Quizglish Privacy Policy covering accounts, quiz content, participant responses, AI processing, notifications, support, retention, and data rights.
This Privacy Policy explains how Quizglish collects, uses, shares, stores, and deletes personal data through the Quizglish mobile application, website, API, public quiz pages, and support services.
Quizglish is operated by Alekseev Aleksandr, an individual developer based in Dnipro, Ukraine.
Quizglish is a general-audience English practice and quiz service. It is not designed as a school or classroom-management service.
1. Controller and contact
Alekseev Aleksandr is the controller responsible for the personal data described in this Policy. Privacy, access, correction, deletion, restriction, objection, and consent-withdrawal requests may be sent to ventarichannel@gmail.com.
A person who creates and shares a quiz remains responsible for the content they upload, the people with whom they share a public link, and having the rights and permissions required for that content.
2. Age requirements
Account holders and public quiz participants must be at least 13 years old. A person below the age of legal majority must have permission from a parent or guardian where local law requires it.
People under 13 must not create an account or submit a public quiz response. Quizglish does not knowingly collect personal data from children under 13. If you believe such data has been submitted, contact us so that we can investigate and delete it.
3. Account and authentication data
- An internal Quizglish account identifier.
- The Apple, Google, or Firebase authentication provider and provider identifier.
- An email address when Apple or Google makes it available. Sign in with Apple may provide a private relay address.
- The display name selected by the account holder.
- Onboarding status, default English level, question-count preference, result-visibility preference, and other account settings.
- Quizglish does not create or store a separate account password.
4. Quiz content and AI-operation data
- Quiz titles, source text, English level, grammar settings, question count, result settings, and publication status.
- Generated or manually edited questions, answer choices, answer keys, explanations, public-link identifiers, and edit state.
- AI prompt instructions, source-derived prompt content, AI output, provider and model, token usage, cost and latency metadata, status, hashes, and error information.
- Users must not include unnecessary medical, financial, biometric, disciplinary, identity-document, or other sensitive information in source text, questions, prompts, or answers.
5. Participant response data
- A display name or nickname entered before the quiz. A legal name is not required.
- Selected answers and free-text answers.
- Score, maximum score, automatic-correctness state, manual-review state, and review results.
- Submission timestamps and a random duplicate-safe attempt identifier.
- Participants do not create accounts and are not asked for an email address, phone number, date of birth, school, or payment information.
6. Moderation, support, analytics, and technical data
- Public quiz reports, including the quiz identifier, selected report reason, optional report details, moderation status, and timestamps.
- Support, privacy, deletion, copyright, abuse, and security correspondence, including the sender email, message, attachments, verification details, and completion notes.
- The quiz-creator mobile app sends Amplitude privacy-limited product events about screens, actions, and request outcomes, together with app version, platform, environment, bounded counts or length buckets, opaque internal record identifiers, and a random device identifier that is not persisted across app restarts.
- Amplitude does not receive prompts, raw quiz text, generated content, names, email addresses, authentication tokens, answers, or other personal content. Amplitude is not used on public web participant pages, and participant activity there is not sent to Amplitude.
- IP address, request date and time, URL, browser or device information, user agent, app version, request logs, error logs, and security events processed by the server and infrastructure provider.
- Quizglish does not currently request precise location, contacts, photos, microphone recordings, or an advertising identifier.
7. Local storage and cookies
The mobile app stores authentication and session information and necessary preferences on the device using platform storage. Firebase may also persist the provider authentication session on the device.
A public quiz page uses browser sessionStorage to temporarily keep the participant display name, answer drafts, submitted result, and a random retry identifier for the current attempt. Starting the same quiz again creates a new attempt identifier.
Quizglish does not currently use advertising cookies, cross-site tracking, or targeted-advertising identifiers.
8. Where data comes from
- Directly from account holders and participants when they sign in, configure an account, create a quiz, enter answers, report content, or contact support.
- From Apple, Google, and Firebase when they authenticate an account.
- Automatically from the app, browser, device, server, and security infrastructure when the service is used.
- From service providers when they return authentication, AI-generation, notification-delivery, or abuse-prevention results.
9. How and why we use data
- To perform our agreement with a user by authenticating an account, creating and publishing quizzes, submitting and scoring responses, generating AI content, showing results, deleting data, and providing requested support.
- For legitimate interests in keeping Quizglish secure and reliable, preventing duplicate responses and abuse, diagnosing errors, moderating reported content, and measuring de-identified service cost and performance.
- With consent for optional push notifications. Any future non-essential analytics or device permission will use consent handling where consent is required. Push-notification permission can be withdrawn through the app or device settings.
- To comply with applicable law and respond to valid requests from users, regulators, courts, or law-enforcement authorities.
10. AI processing
Quizglish uses the standard xAI Grok API for requested quiz generation and regeneration. The request can include source text, prompt instructions, selected settings, and related quiz context. xAI returns generated quiz content.
Under xAI published terms for its standard API, API inputs and outputs may be retained for up to 30 days for safety and abuse review and are not used to train xAI models. Quizglish has not enabled a separate Zero Data Retention mode.
AI output can be inaccurate, biased, incomplete, non-unique, or unsuitable. Account holders must review generated questions, answers, and explanations before publishing or relying on them.
11. Optional push notifications
If an account holder enables notifications, Quizglish stores an Expo push token and sends new-response notifications through Expo Push Service and Apple Push Notification Service.
