Privacy Policy Last updated: March 6, 2024 JLPT Question Generator ("My JLPT Study", "we", "our", or "us") operates the web and API services that let learners practise for the Japanese Language Proficiency Test using AI-generated study sessions (the "Service"). We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and the choices you have. 1. Who We Are We are JLPT Question Generator, operated under the My JLPT Study brand and registered in the United Kingdom. Email: support@myjlptstudy.com Address: [registered or contact address] We act as the "data controller" for purposes of the UK GDPR and, where applicable, the EU GDPR. 2. Information We Collect We collect and process the following categories of data to deliver the Service: a. Information you provide directly - Supabase authentication details such as your email address and password (hashed; we never see your raw password). - Requests you send to our support team. - Inputs you submit when generating or answering JLPT practice questions, including any custom prompts you type. b. Information related to usage - Study progress you generate through the Service (e.g., saved history, question queue, flagged items, and exam session responses). - Device and log information such as IP address, browser type, and interactions required to operate the Service and keep it secure. c. Payment information - Stripe processes your payment card details when you purchase credits. We receive confirmation of the purchase, the credits bundle, and metadata required for invoicing. We never store full card numbers or CVC codes. 3. How We Use Your Information We use your data to: - Authenticate you and keep your account secure. - Deliver adaptive study sessions, queue new questions, and track your progress across devices. - Provide downloadable mock exams that reflect your preferences. - Process payments, manage credits, and send receipts. - Communicate with you about updates, service notices, or support requests. - Monitor and improve system performance, prevent abuse, and comply with legal obligations. We rely on one or more of these lawful bases: performance of a contract, legitimate interests (such as improving and securing the Service), compliance with legal duties, or your consent where required. 4. AI Content Handling Prompts and study responses you submit are processed by our Python generator, which may share the content with OpenAI, L.L.C. to produce JLPT-style items. We do not permit OpenAI to use this data to train its public models, and we only store the resulting questions long enough to deliver them back to your account history or queued sessions. 5. Third-Party Service Providers We rely on trusted partners who process data on our behalf: Purpose | Provider | Data Location Payments | Stripe, Inc. | EU / US Authentication & Database | Supabase (PostgreSQL) | EU / US AI Processing | OpenAI, L.L.C. | US Hosting & CDN | Cloudflare | Global Analytics (optional) | Plausible Analytics or Google Analytics | EU / US These providers act under data-processing agreements that align with GDPR and other applicable privacy regulations. 6. Data Retention - Account and purchase records: retained while your account remains active and for up to six (6) years afterwards for tax and accounting purposes. - Study progress, question history, and queued items: kept until you delete them or request account deletion, after which we either anonymise or remove the data during periodic clean-up cycles. - Support communications: retained as long as necessary to address your request and maintain a record of our correspondence. - Aggregated analytics: stored without personal identifiers. You may request deletion of your account and associated data at any time (see Section 9). 7. International Transfers Your personal information may be transferred and stored outside the UK or EU, including in the United States. We rely on UK/EU adequacy decisions or Standard Contractual Clauses (SCCs) to safeguard these transfers. 8. Data Security We implement administrative, technical, and physical safeguards such as: - HTTPS/TLS encryption for data in transit. - Role-based access controls for administrative tools and Supabase storage. - Monitoring, logging, and automated checks that limit misuse and detect anomalies. While no system is perfectly secure, we work to minimise risks and review our controls regularly. 9. Your Rights (UK/EU) You have the right to: - Access the personal data we hold about you. - Request correction of inaccurate data. - Request deletion of your account or restriction of certain processing activities. - Object to processing carried out under legitimate interests. - Receive your data in a portable format. - Withdraw consent at any time. - Lodge a complaint with the Information Commissioner's Office (ICO) or your local supervisory authority. Submit requests by emailing support@myjlptstudy.com. We respond within one month where feasible. 10. Additional Rights for U.S. Residents If you reside in a U.S. state with privacy legislation (such as California, Colorado, Connecticut, Utah, or Virginia), you may have additional rights, including: - Right to know the categories of personal information we collect and how we use it. - Right to request deletion of your personal data. - Right to opt out of certain data sharing (we do not sell personal data). - Right to non-discrimination for exercising your privacy rights. To exercise these rights, contact support@myjlptstudy.com. 11. Cookies and Tracking Technologies We use cookies and similar technologies to keep you signed in, remember preferences, measure traffic patterns, and support essential functionality. When required by law, we display a cookie notice so you can manage your preferences. You can control cookies via your browser settings; disabling cookies may affect Service functionality. 12. Updates to This Policy We may update this Privacy Policy to reflect changes to our practices or for operational, legal, or regulatory reasons. We will post the updated version on this page with a new "Last updated" date. Material changes may be communicated through additional notice. 13. Contact Us If you have any questions, requests, or complaints about this Privacy Policy, contact: Data Protection Contact JLPT Question Generator / My JLPT Study Email: support@myjlptstudy.com