J&T

Privacy Policy

Effective date: 1 January 2026

1. Information We Collect

When you create an account, we collect:

  • Your display name and email address
  • Phone number (optional, for payment verification)
  • Preferred language (English, Burmese, or Japanese)
  • Quiz session history: answers, scores, time spent per question
  • Payment slip images you upload (KBZPay / WavePay / AYA Pay screenshots)

2. How We Use Your Information

  • To deliver and personalise the practice experience
  • To track your progress and surface weak-area recommendations
  • To verify and process your premium payments
  • To send account-related emails (password reset, payment confirmation)
  • To detect and prevent abuse (rate-limiting, bot detection via Cloudflare Turnstile)

3. Data Storage and Security

Your data is stored on Supabase (a SOC 2-certified database provider) with row-level security policies preventing one user from accessing another's data. Payment slip images are stored in a private, signed-URL-only bucket. Daily encrypted backups are kept on Cloudflare R2 for 30 days.

4. Cookies

We use essential cookies for authentication (Supabase session) and to remember your preferred language. We do not use third-party advertising or analytics cookies.

5. Third-Party Services

  • Google Gemini API — used server-side to generate question explanations and OCR text from uploaded images. Question text is sent; your personal information is never sent.
  • Cloudflare Turnstile — used on signup/login forms to prevent bot abuse. Returns a token; no personal data shared.
  • Vercel — hosts the application. Receives standard HTTP request metadata (IP address, user agent).
  • Upstash Redis — used for rate-limiting; stores per-user request counts with a sliding 60-second window.

6. Data Sharing

We do not sell, rent, or share your personal data with any third party for marketing purposes. We may disclose data only when legally required (court order, fraud investigation).

7. Your Rights

You have the right to:

  • Access the data we hold about you
  • Correct inaccurate information (via the Profile page)
  • Request deletion of your account and all associated data
  • Export your quiz history (contact support for a CSV export)

8. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect data from anyone under 13. Parents who believe their child has provided us with data should contact support for prompt removal.

9. Contact

Privacy questions or data requests? Reach us at the Contact page.