Privacy

Privacy Policy

Last updated: December 13, 2024

1. Introduction

SpacedSmart ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. Please read this policy carefully to understand our practices regarding your data.

2. Information We Collect

2.1 Information You Provide

  • Account Information: When you create an account, we collect your email address and name through OAuth providers (Google, GitHub).
  • Profile Information: Profile picture URL provided by your OAuth provider.
  • User Content: Notes, reflections, and any other content you create within the service.
  • Payment Information: When you subscribe, Stripe collects and processes your payment information. We do not store your full credit card number.

2.2 Information Collected Automatically

  • Usage Data: Problem solving history, review schedules, performance metrics, time spent on problems, and learning progress.
  • Device Information: Browser type, operating system, and device type for improving user experience.
  • Log Data: IP address, access times, pages viewed, and referring URLs.
  • Cookies: We use essential cookies for authentication and session management.

3. How We Use Your Information

We use the collected information to:

  • Provide, operate, and maintain the service
  • Process subscriptions and payments
  • Calculate your spaced repetition schedules using our algorithms
  • Track your learning progress and provide personalized insights
  • Send important service-related communications (e.g., password resets)
  • Respond to your inquiries and provide customer support
  • Improve and optimize our service
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

4. Third-Party Services

We integrate with the following third-party services:

4.1 Authentication

  • Google OAuth: Used for account authentication. Google's privacy policy applies to data they collect.
  • GitHub OAuth: Used for account authentication. GitHub's privacy policy applies to data they collect.

4.2 Payment Processing

  • Stripe: We use Stripe to process payments. Stripe collects payment information in accordance with their own privacy policy. We receive only limited information (last 4 digits of card, expiration date, subscription status).

4.3 Hosting and Database

  • Vercel: Our application is hosted on Vercel's infrastructure.
  • Database Provider: We use a PostgreSQL database hosted on a secure cloud provider.

5. Data Storage and Security

We take the security of your data seriously and implement appropriate technical and organizational measures to protect it:

  • All data is transmitted over HTTPS with TLS encryption
  • Passwords are never stored; we use OAuth for authentication
  • Database access is restricted and monitored
  • Regular security reviews and updates
  • Payment information is handled entirely by Stripe, a PCI-DSS compliant payment processor

However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

6. Your Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate personal data.
  • Deletion: Request deletion of your account and associated data.
  • Export: Request an export of your data in a portable format.
  • Opt-out: Unsubscribe from marketing communications at any time.

To exercise any of these rights, please contact us at spacerephelp@gmail.com.

7. Cookies and Tracking

We use the following types of cookies:

  • Essential Cookies: Required for authentication and session management. Without these, the service cannot function properly.
  • Preference Cookies: Remember your settings such as theme preference (light/dark mode).

We do not use advertising or third-party tracking cookies. You can control cookies through your browser settings, but disabling essential cookies may prevent you from using the service.

8. Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at spacerephelp@gmail.com, and we will take steps to delete such information.

9. CCPA Rights (California)

If you are a California resident, you have additional rights under the CCPA:

  • Right to know what personal information we collect, use, disclose, and sell
  • Right to delete personal information
  • Right to opt-out of the sale of personal information (we do not sell data)
  • Right to non-discrimination for exercising your CCPA rights

10. GDPR Rights (European Union)

If you are in the EU/EEA, you have additional rights under GDPR:

  • Right to access, rectify, or erase your personal data
  • Right to restrict or object to processing
  • Right to data portability
  • Right to withdraw consent at any time
  • Right to lodge a complaint with a supervisory authority

Our legal basis for processing your data is either your consent, performance of a contract (providing the service), or our legitimate interests in operating and improving the service.

11. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with the service. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes. Anonymized or aggregated data (which cannot identify you) may be retained indefinitely for analytics purposes.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on our service prior to the change becoming effective. We encourage you to review this policy periodically for the latest information on our privacy practices.

13. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

Email: spacerephelp@gmail.com