IELTS.international

Privacy Policy

Effective Date: May 11, 2026

1. Introduction

IELTS International (“we”, “us”, or “our”) operates the website www.ielts.international (“Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Service.

We are committed to protecting your privacy and ensuring you have control over your personal information. This policy is designed to be transparent about our data practices and your rights.

By using the Service, you consent to the practices described in this policy. If you do not agree, please do not use the Service.

Data Controller: IELTS International, registered in Brazil. For data protection inquiries, contact us at hello@ielts.international.

2. Data We Collect

Account data: When you create an account, we collect your name, email address, and password (stored as a secure hash). Authentication is managed by Supabase.

Subscription & payment data: When you subscribe to a paid plan, payment is processed by Stripe, Inc. We receive your Stripe customer ID, subscription status, plan type, and billing period. We do notreceive or store your full credit card number, CVV, or bank account details — these are handled entirely by Stripe.

Level test & practice data: Your level test answers, band scores, essay submissions, and practice session data are stored in our database to provide personalised feedback and track your progress.

Audio & voice data:When you use speaking practice features, your voice is recorded via your device’s microphone. Audio is transmitted to our servers for AI-powered transcription and evaluation. Recordings are processed in real time and are not stored permanently unless you explicitly save a session.

Email subscription: If you sign up for our newsletter, we collect your email address and optionally your target IELTS band.

Usage data: We automatically collect information such as your IP address, browser type, operating system, pages visited, time spent on pages, and referring URLs.

Device data: We may collect information about your device, including device type, screen resolution, and language preference.

3. How We Use Your Data

We use the data we collect to:

  • Provide, maintain, and improve the Service
  • Process payments and manage your subscription
  • Deliver personalised preparation feedback and track your progress
  • Send you IELTS preparation tips and updates (if subscribed)
  • Respond to your support requests
  • Analyse usage patterns to improve content and features
  • Detect and prevent fraud, abuse, or security issues
  • Comply with legal obligations

4. Third-Party Services

We share data with the following third-party service providers, each with their own privacy policies:

  • Supabase— Authentication and database hosting. Stores your account data and practice history.
  • Stripe— Payment processing. Receives your payment information directly.
  • OpenAI, Anthropic, Google (Gemini), DeepSeek — AI model providers. Your essay text, audio transcriptions, and practice responses may be sent to these services for evaluation and feedback. We do not send your name, email, or account information to AI providers.
  • Google Cloud— Text-to-speech and translation services for speaking practice and content localisation.
  • PostHog— Product analytics. Collects anonymised usage data to help us improve the Service.
  • Google Analytics / Google Tag Manager— Website analytics. Collects anonymised usage data.
  • Resend— Transactional email delivery. Receives your email address to deliver account notifications, password resets, and preparation tips.
  • Cloudflare Turnstile— Bot protection. Collects device and interaction signals to verify you are human. No CAPTCHAs are shown.
  • Vercel— Website hosting. Processes requests and may log IP addresses.

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

5. Cookies & Tracking

We use the following types of cookies:

  • Essential cookies: Required for the Service to function (authentication session, locale preference).
  • Analytics cookies: PostHog and Google Analytics cookies to understand how users interact with the Service.
  • Payment cookies: Stripe may set cookies during the checkout process for fraud prevention.
  • Bot protection: Cloudflare Turnstile may store cookies or local storage tokens to distinguish legitimate users from automated traffic.

You can disable non-essential cookies in your browser settings. Disabling essential cookies may affect the functionality of the Service.

6. Data Retention

Active accounts: We retain your data for as long as your account is active and you are using the Service.

Deleted accounts: If you delete your account, we remove your personal data within 30 days. Anonymised analytics data may be retained indefinitely.

Cancelled subscriptions: Account data is retained for 12 months after cancellation in case you wish to reactivate. After 12 months of inactivity, data may be deleted.

Email subscriptions: Your email is retained until you unsubscribe. You can unsubscribe at any time using the link in any email we send.

Payment records: Transaction records are retained for 5 years as required by Brazilian tax law.

7. Data Security

We implement industry-standard security measures to protect your data:

  • All data transmitted over HTTPS (TLS encryption)
  • Passwords stored using secure hashing (bcrypt via Supabase)
  • Payment data handled exclusively by PCI-compliant Stripe
  • Database access restricted by Row Level Security (RLS) policies
  • Security headers (CSP, HSTS, X-Frame-Options) on all pages

No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access— Request a copy of the personal data we hold about you
  • Correction— Request correction of inaccurate data
  • Deletion— Request deletion of your personal data
  • Portability— Request your data in a machine-readable format
  • Objection— Object to processing of your data for certain purposes
  • Withdraw consent— Withdraw consent for data processing at any time

To exercise any of these rights, email us at hello@ielts.international. We will respond within 30 days.

9. Children’s Privacy

The Service is not intended for children under 16. We do not knowingly collect data from children under 16. If we learn that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, please contact us.

10. International Data Transfers

Your data may be processed in countries outside your own, including the United States (Supabase, Stripe, Vercel, OpenAI, Anthropic, PostHog), the European Union, and other jurisdictions where our service providers operate. We ensure that appropriate safeguards are in place for international data transfers, including standard contractual clauses where required.

11. European Economic Area — GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the General Data Protection Regulation (GDPR). Our lawful bases for processing are:

  • Contract performance— to provide the Service you signed up for (account, subscriptions, practice features)
  • Legitimate interest— to improve the Service, prevent fraud, and ensure security
  • Consent— for marketing emails and non-essential analytics cookies (you may withdraw consent at any time)
  • Legal obligation— to comply with applicable tax and financial record-keeping laws

You have the right to lodge a complaint with your local data protection authority if you believe your data has been processed unlawfully.

12. Brazil — LGPD

If you are located in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD), including the right to access, correct, delete, and port your data. The data controller is IELTS International, contactable at hello@ielts.international.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the Service at least 14 days before they take effect. The “Effective Date” at the top indicates when the policy was last revised.

14. Contact Us

If you have questions about this Privacy Policy or want to exercise your data rights, contact us at:

Email: hello@ielts.international

We typically respond within 24 hours.

← Back to Home