Privacy Policy Web App

Privacy Policy

CBT Test Potensi Akademik — Web application (Laravel)

Effective August 6, 2026 · Last updated August 6, 2026

This computer-based testing platform handles exam participant data and exam integrity signals. It is installed and operated by the institution running the exam, which decides who is registered and how long results are kept.

Summary
  • Collects participant identity, answers, scores, and exam-session activity.
  • Exam integrity monitoring records events only (tab switches, fullscreen exits) — no webcam, no screen capture, no keystroke logging.
  • Functional cookies only — no advertising or analytics trackers.
  • The institution running the exam is the data controller.

1. Who this policy applies to

CBT Test Potensi Akademik is software that an organization installs and runs on its own infrastructure. The institution operating a given installation decides what data is entered into it and is the data controller for that installation. This page documents what the application itself collects and processes by design; it is the reference policy for the software, and an operator may publish additional terms on top of it. As the developer, I have no access to any production database unless an operator explicitly grants it for maintenance.

2. Data we collect

DataWhy
Participant identityName, participant number, and any field the institution configures (class, school, email). Used to identify whose result is whose.
Login credentialsUsername and a hashed password or exam token, for access control. Passwords are never stored in readable form.
Answers and scoresSelected options per question, the computed score, and per-category breakdown (verbal, numerical, logic).
Session activityExam start and end time, remaining time, and submission timestamps — needed for the countdown and to resume after a disconnect.
Integrity eventsCounts and timestamps of tab switches and fullscreen exits during an exam, so supervisors can review suspicious sessions.
Technical logsIP address, browser user agent, and request timestamps — for troubleshooting and abuse detection.

3. What the anti-cheating feature does and does not do

While an exam is in progress the browser reports page-visibility and fullscreen events to the application. These produce a counter and a timestamp list attached to the exam session.

It does not access your webcam or microphone, take screenshots, read other browser tabs or their contents, record keystrokes outside the exam form, or see anything happening in other applications. A browser page is technically incapable of most of that, and the platform does not attempt any of it.

4. How the data is used

5. Third-party services

None. The platform runs on the institution’s own server, with no external analytics, advertising, or content-delivery tracking.

6. Cookies and sessions

The application uses cookies only for functionality:

There are no advertising cookies, no third-party analytics or tracking pixels, and no cross-site profiling. Clearing cookies simply logs you out.

7. Sharing and retention

Results are visible to exam administrators and supervisors within the institution, and can be exported to Excel by them. Data is not shared outside the institution except where it is legally required.

Retention follows the institution’s academic policy. Technical logs are typically rotated after a short period; question banks and results are kept as long as the institution needs them.

8. Data security

The application applies standard protections: passwords are stored as one-way hashes (never in plain text), access is limited by role, and all traffic between client and server is expected to run over HTTPS/TLS.

No system is perfectly secure. Server hardening, backups, and access management for a live installation are the responsibility of the organization operating it.

9. Children

Exams may be taken by participants under 13 when the institution administers them in an educational setting. In that case the institution obtains the necessary parental or school consent — the platform itself never registers a participant on its own.

10. Your rights

You have the right to ask for access to, correction of, or deletion of your personal data, and to object to certain processing.

Because your data lives in the installation run by the organization you deal with, address those requests to that organization first — they hold the data and can act on it. If you cannot reach them, or you believe the application itself is at fault, contact the developer at mhdlutfidev@gmail.com and I will assist technically.

11. Changes to this policy

If this policy changes, the “Last updated” date at the top of this page will be revised. Material changes will be reflected in the application release notes.

12. Contact

Questions, complaints, or privacy requests about this application:

mhdlutfidev@gmail.com

I aim to respond within 7 business days.