Your data
Privacy policy
Everything here was written from the database and the code that writes to it. Each section names what is stored, which company it reaches, and how long it stays.
Last updated 13 September 2026.
Who this covers
LockInPoint is designed and built by Isaac Arinola Tech, the software studio of Isaac Arinola, and published by Noesis Innovations. This policy covers the website and the Android, iOS, Windows, macOS and Linux apps · they sign in to one account and read one database, so what is written here applies wherever you opened it.
A guardian following a candidate holds a separate account of their own · full name, email, phone, country and which relationship they claim, from parent and teacher through to school administrator, counsellor or sibling. What that account can and cannot read is set out further down.
What you hand over to create an account
Surname, first name and an optional username
Your name appears on your receipt, on the materials you open and on the leaderboard. If you set a username, the leaderboard shows that instead.
Email address
It is how you sign in · so is your username, because the log in field takes either. It also carries the six digit verification code, a password reset code, and your activation receipt.
Phone number and dial code
Checked into one international shape when you type it, then stored. Nothing is ever sent to it · there is no SMS and no one time code by text.
Your country, and your state
Country sets your price and your currency. Students in the exam countries are asked once for their state, so the leaderboard can rank you among people you might actually meet rather than against the whole of West Africa. A student outside those countries is never asked for a state.
Your gender
Male or female, picked once at signup. It is used for the platform’s own count of who is preparing here. It is never shown on the leaderboard and never shown to a guardian.
A referral code, if somebody gave you one
The five character code you type at signup is stored on your account, so whoever referred you is credited when you activate. A code that matches nobody is not stored at all.
Your password
Handled by Supabase Auth and never visible to us. Guardian passwords are stored as a scrypt hash, which cannot be turned back into the password.
What is recorded as you use the platform
Every sitting you submit
The mode, the examination, which questions were served, the letter you chose for each, how long you took and your score. This is what makes your history, your analysis screen and your resumable practice possible.
How a question performs, without naming you
Separately from your attempt, each question keeps a running count of how many times it was served, how often it was answered correctly and how the options were split. That table holds no student identity at all.
Which materials you opened
A note, a video or a file, and how far through the video you reached.
Your streak, and a log of account events
Study days and your longest run, plus a line for each event on the account · signing up, logging in, activating, redeeming a key, sending a transfer notice, asking Lumi, requesting a payout. Your leaderboard points are worked out from the answers you got right, the papers you finished, your visits and your live streak · how long a paper took is only used to separate two students on the same points.
Your school and your subject combination
Both optional, both offered from your own profile. The school you name is shown beside you on the leaderboard. The four subjects you last built a mock from are kept so the picker opens on them next time.
Questions you saved, flagged or reported
A saved question is yours alone. A report on a question that looks wrong reaches a tutor with your account attached, so they can ask you what you saw.
The one device rule, and the device record
A student account signs in on one device at a time. Logging in somewhere new takes the slot and signs the old device out · except during a running CBT, where the takeover waits until that paper is submitted, so nobody loses a timed sitting to somebody else signing in.
Making that work means keeping a short record of the devices you have used:
- a long lived identifier in a cookie, which recognises the same browser again;
- the browser, the platform and the model your phone reports;
- a truncated network address · an IPv4 address is stored with its last part replaced by zero, an IPv6 address is cut to its first three groups. The full address is never written down.
Device rows are deleted with the account. Separately, a row that has not been seen for 180 days is deleted the next time that account signs in or its session is checked. Many students here are minors, and a device record is for spotting an account being passed around, not for following anybody.
Lumi, and exactly what she is told about you
Lumi is an AI tutor. When you send her a message, the request that leaves our server carries your question, up to the last twelve messages of that conversation, and a short memory block. That block holds only:
- your first name, so she can address you;
- your weakest topics with a percentage, worked out from questions you yourself answered;
- the way you asked to be taught, in your own words · “step by step”, “simple English”, “keep it short”;
- the subjects you have named recently, matched against the real subject list;
- the opening line of her last answer to you, so she can pick the thread back up.
Your surname, email, phone number, payment history and device record are never sent to a model. When you ask about a question you are sitting, the question and its options are looked up on our server and sent · the correct answer is not, which is why Lumi gives a hint rather than the key.
Which model answers is set by the team in Admin and can change without a new release. Today that is Google Gemini reached directly at generativelanguage.googleapis.com, or a model reached through OpenRouter or NVIDIA.
