Testonome

Privacy notice

Effective 2026-09-23. It covers this site, including the numerical practice trainer, which went live on 2 September 2026.

Who runs this site

Testonome is operated by Acceptance Testing OÜ, registry code 14193072, Linnamäe tee 25-153, 13912 Tallinn, Harju maakond, Estonia. Write to info@testonome.eu with any question about this notice.

This notice covers personal data. The Terms cover the agreement itself, and the Methodology page explains how a score is worked out and where any comparison figure would come from.

What happens when you open a page

The site is hosted by Vercel Inc., a United States company. Its servers write one line to an access log for each request: your IP address, the page you asked for, the user-agent string your browser sends, and the time. We use those lines to keep the site running and to notice abuse. The legal basis is our legitimate interest in operating the site and protecting it, under Article 6(1)(f) of the GDPR. The log entries are deleted after 30 days. We keep no copy of them. A log entry may be handled outside the European Economic Area, and the safeguard covering that is its certification under the EU-U.S. Data Privacy Framework.

How we count visits

We use Plausible, a measurement service, to count how many people open each page. Its script loads from plausible.io, and it runs on ordinary pages only.

What we see is a count: how many visits a page had, which country they came from, and which site or search engine sent them. We get no name, no email address, no account, and nothing that lets us pick one visitor out and follow them. It handles this for us as our processor, on our instructions. The legal basis is our legitimate interest in knowing which pages are worth writing, under Article 6(1)(f) of the GDPR.

The service is built to work without cookies and without storing anything on your device. That is why we chose it.

The site adds a few named counts on top of that, and this table is all of them. Each is one short message. There is no field in any of them for a question, an answer, a score or anything that identifies you.

404Sent when you open an address on this site that does not exist. It carries an address, which is the one you asked for only where every part of it is a word this site is built from and the fixed word not-listed otherwise, and where you came from, which is a page of this site held to the same test or only the site it was on.
startSent when you press the control that starts a practice session, on the page before the clock. It carries which test type you are starting, and which page you came from.
completeSent when the clock stops on an attempt. It carries which test type it was, which mode, which page you started from, and whether the clock ran out.
reviewSent when you open the review of a finished attempt. It carries which test type it was, which mode, and which page you started from.
compare-requestedSent when you press the control that sends a finished attempt for comparison. It carries which test type it was, which mode, and which page you started from.
compare-succeededSent when an attempt you sent for comparison reached us. It carries which test type it was, which mode, and which page you started from.
compare-failedSent when an attempt you sent for comparison did not reach us. It carries which test type it was, which mode, and which page you started from.
retakeSent when you start a retake from the review. It carries which test type it was, which mode, and which page you started from.
drill-startSent when you press the drill control beside a skill you missed, on the review screen. It carries which test type it was, which mode, and which page you started from.

A timed session is a special case among these. That page loads no measurement script at all, and while the clock runs it contacts nobody. The messages it sends are sent by the page itself, after the clock has stopped.

The page you see when an address on this site does not exist is the other special case, and it works the same way. It loads no measurement script either. It sends one message itself, and that message carries four things: the name of the count, an address, our site name, and where you came from. We use it to find links that point at addresses that no longer work.

The address in that message is not the one you typed unless every part of it is a word this site is built from, such as a language, a test type or a skill. Anything else is replaced with the fixed word not-listed before the message is made, so nothing you typed and nothing that was in the link can travel in it. Where you came from is treated the same way: a page of this site is sent with its address if that address passes the same test, and anything else is cut down to the site it was on.

When a page breaks

When something goes wrong in your browser, the page sends us an error report so we can fix it. We use Sentry for this, a service run by Functional Software, Inc., a United States company. A report says what failed and where: the error message, the place in our code it came from, the address of the page you were on, and the name and version of your browser and operating system. Our account keeps those reports in Germany, and its data-processing addendum allows the company to handle them in the United States as well; the safeguard covering that is its certification under the EU-U.S. Data Privacy Framework.

The report is built from a fixed list of those fields before it leaves your browser, and anything outside the list is dropped rather than sent. Your IP address is not on the list. We also remove email addresses and long runs of digits from the text of the message. We do not collect what you clicked, what you typed, or what you answered, and nothing records your screen.

The code that sends the report is fetched only after something has already failed. If nothing fails, your browser never downloads it. It sets no cookie and stores nothing on your device. The trainer itself sends no reports while a timed test is running.

The legal basis is our legitimate interest in finding and fixing faults in the site, under Article 6(1)(f) of the GDPR.

