Skip to content

Last updated · June 2026

Privacy Policy

We collect the minimum needed to give you CEFR-grade feedback and track your trajectory. Here’s exactly what we store, why, and how to take it back.

1. What we collect

  • Account data — name, email, CEFR target, hashed password (or Google OAuth identifier).
  • Practice data — your mock answers, essay text, speaking recordings, and the AI feedback we produced from them.
  • Usage data — anonymous events (page views, feature usage) for product analytics, plus standard request metadata (IP, user-agent) for security and abuse prevention.
  • Billing data — payment provider transaction IDs and amounts (we never see your card numbers — those stay with Stripe, Click, or Payme).

2. How we use it

To run the service: authenticate you, store your test attempts, generate AI feedback, charge you for paid plans, and surface your progress in the dashboard. Aggregated, anonymised usage data helps us improve scoring accuracy.

3. AI processing

Writing and speaking submissions are sent to Google’s Gemini API for examiner-grade scoring. The data is not used to train any third-party model. We do not sell or share your content with anyone else.

4. Sharing

We share data only with the processors required to run the service: our application backend and database (hosting your account, test, and feedback data), Amazon S3 (private buckets holding audio and image files only, never publicly readable), Vercel (hosting), Google (AI feedback), and your chosen payment provider. Each is bound by data-processing terms equivalent to or stricter than this policy.

5. Retention

Account and test data stays as long as your account is active. When you delete your account from account settings, every row tied to your user id is removed within 30 days and your recordings and uploaded images are deleted from file storage as part of that same deletion, except records we’re legally required to keep (e.g. invoice metadata for tax purposes).

6. Your rights

You can download a full JSON export of your account data at any time from account settings and delete your account from the same page. To exercise any other GDPR right (rectification, restriction, objection, portability): Message us on Telegram.

7. Security

Connections to Vantage use HTTPS with HSTS. Passwords are hashed server-side by our authentication service. Elevated (service-role / admin) access is scoped to server-side code and never exposed to the browser. We audit dependencies regularly.

8. Cookies

We use a small number of essential cookies for session management, plus optional product-analytics cookies that you’ll be asked about before they’re set.

9. Children

Vantage isn’t directed at children under 13. If you’re a parent or guardian and believe your child has registered, Message us on Telegram and we’ll remove the account.

10. Changes

Material changes will be announced 14 days before they take effect via the email tied to your account.