Legal

Privacy Policy

Exactly what we collect, every company we send it to, how long we keep it, and how to get it back or have it erased.

Last updated: 12 September 2026

This Privacy Policy explains how IELTSVega handles your personal data when you use www.ieltsvega.com. We are the data fiduciary under India's Digital Personal Data Protection Act, 2023 and the data controller under the UK and EU GDPR. It is written to be read rather than survived: if anything here is unclear, email hello@ieltsvega.com and we will explain it.

1. The short version

  • We collect what an account needs, what practice produces, and what keeps the account secure. Nothing for advertising.
  • Your essays go to one AI provider and your Speaking recordings to another, to be scored. Nobody else receives them.
  • We use Google Analytics and Microsoft Clarity, and Clarity records how a pointer moves through our pages. You can switch both off without losing anything.
  • We never sell your data, never give it to advertisers, and never train our own models on your answers.
  • One email — hello@ieltsvega.com — gets you a copy of your data, a correction, or permanent deletion.

2. Data we collect

Everything below is either given by you, produced by your use of the Service, or recorded automatically for security. We collect no special-category data, and we ask for no identity document or photograph.

2. Data we collect
CategoryWhat it includesWhy we hold it
AccountName, email address, whether that email is verified, contact phone number, and either a bcrypt hash of your password or your Google account identifier if you use Sign in with Google. We never hold the password itself.To create and secure your account, and to contact you about it.
Study profileTarget module (Academic or General Training), target band, planned exam date, country, profile picture. All optional except the module.To show the right content, price in your currency, and pace your preparation.
Practice contentYour written answers, your Speaking audio recordings, the transcripts made from them, your Reading and Listening responses, the AI band estimates, the criterion-by-criterion feedback, and your attempt and mock test history.To score your work, show your history and track progress. This is the Service.
BillingPlan, term expiry, your Razorpay customer identifier, and a ledger row per payment — amount, currency, status, timestamps. Card and UPI details go straight to Razorpay; we never see or store them.To give you the plan you bought, and to keep lawful books of account.
Security and auditIP address and browser user-agent at sign-in and per session, sign-in and sign-out events, failed-attempt counts and temporary lock state, password change times, and a deactivation reason if an account is disabled.To detect and stop unauthorised access and abuse, and to show you your own active sessions.
Usage analyticsPages viewed, features used, device, approximate city-level location derived from IP, and — through Microsoft Clarity — a replay of pointer movement, clicks and scrolling on our pages.To find where the Service confuses people, and fix it.

4. How we use it

  • Provide practice, mock tests, AI band scoring and criterion feedback.
  • Maintain your account, history, progress reports and active sessions.
  • Take payment, manage renewals and cancellations, and handle refunds.
  • Send service email you cannot opt out of while you hold an account: email verification, password reset and change notices, receipts, and notices about your subscription or these policies.
  • Send study tips and product news only if you asked for them. Every such email carries an unsubscribe link.
  • Answer your support messages.
  • Detect, investigate and stop abuse, scraping, account sharing and fraud.
  • Understand in aggregate which parts of the Service work, and repair the parts that do not.

We make no decision about you by purely automated means that has a legal or similarly significant effect. An AI band estimate affects nothing but your own practice, and no automated score is used to deny you the Service. Deactivation for repeated rate-limit abuse is automated but reversible — write to us and a person will review it.

5. Who we share it with

We do not sell personal data, and we share none of it with advertisers or data brokers. We use the providers below to run the platform. Each processes data only on our instructions, for the purpose named, under its own data processing terms.

