Privacy Policy

Last updated: 1 Oktober 2026

Imajiedu is a set of educational simulators and a 3D design studio, run by one person; the simulators are published under the Imajiplay studio. This page explains what data we keep, why, and what we do not do. It describes how the site actually behaves as of the date above.

If you never sign in

The learning simulators run without an account. In that mode we send no personal data about you to our servers.

Your game progress and the 45-minute free-trial clock are stored in your own browser's localStorage, not on our servers. Clearing your browser data clears them too.

Your visit still counts towards aggregate statistics if you agree to measurement — see Cookies and measurement below. That is a visit count, not your identity.

If you create an account

We store: your email address, a username generated automatically from it, the designs and work you save, your game save points, your daily build-time usage (to enforce plan limits), and your role and subscription status.

We never see or store your password. Authentication is handled by Supabase, which stores it hashed. If you choose Google sign-in, we receive your basic name and email from Google — never your Google password.

Cookies and measurement

We use Google Analytics 4 and PostHog to learn which simulators get used, how many visitors arrive, at which step people abandon sign-up, and which pages are slow or breaking. PostHog may also replay the visual session when we enable that feature; every input value is masked.

This measurement stores cookies or local identifiers only after you press Accept. Before you choose — and permanently if you decline — neither service is activated.

Declining locks nothing. The entire site remains fully open to you.

Changed your mind? Clear this site's data in your browser (site settings → clear data) and you will be asked again on your next visit. You can also install Google's Analytics Opt-out Browser Add-on to block it across every site.

We do not send names, email addresses, design contents, URL parameters, or access codes to analytics services. For signed-in users, PostHog receives the Supabase account UUID so cross-device sessions are not mixed; that UUID is not an email address.

What we do not do

There are no ads on this site and no advertising pixels. Google's advertising signals (ad_storage, ad_user_data, ad_personalization) are set to 'denied' permanently — including after you press Accept.

We do not sell, rent or trade your data to anyone. We do not build a marketing profile of you, and we do not send promotional email.

Third parties that process data

Supabase — database and authentication. Render — website hosting. Google Analytics and PostHog — usage measurement, only after you press Accept. Google Sign-In — only if you choose to sign in with a Google account.

Some files (fonts and the 3D library) are fetched by your browser from the Google Fonts and unpkg content networks. Because those requests come from your browser, those providers can see your IP address. We do not send them any account data.

If payments are enabled later, the payment provider processes the transaction: Xendit or Stripe on the website, and Google Play for subscriptions bought in the Android app. Card details never pass through our servers — the payment page is hosted by the provider. We only receive a record that a payment succeeded; for Google Play, that record is a purchase token we check with Google to activate your paket.

What other people can see

Your designs are private unless you choose to make them public. If you publish one to the gallery, its name and your username become visible to other signed-in users. If you choose collaborate mode, they can also edit it.

Your email address is never shown to other users — the gallery only ever shows a username.

Access codes you create are stored hashed, never as plain text, and expire according to the duration you pick.

Security

All traffic runs over HTTPS. Row-level access is enforced in the database, so one account cannot read another account's data. Passwords and access codes are stored as hashes.

No system is perfectly secure. If you find a security flaw, please tell us first at the email below.

Keeping and deleting data

Account data is kept while your account exists. You may request a copy of your data, or ask for your account and its contents to be deleted, by email. We will action it within a reasonable time.

Deleting an account deletes the designs stored under it. That cannot be undone.

You can also request deletion of selected data without closing your account at /hapus-data/sebagian. We verify account ownership and delete the selected data within 30 days after verification. Data stored only on your device must be cleared on that device.

Transaction records used as accounting documents are kept for 10 years when required by Indonesian tax rules, even when other data is deleted on request.

Children and students

The material here is educational and may be used by students. We collect nothing beyond what this page lists. If you are a parent or guardian and want a child's account removed, email us and we will remove it.

Changes

If this policy changes, the new version is published on this page with an updated date.

Contact

PT Taqwa Amanah Teknologi
Fady Nandita As Shiddiq
Jl. Diklat Pemda Dukuh Pinang No. 24, Bojong Nangka, Kelapa Dua, Kabupaten Tangerang, Banten 15810, Indonesia
imajiedu@gmail.com