What we store

Email delivery

NaviWeb uses Resend to deliver account email and optional package-completion messages. When a message is sent, Resend receives the recipient email address and message content so it can deliver and troubleshoot that email. Resend Free currently retains email data for 30 days. See the Resend privacy policy for provider details.

Optional learning email is off by default and can be changed in Settings. Account invitations and setup messages are sent only when needed and cannot be disabled in learning-email settings.

What practice areas do not collect

Shopping, banking, transport, health, and government-service examples are fictional. NaviWeb does not intentionally store passwords, card numbers, identity numbers, uploaded document contents, or medical records. Do not enter real sensitive information in practice fields or feedback.

Security

Authentication uses signed Supabase access tokens, HTTPS in production, row-level database policies, and server-side authorization for privileged actions.

Account removal

Administrators can suspend or delete accounts. Deleting an account also deletes its NaviWeb preferences, progress, resumable practice state, confidence ratings, feedback, and notification-delivery rows. Copies already processed by an email provider remain until that provider's retention period ends. A production privacy contact and self-service request flow should be added before public launch.