Privacy Policy
Last updated: 28 April 2026
1. Introduction
The IELTS Exam (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our platform.
2. Information We Collect
We collect the following categories of information:
- Account information: Name, email address, and authentication data (password hash or OAuth provider ID).
- Exam data: Your answers, band scores, writing submissions, and AI-generated feedback.
- Payment information: Transaction IDs, payment method used, and uploaded payment proof images.
- Usage data: Pages visited, exam attempts started and completed, device type, and browser information.
3. How We Use Your Information
Your information is used to:
- Provide and personalise the IELTS preparation experience.
- Score your exam attempts and display band analytics.
- Process and verify payment requests for premium exams.
- Send AI-generated writing evaluations via Gemini.
- Improve the platform based on aggregate usage patterns.
- Communicate account-related updates (e.g., password reset).
4. Data Storage & Security
Your data is stored securely using Supabase (hosted on cloud infrastructure with encryption at rest and in transit). We implement Row Level Security (RLS) policies to ensure users can only access their own data. Payment proof images are stored in private buckets accessible only to administrators.
5. Third-Party Services
We integrate with the following third-party services:
- Supabase: Authentication, database, and file storage.
- Google Gemini AI: Writing submissions are sent to the Gemini API for band estimation and feedback. Only the writing prompt and your written response are transmitted — no personal identifiers are included.
- Vercel: Application hosting and edge delivery.
Each third-party service operates under its own privacy policy. We encourage you to review their policies independently.
6. Cookies & Local Storage
We use cookies for authentication session management (Supabase auth tokens). We also use browser localStorageto save in-progress exam drafts so you don't lose work if you navigate away. Draft data is cleared when you submit the exam.
7. Data Retention
Your account data and exam history are retained as long as your account remains active. If you delete your account, your personal data will be removed within 30 days. Anonymised, aggregate analytics data may be retained indefinitely.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate information.
- Request deletion of your account and associated data.
- Withdraw consent for data processing where applicable.
- Export your exam results and band score history.
To exercise any of these rights, contact us at the email address below.
9. Children's Privacy
The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be reflected with an updated “Last updated” date. Continued use of the platform after changes are posted constitutes acceptance of the revised policy.
Privacy questions? Contact us at privacy@theieltsexam.com
