Тестмейт Privacy Policy
This policy explains which personal data Тестмейт processes, why it is needed, who may receive it, and how a user can exercise their rights.
1. Personal-data operator
The personal-data operator is Товарищество с ограниченной ответственностью "Цедра Груп", БИН 230140044071. Address: Kazakhstan, Almaty city, Bostandyk district, Radostovets Street, building 189, apartment 37, postal code 050060. Email: [email protected]. Telephone: +7 706 645 56 37.
2. Scope
This policy applies to the Тестмейт mobile application, the oriapp.org website, accounts, study activity, subscriptions, support, analytics, and related operations. It does not replace Apple’s rules or the independent policies of other services.
3. Data sources
The company receives data from the user, their device and browser, Sign in with Apple, the Apple App Store, RevenueCat, analytics and diagnostics services, and creates data as the account, study, support, and security functions operate.
4. Account data
We process the internal UUID, Apple identifier and authentication results, email address including Apple Private Relay addresses, first and last name, nickname, language, account, onboarding, premium-access and deletion status, and creation, update, and deletion dates.
5. Optional profile data
A user may choose to provide a telephone number, city, grade, selected subjects, daily study target, and preferences. Telephone, city, and grade are not required for the core account unless a particular feature clearly says otherwise.
6. Study data
Тестмейт stores questions and tasks accessed, selected answers and their correctness, an AI-generation marker, scores, points, rank, activity, progress, topics, selected subjects, and study preferences.
7. Subscription data
To verify access, we process the RevenueCat app user ID, product and entitlement identifiers, store and environment, period type, subscription and renewal status, purchase and expiry dates, synchronization time, and operational webhook, delivery, error, and audit data. Apple, not Тестмейт, processes full payment details.
8. Analytics and diagnostics
We may process events and screens, app version, platform, environment, service version, device and installation identifiers, lifecycle, performance, crash and diagnostic data, IP address, user agent, request method and path, error context, stack trace, response details, and UTM source, medium, campaign, and related parameters.
PostHog and AppMetrica are optional analytics. Firebase Crashlytics and Performance are minimized essential diagnostics for stability, security, and fault diagnosis. PostHog session replay is disabled, and sensitive analytics properties are filtered.
The company does not sell personal data and does not use it for cross-site behavioral advertising or advertising profiling.
9. Feedback data
The company processes feedback, error reports, complaints, comments, information attached by the user, request status, and correspondence. Users should not include unnecessary personal, payment, or confidential data.
10. Purposes
- authenticate users and create and maintain accounts;
- provide tasks and preserve answers, progress, points, and selected settings;
- verify subscriptions, provide paid functions, and handle related requests;
- provide support, answer complaints, and correct content;
- protect security, prevent abuse, diagnose faults, and restore operation;
- measure use and improve the product where an applicable basis exists;
- send marketing only after a separate voluntary choice;
- comply with law, lawful requests, accounting duties, and unresolved disputes.
11. Legal bases
Depending on the country and operation, the basis may be contract performance, consent, a legitimate operational need where available, or a legal obligation. Consent applies to optional analytics, marketing, public leaderboard participation, and cross-border transfers where required. Security, fraud prevention, essential diagnostics, and claim defense may rely on contract, obligation, or a permitted legitimate interest. No single basis is presented as universally valid in every country.
12. Required and optional data
The Apple identifier, necessary account statuses, and core study data are required to sign in and operate selected functions. Optional profile fields, public leaderboard participation, marketing, and optional analytics are not a condition of keeping an account or paid features. Refusal may disable only the corresponding optional function.
13. Providers and recipients
- Apple — authentication, App Store distribution, billing, subscription management, and refunds;
- DigitalOcean — application, website, and database infrastructure in Bangalore, India;
- RevenueCat — purchase, subscription-status, and entitlement processing;
- PostHog EU — product and website analytics;
- AppMetrica / Yandex — mobile and website analytics;
- Firebase / Google — crash and performance diagnostics;
- Telegram — operational error notifications that may contain technical context;
- Anthropic — back-office educational-content generation; no direct user requests or prompts are submitted to Anthropic.
