Legal
Privacy Policy
Last updated August 2, 2026
Who we are
kaoshen.co is operated by an independent developer. For everything in this policy — questions, requests, complaints — the contact point is [email protected].
Under the EU and UK GDPR, we are the controller of the personal data described below. We are a small independent operation, not a company with a data protection officer; the contact address above reaches the person responsible.
What we collect
The site is usable without an account, and what we hold depends entirely on whether you sign in.
Before you sign in
- A random identifier
- A cookie called
anon_idholding a random, signed value. It is not derived from you or your device — it is a fresh random number — and it exists so the questions you answer before signing in are still yours afterwards. - Your practice
- Which questions you opened, which option you chose, and whether it was right. This is the product: without it there is no mistake log.
- Your IP address
- Attached to every request the site makes to its own API, and used two ways: as a short-lived key in an in-memory counter that caps what one network can do per day, and — for each free preview question claimed without an account — written into the database alongside that claim. It is an abuse control, not an analytics signal, and we do not use it to locate you. See section 8 for how long the stored copy lasts.
- Page views
- The path you visited, plus any campaign parameters that were in the link you followed (
utm_sourceand friends). Counted by our own server into our own database — and stored against the same random identifier as your practice, so a page-view history is linkable to it, and to your account if you later sign in. - Question images
- The service contains a reader that turns a picture of a question into text. It is not currently offered anywhere in the interface, but the endpoint behind it is still live: if an image reaches it, we keep a re-encoded copy of that image on our server together with the question text taken from it, filed under your random identifier. Pictures of schoolwork can hold more than a question — a name in a margin, a face — so we treat them as personal data. If you want yours removed, email us.
If you sign in with Google
- From Google
- Your email address, whether Google has verified that address, your Google account identifier, your display name, and the URL of your profile picture. That is the entire list, and the verification flag is on it because it decides how your account is linked. We never receive your Google password, and we ask for no access to your Gmail, Drive, contacts, or calendar.
- Your mistake log
- For each question you missed: what you chose, what was correct, the named error behind it, and the dates it is due to come back to you.
- Email records
- For each retest email, the provider's message identifier and whether it was accepted for delivery — so we can tell a bug from a bounce.
When you sign in for the first time, the practice attached to your anon_id is merged into your account, so nothing you did beforehand is lost.
What we never collect
This list is short on purpose, and it is a commitment rather than a description of our current appetite.
- Payment details. There is no paid plan, no card form, and no payment processor. Nothing on this site can charge you.
- Third-party analytics or advertising. No Google Analytics, no advertising pixel, no social media tag, no session recorder, no fingerprinting script. There is nothing on the page that reports to anyone but us.
- Phone numbers, postal addresses, precise location, biometrics, or government identifiers. We have no field for any of them.
- Special category data. We do not ask about health, race, religion, politics, or anything else the GDPR treats as sensitive, and the product has no use for it.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in California law. We never have, and there is no mechanism in the product by which we could.
Why we are allowed to (legal bases)
If you are in the EEA or the UK, the GDPR requires us to name a lawful basis for each use. Ours are:
- Performance of a contract
- Running your account and your mistake log. You asked for a product that remembers what you got wrong; remembering it is the service.
- Legitimate interests
- Keeping the free preview from being drained (the IP cap), counting page views on our own infrastructure, and keeping the site available and secure. We use the least data that works: an IP for a daily counter, a path for a page count.
- Consent
- Retest emails. Every one carries a one-click unsubscribe link, and opting out stops them without affecting anything else.
Where it is stored
The database and the application run on our own server rather than on a managed cloud, and the providers in the previous section are based in the United States. If you use the site from the EEA or the UK, your data therefore leaves your region.
We keep that transfer as small as it can be — the model provider never receives an identity, and the email provider never receives your practice — and where a provider offers the European Commission's standard contractual clauses as part of its terms, those terms apply to our use of it. If you would rather not have your data transferred, do not sign in; the site works without an account.
How long we keep it
We would rather be exact than reassuring, so here is the true state of it.
- The anon_id cookie
- Expires 90 days after it is set. Clearing your browser cookies ends it immediately.
- Your account and mistake log
- Kept for as long as the account exists, because a spaced-repetition schedule that forgets is not one. Deleted when you ask us to.
- Practice never attached to an account
- Retained with its random identifier. We are being straight with you: we have not yet built a job that deletes it on a schedule, so today it stays until we remove it by hand. When that changes this section will say what the schedule is.
- Stored IP addresses
- The same. The daily counter forgets an address within the day, but the copy written alongside a free preview claim has no expiry today and is removed only by hand. This is the part of the policy we are least happy with, and it is the next thing to fix.
- Question images
- Kept on our server with the question text taken from them, under the same terms — no automatic expiry, deleted on request.
There is no self-serve delete button yet either. Until there is, email [email protected] and we will do it — within 30 days, and usually the same week.
Your rights
Wherever you live, one email to [email protected] exercises any of these, free of charge, and we will not treat you any differently for asking.
- Know and access. A copy of what we hold about you.
- Correct. Fix anything inaccurate.
- Delete. Erase your account and the data attached to it.
- Port. Your data in a machine-readable file.
- Object and restrict. Tell us to stop a particular use, including anything we do on the basis of legitimate interests.
- Withdraw consent. Unsubscribe from retest email at any time, from the link in any of them.
If you are in the EEA or the UK you may also complain to your national data protection authority. We would rather you raised it with us first, but that right does not depend on our permission.
Children and teenagers
Kaoshen is built for students preparing for a college admission test, and it is not directed to children under 13.
- You must be at least 13 to use the site. We do not knowingly collect personal information from anyone under 13, and if we learn that we have, we delete it.
- If you are between 13 and 18, please read this policy with a parent or guardian and use the site with their permission.
- A parent or guardian can email [email protected] to see what we hold about their child, or to have it deleted.
Security
No site can promise it will never be breached, so instead here is what is actually in place: the site is served over HTTPS only; the identifying cookie is httpOnly, signed, and unreadable to page scripts; the application server reaches the database over a private network with a shared secret rather than over the public internet; and there is no payment data on the system to lose, because we never take any.
If you believe you have found a vulnerability, email [email protected]. We will not pursue you for reporting one in good faith.
Changes to this policy
When this changes, the date at the top changes with it. If a change is material — a new recipient of your data, a new category collected, a new purpose — we will say so on the site rather than quietly reissuing the page.
Contact
[email protected] reaches a person, not a queue. See also the Terms of Service.