Last updated · June 2026
Privacy Policy
We collect the minimum needed to give you CEFR-grade feedback and track your trajectory. Here’s exactly what we store, why, and how to take it back.
1. What we collect
- Account data — name, email, CEFR target, hashed password (or Google OAuth identifier).
- Practice data — your mock answers, essay text, speaking recordings, and the AI feedback we produced from them.
- Usage data — anonymous events (page views, feature usage) for product analytics, plus standard request metadata (IP, user-agent) for security and abuse prevention.
- Billing data — payment provider transaction IDs and amounts (we never see your card numbers — those stay with Stripe, Click, or Payme).
2. How we use it
To run the service: authenticate you, store your test attempts, generate AI feedback, charge you for paid plans, and surface your progress in the dashboard. Aggregated, anonymised usage data helps us improve scoring accuracy.
3. AI processing
Writing and speaking submissions are sent to Google’s Gemini API for examiner-grade scoring. The data is not used to train any third-party model. We do not sell or share your content with anyone else.
4. Sharing
We share data only with the processors required to run the service: our application backend and database (hosting your account, test, and feedback data), Amazon S3 (private buckets holding audio and image files only, never publicly readable), Vercel (hosting), Google (AI feedback), and your chosen payment provider. Each is bound by data-processing terms equivalent to or stricter than this policy.
5. Retention
Account and test data stays as long as your account is active. When you delete your account from account settings, every row tied to your user id is removed within 30 days and your recordings and uploaded images are deleted from file storage as part of that same deletion, except records we’re legally required to keep (e.g. invoice metadata for tax purposes).
6. Your rights
You can download a full JSON export of your account data at any time from account settings and delete your account from the same page. To exercise any other GDPR right (rectification, restriction, objection, portability): Message us on Telegram.
7. Security
Connections to Vantage use HTTPS with HSTS. Passwords are hashed server-side by our authentication service. Elevated (service-role / admin) access is scoped to server-side code and never exposed to the browser. We audit dependencies regularly.
8. Cookies
We use a small number of essential cookies for session management, plus optional product-analytics cookies that you’ll be asked about before they’re set.
9. Children
Vantage isn’t directed at children under 13. If you’re a parent or guardian and believe your child has registered, Message us on Telegram and we’ll remove the account.
10. Changes
Material changes will be announced 14 days before they take effect via the email tied to your account.