.
- Withdraw consent. Delete your account and the data tied to it (see Section 7).
- Request a copy. Export your data from the app (Profil → Eksport data saya).
- Lodge a complaint with the Personal Data Protection Commissioner of Malaysia (Jabatan Perlindungan Data Peribadi).
7 ·Deleting Your Account
You can delete your account at any time from inside the app: open Profil → Padam akaun and confirm. When you do:
- Your account is scheduled for permanent deletion after a 7-day grace period. Signing in again during those 7 days cancels the deletion.
- After the grace period, your RPHs, generated materials, reflections, classes, profile, and pending sign-in tokens are permanently deleted.
- A small number of records we are required to keep for legal, security, or billing reasons (for example, minimal logs) are retained with your identity removed where possible.
You can also ask us to delete your data by contacting us at the address in Section 10.
8 ·Data Security
We use industry-standard security measures:
- Encrypted connections (HTTPS) for all data we send or receive.
- Your sign-in session is held in your device's secure storage, not in plain text.
- Access to your content is restricted to your authenticated account — your data is keyed to your verified identity, never to a value supplied by the app.
9 ·Children's Privacy
Cigu is built for Malaysian school teachers and is not intended for children under 18. We do not knowingly collect personal data from minors. Cigu is a tool for the teacher's own lesson preparation and is not designed to collect or store any student's personal data.
10 ·Contact Us & Changes
We may update this policy from time to time. We will notify you of significant changes through the app.
Privacy questions · support@cigu.my
To lodge a complaint with the Malaysian data protection regulator:
Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi), Ministry of Digital Malaysia · pdp.gov.my