Privacy Policy
Last updated: April 20, 2026
This Privacy Policy describes how CDI Prep (“we,” “our,” or “us”) collects, uses, and shares personal information in connection with:
- the marketing website at cdiprep.com (the “Site”), and
- the CDI Prep IELTS preparation platform — the web application where registered users take practice tests, receive scores, and manage their accounts (the “Platform”).
Together the Site and the Platform are referred to as the “Service.”
1. Information We Collect
a. Information you provide on the Site
When you submit the contact / review form on cdiprep.com, we collect the fields you enter:
- your name,
- your email address,
- the message you write, and
- the submission type you select (for example, “Leave a review / Share my score”).
b. Account information on the Platform
When you create a CDI Prep account — directly with an email and password, or through “Sign in with Google” or “Sign in with Telegram” — we collect and store:
- your first and last name (where provided),
- your email address,
- a cryptographic hash of your password (for email sign-ups),
- your Google account identifier, profile name, profile picture URL, and whether your Google email is verified (if you sign in with Google),
- your Telegram user ID and associated public profile fields (if you sign in with Telegram),
- your avatar image, if you upload one, and optional profile fields you choose to fill in,
- your role on the Platform (for example, student, moderator, or center manager) and whether your account is active.
c. Learning activity on the Platform
The core purpose of the Platform is to help you prepare for the IELTS exam. To do that, we collect and store:
- Test sessions: which practice tests you start, start/finish times, status, total questions, number answered, number correct, and section scores for Listening, Reading, Writing, and Speaking, as well as an overall band score (0–9).
- Answers: your submitted answers to individual questions, and whether each answer was scored correct.
- Writing submissions: the full text of essays you write (Task 1 and Task 2), along with word count, AI-generated feedback, and individual criterion scores (Task Achievement, Coherence & Cohesion, Lexical Resource, Grammatical Range & Accuracy) plus an overall band.
- Speaking submissions: the audio recording of your spoken responses, its duration, AI-generated feedback, and an AI-estimated band score.
d. Payment and subscription information
When you purchase a subscription or tariff on the Platform we store:
- the tariff purchased, start date, end date, and subscription status,
- transaction records including amount, payment method (for example, Click or Payme), status, provider-side transaction identifiers, and any error metadata returned by the payment provider.
We do not collect or store your full card number, CVV, or bank credentials. Those are entered on the payment provider’s own checkout and handled exclusively by them.
e. Device, browser, and log data
When you use the Service, our servers and hosting provider may automatically record request metadata such as IP address, user-agent string, requested URL, HTTP status, timestamps, and an internal request ID used for debugging.
f. Information stored in your browser (Platform)
To let you pause and resume practice tests, the Platform stores the following locally in your browser’s localStorage /sessionStorage, keyed to a test session ID:
- your in-progress multiple-choice and writing answers,
- bookmarked questions and your annotations/notes on passages,
- timing state (elapsed time per section, timer mode) and which listening audio parts have been played,
- display preferences (font scale, light / dark / high-contrast theme),
- a cache of listening-audio references, and
- a session-integrity flag used to detect tampering.
This data stays on your device and is submitted to our servers only when you submit your answers. You can clear it at any time through your browser’s site-data settings.
g. What we do NOT collect
The Service does not use advertising cookies, ad-network pixels, third-party web-analytics trackers, session-replay tools, or behavioral-profiling tools. We do not sell personal information.
2. How We Use Information
- to create and maintain your account and sign you in (via email / Google / Telegram),
- to deliver IELTS practice tests, score your answers, and generate AI feedback on your written and spoken responses,
- to track your progress over time and show you your history and band scores,
- to process purchases, activate subscriptions, and keep a record of transactions for accounting and dispute resolution,
- to respond to messages, reviews, and support requests sent through the contact form or support channels,
- to operate, secure, and troubleshoot the Service, including abuse and fraud prevention,
- to comply with legal obligations.
3. Third-Party Services and Data Sharing
We share the minimum information needed with the following providers. Each one processes data under its own privacy terms.
- Google — Sign-in (OAuth): if you use “Sign in with Google,” Google shares your email, verified-email flag, name, given name, family name, profile picture, and locale with us. See the Google Privacy Policy.
