1. Who is responsible for the data
The administration of testin.site is the owner of the data you provide while using the site. This policy applies to the testin.site website, authorization through Telegram, taking tests, the reward system and future display of advertisements.
For issues of access, correction or deletion of data, contact the contacts listed on the "Contacts" page. In the request, specify the Telegram username or another way to find your account.
2. What data we receive
Most tests can be taken without registration. If you log in through Telegram, we may receive your Telegram ID, first name, last name, username, profile picture, language code, and authorization time. We do not receive or store the password from Telegram.
While using the site, the selected answers, test result, number of attempts, XP, level, activity streak and open rewards are stored. Server technical logs may contain IP address, date and time of request, page address, browser type, device and server response code.
- Telegram data transferred after your login confirmation;
- test results, progress, XP and achievements;
- session cookie or local token required to save login;
- technical data of security and operation of the server;
- advertising cookies and identifiers - only after connecting advertising and according to your consent settings.
3. Why we use the data
The data is required to authorize the user, show their progress, save results, earn XP, prevent abuse, maintain security and correct technical errors. Aggregated statistics can be used to improve tests and navigation.
The legal basis is the performance of the function you have requested, our legitimate interest in the safe operation of the service and, where necessary, your consent. You can not log in through Telegram and still take public tests.
5. To whom the data may be transferred
We use infrastructure providers for hosting, database, site delivery and server security. Telegram processes login data according to its own rules. Once monetization is enabled, Google and CMP-selected advertising partners can process technical and advertising data.
We do not sell personal data. Transfer is possible only for the operation of the service, compliance with legal requirements, protection of rights and security, or based on your consent. Some suppliers may process data outside of Ukraine; in this case, the protection mechanisms provided by them are applied.
6. Storage and protection periods
An authorization session is usually valid for up to 30 days. Profile data and progress are stored as long as the account exists or as long as it is needed for the operation of the service. Technical logs are kept only for as long as necessary for safety, diagnostics and compliance with legal obligations.
We enforce HTTPS, access restrictions, single database user, environment secrets and application isolation. No data transfer or storage method is guaranteed to be absolutely secure, but we regularly update our technical measures.
7. Your rights
You can request information about your data, copy, correct, delete, limit processing or object to it. Where processing is based on consent, it can be withdrawn without affecting the lawfulness of the previous processing.
You can also log out of your profile, clear cookies and local storage in your browser, or change your advertising settings via CMP. We may ask you to confirm that the request is specific to your account.
8. Children and policy changes
The site is not intended specifically for children under the age of 13 and does not ask them to create a profile. If you believe that a child has provided us with personal data without proper consent, notify the administration to delete it.
The policy may change with site features or legal requirements. The date of the last update is indicated at the top of the page. Material changes will be posted on this page before or when they become effective.
