Privacy Policy
How Xophal handles student data.
What this app actually collects
Xophal is a learning and mock-test platform. We collect only the information needed to create and maintain an account, provide study features, and keep the platform secure and usable.
1. Account and profile information
- Name and email address used for sign-in and account communication.
- Phone number if entered in profile or admin workflows.
- Board and class selections used to personalise learning and mock-test access.
- Role and account status used to manage student and admin access.
2. Test and learning data
- Test attempts, started and submitted timestamps, and timing metadata.
- Responses, bookmarks, review flags, and score details for result tracking.
- Notifications and message history related to test results, reminders, and platform updates.
3. Authentication and technical data
- Authentication data managed by Supabase Auth, including email verification and session state.
- Server and application logs used for reliability, security, and abuse prevention.
- Rate-limiting and cache data used by the platform to protect endpoints and reduce abuse.
4. How the data is used
We use this data to sign users in, keep profiles accurate, show personalised study paths, record mock-test performance, send notifications, and protect the platform from misuse. This site does not sell personal information for advertising purposes.
5. Third-party services used by the platform
- Supabase is used for authentication, database storage, and session-related services.
- Upstash Redis is used for rate limiting and short-lived cache data when configured.
- When payment workflows are enabled, a configured payment provider such as Razorpay may process payment-related records.
This project does not currently use a separate web analytics provider for public website analytics.
6. Cookies and session handling
The site uses authentication cookies and session state to keep users signed in and to support secure access to protected pages. Browser settings can disable or restrict cookies, but some platform features may not work correctly without them.
7. Retention and deletion
Account and test data are stored in the application database as long as the account remains active or until an administrator removes records. The codebase does not currently include an automated self-service account deletion workflow, so deletion requests should be handled manually through support.
8. Your rights and requests
You can review and update profile details from the account profile area. If you need help with account access, a data question, or a support request, contact xophal123@gmail.com. We will respond as needed and can explain the limits of the current implementation without promising automated deletion or bulk export features that are not yet built.
9. Security
We use standard application and platform safeguards to protect user accounts and stored data. No system is completely immune to compromise, which is why users should use a strong password and avoid sharing credentials.