Privacy Policy

Last updated 18 September 2026

This Privacy Policy explains how Moga’em (“we”, “us”, “our”), operating the website mogaem.com and the BTEC Assessor product, processes personal data. It covers signed-in workspace features and the free public PDF tools. It does not invent features we do not operate.

1. Who we are

Moga’em provides web-based assessor tools for BTEC teachers and coordinators, including criteria decoding, evidence mapping, evaluation workflows, season credits, and related workspace features.

Contact for privacy requests: support@btec-assessor.com.

2. Scope of this policy

This policy applies to visitors of mogaem.com, users who create accounts, administrators of the service, and anyone who uses our public PDF tools.

The product is available in English and Arabic (RTL). Your interface language preference may be associated with your session or profile.

3. Account and authentication data

When you sign up or sign in, we process authentication data through Supabase Auth, including your email address and a hashed password (we do not store plaintext passwords).

We use session cookies managed by Supabase SSR so you can stay signed in while using protected workspace routes. These cookies are necessary for the signed-in product to function.

After registration, our systems may confirm or activate the account using server-side Supabase administration helpers so you can use the product without a separate confirmation step in some environments.

4. Profile information

You may optionally add profile details such as full name, phone number, organisation, and job title. We store these in your profile record in our database so they appear in your account settings.

Profiles also store role information used by the product (for example teacher, internal quality assurance / IQA, or admin), locale preference when set, and billing-related fields described below.

5. Workspace content you upload or create

Signed-in teachers can create submissions and related assessment records. Depending on the tools you use, this may include:

  • Submission metadata such as student registration number, student name, teacher name, unit type (PSA/AAB), aim details, unit code and title, assignment title, and important dates.
  • Uploaded student work files (PDF, DOC, or DOCX) stored in Supabase Storage (student-work bucket) and linked to your submission.
  • Specification documents for units you add to your own library (unit specification book, assignment brief, delivery guide) stored in Supabase Storage (spec-library bucket) and isolated to your account.
  • Decoded criteria results, evidence mapping results and teacher review decisions, on-screen review prompt sets, evaluation criteria JSON, evaluation text, filled assessment-record templates, knowledge notes, AI chat messages, and evaluation/consistency check records associated with your account.
  • Credit account balances and credit transaction history for season packs and on-demand top-ups.

6. Artificial intelligence processing

Assessor features such as Criteria Decoder, Evidence Mapper, On-Screen Review, evaluation assistance, and in-product AI chat send relevant text extracted from your uploaded materials and prompts to AI models through OpenRouter (for example models such as openai/gpt-4o), via our application backend and/or a Supabase Edge Function proxy.

The purpose is to return decoded criteria, evidence locations, on-screen review questions, evaluation drafts, or chat replies inside your workspace. Model providers process the content you submit in order to generate those outputs. Do not upload materials you are not authorised to process.

The public PDF toolkit described below does not send PDF contents to our servers or to AI providers.

7. Billing and payments

Subscriptions and credit purchases are processed by Polar.sh. We store Polar customer and subscription identifiers, subscription tier and status, and related credit provisioning metadata on your profile and in credit ledgers so we can unlock features and grant credits after checkout.

Payment card details are handled by Polar (and its payment processors). We do not store full payment card numbers on our servers. Polar may send you checkout or receipt emails related to a purchase.

Webhooks and post-checkout sync endpoints update your subscription and credit state after purchase.

8. Public PDF tools (no server storage)

Our free public PDF splitter/trimmer and merger run entirely in your browser using client-side libraries. PDF files you select for these public tools are not uploaded to our servers, are not written to our database, and are not analysed by our AI pipelines.

In the signed-in workspace PDF trimmer, a trimmed file may be kept temporarily in your browser’s IndexedDB only on your device so it can be passed to the Criteria Decoder upload flow. That handoff is local to your browser unless you later upload the file into a workspace feature that stores it.

9. Analytics and usage measurement

We use Plausible Analytics on mogaem.com to understand aggregate page traffic in a privacy-oriented way.

If a Microsoft Clarity project identifier is configured for the deployment, Clarity may collect usage analytics such as page interactions and session insights. When enabled, Clarity’s own privacy terms also apply to that processing.

If a Sentry project identifier is configured, we send application error diagnostics (stack traces and related technical metadata) to Sentry so we can fix outages. Sentry is not used for advertising.

We do not sell the contents of teacher or learner files to third parties for advertising.

10. Hosting and processors

We use infrastructure and processors needed to run the product, including Vercel (application hosting), Supabase (authentication, PostgreSQL database, file storage, and Edge Functions), Polar.sh (checkout and subscriptions), OpenRouter (AI model routing), Plausible (analytics), optionally Microsoft Clarity, and optionally Sentry (error monitoring).

These providers process data on our instructions to deliver the service. Exact data centre regions depend on each provider’s configuration for our project.

11. Administration access

Authorised administrators may access operational areas of the product (for example users, billing status, usage, content, and configuration) to support customers, prevent abuse, and keep the service running.

IQA-capable roles may access compliance-oriented workspace tools according to product permissions.

12. Cookies and similar technologies

Essential cookies and similar storage are used for authentication sessions (Supabase) so protected pages know who you are.

The site is served in English and Arabic under URL prefixes (/en, /ar). next-intl middleware may store a locale preference cookie so language selection can persist.

Browser local storage / IndexedDB may be used for short-lived client-only PDF handoff in the workspace trimmer, as described above.

Analytics scripts may set or read their own identifiers according to each analytics provider’s design (Plausible is generally cookie-light; Clarity, when enabled, may use cookies or similar technologies).

14. Retention and deletion

We retain account, workspace, billing, and credit records while your account is active and for a reasonable period afterward as needed for backups, dispute resolution, fraud prevention, and legal compliance.

The product does not currently offer a self-serve account deletion button. To request access, correction, export, or deletion of personal data we control, email support@btec-assessor.com. We may need to verify your identity before fulfilling a request. We aim to complete verified deletion requests within 30 days, except where we must retain records for billing, fraud prevention, or legal compliance.

Public PDF tool files are not retained by us because they are not uploaded.

15. Security

We use industry-standard protections appropriate to a hosted web application, including encrypted transport (HTTPS), access-controlled storage, and separation of privileged server keys from the browser.

No method of transmission or storage is perfectly secure. Please use a strong unique password and share workspace access only with people who are allowed to see learner materials.

16. Children

The service is designed for teachers and education professionals. It is not directed at children. Learner materials may include personal data about students; teachers are responsible for having a lawful basis and institutional permission to upload that material.

17. International transfers

Because we use cloud processors, personal data may be processed in countries other than where you live. We rely on appropriate contractual and technical measures offered by our processors.

18. Changes to this policy

We may update this Privacy Policy when the product or legal requirements change. The “Last updated” date at the top will change when we do. Continued use of the service after an update means you accept the revised policy where permitted by law.

19. Contact

Questions about privacy: support@btec-assessor.com. Website: https://mogaem.com.