Skip to content

Version 1.0

Privacy Policy

Effective 18 August 2026 · Algomatrix Enterprise

How we handle your thesis, your voice, and your personal data. It is written against what our code actually does today, not against what we intend it to do later — where the two differ, this page describes the weaker of them on purpose. Also available in Bahasa Malaysia, and in plain language as Your thesis is safe.

1. Who handles your data

EasyViva is operated by Algomatrix Enterprise, registered in Malaysia under SSM registration 202403131295 (CT0136618-D), at Palm Spring @ Damansara, No. 1, Jalan PJU 3/29, Section 13, Kota Damansara, 47810 Petaling Jaya, Selangor, Malaysia. We are the data controller for the purposes of the Personal Data Protection Act 2010, and we are responsible for the personal data described in this policy.

2. What we collect

Four kinds of data, and nothing else:

  • Your account. Your email address and password, or your name and email if you sign in with Google. Your field of study, your country and university, and the other details you give during onboarding.
  • Your thesis. The document you upload, and everything we derive from it — extracted text, passage embeddings, the question bank, argument map, and weak-spot analysis.
  • Your practice. The text transcript of what you say in mock viva and practice sessions, your scores, and your progress. Your voice is transcribed live and the audio is discarded; the optional self-view camera is not collected at all — see below.
  • Usage. Which pages you visit and which features you use, tied to your account id. Plus the ordinary technical data any website receives, such as your IP address and browser.

Payments are handled by Stripe. When you pay, your card details go to Stripe directly — we never see or store your card number. What we keep is the record of the purchase itself: what you bought, when, how much it cost, and the links to your Stripe receipt and invoice.

3. Your voice, and your camera

Mock viva sessions and spoken practice answers are transcribed as you speak, and the audio is not kept. It exists in memory for as long as it takes to turn it into text, and is then gone. There is no column in our database for it and no file written to storage — this is a property of how the system is built, not a policy we could quietly change.

What we do keep is the text transcript, which you can read in your session debrief and delete with the rest of your data.

A mock viva can also show you your own camera, so you can watch your posture while you answer. That is optional, off unless you switch it on, and it goes nowhere: the picture is drawn by your browser from your own webcam and is never sent to us, never sent to the service carrying the audio, never recorded, and never scored. It stops the moment you switch it off or close the tab. As with the audio, this is a property of how it is built — there is nothing for a video to be sent to.

4. How we use it

We use your data to run the service you paid for, specifically to:

  • analyse your thesis and generate your prep material — questions, argument map, weak spots;
  • run your practice sessions and let an examiner persona cite the right passage;
  • tune your panel to how vivas run where you study — the format differs by country, and your country is what tells us which one to rehearse;
  • score your answers, track readiness, and show you your progress;
  • manage your account, verify your email, and handle your purchase and support;
  • understand which features get used, so we can improve the product, and keep the service secure and working.

We do not sell your data, share it for advertising, or use your thesis to train AI models — ours or anyone else’s. We do not use your thesis to build features for other users.

About your university. We ask which institution you are at so we can say how many students use EasyViva, and where. If we ever publish that, it is a count — “students at 40 universities” — or at most a list of institution names. Your name is never attached to your institution publicly, and we do not display any university’s logo or claim it endorses us. We do not contact your university about you, and we do not tell it that you are a user.

5. Who else touches your data

We rely on the providers below. Each is bound to process your data only to deliver this service. This list is the complete set that handles your data today — not a representative sample.

  • Supabase — accounts, sign-in, the database holding your prep material and transcripts, and the emails that verify your address.
  • Cloudflare R2 — private storage for the thesis file you upload.
  • OpenAI — the language models that analyse your thesis and act as your examiners, the embeddings that let them cite it, and the speech-to-text and text-to-speech behind voice sessions. Your thesis text and your spoken answers both reach OpenAI. OpenAI does not use any of it to train or improve its models — that is the standing default on its API, not an option we switch on. It does keep what we send for up to 30 days so it can police misuse of its own service, and its staff may review material held in that window before it is deleted. That is the one point at which someone outside EasyViva could read your work; nobody inside EasyViva can, at any stage.
  • LiveKit — carries the live audio between your browser and the examiner during a session. It receives your account id and the audio stream, and not your name or email. Audio only: if you switch on the self-view, no video is published to LiveKit or to anyone else.
  • Trigger.dev — runs the background job that processes your thesis after upload.
  • PostHog — product analytics. See the section on analytics below.
  • Google — only if you choose “Continue with Google” to sign in.
  • Stripe — payments. When you buy a plan, Stripe receives your email address and your card details and takes the payment. Your card number goes to Stripe directly and never reaches us.

One disclosure we would rather make plainly than bury: background jobs run on Trigger.dev’s infrastructure, which means your thesis text passes through it in transit while it is being processed, even though it is not stored there.

6. Where your data is held

Every provider we use is based outside Malaysia, so your thesis, your transcripts, and your account details are stored and processed overseas. Where we can name the country, we name it:

  • Singapore — your account, your thesis text and everything derived from it (the question bank, the argument map, your session transcripts and scores). This is the Supabase database, and it is where the substance of your work sits.
  • United States — analytics, if you allowed it. Also where your thesis text and your spoken answers are sent for processing by OpenAI, and where our payment records sit with Stripe.
  • No single country — the uploaded file itself, and live session audio. Cloudflare R2 stores the file across its own global network and does not commit to one country for it; LiveKit carries session audio through whichever of its edge locations is nearest you, and keeps none of it. We would rather tell you this than name a country we cannot stand behind.

Trigger.dev, which runs the background job that processes your thesis, is United States based; your text passes through it while being processed and is not stored there.

We chose these providers for security and reliability, and each is contractually bound to protect your data to the standard this policy describes. By using EasyViva you consent to your data being transferred and processed outside Malaysia.

7. Analytics & cookies

We use PostHog to see which pages and features get used. We have deliberately turned off the intrusive parts: no session replay, no automatic capture of what you click, and no heatmaps. This matters more here than on most products, because a recording of your prep hub would be a recording of your unpublished thesis.

Analytics is tied to your account id, never your email or name, and signing out resets it. PostHog stores an identifier in your browser so it can tell one visit from the next. We also ask PostHog to discard your IP address; the country it implies is kept, the address itself is not.

None of it starts until you say yes, and we ask before anything loads. On your first visit you get one question at the bottom of the page, with two equally sized buttons. Until you answer it, PostHog is not loaded at all — not muted, not queued: the code is never fetched and no identifier is written into your browser. Answer no and we keep that answer, so you are not asked again on the next page or the next visit.

You can change your mind either way at Settings → Data & Privacy → Analytics. Turning it off stops collection immediately and clears the identifier. Your browser’s own tracking protection works too, and you can ask us to exclude you by email.

Because analytics is off until you allow it, we record your answer in two places so that all of it actually stops. Your browser holds a small cookie — the only one we set, and it contains nothing but the word “granted” or “denied”. If you have an account, the answer is saved to it as well, because some of what we measure is reported by background jobs that finish long after you have closed the tab (“the analysis is ready”, “the session was scored”), and there is no browser left for those to ask.

8. How we protect it

Your data is encrypted in transit. Your thesis file is held in a private store with no public access, reachable only through short-lived links issued to your account, and database access is restricted per user at the database itself so one account cannot read another’s work. Processing is automated — no member of staff reads your thesis in normal operation.

No system is perfectly secure. If a breach puts your personal data at significant risk, we will notify the Personal Data Protection Commissioner within 72 hours and tell you without undue delay.

9. Retention & deletion

You can delete your data at any time from your settings, and we will act on it. If you ask us by email instead, we will do it for you.

Beyond that, your document and everything derived from it are erased automatically: 30 days after your access window ends on a paid plan, or 90 days after upload on the free preview, which has no access window. Data you are finished with does not sit on our systems indefinitely, and the countdown to your own deletion date is shown in your settings.

We keep the billing records we are legally required to keep, and these survive deletion of your account.

10. Your rights

Wherever in the world you are, and at no charge for a reasonable request, you may ask us to:

  • tell you what personal data we hold about you, and give you a copy;
  • correct it if it is wrong or out of date;
  • delete it, and stop processing it for a particular purpose;
  • withdraw a consent you gave us, without affecting what we did before you withdrew it.

Most of this you can do yourself in your settings. For anything else, email us at the address below and we will respond within the period the law allows. These rights are the baseline we give everyone under Malaysia’s Personal Data Protection Act 2010; if the law where you live gives you more, you keep it.

11. If you are in the EEA or UK

EasyViva is run from Malaysia and we do not target the European market — we do not advertise there or price in euros or pounds. But you are welcome to use the service, and if you are in the European Economic Area or the United Kingdom, data- protection law there gives you rights on top of the ones above: to object to processing, to ask us to restrict it, and to data portability.

Our legal basis for processing your data is the contract to provide you the service, our legitimate interest in running and improving it, and your consent for analytics. Because our providers are outside Europe, using EasyViva means your data is transferred out of the EEA/UK, and by signing up you consent to that transfer.

You can exercise any of these rights at the contact below, and you may complain to your local data-protection authority if you are not satisfied.

12. Where this policy applies

EasyViva is available to students worldwide and is operated from Malaysia. This policy is written to Malaysian law, which governs how we handle your data; where your local law gives you additional rights, this policy does not take them away.

13. Changes to this policy

We will update this policy as the product changes. If a change materially affects how we handle your data we will tell you by email or in the app before it takes effect, and the date of the current version is shown at the top of this page.

14. Contact

Questions about your data, or a request to exercise any right above, go to privacy@easyviva.app. Data controller: Algomatrix Enterprise (202403131295 (CT0136618-D)), Palm Spring @ Damansara, No. 1, Jalan PJU 3/29, Section 13, Kota Damansara, 47810 Petaling Jaya, Selangor, Malaysia.

If we cannot resolve your concern, you may complain to the Personal Data Protection Commissioner of Malaysia, or, if you are in the EEA or UK, to your local data-protection authority.