A current notification includes the participant display name and quiz title, together with internal quiz and response identifiers used to open the relevant result. This information may appear on the device lock screen.
Notifications are optional and can be disabled through Quizglish or the operating-system settings.
12. Public links and reports
Anyone who receives an enabled public quiz link can open it. Quiz creators should share links only with intended participants and disable or delete a link that should no longer be available.
A participant display name, answers, and result are available to the account holder who created the quiz. They are not displayed as a public participant directory.
Anyone using a public quiz page can report misleading, offensive, privacy-invasive, copyright-infringing, or other problematic content. Reports are reviewed for moderation and Terms enforcement.
13. How we share data
- With Contabo GmbH for the VPS that hosts the website, API, self-hosted MongoDB database, and operational logs.
- With Google LLC and Firebase for Apple/Google authentication and related security processing.
- With X.AI LLC when an account holder requests Grok generation or regeneration.
- With Amplitude, Inc. for privacy-limited product and UX analytics in the quiz-creator mobile app only.
- With 650 Industries, Inc. (Expo) and Apple for optional push delivery and mobile-app infrastructure.
- With Apple and Google for sign-in and app-store distribution, and with Google for the Gmail support inbox.
- With advisers, regulators, courts, law enforcement, or another party when disclosure is required by law or reasonably necessary to protect users, the service, or legal rights.
- The current provider details and processing purposes are listed on the Subprocessors page.
14. International transfers
The primary Quizglish VPS is in Contabo's selected European Union region; the current public IP is registered to Contabo in Germany. Firebase Authentication is operated from the United States, and xAI, Amplitude, Expo, Apple, and Google may process data in the United States or other countries where they operate.
Where applicable law requires a transfer mechanism, Quizglish assesses and uses available contractual or legally recognized safeguards, such as provider data-processing terms, standard contractual clauses, or an applicable adequacy mechanism.
15. Retention
- Account data, quizzes, and participant responses are kept until the account, quiz, or individual response is deleted, unless a valid request or legal obligation requires earlier or longer handling.
- Raw AI prompts and output stored by Quizglish are kept while the related quiz and account exist. Quiz or account deletion scrubs the prompt and output content and removes the related account and quiz identifiers.
- After content and identifiers are removed, de-identified AI provider, model, status, token, cost, latency, and pricing metadata may be kept indefinitely for service-cost and performance measurement.
- xAI standard API inputs and outputs may be kept by xAI for up to 30 days under its published terms.
- Server, nginx, API, error, and security logs are kept for up to 30 days.
- A push token is kept until notifications are disabled, the provider reports that the token is invalid, or the account is deleted.
- Moderation reports are kept while needed to investigate and enforce the Terms, normally no more than two years after resolution.
- General support correspondence is kept for up to two years after the request is closed. Privacy and deletion request records are kept for up to three years after completion.
- Quizglish does not currently operate a separate application or database backup service.
16. Deletion
An account holder can permanently delete the account through Settings → Data & Privacy → Delete account. The process deletes the Quizglish account record, owned quizzes, participant responses and answers, and the related Firebase authentication identity. It also scrubs identifying and content fields from related AI-run records.
A user who cannot sign in can request account deletion at ventarichannel@gmail.com. A participant can request correction or deletion of a response by providing the quiz link, display name, and approximate submission time.
Deletion from a provider may take the provider retention period described above. De-identified technical metrics that can no longer be linked to a person or quiz may remain.
17. Your rights and choices
- Request access to and a copy of personal data.
- Request correction, deletion, or restriction of processing.
- Object to processing based on legitimate interests where applicable.
- Withdraw consent for an optional permission without affecting earlier lawful processing.
- Disable push notifications in the app or device settings.
- Complain to a competent privacy or data-protection authority where applicable.
- Send a request to ventarichannel@gmail.com. We aim to respond within 30 calendar days, subject to a different period required by law.
18. Identity verification
To protect user data, Quizglish may ask an account holder to write from the account email, sign in again, or provide other minimum information needed to verify control of the account.
For a participant response, Quizglish may ask for the quiz link, display name, approximate submission time, and other limited context needed to locate the record. We do not ask for more information than is reasonably necessary for verification.
19. Automated scoring
Quizglish automatically scores questions that have an objectively configured correct answer. Free-text answers may require manual review by the account holder who created the quiz.
Quizglish does not use quiz results for employment, credit, insurance, medical, legal, or similarly significant decisions and does not make decisions producing legal or similarly significant effects about participants.
20. Security
Quizglish uses measures designed to protect data, including HTTPS/TLS in transit, third-party authentication, access controls, data minimization, and controlled deletion cascades. No online service can guarantee absolute security.
Users should protect their Apple or Google account, avoid sharing private quiz links broadly, and report suspected unauthorized access or exposed content to ventarichannel@gmail.com.
21. No advertising or sale of data
Quizglish does not sell or rent personal data, show advertising, use data for targeted advertising, or send marketing email.
Quizglish uses Amplitude only for the privacy-limited mobile-app analytics described above. It does not use Amplitude for advertising, targeted advertising, public web participant tracking, autocapture, or session replay.
22. Changes to this Policy
We may update this Policy when the service, providers, or legal requirements change. We will update the effective date and provide a material notice on the website or in the app when appropriate.
23. Contact
Operator: Alekseev Aleksandr, individual developer, Dnipro, Ukraine. Email for privacy, deletion, support, copyright, abuse, and security requests: ventarichannel@gmail.com. Support is available in English and Ukrainian.