Privacy Policy

Vindica Inc. · Effective September 29, 2026 · Version 2026-09-29.1 · 한국어

This policy covers the services operated by Vindica Inc., a Delaware C-Corp: this site (vindicaseneca.com), Seneca, FORGE (forgesat.com), Maro, our TOEIC Speaking practice service, and Vindica for academies. In this policy, “we” means Vindica Inc. and “the services” means any of these products.

The short version: we collect what the services need to work, we use it to run and improve the services for you, and we do not sell it. Your learning record belongs to you.

What we collect

Google sign-in and the optional Gmail connection

If you use Google only to sign in, we receive your basic profile information: name, email address, and profile picture. We use it solely to create and operate your account. Google sign-in does not give us access to Gmail, Drive, contacts, or calendar.

Gmail invitation detection is a separate, optional connection. If you explicitly connect Gmail, we request read-only Gmail access so Seneca can find assessment invitations and show you a quiet reminder in a Vindica service. You can use Seneca without connecting Gmail.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

How we use your data

We do not sell your personal data, and we do not use it for third-party advertising.

Who can see your data

We may also disclose information if required by law, or as part of a corporate transaction such as a merger, in which case this policy continues to apply to it.

Retention and deletion

We keep consumer learning data while an account is active. Gmail access continues only while the optional connection is active. Disconnecting Gmail revokes access and removes the stored mailbox identity and synchronization state; derived invitation records remain under your control through the service’s inspect and delete tools.

You can ask us to delete your account at any time by emailing kevinchoi@vindicaseneca.com. Our target is to resolve a verified request within 30 days. We do not report deletion as complete if a system step failed. Specific records may remain where a legal duty, security hold, protected provider backup, or school-controlled retention instruction applies; we will identify that limitation. See the retention and deletion schedule.

Security

Data is encrypted in transit (HTTPS with HSTS enforced) and at rest (AES-256 on Supabase's SOC 2 Type 2 and ISO 27001 certified platform; Vindica holds no certification of its own), and protected by application, database, and provider access controls. Credentials are stored only as one-way hashes. Our primary Supabase database region is Singapore. Authorized Vindica personnel may administer and support the services from South Korea, and providers may process data in other locations described on our subprocessor page. No system is perfectly secure; our security page states both current controls and known gates.

Students and minors

We do not currently accept identifiable K–12 student records or minor accounts for a new school pilot until the school and Vindica verify authority, define program scope and retention, complete the required agreement, and approve any AI processing. Until then, school evaluations must use synthetic data or pseudonymous adult testers. Our student privacy page explains this fail-closed posture and the request path for parents and students.

Changes to this policy

If we change this policy, we will post the updated version here with a new effective date. If a change meaningfully reduces your rights over your data, we will tell you before it takes effect.

Contact

Vindica Inc.
Representative: Jiwon Hur, President & CEO
Privacy officer: Seong Won (Kevin) Choi, Secretary
kevinchoi@vindicaseneca.com · +82 10-4247-1424