Privacy Policy
Last Updated: February 2026
At ExamLens Inc. ("ExamLens," "we," "us," or "our"), we are committed to protecting the privacy and security of our users. ExamLens is an AI-powered exam preparation platform designed for students ages 12 to 18 in Taiwan. This Privacy Policy explains how we collect, use, store, and share information when you use our mobile application, website, and related services (collectively, the "Services"). By accessing or using our Services, you agree to the practices described in this Privacy Policy. If you are under 18 years of age, please review this policy with your parent or legal guardian.
1. Information We Collect
We collect information to provide and improve our Services. The types of information we collect include:
Personal Information: When you create an account, we may collect your name, email address, date of birth (to verify age eligibility), school grade level, and profile information. If you sign in through a third-party provider (such as Apple or Google), we receive basic profile information from that provider.
Usage Data: We automatically collect information about how you interact with our Services, including questions answered, subjects studied, accuracy rates, study streaks, time spent per session, feature usage patterns, and performance analytics.
Device Information: We collect device-related information such as device model, operating system version, unique device identifiers, IP address, browser type, language preferences, and mobile network information.
Photos and Images: When you use our photo-to-question or AI solution features, you upload images of textbook pages, worksheets, handwritten notes, or exam papers. These images are processed using optical character recognition (OCR) and AI models to extract text and generate questions or solutions. Uploaded images are processed on our servers and are not shared with other users.
Payment Information: If you subscribe to the Pro Scholar plan, payment is processed through Apple App Store or Google Play Store. We do not directly collect or store your credit card numbers or bank account details. We receive only transaction confirmations and subscription status from the respective platform.
2. How We Use Your Information
We use the information we collect for the following purposes:
Providing Services: To deliver the core functionality of ExamLens, including AI question generation, instant solutions, the Wrong Answer Notebook, GSAT/CAP mock exams, performance analytics, and leaderboard features.
Improving Our AI: To train, evaluate, and improve our AI models, OCR accuracy, and question generation quality. When images or text are used for model improvement, they are anonymized and aggregated so that no individual user can be identified.
Analytics and Research: To analyze usage patterns, measure the effectiveness of our features, conduct academic research on learning outcomes, and develop new features. All analytics data is processed in aggregate form.
Communication: To send you important service-related notifications, such as account verification, security alerts, subscription reminders, and updates to our terms or policies. With your consent, we may also send promotional communications about new features or educational content. You may opt out of promotional communications at any time.
Safety and Moderation: To enforce our content policies, detect and prevent misuse of the platform, verify that uploaded images contain legitimate educational content, and maintain a safe learning environment for all users.
3. Data Storage and Security
We take the security of your data seriously and implement industry-standard measures to protect it:
Encryption: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher. Sensitive data at rest, including authentication tokens and personal information, is encrypted using AES-256 encryption.
Secure Infrastructure: Our servers are hosted on reputable cloud platforms with SOC 2 compliance, regular security audits, and physical access controls. Data is stored in data centers located in the Asia-Pacific region.
Authentication: We use secure token-based authentication (JWT) with platform-native keychain and keystore storage. Authentication tokens are refreshed regularly and can be revoked at any time. We support secure third-party sign-in through Apple and Google.
Access Controls: Access to user data within our organization is restricted to authorized personnel on a need-to-know basis. All access is logged and audited regularly.
Incident Response: We maintain an incident response plan and will notify affected users and relevant authorities in the event of a data breach, as required by applicable law.
4. Third-Party Services
We work with trusted third-party service providers to operate and improve our Services. These providers are contractually obligated to protect your data and may only use it for the specific purposes we define:
Analytics Services: We use analytics tools to understand how users interact with our app, measure feature performance, and identify areas for improvement. Analytics data is collected in aggregate and does not identify individual users.
Cloud Services: We use cloud infrastructure providers for data storage, computing, and AI model hosting. These providers adhere to strict security and privacy standards, including SOC 2 and ISO 27001 certifications.
Payment Processing: Subscription payments are handled entirely by Apple App Store and Google Play Store. We do not process, transmit, or store your payment card information. Please refer to Apple's and Google's respective privacy policies for details on how they handle payment data.
