Leveling Tower

Legal

Privacy policy

Last updated · 31 August 2026

This policy sets out which personal data Leveling Tower collects, why, who it is shared with and how to exercise your rights. It applies to the levelingtower.com website.

Disclaimer

This page describes the collection, use and disclosure of your personal data when you use Leveling Tower. We do not share your data with anyone except as described in this policy. By using the service, you agree to the collection and use of your information in accordance with this policy.

Data controller

The Leveling Tower website (levelingtower.com) is published by Oikawa Corporation (trading name) - Vincent Sacau, controller of your personal data.

For any question about your data: levelingtower@gmail.com.

Data we collect

We only collect what the service needs to work:

  • Account: email address, username, display name, password (stored hashed, never in plain text), interface language, display preferences and time zone, detected automatically from your browser to work out your streaks and daily resets.
  • Third-party sign-in (Google): the account identifier, email address and name provided by the provider. We access nothing else on those accounts.
  • Learning data: declared level, goals, progress, quiz results, review history, streaks and statistics.
  • Payment: payments are handled by Stripe; your card numbers never pass through our servers and are never stored there. We keep your Stripe customer identifier, your subscription status and your billing history.
  • Technical logs: error and incident logs, needed for diagnosis. No audience measurement or browsing analytics tool is used.
  • IP address: used only to limit repeated sign-in and email attempts, to prevent abuse. It is never linked to your profile, and reaches our error-tracking tool in hashed form only.

Why we use them

Each processing operation rests on a legal basis under the GDPR:

  • Providing the service (account, progress, subscription, support) - performance of the contract.
  • Billing and accounting - performance of the contract and legal obligations.
  • Account emails (address verification, password reset and change, welcome) - performance of the contract. They are required for the account to work and cannot be turned off while it exists. We send no promotional email and never use your address on behalf of third parties.
  • Security: abuse prevention, limits on repeated attempts, technical logs - legitimate interest.
  • Diagnosing errors and improving the service from technical logs - legitimate interest.

We neither sell nor rent your personal data to anyone.

Which data is required

An email address and a password are required to create an account: without them the service cannot be provided. Other profile details (display name, level, goals) are optional and can be changed at any time; they only serve to tailor your learning path.

Processors and recipients

We rely on providers that process data on our behalf:

  • Supabase - database hosting and authentication.
  • Google - sign-in with a Google account, for users who choose it. Google acts as an independent controller for the Google account itself.
  • Stripe - payment processing and billing.
  • Resend - sending account-related emails.
  • Sentry - collecting technical errors.
  • Vercel - application hosting.

Your data is never sold, transferred to others, or used for advertising.

Transfers outside the European Union

Some of our providers are based in the United States or transfer data there: Stripe, Google, Vercel, Sentry and Resend. Supabase, which hosts your data, is based in the European Union. These transfers outside the EU are governed by:

  • Stripe and Google are certified under the EU-U.S. Data Privacy Framework, recognised by an adequacy decision of the European Commission.
  • Vercel, Sentry and Resend apply the European Commission's standard contractual clauses, set out in their data processing agreements.

You can obtain a copy of these safeguards by writing to us at the contact address given in this policy.

How long we keep data

Account and learning data is kept for as long as your account exists, then deleted or anonymised within 30 days of it being closed.

Billing data is kept for ten years, in line with accounting obligations.

Technical logs are kept for at most thirty days.

IP addresses used for attempt limiting are kept for the length of the limiting window, from a few minutes to one hour depending on the operation, then erased automatically.

Requests to exercise your rights (access, rectification, erasure...) are kept for three years for evidence purposes, independently of the deletion of the data they relate to.

Your rights

Under the General Data Protection Regulation and the French Data Protection Act, you have the following rights:

  • Right of access: obtain a copy of the data concerning you.
  • Right to rectification: correct inaccurate data.
  • Right to erasure: request deletion of your data.
  • Right to portability: receive your data in a reusable format.
  • Right to restriction: request that a processing operation be temporarily suspended.
  • Right to object: object to certain processing.

To exercise these rights, write to us at levelingtower@gmail.com from the email address linked to your account.

You can also close your account directly from your settings: the associated data is then deleted or anonymised within the period stated above.

You also have the right to lodge a complaint with the French data protection authority (cnil.fr).

Cookies and trackers

The site only uses cookies that are strictly necessary for it to work: keeping you signed in, remembering your language and display preferences.

No advertising cookies and no third-party analytics are used. No prior consent is therefore required.

Security

Exchanges with the service are encrypted (TLS), passwords are never stored in plain text, and data access is scoped per user at the database level.

No system being infallible, we would notify you without undue delay in the event of a data breach likely to affect you, in accordance with the GDPR.

Minors

The service is not intended for children under 15 without the consent of a holder of parental authority. If you believe a minor has provided us with data without that consent, contact us so we can delete it.

Changes to this policy

We may update this policy to keep up with regulatory changes. The last-updated date appears at the top of the page; in the event of a material change, we will inform you through the service or by email.

Contact

For any question about this policy or about your personal data, write to us at levelingtower@gmail.com.