Providers receive only the information needed for their role and may act as processors or independent controllers under their mandatory terms.
14. International processing
DigitalOcean’s principal production infrastructure is in Bangalore, India, including the website, API, admin API, PostgreSQL, Redis, and object storage. Processing therefore includes cross-border transfers; this disclosure does not mean that the primary database is localized in Kazakhstan. Other providers may process data in multiple countries. The company uses contractual, technical, and other measures available under applicable law and seeks consent where required.
15. Public leaderboard
Participation is optional. After a separate choice, other authenticated users may see only nickname, points, and rank. Email, first name, and last name are not approved public fields. Consent may be withdrawn through support without deleting private study history needed for the account.
16. Marketing
Marketing by email, SMS, telephone calls, push notifications, Telegram, or other messengers requires a separate voluntary choice and is not required for an account or paid features. Each available channel includes an unsubscribe or equivalent withdrawal method; transactional, security, and necessary Service messages are not marketing.
17. Minors
A user under 18 must first obtain permission from a parent or other legal guardian. The company does not automatically verify that permission. Stricter rules in the user’s country take priority; a guardian may request access, correction, withdrawal, marketing opt-out, or deletion.
18. Retention
Active-account data is kept while needed for the Service. Records needed for law, accounting, fraud prevention, security, or a dispute remain only for the applicable statutory or claim period. Identifiable or pseudonymous website analytics and UTM attribution are kept for 12 months and are then deleted or aggregated.
19. Account deletion
After a verified request, all covered account-linked personal data, including account data and the Apple identifier, profile and study history, subscription and webhook data, account-linked analytics, device and diagnostic data, feedback, and leaderboard data, will within 30 days be permanently deleted or irreversibly anonymized. The only lawful exceptions are records that must be retained for law, accounting, fraud prevention, security, or an unresolved dispute. Account deletion does not cancel an Apple subscription.
20. Backups
Production backups are protected with encryption. Personal data in those backups is covered by the same commitment to permanent deletion or irreversible anonymization within 30 days after a verified request, subject only to lawful retention exceptions.
21. Security
Measures include TLS encryption in transit, DigitalOcean and database encryption at rest, encrypted backups, role-based administrative access, multi-factor authentication for administrators, access and database audit logs, secrets stored outside source code, regular dependency and security updates, and incident detection and response.
22. User rights
Depending on applicable law, a user or guardian may request access, correction, restriction, object to processing, withdraw consent, request portability or deletion, and complain to a competent authority. The company preserves mandatory rights under the law of the user’s country and will complete a request within 30 calendar days or a shorter statutory period after reasonably verifying its connection to the account.
23. Automated processing
The Service automatically calculates correctness, points, progress, access status, and technical indicators. These operations are not intended to make decisions with legal or similarly significant effects. Anthropic is used only for back-office content production, not to decide anything about a user.
24. Incidents and breaches
The company investigates confirmed incidents, limits their effects, restores safeguards, and notifies users or authorities where applicable law requires. A suspected incident may be reported through the unified contact details.
25. Policy changes
This policy may be updated when laws, functions, providers, or processes change. The company will give advance notice of material changes where practicable and seek fresh consent where the law requires it.
26. Contact details
Товарищество с ограниченной ответственностью "Цедра Груп", БИН 230140044071. Address: Kazakhstan, Almaty city, Bostandyk district, Radostovets Street, building 189, apartment 37, postal code 050060. Email: [email protected]. Telephone: +7 706 645 56 37. These details are used for privacy questions, rights requests, consent withdrawal, analytics objections, deletion, and complaints.
Company contact details
- Registered name
- Товарищество с ограниченной ответственностью "Цедра Груп"
- Business identification number
- 230140044071
- Address
- Kazakhstan, Almaty city, Bostandyk district, Radostovets Street, building 189, apartment 37, postal code 050060
- [email protected]
- Phone
- +7 706 645 56 37