Skip to main content

Privacy Policy

Last updated: June 2026

This Privacy Policy explains what personal data NewRoleKit collects, why we collect it, how we use it, and what rights you have. We are committed to handling your data with care and transparency.

NewRoleKit is operated by Ofir Ozon, based in Israel. Contact: ofirozon@gmail.com

1. What Data We Collect

Account data

When you register, we collect your email address, display name (optional), and a hashed password. We never store your password in plain text.

Learning progress

We record which topics you have completed and which quizzes you have passed. For guests (no account), this data is stored only in your browser's local storage and never sent to our servers. For registered users, progress is stored in our database and synced to your account when you log in.

Subscription and payment data

Payments are not yet enabled. When billing is introduced, payment processing will be handled by a third-party merchant of record (such as Paddle or Lemon Squeezy). We will never receive or store your card number. We will store your subscription status (free or pro) and the provider's transaction reference.

Analytics data

If you accept analytics cookies, we use PostHog to collect anonymised usage data: which pages you visit, which features you use, and general behaviour patterns. This data does not identify you personally and is used only to improve the product. If you decline, no analytics data is collected.

Technical data

Our infrastructure provider (Supabase / Vercel) may log standard technical data such as IP addresses and browser type for security and reliability purposes. We do not use this data for marketing.

2. Why We Collect It (Legal Basis)

3. How We Use Your Data

4. Who We Share Your Data With

We do not sell your personal data. We share it only with:

5. Data Storage and Security

Your data is stored on Supabase servers located in the United States (us-east-1 region). We use Row-Level Security (RLS) on all database tables, meaning your data is only accessible to your own account. Passwords are hashed and never stored in plain text. All connections use HTTPS/TLS encryption.

No system is completely secure. If we become aware of a data breach that affects your personal data, we will notify you within 72 hours by email.

6. How Long We Keep Your Data

7. Your Rights

Depending on where you are located, you may have the following rights regarding your personal data:

To exercise any of these rights, email ofirozon@gmail.com. We will respond within 30 days. If you are in the EU or EEA, you also have the right to lodge a complaint with your local data protection authority.

8. Cookies and Local Storage

NewRoleKit uses the following:

We do not use advertising, tracking, or social-media cookies.

9. Children's Privacy

NewRoleKit is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. International Transfers

Your data is stored in the United States (Supabase / AWS us-east-1). If you are located in the EU or EEA, this constitutes a transfer of data outside the European Economic Area. Supabase and Vercel maintain Standard Contractual Clauses (SCCs) with their EU customers as a transfer mechanism.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice on the platform at least 14 days before the changes take effect.

12. Contact

For any privacy-related questions or requests: ofirozon@gmail.com


This Privacy Policy was drafted in plain language as a starting point and has not yet been reviewed by a qualified lawyer. If you have users in the EU, obtain legal review to ensure full GDPR compliance before collecting personal data at scale.