Last updated July 8, 2026
Privacy Policy
This Privacy Policy explains what BrightSAT collects, why we collect it, how long we keep it, who we share it with, and the rights you can exercise. It applies to brightsat.today and all study features linked from that domain.
1. Who we are
BrightSAT ("BrightSAT", "we", "us", "our") operates brightsat.today, an independent digital SAT preparation service for individual learners. BrightSAT is operated by Amangeldi Bekaidar, based in Almaty, Kazakhstan, and is not affiliated with, endorsed by, or sponsored by College Board.
For any privacy request, email amangeldibekaidar00@gmail.com from the address associated with your account. We aim to respond within 30 days.
2. What BrightSAT does
BrightSAT provides Bluebook-style Digital SAT practice tests, a question bank with per-choice explanations, targeted practice, vocabulary tools, score estimates on the 400–1600 scale, and study analytics. Free features are available with a confirmed-email account. A paid Premium tier unlocks deeper analytics and additional study features.
3. Information we collect
What we do NOT collect. BrightSAT does not collect: government-issued IDs, biometric identifiers, precise location data (GPS), contact lists or address books, health data, sexual-orientation data, political opinions, or full payment-card numbers. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
Account data. When you create an account we collect your email address, a hashed password (or your provider identifier if you sign in with Google), display-name/profile information you choose, and account timestamps (created, last sign-in, email-confirmation).
Practice data. As you use the service we collect answers you submit, per-question timing, marked and highlighted state, module routes taken during full-length tests, computed score estimates, question-bank progress, vocabulary study state, and any notes or summaries generated on your behalf.
Communications data. Support emails, in-product messages, and password-reset events.
Billing metadata. If you subscribe to Premium, our payment provider (Stripe) processes the transaction and returns to BrightSAT: customer identifier, subscription status, plan, renewal and cancellation events, country for tax, receipt identifiers, and refund/chargeback events. BrightSAT never receives or stores your full card number, CVV, or bank credentials.
Device and technical data. Server access logs, IP address, browser and device type, operating system, viewport, referrer, error traces, and locale. Used for security, abuse prevention, and debugging.
Cookies and local storage. Session cookies, CSRF tokens, and small amounts of local/session storage used to keep you logged in, remember study progress mid-attempt, and enforce rate limits. See section 5.
4. How we use information
- Provide the service: authenticate you, deliver practice tests, save your progress and answers, compute score estimates, generate explanations, and show analytics.
- Process subscriptions: create and update Premium access based on payment-provider events, handle refunds, and detect billing fraud.
- Secure the service: enforce rate limits, detect scraping and account abuse, investigate incidents, and comply with lawful requests.
- Communicate: send transactional email (verification, password reset, receipts, security alerts) and reply to support. We do not send marketing email without opt-in consent where required by law.
- Improve the product: analyze aggregated usage to fix bugs, prioritize features, and improve question quality.
- AI model training: BrightSAT does not use your account, practice, or payment data to train its own AI models. We also do not permit our AI providers (Anthropic and OpenAI) to train their models on our users' data — this is contractually enforced through enterprise agreements with zero data-retention terms.
5. Cookies and similar technologies
BrightSAT uses first-party cookies and browser storage only. We do not use advertising cookies or third-party tracking pixels.
- Authentication cookies (Supabase session): keep you signed in. Duration: up to 30 days or until sign-out. Opt out: sign out or clear browser data.
- CSRF and security tokens: protect form submissions against forged requests. Duration: session. Opt out: not recommended; blocking these breaks logins.
- Local storage for study state: remembers your position in a practice test and unsaved answers. Duration: until you complete or clear the attempt. Opt out: clear site data in your browser.
- Product analytics (aggregate, first-party): counts page views and study events to guide product decisions. Duration: up to 14 months. Opt out: enable your browser's tracking-protection or block first-party analytics for brightsat.today.
6. Third-party processors
BrightSAT uses the following processors under written agreements. Their processing of your data is governed by their own privacy notices.
- Supabase — authentication, Postgres database, and file storage. Privacy: https://supabase.com/privacy
- Stripe — subscription checkout, payment processing, and tax handling. Privacy: https://stripe.com/privacy
- Anthropic — AI features (explanations, summaries). Enterprise agreement with zero data retention; not used for training. Privacy: https://www.anthropic.com/legal/privacy
- OpenAI — AI features (explanations, summaries). Enterprise agreement with zero data retention; not used for training. Privacy: https://openai.com/policies/privacy-policy
- Vercel (or the hosting provider disclosed at the time) — application hosting, CDN, and DDoS protection. Privacy: https://vercel.com/legal/privacy-policy
- Email delivery provider (used for verification, password reset, receipts). Privacy: available on request.
7. Data retention
We keep personal information only as long as needed to run the service, meet legal or tax obligations, and defend or exercise legal claims.
- Account records: kept while the account exists, plus up to 30 days after account deletion to allow reversal of accidental deletions and satisfy backup expiration.
- Practice attempts, answers, timing, and score estimates: kept while the account exists. Anonymized aggregates may be kept indefinitely for question-quality analysis.
