Privacy Policy
Last updated: April 1, 2026
TolfexWorld ("we," "our," or "us") operates the TolfexWorld mobile application (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
1. Information We Collect
We may collect the following types of information:
- Account Information: When you create an account, we collect your display name, email address, and password (stored in hashed form).
- Usage Data: We collect data about how you interact with the app, including cases completed, XP earned, streak history, skill progress, and session timestamps.
- Device Information: We may collect device type, operating system version, unique device identifiers, and general network information to improve app performance.
- Cookies & Similar Technologies: Our website uses cookies to store user preferences, session tokens, and consent choices. See our cookie consent banner for details.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Track your learning progress, XP, and streak data
- Personalize your experience and recommend relevant case studies
- Communicate with you about updates, new features, or support requests
- Analyze aggregate usage trends to improve content quality
- Ensure the security and integrity of the Service
3. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties. We may share your data only in the following circumstances:
- Service Providers: With trusted third-party vendors who assist in operating the Service (e.g., cloud hosting, analytics), bound by confidentiality agreements.
- Legal Requirements: When required by law, regulation, legal process, or enforceable government request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction.
4. Data Security
We implement industry-standard security measures to protect your personal information, including encryption in transit (TLS/SSL), encrypted storage, access controls, and regular security audits. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention).
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing activities
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, please contact us at privacy@tolfex.world.
7. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete such information promptly.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable data protection laws.
9. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.
10. Cookies and Tracking Technologies
TolfexWorld and its website use cookies and similar tracking technologies to enhance your experience:
- Essential Cookies: Required for basic site functionality, such as session management and cookie consent storage. These cannot be disabled.
- Analytics Cookies: Help us understand how visitors interact with our website by collecting anonymous usage data (e.g., pages visited, session duration). We use this data to improve the Service.
- Preference Cookies: Store your settings and preferences (e.g., language, display options) so you do not need to re-enter them on each visit.
When you first visit our website, a cookie consent banner is displayed. You may accept or decline non-essential cookies. Your choice is stored in a cookie named ct_consent for up to 365 days. You can change your cookie preferences at any time by clearing your browser cookies and revisiting the site.
You may also configure your browser to block or delete cookies. Please note that disabling cookies may affect the functionality of certain features.
11. GDPR Compliance (EEA Users)
If you are located in the European Economic Area (EEA), the following additional rights and protections apply under the General Data Protection Regulation (GDPR):
- Legal Basis for Processing: We process your personal data based on: (a) your consent (e.g., when you accept cookies or submit a contact form); (b) performance of a contract (e.g., providing the Service to you); (c) compliance with a legal obligation; or (d) our legitimate interests (e.g., improving the Service), provided these do not override your fundamental rights.
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to Be Forgotten"): You may request deletion of your personal data, subject to legal retention requirements.
- Right to Restrict Processing: You may request that we limit how we use your data in certain circumstances.
- Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format.
- Right to Object: You may object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@tolfex.world. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.
Data Controller: TolfexWorld is the data controller responsible for your personal data as described in this Privacy Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the app or on our website and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.
13. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us: