Legal
Privacy Policy
Last updated: April 6, 2025
CEFR AI ("we", "our", or "us") operates the website cefrai.uz and provides AI-powered English exam preparation services. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
By using CEFR AI you agree to the practices described in this policy. If you do not agree, please stop using the service.
1Information We Collect
Account Information
When you register, we collect your first name, email address, and a hashed password. If you sign in with Google, we receive your name, email, and profile picture from Google.
Usage Data
We record your test attempts, scores, AI-graded feedback, and practice session history. This is used to show you your progress and generate your dashboard statistics.
Payment Information
When you subscribe, we collect a screenshot of your bank transfer receipt. We do not store your card number. Screenshots are used solely to verify your payment and are retained for fraud prevention. A cryptographic hash (SHA-256) of each screenshot is stored to detect duplicate submissions.
Technical Data
We automatically collect your IP address, browser type, and pages visited for security and performance monitoring. We do not use this data for advertising.
2How We Use Your Information
- To create and manage your account
- To grade your writing and speaking tests using AI
- To activate and manage your subscription
- To detect and prevent fraudulent payment submissions
- To show you your learning progress and achievements
- To send important service notifications (e.g. subscription expiry)
- To improve the quality of our tests and AI grading
We do not sell your personal data to third parties. We do not use your data for targeted advertising.
3Third-Party Services
We use the following third-party services to operate CEFR AI:
| Service | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude AI) | AI grading of writing & speaking tests; payment screenshot verification | Test responses, payment screenshots |
| Vercel | Website hosting and deployment | Request logs, IP addresses |
| PostgreSQL (Neon) | Database storage | All user data listed above |
| Google OAuth | Optional sign-in with Google | Name, email (if you choose Google login) |
| Telegram | Optional support channel | Only what you send voluntarily |
Each third party has its own privacy policy. We choose providers that maintain appropriate data security standards.
4Data Retention
- Account data — kept for as long as your account is active.
- Test results and feedback — kept indefinitely to show your progress history.
- Payment screenshots — kept for 2 years for fraud prevention, then deleted.
- Rejected/blocked submissions — kept for audit trail; the screenshot image is not stored, only the hash.
You may request deletion of your account and associated data at any time (see Section 6).
5Cookies
We use a single session cookie (next-auth.session-token) to keep you logged in. This is a strictly necessary cookie and does not track you across other websites. We do not use advertising or analytics cookies.
6Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate information.
- Deletion — request that we delete your account and personal data.
- Objection — object to how we process your data in certain circumstances.
To exercise any of these rights, contact us at the address below. We will respond within 30 days.
7Security
We take reasonable technical measures to protect your data: passwords are hashed and never stored in plain text, all data is transmitted over HTTPS, and database access is restricted. No system is 100% secure — if you believe your account has been compromised, contact us immediately.
8Children
CEFR AI is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
9Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top. Continued use of CEFR AI after changes are posted constitutes your acceptance of the updated policy.
10Contact
If you have questions about this Privacy Policy or your personal data, please contact us: