Legal information
Privacy Policy
Effective and updated date: 2026-10-10
1 Who we are and what this policy covers
This Privacy Policy explains how Evanalysis Studio LLC (“we,” “us” or “our”) collects, uses, retains and discloses personal data in operating evanalysis.net (the “Website”), and the rights available to you.
Evanalysis Studio LLC is a Wyoming limited liability company with state registration number 2026-002018562. Its registered and company correspondence address is 30 N Gould St Ste R, Sheridan, WY 82801, United States. For privacy matters, contact contact@evanalysis.net. Operator telephone: +1 469 349 6708.
This policy applies when you browse the Website, create or use an account, save practice records or contact us. It does not apply to websites or services independently operated by third parties.
This policy is prepared in English and translated into Simplified Chinese and Traditional Chinese. If the language versions differ or are ambiguous, the English version prevails, except where applicable law requires otherwise. No language version limits your mandatory rights under applicable law.
2 Data we collect and its sources
Browsing and operational data: The website and infrastructure providers process request data needed to deliver pages, maintain security and troubleshoot problems. This may include IP addresses, request times and paths, browser or device information, response status and error records.
Account and authentication data: We process your email address, account identifier, basic account details you provide, such as a name or profile picture, and information needed for verification, password resets and login sessions. Available sign-in methods include email and password, a one-time email code, Google and GitHub; the login page shows the available options. Passwords and verification data are handled by the authentication system. Do not email us passwords or verification codes.
Third-party sign-in: When you sign in through Google or GitHub, that provider supplies the sign-in identifier and basic account details you authorize, such as an email address, name or profile picture. The information depends on the provider, your account settings and the authorization scope. The authorization screen and the provider’s privacy notice explain its own processing.
Practice and learning data: Saved data includes course, chapter, unit and question identifiers; submitted answers, attempt counts, correctness, scores and attempt times; and best scores, completion status, latest submissions and section-level progress summaries. Records are linked through an account or a previously used guest-practice identifier. Browser-local reading markers and server-side practice records are stored separately and may not synchronize automatically.
Contact data: When you email us, we receive your sender address, message and any information you choose to attach. Provide only what is needed to handle the issue. Do not send passwords, full payment-card details or unrelated identity documents.
Parental and age arrangements: Parental-consent and child-profile features are not yet available. Before the relevant process opens, we will explain the age-band and regional information, parental contact details and authorization or consent records required for the account rules, and their specific purposes.
3 Purposes and required information
We use this data to provide and protect the website, create and manage accounts, send verification or password-reset emails, save and display your practice records, handle support and privacy requests, and meet applicable legal obligations. Public-page usage statistics help us understand content usage and improve the website.
An account identifier, the email or verification data required for your chosen sign-in method, and the records needed to save practice activity are necessary for those features. Without them, you may be unable to register, sign in or save account-based practice records. You can still browse public learning materials that do not require an account. Optional information does not have to be provided.
4 Who can see your practice records
Practice records associated with your personal account are not disclosed to other ordinary users. You can view the relevant records by signing in to your account. Access by authorized personnel and service providers is limited to what is necessary to provide the service, handle support requests, maintain security or meet legal obligations. Protect your account and sign out on shared devices.
Once parent-managed child profiles become available, a verified parent or legal guardian may manage and review a child’s records within their authorized parental link. For minors who may lawfully register independently, parental permission to use the service does not automatically grant access to the account or learning records. Requests for access are handled according to applicable law and verified authority.
5 Cookies and browser storage
Authentication cookies support verification and maintain login sessions. Browser storage remembers your theme, contrast, language, last reading position and completion markers. A Service Worker may also cache some static resources to help pages load or support offline access.
You can clear cookies, local storage and caches through your browser’s site-data settings. Doing so may sign you out and remove local preferences and reading records, but it does not delete your account or practice records on the server. Deleting your account likewise does not automatically clear this data from your devices. The purposes of necessary storage and analytics are described separately in this Policy.
The previous guest-practice feature used a browser credential lasting up to 90 days to link records. Expiry or clearing of that credential may prevent access from the original browser; it does not automatically delete server records. Contact us for requests concerning those records.
6 Website analytics
We use Vercel Web Analytics to understand how public pages are used and to improve the Website. Analytics data may include visit times, page paths, referring pages, browser and device information, and approximate location. The service does not use third-party cookies and distinguishes visits using a hash generated from incoming requests.
The Website’s analytics configuration is designed to exclude private pages such as login and account settings and to remove query parameters and fragments from transmitted page URLs.
Visits to public pages trigger analytics processing under the configuration described above. The Website does not currently provide an analytics preference or withdrawal control, or gate analytics by age or region. For access, objection or other applicable rights requests concerning analytics data, contact contact@evanalysis.net. Necessary operational and security processing is described separately in this Policy.
7 Service providers and other disclosures
We use the following providers to support the Website: Vercel for hosting, content delivery and analytics; Neon Auth and the Neon database for authentication and data storage; and Zoho for our operational contact mailbox. Authentication-related transactional messages, including verification, one-time-code and password-reset emails, are initiated by Neon Auth and delivered through the configured Zoho SMTP service. Google or GitHub also participates in the sign-in process if you choose that provider.
Providers process data as necessary to perform their respective functions. Services such as third-party sign-in providers may also independently process related activity data under their own privacy notices.
Where necessary and supported by a lawful basis, we may disclose data to providers supporting our operations, professional advisers and bodies legally entitled to receive it, including to meet valid legal requirements or protect the Website and its users.
8 International processing
The Website’s application runtime, production database and authentication service are primarily hosted in the eastern United States. Our operational contact mailbox is primarily stored in the United States. The Website uses a global content delivery network. Email delivery, logs, operations, support and related services may involve providers’ processing locations outside the United States, depending on the services and configurations used.
Providers may process data outside your country or region, where protection rules may differ. The principal hosting and mailbox storage locations described above do not mean that all processing occurs solely in the United States.
Where required by applicable law, we will undertake the relevant processing after putting the necessary international-transfer conditions or safeguards in place, such as applicable contractual safeguards, adequacy arrangements or required consent. You can contact us to ask about the recipients, processing locations and safeguards relevant to your data.
9 Retention and deletion
We determine retention by the purpose of the data and its continuing necessity. Account data supports and protects your account. Raw answers and attempt details support your revision, review of mistakes and understanding of results; aggregate progress supports continued courses and revision across academic years. In assessing continuing necessity, we consider actual account and course use, whether you still need the saved records, and requests to clear records, close the account or delete data. Contact emails are retained as needed to resolve the matter and handle necessary follow-up. Security logs support troubleshooting, security investigations and abuse prevention. Consent and rights-request records are limited to what is needed to demonstrate the relevant authorization or handling of the request.
A maximum retention period of 24 calendar months from creation has been selected as the target for raw answers and attempt details. This fixed-period clearing arrangement has not yet been implemented and does not currently cause automatic deletion of existing records. You can use the practice-clearing feature described below or contact us with other data requests. We handle data that is no longer needed or must legally be deleted under applicable requirements. Data needed for a specific legal obligation or dispute is subject to restricted use and access. Clearing practice records does not also delete authentication data, historical anonymous records or all provider copies.
Backups and provider recovery copies may be removed through their actual rotation or cleanup processes and cannot be guaranteed to be deleted record by record at the same time as online practice records. Their handling depends on the provider’s configuration, recovery arrangements and lawful retention obligations. This Policy does not present a particular recovery window as a universal deletion period for all copies. If a backup containing deleted data is restored, the relevant deletions must be applied before that data is used again. Browser-local data generally remains until you clear site data or your browser clears its storage.
10 How to make a data request
After signing in, you can view and clear your account’s attempts, problem progress and section progress on the Practice Records page in account settings. This feature does not close your account or delete authentication data, historical anonymous practice records, browser-local data or other records that must lawfully be retained. Contact us as described below to request account closure or broader deletion.
Email contact@evanalysis.net and explain which data you want to access, correct, receive a copy of or delete, or whether you want to close your account. You can also ask about any applicable rights to restriction, objection, portability or withdrawal of consent. Where possible, use your registered email and give enough information to locate your account. Do not send identity documents without being asked.
The usual process is to receive your request; verify identity proportionately through registered-email confirmation, account verification or another appropriate method; clarify its scope and locate relevant account, practice, authentication and necessary provider records; carry out applicable actions and explain any lawful retention exceptions; and explain the outcome and any device-side clearing you still need to do. We may need to verify the identity and authority of a representative or parent making a request.
We handle requests within the time limits required by applicable law. Where EU or UK data-protection rules apply, responses are generally due without undue delay and within one month. Legally permitted extensions for complex or multiple requests will be explained within the original period. Requests from other regions are handled within the applicable time limits. If we cannot fully fulfil a request, we will explain the reason and available complaint routes as required.
Withdrawing consent does not affect lawful processing before withdrawal. It may affect a feature that depends on that processing. Account deletion may prevent you from retrieving its learning records, so tell us if you need a copy first.
11 Protection of children and minors
Scope and eligibility: Minors’ personal data is subject to the protections required by applicable law. Independent registration requires compliance with the minimum product threshold of age 13 stated in the Terms of Use and any higher applicable age requirement. This product threshold is distinct from the age of majority, the age for independent consent and contractual capacity. Any parental or legal-guardian authorization required by law must be obtained separately.
Current service and proposed arrangements: A parental-consent process and parent-managed child profiles are not currently provided. Persons below the applicable threshold must not register or submit personal data for cloud saving, including where a parent or guardian has given informal permission. Public materials remain accessible without an account, but browsing may involve the operational and analytics processing described in this Policy. Where Mainland China’s Personal Information Protection Law applies, the current service model does not admit users under 14 to these account and cloud-saving features. The parental process below is proposed and applies only after implementation, verification and notice that it is available.
Controls before registration and collection: The proposed process must use only the minimum information necessary to determine age eligibility and the applicable regional process, without presuming adulthood. Before required parental or guardian consent is obtained, no child account may be created, and no child’s name, email address, personal profile or cloud learning records may be collected or saved. Technical processing necessary to deliver pages and maintain security is limited to what applicable law permits.
Direct notice and valid consent: The parent or legal guardian initiates the process using their own email address and directly receives a notice concerning the child’s data. The notice must identify the operator and contact details, proposed data categories and purposes, necessary recipients, retention and deletion arrangements, and the means of exercising parental rights. The parent or guardian must expressly confirm their authority and provide valid consent to the specified processing. Where verifiable consent is required, the method must satisfy that requirement and be proportionate to the risk. Email consent must include the additional confirmation stated in the notice and be suitable for the actual uses of the data. Email verification, authorization under the Terms and consent to data processing must be obtained and recorded separately. Failure to respond does not constitute consent.
Activation and processing restrictions: A parent or guardian may create a private child profile with a nickname that does not directly identify the child only after the required notice, consent and confirmation are complete. A separate child email address is not required. Saved data is limited to account identifiers, age eligibility, the parental relationship, answers and learning progress, and security information necessary for the learning features. Proposed child profiles do not provide public personal profiles, public posting, direct messaging or sharing with other users; account and privacy notices are directed to the parent or guardian. This proposed model excludes the sale of children’s data and targeted advertising, and requires non-essential analytics to be disabled for users under 18 or whose age is unconfirmed.
Parental rights and withdrawal: A parent or legal guardian may use their verified contact email to request access, correction or deletion of the child’s data, withdrawal of consent or cessation of further collection at contact@evanalysis.net. Verification is limited to information reasonably necessary to establish identity, the parental relationship and authority. Following valid withdrawal, processing that relies on the withdrawn consent must cease without undue delay. Withdrawal does not affect prior lawful processing or exclude limited processing required by law. Features dependent on cloud records may consequently become unavailable. Required deletion covers applicable account data, learning records and relevant provider data, subject to lawful retention exceptions and backup arrangements. Disabling an account or clearing practice records does not replace any broader deletion duty.
Non-compliant collection and independent rights: If we identify children’s data collected without the applicable requirements being met, we will assess the matter promptly and take required measures, which may include restricting processing, stopping further collection, deletion or other remedies permitted by law. Children’s data must not be retained indefinitely beyond the needs of a specified purpose. Where the relevant Mainland China laws apply, data about children under 14 is subject to sensitive-personal-information, guardian-consent and child-specific requirements. For minors legally entitled to use the relevant features independently, parental requests must also take account of their understanding, independent rights and applicable law. Parental permission does not itself confer access to the account or learning records.
12 Legal grounds and statutory rights
EEA and United Kingdom: Where the EU GDPR or UK GDPR applies to the relevant processing, we identify a lawful basis for each purpose. Account information and cloud learning records are processed to provide the services you request only to the extent objectively necessary for a valid service agreement and legally permissible on that basis. Limited technical and security data may be processed for our legitimate interests in service security, abuse prevention and troubleshooting, subject to balancing those interests against your rights and interests, with particular regard to children. Where consent is required, valid consent must be obtained separately before that processing begins. Processing necessary to fulfil an applicable legal obligation may rely on that obligation. Acceptance of the Terms does not itself constitute consent to all processing.
Other applicable laws: These grounds apply only to the extent recognised by the law governing the processing. Where Hong Kong’s Personal Data (Privacy) Ordinance applies, collection and use are subject to its data protection principles and applicable consent requirements. Where Mainland China’s Personal Information Protection Law applies, processing must rely on a ground recognised by that law, with consent, separate consent or guardian consent obtained where required. Legitimate interests under the GDPR is not treated as an independent ground under that law.
Scope of rights: Depending on the law applicable to the processing and satisfaction of its conditions, you may have rights to information about processing; access or a copy of your data; correction of inaccurate or incomplete data; erasure; restriction or objection to processing; receipt or transfer of data in a portable format; and withdrawal of consent where processing relies on consent. Withdrawal does not affect the lawfulness of prior consent-based processing. The scope, conditions and exceptions for each right are determined by applicable law; rights are not identical in every jurisdiction.
Exercise and remedies: Rights requests and privacy complaints may be submitted using the email or correspondence address in this Policy. We require only information reasonably necessary and proportionate to verify identity and representative authority. Do not submit identity documents unless requested. Requests are handled under section 10 and applicable legal deadlines. Any lawful extension, refusal or limitation will be explained, together with available remedies, as required. You may also complain to a competent data protection authority, such as Hong Kong’s Privacy Commissioner for Personal Data, the UK Information Commissioner’s Office or the relevant EEA supervisory authority where applicable, or pursue other remedies provided by law.
UK complaints procedure: Where UK data protection law applies, data protection complaints may be submitted through those contact details. We will acknowledge receipt within 30 days and, without undue delay, make appropriate enquiries, provide progress information and communicate the outcome. This acknowledgment deadline is separate from the statutory deadlines for rights requests and is not a promise that all data will be deleted within 30 days.
13 Security and policy changes
The website uses HTTPS and protects account data through authentication and access controls. No online service can guarantee absolute security. If you notice suspicious account activity, contact us promptly and use available protective measures such as password reset.
We will state the effective and updated dates on this page. Material changes to processing will be explained appropriately. Where renewed notice or separate consent is required, we will follow the applicable requirements. Contact us at contact@evanalysis.net.