Privacy Policy
Last Updated: January 12, 2025
Introduction
BAND9AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered IELTS mock testing platform and related services (the "Service").
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you disagree with our policies and practices, please do not use our Service.
Information We Collect
Personal Information
We collect the following personal information when you use our Service:
- Name: First and last name for account creation and identification
- Email Address: For account verification, communication, and support
- Payment Information: Processed securely through Stripe (we do not store payment details)
- Access Codes: Unique passcodes for test authentication
Test Data
During your use of our IELTS mock tests, we collect:
- Test Responses: Your answers to listening, reading, writing, and speaking questions
- Audio Recordings: Voice recordings from speaking tests for AI analysis and grading
- Session Data: Test timestamps, completion rates, and performance metrics
- Usage Analytics: Test section preferences, time spent, and navigation patterns
Technical Information
We automatically collect certain technical information:
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP addresses, access times, pages viewed, and referral URLs
- Session Information: Unique session identifiers and security tokens
- Performance Data: Error logs and system performance metrics
How We Use Your Information
We use the collected information for the following purposes:
Service Provision
- Provide and maintain our IELTS mock testing platform
- Generate personalized test content using AI technology
- Grade your tests and provide detailed feedback
- Track your progress and performance across test sessions
- Enable audio processing for speaking test evaluation
Communication
- Send you access codes and test confirmations
- Provide customer support and respond to inquiries
- Send important updates about our Service
- Notify you of system maintenance or technical issues
Improvement and Development
- Analyze usage patterns to improve our AI algorithms
- Enhance test content quality and relevance
- Develop new features and functionalities
- Ensure platform security and prevent fraud
Third-Party Services
We integrate with the following third-party services to provide our platform:
- Stripe: Payment processing (credit card information is processed directly by Stripe and not stored by us)
- Mistral AI: AI model services for content generation and test grading (may process your test responses and transcripts)
- Google Speech Recognition: Speech-to-text conversion for speaking test analysis
- Zoho SMTP: Email delivery services for notifications and support
These third-party services have their own privacy policies. We recommend reviewing their privacy practices as we are not responsible for their data handling procedures.
Data Storage and Security
Test Session Data
Important: All tests must be completed in one sitting. Test progress is stored in temporary browser sessions only. If you exit your browser, close the page, refresh, or navigate away during a test, your progress will be lost and you may need to restart. We are not responsible for data loss due to browser issues, connectivity problems, or user actions that interrupt test sessions.
Access Code Usage Window
3-Hour Access Window: Access codes remain valid for 3 hours from the moment you first use them to start a test session. During this window, you can log back in with the same access code if you experience internet disconnection or browser issues. This allows you to continue or restart your test within the time limit. After 3 hours, the access code expires and cannot be reused. Your session data and test progress are retained only within this 3-hour window.
Storage
Your data is stored:
- On secure servers with encryption at rest and in transit
- In JSON files and MySQL databases with access controls
- In temporary session files that are automatically cleaned up
- In audio files that are processed and then securely deleted
Security Measures
We implement industry-standard security measures including:
- SSL/TLS encryption for all data transmission
- Secure session management with unique identifiers
- Regular security audits and vulnerability assessments
- Access controls and authentication mechanisms
- Data backup and disaster recovery procedures
Data Retention
We retain your information for the following periods:
- Access Codes: Valid for 3 hours from first use, then permanently expired
- Active Session Data: Retained for 3 hours during access window, then deleted
- Account Information: Until account deletion or 2 years of inactivity
- Test Data: 1 year from last test session for progress tracking
- Audio Recordings: Processed immediately and deleted within 30 days
- Session Logs: 90 days for security and troubleshooting
- Payment Records: As required by law and payment processor policies
Your Privacy Rights
Depending on your location, you may have the following rights:
- Access: Request access to your personal information
- Correction: Request correction of inaccurate personal information
- Deletion: Request deletion of your personal information
- Portability: Request a copy of your data in a portable format
- Objection: Object to certain uses of your personal information
- Restriction: Request restriction of processing in certain circumstances
To exercise these rights, please contact us at band9ai@gmail.com with your request and access code for verification.
Children's Privacy
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure appropriate safeguards are in place to protect your information during such transfers.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: band9ai@gmail.com
- Subject Line: Privacy Policy Inquiry - [Your Access Code]
- Response Time: We will respond within 72 hours
For data protection inquiries, please include your access code in the subject line to help us locate your information quickly and securely.