5. Who we share it with
ProviderWhat it processesWhere
Vercel Inc.Hosts and serves the application. Every request passes through it, so it processes your IP address and request metadata in transit.United States, and its global edge network
Neon Inc. (managed PostgreSQL)The database of record: account, study profile, answers, transcripts, scores, billing ledger and audit log.United States
Amazon Web Services (S3)Stores your Speaking audio recordings in a private bucket, reachable only by short-lived presigned link.United States (us-east-1)
Automated speech evaluation providerReceives a presigned link to a single Speaking recording, transcribes it, and returns pronunciation, fluency and band assessment. The audio is fetched straight from storage and does not pass back through our servers.Outside India
Automated writing evaluation providerReceives your Writing Task 1 and Task 2 answers and returns a band estimate with criterion feedback. Sent over an API whose inputs the provider does not use to train its models.United States
Razorpay Software Private LimitedTakes payment and runs subscriptions. Receives your name, email, phone and payment instrument, which it — not we — stores.India
Google LLC (Sign in with Google)When you choose it, Google confirms your identity and passes us your name, email address and account identifier.United States
Google Analytics 4 (Google LLC)Aggregate usage analytics: pages, events, device, approximate location from IP.United States
Microsoft Clarity (Microsoft Corporation)Session replay and heatmaps: pointer movement, clicks and scrolling on our pages.United States
Email delivery provider (SMTP)Delivers transactional email — verification, password reset, receipts, service notices.Varies by provider

We may also disclose data where the law compels it, to establish or defend a legal claim, or to a successor in a merger or acquisition — in which case this policy continues to apply to it. We will tell you before any such transfer takes effect.

6. Cookies

A cookie is set on this site for one of three reasons: to keep you signed in, to finish a sign-in or a payment you started, or — for the two analytics tools — to count and replay visits. We run no advertising, retargeting or cross-site tracking cookies, and no ad network has a tag on this site.

6. Cookies
CookieSet byPurposeLifetime
__Host-ielts_sessionUs — strictly necessaryKeeps you signed in. Holds a random opaque token, of which only a SHA-256 hash is stored on our servers, so the cookie cannot be reconstructed from our database. HttpOnly, Secure, SameSite=Lax, and carries the __Host- prefix so no subdomain or script can reach it.Expires after 7 days unused, and always after 30 days. Cleared on sign-out.
g_oauth_stateUs — strictly necessaryWritten only when you choose Sign in with Google, and only for the length of that redirect. It holds a random value that Google hands back to us, which is how we know the sign-in returning to us is the one you started rather than a forged request. HttpOnly, and says nothing about you.10 minutes
_ga, _ga_*Google AnalyticsDistinguishes visitors and sessions for aggregate reporting.Up to 2 years
_clck, _clsk, CLID, ANONCHK, MR, SMMicrosoft ClarityTies a session replay and heatmap data to a returning browser.1 day to 1 year, depending on the cookie
Razorpay checkout cookiesRazorpaySet on razorpay.com rather than on this site, when the payment window opens. They carry your checkout session and Razorpay's own fraud checks, and are governed by Razorpay's privacy policy, not this one. The checkout script loads only when you start a payment — it is on no other page of the site.Set and controlled by Razorpay
  • To refuse the analytics cookies: block third-party cookies or add an exception for this site in your browser settings, use a content blocker, or install Google's official Analytics opt-out add-on. Nothing about the Service changes if you do.
  • The two strictly-necessary cookies cannot be refused while you are signing in or signed in — sign out, or browse without an account, to be rid of them. Neither carries any information about you: one is a random token, the other a random anti-forgery value.
  • We honour Global Privacy Control and Do Not Track signals where the provider supports them, and in any case we do not use cookies to build an advertising profile of you.

7. Data kept in your browser

Separately from cookies, the Service keeps a few things in your own browser's local and session storage. These are not cookies: they are never attached to a request, never sent to us, and cannot be read from our servers. Clearing your browser's data for this site removes all of them.

7. Data kept in your browser
What is storedWhyKept until
Your draft answers to a practice setSo that a refresh, a dropped connection or a closed tab does not cost you work you have already typed.The set is submitted, or you clear site data
The page of a set you last had openSo you resume where you stopped instead of at the beginning.You clear site data
Your exam text sizeSo the reading size you chose persists between sittings.You clear site data
Your Listening playback volumeSo audio starts at the level you last set.You clear site data
The position of the passage/questions dividerSo the split you dragged in the exam view is still there next time.You clear site data
Whether the opening animation has playedSo it does not replay on every page you visit.You close the tab

Your unsubmitted drafts sit in your own browser, not on our servers. On a shared or public computer, sign out and clear the site's data when you finish — that is what removes them.

8. International transfers

Most providers above operate in the United States, so your data is transferred out of India and, if you are in the EEA or UK, out of those areas. We rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) or the provider's certification under the EU–US Data Privacy Framework, together with encryption in transit and at rest, and we send only what each provider needs to do its job.

