Privacy Policy

Last updated

This policy describes exactly what Examoji does with your personal data. It is written from what the application actually does, not from a template — so it is specific, and it is short, because Examoji collects very little.

1. The short version

  • We store your email address, your practice attempts and answers, and what those answers suggest about your strengths and weaknesses. That is essentially all of it.
  • We do not run analytics, advertising or any third-party tracking. There are no tracking cookies, so there is nothing to ask your consent for.
  • We never sell or share your data for anyone else's marketing.
  • Speaking practice asks for microphone access so you can record real answers, which a human reviewer listens to for feedback — nothing else on the site asks for microphone or camera access, and we never record video.
  • If you pay for Premium, your card/UPI/netbanking details go straight to Razorpay, our payment processor — we never see or store them, only the fact and amount of the payment.

The rest of this page is the detail behind those five points, plus how to get your data changed or deleted.

2. Who this policy applies to

This policy covers the Examoji website and the practice tests you take on it. It applies whether you are signed in or just browsing.

You can browse the catalogue and read this page without an account. We only start storing anything about you personally once you create one.

3. What we store, and why

The table below is the complete list. The third column names the actual database table each item lives in, so that this description can be checked against the system rather than taken on trust.

Personal data Examoji stores, why, and where it is held.
What we storeWhy we store itWhere it lives
Your email addressIt is how you sign in, how we send you a verification or password-reset link, and how we identify your account if you contact support.User.email
A hashed version of your password — never the password itselfTo check your password at sign-in without our ever being able to read it. Hashed with bcrypt. Accounts that only ever sign in with Google have no password stored at all.User.passwordHash
Your name, only if you gave us oneTo greet you by name. The sign-up form does not ask for a name; this is only set if you supplied one when registering or if it came from your Google profile.User.name
Whether, and when, you confirmed your email addressSo we know the address is really yours. Google sign-ins are marked confirmed straight away, because Google has already checked it.User.emailVerified
Your study goals, if you answer the optional setup questions: a target score, a target date, how you rate yourself in each skill, which skills you find hardest, and how much time you can study each dayTo make your practice recommendations and pacing advice specific to you rather than generic. Every one of these questions can be skipped, and skipping is a genuinely supported answer, not a degraded one.OnboardingProfile
Every practice test you start: which test, when you started and submitted it, whether it is still in progress, your score, and a snapshot of where you had got to (which question you were on, and what each countdown said) so you can resumeTo run the test itself, to let you pick a test back up where you left it, and to show your history and progress.TestAttempt
Your answers: the option you chose on a multiple-choice question, the text you wrote for a writing task, how long you spent on each question, and whether the answer was right and what it scoredTo mark the test, to let you review your answers afterwards, and to work out what to recommend next.Answer
Your Speaking practice recordings, once you submit them for reviewSo a human reviewer can listen to your actual answer and score it on the same four criteria a real examiner uses, then give you written feedback — the same way a Writing task is read by a person, not graded automatically.Answer.responseMediaUrl
The band scores and written feedback a reviewer gives your Speaking submissionSo the feedback you received stays available when you come back to review it, the same way a completed Writing review does.SpeakingSubmissionReview
What your answers suggest about your ability, per question type — a running estimate, how confident we are in it, and which mistakes have recurredThis is what makes the feedback and recommendations useful rather than generic. It is our inference about you, derived from your answers; it is not something you tell us.MasteryState
The feedback report generated after each completed testSo the feedback you saw after a test stays available and unchanged when you come back to it later.FeedbackReport
Which paid content you have access to, when it started, when it expires, and whether it came from a real payment or a manual grant by usTo know what to unlock for you, and for how long. A Premium purchase is a one-time payment, not a subscription — see the Terms for what it buys and for how long.Entitlement
If you have started a Premium purchase: the order amount, currency and status (created/paid/failed) and Razorpay's own order id for it — never your card, UPI or bank details, which go to Razorpay directly and never reach usTo know what you were charged for and whether it went through, and to match Razorpay's payment confirmation back to the right order before granting access.PaymentOrder
A record of each Razorpay payment notification we have received and processed, keyed by Razorpay's own payment idSo a payment confirmation is never acted on twice — if Razorpay sends the same notification more than once, we can tell and grant access only once.PaymentWebhookEvent
Single-use codes stored only as a salted SHA-256 hash, never as the plain code itself: verification and password-reset links, and 6-digit sign-in codes emailed to you if you choose "email me a code" instead of your passwordSo a verification link, reset link or sign-in code can be checked and then used up. Because only the hash is stored, someone who obtained a copy of our database still could not use them.AuthToken
Abuse counters, keyed by a string derived from your IP address and/or the email address used — plus a count and the time the current window startedTo stop password-guessing and bulk sign-up abuse. This is the only place your IP address is used, and it is stored as part of that key, not as a browsing record.RateLimitCounter

On the IP-derived key: the abuse counter's key is a plain string such as login:ip:203.0.113.4. Your IP address is therefore present in our database while a counter exists. It is never linked to which pages you visited or which tests you took — those records have no IP on them at all.

