Privacy policy
Last updated 11 September 2026. This is written in plain language on purpose, and it describes what the site does — not what a site like it might do.
Who runs this
JLPT Open Catalogue at jlptopencatalogue.com is run by an individual, Kyle Pastor. For anything about your data, write to kyleanthonypastor@gmail.com. It is not affiliated with the Japan Foundation, JEES, or any publisher whose work a study deck accompanies.
What is collected, and why
If you create an account
You can sign in with Google or with an email address and password. Either way the account holds your email address, a display name, and — if you used Google — the profile picture Google provides. A password is stored only as a one-way hash; the site never holds the password itself. You may add a self-reported JLPT level, which is shown beside your comments.
With Google sign-in the site requests only your name, email and picture. It does not read your contacts, calendar, Drive, or anything else in your Google account.
Your study activity
The site records which questions you answer, whether you got them right and which option you chose; your spaced-repetition schedule for questions, vocabulary and study decks; questions you bookmark; and kanji you save. This is what makes the site work — it is how reviews come back at the right time and how your progress page is built. If you are signed in, it is tied to your account so it follows you between devices.
If you are not signed in
Your schedule and progress live in your own browser’s storage and are not sent to an account. When you answer a question, the answer is recorded together with a random identifier that your browser generates and keeps. It is a random string and nothing more — not derived from your device, your IP address, or anything about you — and it exists so the site can tell a returning visitor from a new one when looking at how questions perform. Clearing site data removes it, and a private window gets a fresh one.
Things you contribute
Questions you submit, suggested edits, votes, flags and comments are public by design, along with the name you attach to them. They are part of the catalogue and are shown to everyone.
Analytics
Two tools measure how the site is used. Vercel Analytics counts page views without cookies and cannot identify you. Google Analytics 4 does set cookies, with IP anonymisation switched on; it is used to understand which parts of the site people use and where they stop. If you block third-party scripts, the site works exactly the same.
Technical logs
Like every website, the hosting provider keeps standard server logs — IP address, browser type, pages requested, timestamps — for a short period, for security and to diagnose faults.
Cookies and browser storage
A single session cookie keeps you signed in. Google Analytics sets its own cookies, described above. Everything else — your preferences, your level, your unsynced study progress, and whether you have dismissed a notice — is kept in your browser’s local storage, which is not a cookie and is never sent anywhere on its own. Pages you have visited may be cached on your device so the study decks work offline.
Who else sees it
No data is sold, and nothing is shared for advertising. The services that necessarily handle it are:
- Vercel — hosts the site and provides the cookieless analytics.
- Neon — the database where accounts and study records are stored.
- Google — sign-in (if you choose it), Google Analytics, and the fonts the site uses, which are loaded from Google’s servers. Loading a font sends your IP address to Google in the same way loading any file from any server does.
- Discord — only if you click the community link. Nothing is shared until you do.
Google API Services
The site’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Sign-in uses only your name, email and picture, for the sole purpose of operating your account. Separately, the site’s own publishing tool uses the YouTube Data API to upload videos to the site’s own channel; it accesses no other person’s data.
How long it is kept
Account data is kept until you ask for the account to be deleted. Answer records without an account are kept because, in aggregate, they are what tells everyone how hard each question is; they carry no name and no email. Contributions you have made public stay in the catalogue unless you ask for them to be removed.
Deleting your data, and other requests
There is no delete button yet. Email kyleanthonypastor@gmail.com from the address on the account and the account and everything tied to it will be deleted; the same address will send you a copy of what is held, or correct anything that is wrong. If you are in the EU or UK, these are your rights under the GDPR and they apply here.
To remove signed-out progress, clear this site’s data in your browser — there is nothing on the server to ask for.
Children
The site is not directed at children under 13, and no account is knowingly kept for one.
Changes
If this policy changes, the date at the top changes with it. A change that affects what is collected will be announced on the site, not slipped in.