Legal
Privacy
UniGenius is operated by Lightcube. This page explains what the product stores and why.
Who controls the data?
Lightcube is the controller for data collected on this site. Contact ops@lightcube.app for privacy questions or requests.
Accounts and purchases
When you create an account, we store your email address, the account timestamps and the exam surface where you signed up. If you set a password, we store a one-way password hash rather than the password. If you use Google sign-in, we also store the Google account identifier and any name or profile-photo URL Google provides. A signed-in session is represented by an HttpOnly cookie.
If you buy access, we store the purchase, product, amount, currency, status, buyer email and the Stripe checkout, payment and customer identifiers needed to grant access, handle refunds and support the transaction. Stripe processes payment details; UniGenius does not receive your full card number.
Learning and saved results
Anonymous learning uses a signed session cookie. A diagnostic run can store its platform, selected modules, questions, responses, timing and computed result before an account is required. If you choose to save an ESAT result, the run is linked to your account and its associated attempts are linked to the same account.
Saving a result uses a short-lived, HttpOnly claim cookie. It expires after 10 minutes, is restricted to the ESAT API path, and is cleared after the handoff. The server stores a hash of the receipt rather than the receipt value. Optional product measurement is recorded only after you accept its consent prompt; that record contains the consent version and time plus an activation event with no direct contact fields, but it can be linked to the diagnostic run.
Reminders, cookies and analytics
If you request a deadline reminder, we store your email address, the reminder requested, the consent wording version and signup time in private storage. No deadline-reminder email is currently sent. Password-reset and paid-course welcome messages may be sent through Resend when transactional email is enabled. We do not sell personal data.
Guest and standard signed-in account session cookies expire after 180 days. A checkout-created authenticated session expires after 30 days. Learning diagnostic session cookies expire after 30 days, and the Google sign-in state cookie expires after 10 minutes. Expiry stops a cookie being accepted. Session and claim records are not currently removed by an automatic cleanup job, and we do not currently implement an automatic deletion schedule for account, purchase, diagnostic, attempt or reminder records. Vercel Analytics is separate from the consent-gated product measurement described above and may process analytics data when enabled on the deployment.
Service providers
Vercel hosts the site, may process request and analytics data, and stores reminder leads in private blob storage. Neon hosts the application database. Google handles optional sign-in and returns the verified account identity. Stripe handles checkout and payment processing. Resend sends password-reset and paid-course welcome email when that feature is enabled.
Access and deletion
There is no self-service account deletion control today. You can ask us to access, correct or delete account, learning, reminder or other personal data, and you can withdraw reminder or measurement consent. Email ops@lightcube.app and include the address concerned and the request you want us to handle. Requests are handled manually; payment, security, provider or other records may need to be retained where applicable, and we will explain the scope.