- Google — Gemini API (AI scoring): when you submit a Writing or Speaking task, the content of your submission — your essay text or your audio recording, together with the task prompt — is sent to Google’s Gemini API so it can return structured feedback and an estimated band score. Please do not include sensitive personal information in your essays or recordings that you do not want processed by this provider.
- Google Forms: contact-form submissions on the Site (cdiprep.com) are forwarded to a Google Form we own so we can review them in one place.
- Google Fonts: the Site and Platform load web fonts from Google. When your browser fetches a font, Google may receive your IP address and user-agent as part of the normal HTTP request.
- Telegram: (a) if you use “Sign in with Telegram,” the Telegram Login widget, loaded from telegram.org, returns your Telegram user ID and associated public profile fields to us; (b) selected feedback and support notifications may be forwarded to our internal Telegram support chat through the Telegram Bot API.
- Cloudflare R2 (object storage): files you or our moderators upload — avatar images, your speaking-module audio recordings, listening audio clips, and other attachments — are stored in Cloudflare R2 and served to authorized users via time-limited (presigned) URLs.
- Payment providers (Click & Payme): when you purchase a subscription, you are redirected to or interact with Click (click.uz) or Payme (payme.uz), which handle card data on their own infrastructure. We receive back transaction identifiers, status, amount, and error details, which we store on your account.
- Hosting & infrastructure providers: our servers, database, and network are operated on commercial hosting infrastructure that necessarily processes traffic to and from the Service.
We do not sell personal information, and we do not share it with advertisers or data brokers. We may disclose information when required by law, to enforce our terms, or to protect the rights, property, or safety of CDI Prep, our users, or others.
4. Cookies and Sessions
The Platform signs you in using a JSON Web Token (JWT) rather than a traditional session cookie; depending on your browser and the authentication provider, a small number of strictly necessary cookies or storage items may be set to keep you logged in and to maintain OAuth state. The Service does not set advertising or cross-site tracking cookies, and does not run a cookie-consent banner because only essential storage is used.
5. Data Retention
- Account & learning data: retained while your account is active so you can see your history and progress. Most records in our database use soft-delete, meaning they are marked as deleted and later purged.
- Writing essays & speaking audio: retained with your test history so you can revisit feedback. You can request deletion at any time using the contact details below.
- Transaction records: retained as long as needed for accounting, tax, and dispute-resolution purposes.
- Contact-form submissions: retained in our Google Form responses for as long as we reasonably need them to respond or keep a record of feedback/reviews.
- Server logs: retained for a short operational window for security and debugging.
6. Security
Traffic to and from the Service is transmitted over HTTPS. Passwords are stored only as cryptographic hashes, never in plain text. Access to files in object storage is granted through short-lived presigned URLs. We rely on our infrastructure providers’ security controls for data at rest. No online service can be guaranteed 100% secure; if you believe your account or data may have been compromised, contact us immediately.
7. Your Rights and Choices
Depending on where you live (for example, under the GDPR in the EU/UK, or similar laws elsewhere), you may have the right to:
- access the personal data we hold about you,
- correct inaccurate or incomplete data,
- request deletion of your account and associated data (including essays and speaking recordings),
- request a copy of your data in a common machine-readable format,
- object to or restrict certain processing, and
- withdraw consent where processing is based on consent.
Because self-service account-deletion and data-export tools are not yet exposed in the Platform UI, the easiest way to exercise any of these rights today is to email us at [email protected]. You can also avoid using optional features (for example, by not submitting the contact form or by not attempting Speaking / Writing tasks you don’t want analyzed by our AI scoring provider).
8. Children’s Privacy
The Service is intended for people preparing for the IELTS exam and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information through the Service, contact us and we will delete it.
9. International Users
CDI Prep is operated from Uzbekistan. If you use the Service from outside Uzbekistan, your information will be transferred to and processed in Uzbekistan and in the countries where our third-party providers (Google, Cloudflare, Telegram, and our payment partners) operate, which may include the United States and other countries outside your own. Where required, we rely on appropriate safeguards for such transfers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date at the top of this page. Material changes will be highlighted on the Service when appropriate.
11. Contact Us
If you have any questions about this Privacy Policy, want to exercise any of the rights above, or would like us to delete your account and associated data, contact us at [email protected].