YABAI SENSEI · SEPTEMBER 2026
Privacy
Prelaunch draft. The owner’s legal identity, contact address and applicable jurisdiction still need to be supplied for this free launch. No payment details are collected.
What we store
Neon Auth manages your email, name, password hash and login sessions. We use your account ID to store your lesson sessions, exercise answers, review schedule, preferences, product feedback and support requests. We also store first-party page visits, anonymous visitor and 30-minute session identifiers, and learning milestone events so we can understand whether the course is useful. Your name is used for display. Passwords are handled by the authentication provider; payment card details are not collected.
Why we use it
We save activity to provide recommendations, corrections, account history and daily goals. The N5 course is free and billing is disabled. No checkout requests are sent to a payment provider during the free launch.
Storage and providers
The application is hosted on Vercel, with Postgres storage and authentication provided by Neon. These providers process hosting, authentication, network and operational data. We do not add advertising trackers, third-party behavioral analytics or live AI chat. No microphone recording is required.
First-party analytics
Analytics are stored in our own application database. We measure page visits, signups and learning milestones, but do not store IP addresses, browser fingerprints, exercise answers or full URL query strings in the analytics event record. Privacy-enabled browsers that send Do Not Track or Global Privacy Control are not tracked by the page-view collector.
Device storage and offline practice
Your browser may store a roast preference, temporary sample answers and queued offline submissions. These are linked to the account that created them and synchronized after you reconnect. Shared devices should be signed out after use. Offline practice can remain on the device until synchronized or cleared. Sign-out clears cached lessons and preferences, but preserves answer queues, including empty queue keys with account references, so another open tab cannot lose newly queued work. Close lesson tabs and sync answers before leaving a shared device. Older offline queues may retain previously synchronized answers to avoid overwriting work from an older open tab. Account deletion or clearing this site’s browser data removes those retained local copies; only clear browser data after confirming all pending answers have synchronized. An older saved lesson may also remain locally after a newer one is selected, until sign-out, account cleanup or browser-data clearing. After a newer selection is synchronized, the app does not reopen that older copy automatically. If another account is signed in during deletion recovery, cleanup removes cached lessons identifiable as belonging to the deleted account and preserves other or unidentifiable cached data. An account-free random marker remains on this device to prevent downloads started before cleanup from restoring saved lessons. This marker is not sent to the server.
To recover an interrupted account deletion, this browser tab keeps a random confirmation token and the original account reference until cleanup finishes. Browser session restoration may retain it after a tab is closed. The server stores only a hash and expiry, with no account details or learning data. Confirmation is available for 24 hours; expired hashes are removed during later account deletions or application-data restoration.
Retention and your choices
Learning data is retained until you delete your learning account. Export and deletion controls are in Settings. Account deletion removes application records and your login account; hosting provider backups may persist under those providers’ retention policies. Owner-created operational backups are kept privately for up to 30 days; any restoration must reapply account deletions before service reopens.
First-party analytics events are automatically deleted after 180 days. Administrator security events are kept for up to 365 days and contain action names, account IDs, affected lesson IDs, timestamps and success status—not passwords, tokens, feedback text or support messages. They are also removed if the administrator deletes that account. Expired application rate-limit counters are cleared after a 24-hour safety period. Network abuse counters use a keyed one-way value derived from the request address; the application does not store the raw address in those counters.
Operational logs
Application error messages record a failure category without answer text, email, tokens or payment details. Hosting providers may separately retain access and security logs. We do not claim a specific provider retention period that has not been configured.
Contact
Signed-in users can submit private product feedback or a support request from the Support and feedback page. A public owner contact address remains a launch requirement.