Legal

Privacy Policy

Last updated: April 6, 2025

CEFR AI ("we", "our", or "us") operates the website cefrai.uz and provides AI-powered English exam preparation services. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

By using CEFR AI you agree to the practices described in this policy. If you do not agree, please stop using the service.

1Information We Collect

Account Information

When you register, we collect your first name, email address, and a hashed password. If you sign in with Google, we receive your name, email, and profile picture from Google.

Usage Data

We record your test attempts, scores, AI-graded feedback, and practice session history. This is used to show you your progress and generate your dashboard statistics.

Payment Information

When you subscribe, we collect a screenshot of your bank transfer receipt. We do not store your card number. Screenshots are used solely to verify your payment and are retained for fraud prevention. A cryptographic hash (SHA-256) of each screenshot is stored to detect duplicate submissions.

Technical Data

We automatically collect your IP address, browser type, and pages visited for security and performance monitoring. We do not use this data for advertising.

2How We Use Your Information

  • To create and manage your account
  • To grade your writing and speaking tests using AI
  • To activate and manage your subscription
  • To detect and prevent fraudulent payment submissions
  • To show you your learning progress and achievements
  • To send important service notifications (e.g. subscription expiry)
  • To improve the quality of our tests and AI grading

We do not sell your personal data to third parties. We do not use your data for targeted advertising.

3Third-Party Services

We use the following third-party services to operate CEFR AI:

ServicePurposeData shared
Anthropic (Claude AI)AI grading of writing & speaking tests; payment screenshot verificationTest responses, payment screenshots
VercelWebsite hosting and deploymentRequest logs, IP addresses
PostgreSQL (Neon)Database storageAll user data listed above
Google OAuthOptional sign-in with GoogleName, email (if you choose Google login)
TelegramOptional support channelOnly what you send voluntarily

Each third party has its own privacy policy. We choose providers that maintain appropriate data security standards.

4Data Retention

  • Account data — kept for as long as your account is active.
  • Test results and feedback — kept indefinitely to show your progress history.
  • Payment screenshots — kept for 2 years for fraud prevention, then deleted.
  • Rejected/blocked submissions — kept for audit trail; the screenshot image is not stored, only the hash.

You may request deletion of your account and associated data at any time (see Section 6).

5Cookies

We use a single session cookie (next-auth.session-token) to keep you logged in. This is a strictly necessary cookie and does not track you across other websites. We do not use advertising or analytics cookies.

6Your Rights

You have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate information.
  • Deletion — request that we delete your account and personal data.
  • Objection — object to how we process your data in certain circumstances.

To exercise any of these rights, contact us at the address below. We will respond within 30 days.

7Security

We take reasonable technical measures to protect your data: passwords are hashed and never stored in plain text, all data is transmitted over HTTPS, and database access is restricted. No system is 100% secure — if you believe your account has been compromised, contact us immediately.

8Children

CEFR AI is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top. Continued use of CEFR AI after changes are posted constitutes your acceptance of the updated policy.

10Contact

If you have questions about this Privacy Policy or your personal data, please contact us:

CEFR AI

Tashkent, Uzbekistan

Email: mboltaboev@gmail.com

Website: cefrai.uz