Privacy Policy
This policy covers the services operated by Vindica Inc., a Delaware C-Corp: this site (vindicaseneca.com), Seneca, FORGE (forgesat.com), Maro, our TOEIC Speaking practice service, and Vindica for academies. In this policy, “we” means Vindica Inc. and “the services” means any of these products.
The short version: we collect what the services need to work, we use it to run and improve the services for you, and we do not sell it. Your learning record belongs to you.
What we collect
- Account information. When you create an account — with an email address or by signing in with Google — we receive your name, email address, and, with Google sign-in, your Google profile picture. We use this to create your account, sign you in, and contact you about the service.
- Learning activity. When you use the services, we record the work you do in them: answers you submit, timing, scores, written and spoken responses, and practice history. This data is the product — it is what builds your learning record and powers your feedback.
- Technical basics. Like most websites, our servers receive standard technical information such as browser type and IP address, used for security and to keep the services running.
- Anonymous usage counts on our developer pages. On the Starter Kit pages for developers (/developers/starter-kit), we count page visits and tool use, for example how often the tester runs. Each count is an event name with a label from a fixed list, kept only as a daily total. It uses no cookies or identifiers, never includes anything you type or paste, and is not linked to you or to any account. Browsers that send Global Privacy Control or Do Not Track are not counted.
Google sign-in and the optional Gmail connection
If you use Google only to sign in, we receive your basic profile information: name, email address, and profile picture. We use it solely to create and operate your account. Google sign-in does not give us access to Gmail, Drive, contacts, or calendar.
Gmail invitation detection is a separate, optional connection. If you explicitly connect Gmail, we request read-only Gmail access so Seneca can find assessment invitations and show you a quiet reminder in a Vindica service. You can use Seneca without connecting Gmail.
- What we examine. For new messages currently in your Inbox, we first read only the sender and date. We read a message body transiently only when its sender domain is on our reviewed assessment-partner list.
- What we store. We store your connected Gmail address so Google notifications reach the correct connection. For a matched invitation, we store only the partner, invitation identifier, invitation type, deadline, and processing timestamps. We do not store the email subject, sender address, body, snippet, attachment, or invitation link.
- How we use it. Gmail data is used only to provide the invitation-reminder feature you chose. It is not used for advertising, sold, used to train general-purpose AI models, or disclosed to assessment partners.
- How to stop it. You can disconnect Gmail from Connections. Disconnecting immediately stops synchronization, asks Google to revoke access, and removes the stored mailbox identity and synchronization state. You can separately delete derived invitation records or request account deletion.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
How we use your data
- To operate the services: sign you in, save your work, score your practice, and generate your feedback and reports.
- To build your learning record — the persistent model of how you learn that the services are for.
- To improve the services, including fixing bugs and improving the quality of questions and feedback.
- To communicate with you about your account and the service.
We do not sell your personal data, and we do not use it for third-party advertising.
Who can see your data
- Service providers. We store data with established infrastructure providers (such as Supabase for our database and Netlify for hosting) that process it on our behalf.
- AI processing. Some features send selected responses and relevant learning context to the Google Gemini API to generate feedback or structured learning signals. We do not opt this content into general-purpose model training. See our subprocessor page.
- Apps you connect. If you connect an app to your Seneca record, for example by adding the Seneca connector to an AI assistant such as Claude (Anthropic, PBC) or ChatGPT (OpenAI), that app's operator receives what you approved on the consent screen and nothing else: a private identifier unique to that app, and the summaries or materials named in each permission. Item-level questions and answers are not included unless you approve a full export. The app is named on the consent screen and in your learning record, where you can disconnect it at any time and see a receipt of everything you have agreed to. Item-level data another company sends to your record is never passed on to a different company.
- Your school or academy. If you use a service through an authorized school program, permitted staff may see work and progress created within that program. Consumer history is not automatically authorized for school access; new identifiable school programs remain blocked until that separation is implemented and verified.
We may also disclose information if required by law, or as part of a corporate transaction such as a merger, in which case this policy continues to apply to it.
Retention and deletion
We keep consumer learning data while an account is active. Gmail access continues only while the optional connection is active. Disconnecting Gmail revokes access and removes the stored mailbox identity and synchronization state; derived invitation records remain under your control through the service’s inspect and delete tools.
You can ask us to delete your account at any time by emailing kevinchoi@vindicaseneca.com. Our target is to resolve a verified request within 30 days. We do not report deletion as complete if a system step failed. Specific records may remain where a legal duty, security hold, protected provider backup, or school-controlled retention instruction applies; we will identify that limitation. See the retention and deletion schedule.
Security
Data is encrypted in transit (HTTPS with HSTS enforced) and at rest (AES-256 on Supabase's SOC 2 Type 2 and ISO 27001 certified platform; Vindica holds no certification of its own), and protected by application, database, and provider access controls. Credentials are stored only as one-way hashes. Our primary Supabase database region is Singapore. Authorized Vindica personnel may administer and support the services from South Korea, and providers may process data in other locations described on our subprocessor page. No system is perfectly secure; our security page states both current controls and known gates.
Students and minors
We do not currently accept identifiable K–12 student records or minor accounts for a new school pilot until the school and Vindica verify authority, define program scope and retention, complete the required agreement, and approve any AI processing. Until then, school evaluations must use synthetic data or pseudonymous adult testers. Our student privacy page explains this fail-closed posture and the request path for parents and students.
Changes to this policy
If we change this policy, we will post the updated version here with a new effective date. If a change meaningfully reduces your rights over your data, we will tell you before it takes effect.
Contact
Vindica Inc.
Representative: Jiwon Hur, President & CEO
Privacy officer: Seong Won (Kevin) Choi, Secretary
kevinchoi@vindicaseneca.com · +82 10-4247-1424