Privacy Policy
Effective date: July 16, 2026
Lodera (“Lodera,” “we,” “us”) is an adaptive math practice service at lodera.ai. This policy explains, in plain English, what information we collect, why we collect it, who processes it for us, and the choices you have. Using Lodera means this policy applies to you; it works together with our Terms of Service.
The short version: we collect your email, a username, and your practice activity, because the product literally cannot adapt to you without it. We don’t sell personal data, we don’t run advertising trackers, and you can delete your account — and the data that goes with it — yourself, in settings.
1. What we collect
- Account information. Your email address, a username, and your password. Authentication is handled by Supabase Auth; your password is stored only as a cryptographic hash — we never see or store it in plain text.
- Practice activity. The questions you are served, the answers you choose, whether they were correct, response timing, hint usage, the topics you select, and the per-skill mastery estimates our model computes from all of that. This is the core data the adaptive engine runs on.
- Payment information. If you subscribe, payment is handled entirely by Stripe on Stripe-hosted pages. We never receive or store your card number. We receive limited billing metadata from Stripe, such as your subscription status, plan, and billing dates.
- Device and log data. Standard technical data such as IP address, browser type, requested pages, and timestamps — used for security, rate limiting, and debugging. We also use privacy-focused, aggregate usage analytics (Vercel Analytics), which does not use cookies or track you across sites.
2. How we use it
- To run the product. Your practice history drives question selection, difficulty, and your mastery map — this is the reason the data exists.
- To manage your account and billing — signing you in, enforcing the free plan’s daily limit, and keeping your subscription state correct.
- To send transactional email only — password resets, email verification, and billing notices. We do not send marketing email.
- To keep the Service safe — preventing abuse, scraping, and fraud, and diagnosing problems.
- To improve content — aggregate answer statistics and your reports/feedback help us find and fix bad questions.
3. What we don’t do
- We do not sell your personal data.
- We do not show third-party advertising or use advertising trackers.
- We do not share your personal data with anyone except the service providers below, or where the law requires it.
4. Service providers (processors)
These companies process data on our behalf, only to provide the Service:
- Supabase — database hosting and authentication. Your account and practice data live here.
- Stripe — payment processing and subscription management. Stripe handles your card details under its own privacy policy.
- Vercel — application hosting and the cookieless aggregate analytics described above.
- An email delivery provider — sends the transactional emails described above (password reset, verification, billing notices).
5. Cookies and localStorage
We use cookies for one job: keeping you signed in (Supabase Auth session cookies). We use your browser’s localStorage for preferences — such as your selected course and topics and small UI state — so the app remembers how you left it. There are no advertising or cross-site tracking cookies.
6. Retention and deletion
We keep your data while your account is active, because the adaptive engine needs your history to work. You can delete your account yourself in the in-app settings: deletion first cancels any active subscription, then removes your account and practice data. Residual copies in backups are removed on a rolling basis. Some billing and transaction records may be retained where the law requires it (and Stripe retains its own transaction records under its policies).
7. Children’s privacy
Lodera is not directed at children under 13, and we do not knowingly collect personal information from children under 13, consistent with the U.S. Children’s Online Privacy Protection Act (COPPA). If we learn that a child under 13 has created an account, we will delete the account and its data. Users aged 13–17 may use Lodera only with the consent of a parent or guardian. If you are a parent or guardian and believe your child has provided us personal information — or you want to review or delete your teen’s data — contact us at support@lodera.ai.
8. Security
Data is encrypted in transit (HTTPS), passwords are stored only as hashes, payment details never touch our servers, and we host with established providers. No online service can promise perfect security, but we design so that the sensitive things (like card numbers) are never ours to lose. If you believe you’ve found a security issue, please email support@lodera.ai.
9. Your choices and rights
- Update your email or password in the in-app settings.
- Delete your account and data in the in-app settings, anytime.
- Email us for a copy of your data or with any privacy question or request.
- Depending on where you live (for example California or the European Economic Area), you may have additional legal rights to access, correct, delete, or port your data — contact us and we will honor the rights that apply to you.
10. Changes to this policy
We may update this policy from time to time. If a change is material, we will give notice — for example by email or an in-app notice — before it takes effect. The effective date at the top always reflects the current version.
11. Contact
Privacy questions or requests: email support@lodera.ai.
See also: Terms of Service · Back to home