Data Privacy Act notice · Pilot draft

Privacy Policy

CrimForge is in its pilot period. This notice explains how we handle your data today; it will be finalized with our Data Protection Officer before public launch.

Data we collect

  • Account information you provide when you sign up: your name, email address, and school if you share it.
  • Study activity on your account: practice and mock exam attempts, answers, scores, and the readiness analytics computed from them.
  • Basic device and usage events that keep the service secure and working, such as sign-in records and error diagnostics.
  • Most study state (streaks, focus rounds, saved items, reading progress) lives in your browser's local storage on your device, and you can export or clear it from Settings.

Why we process it

  • To operate your account and sign you in securely.
  • To personalize your review: readiness scoring, weakness targeting, spaced review scheduling, and study recommendations.
  • To keep the service secure, debug problems, and improve question quality.
  • For institutional pilots, to show participating faculty aggregate section progress. Individual data is only shared with your school under a pilot agreement you are informed of.

Lawful basis

  • We process your data based on the consent you give at sign-up and, for core account features, because processing is necessary to provide the service you asked for. You can withdraw consent at any time through a data-subject request.

Retention

  • Account and study records are kept while your account is active. When a verified deletion request is processed, hosted records are removed except where a legal obligation requires keeping them.
  • Final retention schedules per record category will be published here before public launch.

Third-party processors

  • CrimForge runs on Supabase (database and authentication) and Vercel (hosting). Both act as processors of account data under their standard security and data-processing terms.

Your rights under RA 10173

  • You may request access, correction, objection, erasure or blocking, portability, and lodge complaints under the Data Privacy Act of 2012.
  • File a request from Settings, under Privacy, using the data-rights request queue. We verify your identity first, and respond within 15 working days of verification.

Minors and parental or guardian consent

  • If you are under 18, your parent or guardian must be aware of your account. We ask for this acknowledgment at sign-up.
  • A guardian may exercise data-subject rights on a minor's behalf through the same request queue.

Data Protection Officer

  • The designated Data Protection Officer and direct contact channel will be published here before public launch.
  • Until then, data-subject requests are received through the in-app request queue in Settings, under Privacy, and handled on the same verification and response timeline.