Your conversations are stored so the tutor still knows you tomorrow. Fifteen are kept · when the list is full you are told which is oldest and you choose what to delete, rather than one quietly disappearing.
Payments
Card and online payment. Checkout runs at Paystack. Your email and the amount go to them; card numbers never touch this platform and are never stored here. What comes back and is kept is a reference, the amount, the currency, the channel and whether it succeeded.
Bank transfer. The screenshot you upload is stored in a private bucket at Supabase. It has no public address: an admin opens it through a link this server signs, and that link stops working after sixty seconds. It is kept with the transfer notice.
Google Play and the App Store. The app sends us the purchase token the store issued. We check it with Google at androidpublisher.googleapis.com or with Apple at api.storekit.itunes.apple.com, and store the token so the same purchase cannot activate a second account.
Referral payouts. Asking for a withdrawal stores the account name, bank name and account number you typed, so the team can pay it.
The companies your data actually reaches
Supabase
The database, sign in, and file storage for uploads and study material. Everything described on this page lives here.
Paystack
Card and transfer checkout. Receives your email and the amount to charge.
Brevo
Transactional email · the verification code, reset codes, receipts and announcements. Receives your email address and the message.
Google Gemini, OpenRouter or NVIDIA
Whichever model the team has configured for Lumi. Receives exactly what is listed in the Lumi section above.
Google Play and Apple
Only when you buy inside the app, and only the purchase token, so it can be verified.
YouTube
Video lessons are embedded through youtube-nocookie.com, which is YouTube’s no cookie player. Pressing play contacts Google.
There is no advertising network on this platform, no third party analytics or tracking script, and nothing is sold or handed to a data broker.
What other people can see
The leaderboard shows your username · or your first name with the initial of your surname if you have not set one · alongside your points, your streak, your state and your institution. Your email, phone number, payment record and device are never on it. The wall of fame and the list of competition winners work the same way · a username or a name, and never an email address.
Study materials carry your own name repeated across the page, and a PDF opened through LockInPoint has your identity burned into every page on our server before it reaches you. That is deliberate: it makes a leaked copy traceable to the account it came from.
The Guardian Portal
A parent, teacher or school can follow a candidate. They link by typing the candidate’s Product Key · the code shaped like LIP-7K4M-92QT that sits in the student’s own profile. A correct key returns one thing, the candidate’s name, so that the guardian can check they linked the right child. Everything afterwards is checked against the link itself, not against the key.
A linked guardian sees:
- the papers that candidate has actually sat, and the scores;
- subject and topic strengths, and whether they are trending up or down;
- their study streak, their state, their Product Key and whether the account is activated.
A linked guardian never sees:
- the student’s password · there is no route that could return it;
- their email address, phone number or device history;
- their payment history or receipts;
- their conversations with Lumi;
- anything at all belonging to any other candidate.
A guardian can remove a candidate from their own portal at any time. To have a link taken down from the student’s side, write to info@lockinpoint.com from the address on the account.
Students under 18
Most candidates preparing for JAMB and WAEC are under 18, so this is the normal case here rather than the exception. We do not ask your age and nothing on the platform is decided by it.
A parent, guardian or teacher may ask on a student’s behalf for a copy of what is held, for something to be corrected, or for the account to be deleted. Write to info@lockinpoint.com. Because that request affects somebody else’s account, we will ask you to confirm it from the email address the account uses, or with the student’s Product Key.
How long any of this is kept
Your account data is kept while the account exists. When an account is deleted, the database removes with it your profile, every attempt and score, your saved questions, your material progress, your device records, your Lumi conversations and what Lumi remembered, your referral credits, your withdrawal requests and your guardian links.
Three things deliberately outlive the account, and it is fairer to say so:
- Payment records. The reference, amount and the email the payment was made with stay, detached from the deleted account. A receipt is a financial record and deleting it would leave a real payment with no trace on either side.
- Questions you contributed to the Question Harvest, and reports you filed on a faulty question. The submission stays so other students keep the question; your account is unlinked from it.
- The administrative activity log, which keeps the display name as it was written at the time so an old line still reads correctly.
Separately from deletion: a device row unseen for 180 days is deleted the next time that account is used, and Lumi keeps fifteen conversations per student.
Deleting your account, or asking what is held
Start at the delete your account page. Deletion cannot be undone, and your activation does not survive it · do not use it to try to fix a sign in problem.
For a copy of what is held, a correction, or any question about this page, write to info@lockinpoint.com from the address on the account. When this policy changes, the date at the top of this page changes with it.