4. What we do not do

Being specific about the absences is more useful than a vague reassurance, so here is the list. Each of these is a fact about the code as it stands today, not an aspiration.

  • No analytics. There is no analytics product on this site — no page-view tracking, no session recording, no heatmaps, no product-analytics SDK of any kind.
  • No advertising and no third-party trackers. No ad network, no pixels, no social embeds, no tag manager. The site loads no third-party scripts. Even the web fonts are served from our own domain rather than fetched from Google by your browser.
  • No selling or sharing your data. We do not sell personal data, and we do not share it with anyone for their own marketing or advertising.
  • Microphone access only for Speaking practice, and never video. When you tap record on a Speaking question, your browser asks your permission for the microphone, and the recording is uploaded to our own storage once you submit — it is not analysed automatically. A human reviewer listens to it to score and give you feedback, the same way a real writing submission gets read by a person. Outside the Speaking recorder, nothing on the site accesses your microphone or camera, and we never record video anywhere.
  • No card or bank details stored by us. Premium payments are processed by Razorpay. When you pay, your card number, UPI id, netbanking login or billing address goes to Razorpay directly and never passes through our servers at all — we only ever learn the amount, the currency and whether the payment succeeded.
  • No marketing email. We send exactly two kinds of email, both of which you triggered yourself — see below.
  • A few small preferences stored in your browser, and nothing else. The site keeps a localStorage entry, examoji-theme, holding one of light, dark or system — which colour theme you picked with the light/dark switch in the top bar. It keeps one more, written only if you drag the divider on the Listening transcript panel, remembering that panel's width so it does not reset every time you open a Listening test. It keeps one more, written only if you dismiss the “install Examoji” prompt shown after you submit Writing or Speaking for review, remembering not to show that prompt again for a while. And it keeps up to two more for the separate, smaller “install the app” banner shown on mobile screens elsewhere in the site: a timestamp if you dismiss it, so it stays quiet for a while, and a count of how many times you have, so it can stop offering itself for good after the second time rather than asking indefinitely. All of these are written only when you use the control they belong to, none ever leaves your browser, and none is ever sent to or read by our servers. Clearing your browser's site data removes them, and the site falls back to your device's own light/dark setting, the panel's default width, and showing both install surfaces again. Nothing else is stored: no other localStorage entry, and no sessionStorage at all. Installing Examoji (or just visiting) also registers a background service worker (public/sw.js) in your browser, which exists only to make installing possible and to receive notifications you've separately agreed to — it never caches or stores any of your pages, answers, scores or other data, and every request it sees still goes straight to our servers exactly as if it weren't there.

5. Cookies

Examoji sets only the cookies needed to sign you in and keep that sign-in secure. They are set by our authentication library and are all first-party:

  • A session cookie, which is what keeps you signed in. If you tick "keep me signed in" it lasts 30 days; if you do not, it lasts 24 hours.
  • A CSRF token cookie, which protects the sign-in form from being submitted from another site on your behalf.
  • A short-lived callback-URL cookie, so that signing in returns you to the page you started from.

There are no analytics, advertising or preference cookies. Your light/dark choice is deliberately not a cookie — it is kept in your browser's own storage (see above) precisely so it is never transmitted to us with your requests. That is why you are not asked to accept cookies here: there is nothing optional to accept, and a banner offering a choice that does not exist would be misleading. Signing out clears the session cookie.

Starting a Premium purchase loads Razorpay's own checkout script and opens its payment sheet. Anything it sets while that sheet is open is set on Razorpay's own domain under Razorpay's own policy, not by us — we do not control it and it is not part of our own cookie list above.

6. Signing in with Google

"Continue with Google" is optional, and it is only offered when we have configured it. If it is not configured, the button is shown disabled and nothing at all is sent to Google — the credentials for it simply are not present in the running application.

When you do use it, Google tells us your email address and, if your Google profile has one, your name. That is all we ask for and all we receive: no contacts, no calendar, no files, and never your Google password. We match the email address against any existing Examoji account and treat it as the same person, and we mark the address as verified, because Google has already confirmed it.

Google's own handling of that sign-in is covered by Google's privacy policy, not ours.

7. Email we send you

There are exactly three emails this site can send, and all three are ones you asked for:

  • A welcome and verification email when you register, containing a link that confirms your address. The link expires after 24 hours.
  • A password reset email, when you ask to reset your password. It shows the address it was sent to and contains a single-use link that expires after 30 minutes.
  • A sign-in code email, if you choose "email me a code" instead of typing your password. It contains a 6-digit code, good for 10 minutes and for five attempts, after which you would need to request a fresh one.

