Plain-language information
Privacy
NaviWeb stores only what is needed to provide accounts, preferences, and lesson progress.
What we store
- Your email address and authentication records in Supabase Auth.
- Your display name, role, account status, and accessibility preferences.
- Lesson start and completion records, including the lesson version.
- Administrator audit records for security-sensitive changes.
What practice areas do not collect
Shopping, banking, transport, health, and government-service examples are fictional. Do not enter real card numbers, passwords, identity numbers, medical information, or other sensitive data.
Security
Authentication uses signed Supabase access tokens, HTTPS in production, row-level database policies, and server-side authorization for privileged actions.
Account removal
Administrators can suspend or delete accounts. A production privacy contact and self-service request flow should be added before public launch.