Privacy Policy
Effective Date: March 1, 2026
At Sataday, we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights in relation to it.
1. Who We Are
Sataday is an independent SAT practice platform available at sataday.app. If you have any questions about this policy, please contact us at support@sataday.app.
2. Data We Collect
2.1 Information You Provide
When you register or use Sataday, we collect:
- Name and email address (via registration form or Google Sign-In)
- Username chosen during registration
- Country and city of residence (for regional rankings)
- Password (stored in encrypted form; never stored in plain text)
2.2 Exam and Usage Data
When you take an exam, we collect:
- Your answers and exam scores
- Exam date and test identifier
- Section scores (Reading & Writing, Math)
- Time of submission
2.3 Automatically Collected Data
We may collect standard technical data including:
- Browser type and device information
- IP address (used for security and abuse prevention only)
- Session cookies (required for authentication)
3. How We Use Your Data
We use the information we collect to:
- Create and manage your account
- Display your exam scores and percentile rankings
- Calculate and display worldwide, country, state, and city leaderboards
- Send transactional emails (account-related notifications)
- Detect and prevent fraudulent activity or cheating
- Improve the platform and fix technical issues
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Data Storage and Security
Your data is stored securely using Supabase, a PostgreSQL-based cloud database with row-level security. We implement the following safeguards:
- Passwords are hashed using bcrypt and never stored in plain text
- All data is transmitted over HTTPS/TLS encryption
- Database access is restricted to authorised server-side processes only
- Google OAuth tokens are managed securely and never stored long-term
While we take security seriously, no system is completely immune to breaches. We will notify affected users promptly in the event of a data breach.
5. Cookies
Sataday uses cookies solely for authentication purposes:
- A session cookie is set to keep you logged in during your visit
- No advertising or tracking cookies are used
- No third-party analytics cookies are currently deployed
You can disable cookies in your browser settings, but this will prevent you from logging in to the platform.
6. Third-Party Services
To operate Sataday, we use the following third-party services that may process your data:
- Google OAuth — used for Sign in with Google. Google Privacy Policy
- Supabase — database and authentication backend. Supabase Privacy Policy
- Vercel — hosting provider. May log request metadata for security purposes.
- Zoho Mail — used to send transactional emails from support@sataday.app.
We only share with these providers the minimum data necessary for them to deliver their services.
7. Data Retention
We retain your personal data for as long as your account is active. If you request account deletion, we will remove your personal information within 30 days, except where we are required to retain it for legal or security reasons. Anonymised exam score data may be retained for platform analytics.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request deletion of your account and personal data
- Portability — request your data in a structured, machine-readable format
- Objection — object to certain types of data processing
To exercise any of these rights, please contact us at support@sataday.app. We will respond within 30 days.
9. Children's Privacy
Sataday is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13 without parental consent, we will delete it promptly. Users between 13 and 17 must have parental or guardian consent to use the platform.
10. International Users
Sataday is operated from and stores data in cloud infrastructure that may be located outside your country of residence. By using Sataday, you consent to the transfer of your data to these systems. We take steps to ensure your data is handled in accordance with this Privacy Policy regardless of where it is processed.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this document. Continued use of the platform after changes are posted constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
Email: support@sataday.app
Website: https://sataday.app