There is no newsletter, no promotional email and no digest. There is nothing to unsubscribe from, because we do not have a list.

8. Who else can see your data

We do not share your data with anyone for their own purposes. A small number of service providers process it on our behalf, purely to run the site:

  • Our hosting provider (Vercel), which runs the application and therefore handles the network requests your browser makes.
  • Our database provider (Supabase), which hosts the PostgreSQL database everything in the table above is stored in.
  • Our email provider (Resend), which delivers the three emails above. It receives your email address and the contents of those messages, and nothing else.
  • Our payment processor (Razorpay), if you start a Premium purchase. Razorpay receives your email address (so its checkout screen can be pre-filled rather than asking you to retype it), the amount and currency of the order, and — directly from you, never through us — whatever card, UPI or netbanking details you enter to actually pay. Razorpay reports back to us only the order id, the payment id, and whether the payment was captured; it does not report your card or bank details back to us either. Razorpay is an RBI-regulated Indian payment aggregator and handles that data under its own privacy policy and PCI-DSS obligations, not ours.
  • An error-monitoring service, if one is configured for the environment you are using. It receives crash reports as described in the next section. When none is configured, error reports stay in our own server logs.

Inside Examoji, administrators can look up an account to help with support and to grant or remove paid access. What that internal tool shows is an account's email address, name, whether the address is verified, its access grants, and how much of the free allowance has been used. It does not show passwords — we do not have them — and it is not used for anything other than support and access management.

9. Error logs

When something goes wrong on the server we record the error so we can fix it. Those records contain the name of the operation that failed, the error message and its technical stack trace, and internal identifiers — for example an account id or a test-attempt id.

They deliberately do not contain your answers, anything you wrote in a writing task, your password, or your email address.

10. How long we keep things

  • Your account and your practice history are kept for as long as your account exists. Your history is the product — deleting last month's attempts would delete your progress — so there is no automatic expiry on it.
  • Verification, password-reset and sign-in-code tokens stop working after 24 hours, 30 minutes and 10 minutes respectively, and after a single use. The (hashed) record of a used or expired token stays in the database until the account is deleted.
  • Abuse counters reset when their time window passes, and a login counter is cleared as soon as you sign in successfully. We want to be straightforward about a limitation here: there is no scheduled job that purges old counter rows today, so an unused row containing an IP-derived key can persist until it is next reused or manually cleared.
  • Your payment order records (amount, status, Razorpay's order id) are kept for as long as your account exists, like the rest of your history, and are deleted with it. The underlying ledger of Razorpay payment notifications we received is not tied to any account and is not deleted by an account deletion — it is a payment-processing audit trail, not personal data about you specifically.

11. How your data is protected

  • Passwords are stored only as bcrypt hashes. Nobody at Examoji can read your password, and we cannot tell it to you if you forget it — only reset it.
  • Verification links, reset links and sign-in codes are stored only as a hash, are single-use, and expire.
  • Repeated failed sign-in attempts are rate-limited both per account and per IP address, so a password cannot be guessed by brute force.
  • The site is served over HTTPS in production, so traffic between your browser and us is encrypted in transit.
  • A Razorpay payment notification is only ever acted on after we verify its cryptographic signature ourselves — an unsigned or incorrectly signed request granting Premium access is rejected outright, not trusted.

Encryption of the database at rest, backups and physical security are provided by our database and hosting providers under their own security practices.

No system is perfectly secure, and we would rather say so than claim otherwise. If you believe you have found a security problem, please email us at support@examoji.com before disclosing it publicly.

12. Seeing, correcting or deleting your data

Most of what we hold about you is already visible to you while signed in: your dashboard shows your attempts, scores and progress, and review mode shows every answer you gave.

To get a copy of your data, correct it, or have your account deleted, email support@examoji.com from the address on the account. We are being deliberately plain about this: there is no self-service export or delete button on the site yet, so these requests are handled by hand.

Deleting an account removes the account record together with everything attached to it — your practice attempts and answers, your study-goal profile, our ability estimates, your feedback reports, your access grants, your payment order records, and your sign-in tokens. That is a cascading delete in the database, not a flag: the rows go. The one exception is the payment-notification ledger described above, which isn't linked to your account in the first place and survives it — nothing in it identifies you by name or email once it is no longer connected to a live order.

13. Age

Examoji is built for people preparing for an English-language proficiency exam, which in practice means adults and older teenagers. We do not ask for your date of birth and we have no way to verify anyone's age. If you are a parent or guardian and believe a child has created an account, email us and we will delete it.

14. Changes to this policy

If what the product does with your data changes, this page changes with it and the "last updated" date at the top moves. For a change that materially affects you — a new category of data, or a new provider handling it — we will tell you by email rather than relying on you noticing the date.

15. Contact

Questions about this policy, or about your data, go to support@examoji.com. The rules for using the service itself are in our Terms of Service.