- Billing records (Stripe events, receipts, refund history): kept for up to 7 years to satisfy tax and consumer-protection recordkeeping.
- Server access logs: kept for up to 30 days for security and debugging, then deleted or aggregated.
- Support correspondence: kept for up to 2 years after the last message.
- Backups: encrypted backups may retain deleted records for up to 30 days before automatic expiration.
8. Your rights
You may access, correct, export, restrict, or delete your BrightSAT data. To exercise any of these rights, email amangeldibekaidar00@gmail.com from your account email. We may ask you to confirm control of the account. We aim to respond within 30 days and will explain in writing if we deny a request.
You can also close your account from the Data Deletion page. Some billing, security, or legal records may be retained after account deletion where required by law.
You will not be discriminated against for exercising your rights.
9. International transfers
BrightSAT and its processors may store or process your personal information in countries other than yours, including the United States and the European Economic Area. Where we transfer personal information out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (with the UK addendum where applicable) or on the recipient being located in a country recognised as providing adequate protection.
10. Children and students
BrightSAT is designed for high-school-age SAT test-takers. It is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and believe a child under 13 has created an account, email amangeldibekaidar00@gmail.com and we will delete the account and its data.
In the European Economic Area and the United Kingdom, users under 16 may need a parent or guardian to consent on their behalf. Parents and guardians may exercise privacy rights on behalf of a minor by writing to amangeldibekaidar00@gmail.com from an email address they can prove ownership of.
11. Security
We use TLS/HTTPS for data in transit and provider-managed encryption at rest. Passwords are stored as salted hashes by Supabase; BrightSAT never sees your plaintext password. Full payment-card details never touch BrightSAT servers — they are handled by Stripe. Access to production data is limited to the operator and is audit-logged.
No online service can be perfectly secure. If we discover a breach affecting your personal information, we will notify affected users and the appropriate authorities as required by applicable law, without undue delay.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes we will provide additional notice — for example a banner on the site or an email to your account address — before the change takes effect. Please review this page periodically.
13. Contact
For any question, request, or complaint about your personal information, email amangeldibekaidar00@gmail.com. We aim to respond within 30 days.
14. Notice to European users (EEA / UK)
If you are located in the European Economic Area or the United Kingdom, this section applies to you in addition to the sections above.
Controller. BrightSAT is the controller of your personal information for the purposes of the GDPR and the UK GDPR. Contact: amangeldibekaidar00@gmail.com.
Legal bases. We rely on the following legal bases under Article 6 GDPR: performance of the contract to deliver the service you signed up for (account, practice, Premium billing); legitimate interests to keep the service secure, prevent abuse, and improve product quality (balanced against your rights); consent for any optional analytics or communications where required by local law; and compliance with legal obligations (tax, consumer protection, law-enforcement requests).
Your rights. You have the right to access, rectify, erase, restrict, port, and object to processing of your personal information, and to withdraw consent at any time. You also have the right to lodge a complaint with your local data-protection authority. In the EEA, you can find your authority at https://edpb.europa.eu/about-edpb/board/members_en. In the UK, contact the ICO at https://ico.org.uk/make-a-complaint.
Automated decisions. BrightSAT does not make decisions producing legal or similarly significant effects on you using solely automated processing.
International transfers. See section 9. We rely on Standard Contractual Clauses and, where relevant, the UK addendum for transfers outside the EEA/UK.
15. Notice to California users
If you are a California resident, this section supplements the sections above under the California Consumer Privacy Act (as amended by the CPRA).
Categories of personal information we collect. Identifiers (email, IP, device identifiers); commercial information (subscription plan, payment history via Stripe); internet or other electronic-network activity (log data, browsing within the service); geolocation data (approximate, from IP only); and inferences (score estimates and study analytics derived from your practice).
Sale and sharing. BrightSAT does not sell personal information and does not share personal information for cross-context behavioral advertising.
Your rights. You have the right to know, delete, correct, and limit certain uses of your personal information, and the right not to be discriminated against for exercising those rights. To exercise these rights, email amangeldibekaidar00@gmail.com from your account email. You may designate an authorized agent to submit a request on your behalf; we will require written proof of the authorization.
Retention. See section 7.
16. Notice to users in the Republic of Kazakhstan
If you are a resident of the Republic of Kazakhstan, this section applies to you in addition to the sections above.
BrightSAT processes personal data in accordance with the Law of the Republic of Kazakhstan No. 94-V dated 21 May 2013 "On Personal Data and Its Protection" and its subsequent amendments. As a resident of Kazakhstan you have the right to obtain information about the processing of your personal data, to require correction of inaccurate data, to require blocking or destruction of data processed in breach of law, to withdraw consent where consent is the legal basis, and to challenge processing before the authorized body for personal-data protection.
To exercise these rights, email amangeldibekaidar00@gmail.com from your account address. You may also file a complaint with the authorized body for personal-data protection under the Ministry of Digital Development, Innovations and Aerospace Industry.
17. Legal review
This page is written to be readable rather than exhaustive. It is not legal advice. If you operate BrightSAT from a specific jurisdiction or add a feature that changes the data flows described above, have this policy reviewed by a qualified lawyer.