Ask us and we will tell you which safeguard covers a specific provider.

9. If an institution created your account

Some candidates are enrolled by a coaching centre, school or agent holding a partner account that pays for their access. If yours was, that institution can see your name, email address, phone number, how many attempts you have made and your band scores, and it can create or suspend your access. It cannot listen to your Speaking recordings or read your individual answers.

We act on the institution's instructions for the enrolment itself, and the institution is responsible for having told you it was enrolling you. If you would rather it did not see your results, ask us to detach the account: it becomes an ordinary personal account and keeps your history.

10. How long we keep it

10. How long we keep it
DataKept for
Account, study profile, practice answers, recordings, transcripts and scoresAs long as your account exists. Deleted when you ask us to delete the account.
Sign-in sessionsExpire automatically after 7 days idle or 30 days absolute, whichever comes first. Deleted at once on sign-out or when you revoke a session.
Email verification and password reset tokensSingle use, expiring shortly after being issued, and stored only as a hash.
Security and audit eventsUp to 12 months, so unauthorised access can be investigated; then deleted.
Payment ledger and invoicesAs long as tax and accounting law requires books of account to be kept — up to 8 years in India. These rows survive account deletion because the law requires it, reduced to what a record of payment needs.
Analytics and session replayPer the provider's own retention: up to 14 months in Google Analytics, up to 30 days in Microsoft Clarity.

Encrypted backups roll over on their own schedule, so deleted data can persist in a backup for a short period after deletion, until it is overwritten.

11. Your rights

Wherever you live, we honour the following. Email hello@ieltsvega.com from your account address; we reply within 30 days, and charge nothing.

  • Access — a copy of the personal data we hold about you, including your practice history.
  • Correction — fix anything inaccurate. Most of it you can edit yourself in Settings.
  • Erasure — permanent deletion of your account, answers, recordings and scores. We will tell you what we must keep for tax purposes, and why.
  • Portability — your data in a machine-readable format.
  • Withdraw consent — switch off analytics, marketing email or optional profile fields at any time.
  • Object or restrict — ask us to stop or limit processing that rests on our legitimate interests.
  • Nominate — under the DPDP Act, name someone to exercise these rights for you if you die or become incapable of exercising them.
  • Complain — to us first, please; and to your data protection authority if we fail you, whether that is the Data Protection Board of India, the UK Information Commissioner's Office, or your EEA supervisory authority.

Deletion is irreversible. Once your practice history and recordings are erased we cannot bring them back, so export anything you want to keep before you ask.

12. Security

  • Passwords are stored only as bcrypt hashes, never in plain text or any reversible form.
  • Session tokens are random, opaque, stored only as SHA-256 hashes, carry both an idle and an absolute expiry, and can be revoked.
  • All traffic is served over HTTPS, under a strict Content Security Policy with a per-request nonce.
  • Speaking recordings sit in a private bucket and are reachable only through short-lived presigned links.
  • Repeated failed sign-ins lock an account temporarily, rate limits cap how fast any account can be used, and security-relevant events are logged.
  • Access to production data is limited to those who need it.

No system is perfectly secure and we do not claim otherwise. If a breach affects your personal data we will notify you and the relevant authority as the law requires — under the DPDP Act and the CERT-In directions in India, and within 72 hours under the GDPR. If you think you have found a vulnerability, please report it privately to hello@ieltsvega.com and give us the chance to fix it.

13. Children

The Service is for candidates aged 18 and over, and for 16- and 17-year-olds with a parent or guardian's consent. We do not knowingly collect data from anyone under 16, we do not track or profile a child for advertising, and we serve no behavioural advertising to anyone. If you believe a child has given us data, email us and we will delete it.

14. Changes to this policy

We keep this page current, and the date above tells you which version you are reading. If a change materially affects how we use your data we will tell you in the Service or by email before it takes effect, and where consent is the basis we rely on, we will ask for it again.

15. Contact and grievances

Email hello@ieltsvega.com with any privacy request or question. Write from your account address, and say what you would like us to do.

The Grievance Officer, IELTSVega is our grievance contact for the purposes of India's Information Technology Rules, 2021 and the Digital Personal Data Protection Act, 2023, at the same address. We acknowledge within 48 hours and resolve within 30 days.