AI and OCR Services: We may use third-party AI model providers to process images and generate educational content. Data sent to these providers is limited to the minimum necessary for processing and is subject to strict data processing agreements.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5. Children's Privacy
ExamLens is designed for students ages 12 to 18. We are committed to protecting the privacy of young users and comply with applicable child protection regulations, including principles consistent with the Children's Online Privacy Protection Act (COPPA) and Taiwan's Personal Data Protection Act (PDPA).
Age Verification: During account registration, we collect date of birth information to verify that users meet our minimum age requirement of 12 years. Users under the age of 12 are not permitted to create accounts.
Parental Involvement: We encourage parents and legal guardians to be actively involved in their children's use of ExamLens. Parents can review their child's study progress, performance analytics, and account settings. For users under 16, we recommend that a parent or guardian review and consent to account creation.
Limited Data Collection: We collect only the minimum amount of personal information necessary to provide our educational services to young users. We do not collect sensitive personal information beyond what is required for account operation and learning functionality.
No Behavioral Advertising: We do not serve behavioral or targeted advertisements to users under 18. Any communications sent to minor users are limited to service-related and educational content.
If you are a parent or guardian and believe your child under 12 has provided personal information to ExamLens, please contact us at [email protected] and we will promptly delete the information.
6. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law:
Account Data: Your account information, study history, Wrong Answer Notebook entries, and performance data are retained for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law.
Uploaded Images: Images uploaded for OCR processing and AI question generation are retained on our servers for up to 90 days to facilitate re-processing and feature improvements, after which they are automatically deleted. You may request earlier deletion at any time.
Usage Logs: Anonymized usage logs and analytics data may be retained for up to 24 months for the purposes of service improvement and research.
Legal Requirements: We may retain certain data for longer periods if required to comply with legal obligations, resolve disputes, or enforce our agreements.
You can request deletion of your data at any time by contacting us at [email protected] or by using the account deletion feature within the app settings.
7. Your Rights
Under applicable data protection laws, including Taiwan's Personal Data Protection Act, you have the following rights regarding your personal information:
Right of Access: You may request a copy of the personal information we hold about you. We will respond to your request within 30 days.
Right of Correction: You may request that we correct any inaccurate or incomplete personal information. You can also update most of your information directly through the app settings.
Right of Deletion: You may request that we delete your personal information. Upon receiving a verified deletion request, we will delete your data within 30 days, except where retention is required by law or for legitimate business purposes.
Right to Data Portability: You may request a copy of your data in a structured, commonly used, and machine-readable format (such as JSON or CSV), including your study history, performance data, and Wrong Answer Notebook entries.
Right to Restrict Processing: You may request that we limit or stop processing your personal information in certain circumstances.
Right to Withdraw Consent: Where we rely on your consent to process personal information, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
To exercise any of these rights, please contact us at [email protected]. We may need to verify your identity before processing your request. If you are a minor, your parent or legal guardian may exercise these rights on your behalf.
8. International Data Transfers
ExamLens Inc. is based in Taipei, Taiwan. Our primary data storage and processing occurs within the Asia-Pacific region. However, in the course of providing our Services, your data may be transferred to and processed in countries outside of Taiwan, including for AI model processing and cloud infrastructure services.
When we transfer data internationally, we ensure that appropriate safeguards are in place to protect your information in accordance with applicable data protection laws. These safeguards may include data processing agreements with our service providers that incorporate standard contractual clauses and require equivalent levels of data protection.
By using our Services, you acknowledge that your data may be processed in jurisdictions outside of Taiwan where data protection laws may differ. We will always ensure that your data receives the same level of protection regardless of where it is processed.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes to this policy, we will:
Post the updated Privacy Policy on our website and within the app with a revised "Last Updated" date.
Notify you through an in-app notification or email at least 14 days before the changes take effect, if the changes are material.
Obtain fresh consent where required by applicable law, particularly for changes that affect how we process the data of users under 16.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our Services after the effective date of any changes constitutes your acceptance of the updated policy.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
ExamLens Inc.
Email: [email protected]
Address: Taipei, Taiwan
For data protection inquiries, please include "Privacy Request" in your email subject line. We aim to respond to all inquiries within 14 business days.
This Privacy Policy is governed by the laws of the Republic of China (Taiwan). Any disputes arising from or relating to this policy shall be subject to the exclusive jurisdiction of the courts located in Taipei, Taiwan.