← Back to Home

Privacy Policy

Last updated: November 28, 2025

1. Introduction

IELTS EQ ("we," "our," or "us") respects your privacy. This Privacy Policy explains how we collect, use, and protect your personal information when you use our Service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address (via Google OAuth)
  • Audio Recordings: Your voice recordings for speaking practice
  • Test Responses: Written transcripts and AI analysis of your performance
  • Support Tickets: Information you provide when contacting support

2.2 Automatically Collected Information

  • Usage Data: Test history, vocabulary progress, pronunciation scores
  • Technical Data: IP address, browser type, device information
  • Session Data: Authentication tokens (managed by NextAuth)

3. How We Use Your Information

We use your information to:

  • Provide and improve the Service
  • Analyze your speaking performance using AI (OpenAI)
  • Track your learning progress
  • Communicate with you about your account
  • Provide customer support
  • Ensure security and prevent fraud

4. Data Storage and Security

Audio Storage: Your audio recordings are stored securely on AWS S3 with encryption.

Database: Your account data and test history are stored in a PostgreSQL database (Neon) with SSL encryption in transit.

Security Measures: We implement industry-standard security practices including:

  • Encrypted connections (HTTPS/SSL)
  • Secure authentication (Google OAuth)
  • Access controls and role-based permissions
  • Regular security audits

5. Third-Party Services

We use the following third-party services:

  • Google OAuth: For authentication (Google Privacy Policy applies)
  • OpenAI: For AI-powered feedback (OpenAI Privacy Policy applies)
  • AWS S3: For secure audio file storage
  • Resend: For transactional emails
  • Vercel: For hosting and analytics

Each service has its own privacy policy. We recommend reviewing them.

6. Data Sharing

We do NOT sell your personal data. We may share data only:

  • With service providers necessary to operate the Service (AWS, OpenAI, etc.)
  • If required by law or legal process
  • To protect our rights or the safety of users
  • With your explicit consent

7. Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update or correct your information
  • Deletion: Request deletion of your account and data
  • Export: Download your test history and recordings

To exercise these rights, contact us through the support section in your dashboard.

8. Data Retention

We retain your data while your account is active. If you delete your account:

  • Personal information is deleted within 30 days
  • Audio recordings are permanently removed from AWS S3
  • Anonymized usage statistics may be retained for analytics

9. Cookies and Tracking

We use essential cookies for:

  • Authentication (NextAuth session cookies)
  • Security and fraud prevention

We do not use third-party advertising cookies. Essential cookies do not require consent under GDPR.

10. Children's Privacy

The Service is not intended for users under 13 years old. We do not knowingly collect information from children under 13. If we learn we have collected such data, we will delete it promptly.

11. International Data Transfers

Your data may be processed in countries outside your residence (e.g., US for AWS, OpenAI). We ensure appropriate safeguards are in place for such transfers.

12. Changes to This Policy

We may update this Privacy Policy. We will notify you of significant changes via email or a notice on the Service.

13. Contact Us

For privacy-related questions or to exercise your rights, contact us through the support section in your dashboard.