What the trainer keeps in your browser

The trainer has no account and no sign-up, so your browser is where your practice history lives. The table below is the whole list. Every key is first-party, written and read by this site only, and no other company receives what is in it.

tn.activeIn session storage. It holds the attempt you are taking now — which question you are on, the option you picked for each one, how long each one was on screen, and the moment the clock started. It holds no question text and no explanation. Written when you start a practice session. Kept until the attempt is written to the history below, or until you close the tab. A new tab does not see it and starts a fresh attempt.
tn.sessionsIn local storage. It holds your finished attempts, question by question: which question was served, the skills it covered, the option you picked, whether it was right, and how long it took. The 50 most recent attempts are kept. Written when you finish a practice session. Kept until you clear this browser's data for the site. The 51st attempt drops the oldest one.
tn.indexIn local storage. It holds the summary the trainer reads on every page: your score history per test type, your settings, and your practice streak. It holds no identifier for you. A random identifier is created if you turn on result sharing.. Written when you finish your first practice session. Kept until you clear this browser's data for the site.
tn.seenIn local storage. It holds the questions you have already been served, per test type, so a retake gives you ones you have not seen. Written when you finish a practice session. Kept until you clear this browser's data for the site. The list is capped per test type and drops the oldest ids first.
tn.participationIn local storage. It holds your choice about sharing results, if you make one: whether sharing is on, when you turned it on, which Terms of use and privacy notice applied, and your own copy of the agreement. It holds no name and no email address. Written when you turn on result sharing at the end of a test. Kept until you clear this browser's data for the site.
tn.themeIn local storage. It holds one word, light or dark, when you have chosen a colour mode instead of following your device. It is read before every page paints, so the page does not flash the wrong colours. Written when you choose a colour mode. No screen offers that choice yet, so nothing writes it today. Kept until you go back to following your device, or clear this browser's data for the site.

Reading a page writes none of these: one when you start a practice session; three when you finish one; one if you choose a colour mode, which no screen offers yet; and one if you turn on result sharing. A visitor who only reads the pages leaves with an empty browser store.

Clearing this site's data in your browser removes all of it, which costs you any attempt you are part-way through; your attempt history; your scores, streak and settings; which questions you have already been served; your copy of the sharing agreement and the record of the choice you made; and your colour-mode choice. Nothing else on the site depends on it. Your browser may also cache the page files and keep its own settings, as it does on any site; that is the browser's housekeeping rather than ours.

Why there is no consent banner

Storing and reading things on your device is regulated in the EU under Article 5(3) of the ePrivacy Directive, whether or not a cookie is involved. Permission is not needed where the storage is strictly necessary for the service you asked for.

Our position is that each key above is that kind of storage. The service this site offers is a practice trainer that keeps your results on your device instead of in an account, so the keys that hold the attempt, the history and the settings are the service rather than an addition to it. We do not use any of them for advertising, for measurement, for recognising you on another site, or for anything else. If that changes, this notice changes with it before the code does.

The two third-party services on the site are covered separately above. Neither writes to your device. When advertising begins, the position above is re-examined and the permission the law then requires is asked for before any advertising code loads.

What happens to your answers and scores

Your answers, the options you picked and your practice history stay in your browser. One thing can leave it, and only if you turn it on: the results screen offers a control that shares a summary of a finished attempt, so it can be compared with other attempts on this site.

The summary is the whole of what is sent: the test type and the mode, which question set you used, whether each question was answered correctly, how long each one took to the nearest half second, the total time, whether you finished, a neutral timing setting, the version of this notice and of our Terms, and a random code created in your browser the first time you turn sharing on. It carries no name, no email address, no account, and none of the answers you picked. No email address is needed to practise or to compare.

The random code is what connects a stored row to a browser. We store it as a one-way hash, so reading our table gives nobody a code they could present. It is created when you first turn sharing on and not before, and it is kept in your browser as tn.index — the storage table above lists it.

A documented assessment under Article 6(1)(f) of the GDPR covers what we do with a shared attempt: keeping it in the comparison pool, checking that the pool is not being gamed, and measuring how hard each question turns out to be. Sharing an attempt sends you nothing back. The comparison figures are published as a file your browser fetches, and the comparison itself is worked out on your device, so we do not claim the transfer is needed to perform a contract with you. You can object to our use of a shared attempt at any time, and we stop. Records of the agreement, of stopping and of withdrawing sit on Article 6(1)(c), because the law requires us to keep them.

You decide once. Turning sharing on covers that attempt and later finished attempts from this browser, never anything you did before it, and you can stop at any time from one place. Practising never requires it. We keep a row for 12 months from the day we received it, then delete it. If you have paused our use of a row, we keep it until you lift the pause, because deleting it would remove the record you asked us to hold on to.

Your data shows every attempt this browser has sent. From there you can object to our use of them, delete them on our side, and clear this browser. That page reads what your browser holds and asks us only when you press one of its controls.

Your copy of the agreement

Turning sharing on forms an agreement with us, and the law says we have to give you a copy of it you can keep. Your browser writes that copy before anything is sent, and Your data keeps it. It holds the Terms and their version, the version of this notice, the date and time, the company's details, and how to withdraw.

At that moment you choose what else happens to it, and nothing is downloaded unless you press for it: save a copy, have it emailed to you, or carry on without an outside copy. The screen says what the last one costs before you pick it. Browser storage and devices get lost, which makes the exact terms that applied harder to keep afterwards; it is not a risk to the agreement itself. Closing the tab chooses nothing: the step is still waiting when you come back.

If you choose email, the same provider that runs our mailbox sends it for us on our instructions. It receives the address you supplied for that one delivery, and the document sent to it, and what it keeps afterwards is a delivery log for 60 days — who it went to, who it came from, the subject line, the date and time, whether it arrived and how it was delivered, and the internet address the sending request came from, which is our server's rather than yours — and no copy of the message itself, because the account's content-retention setting is off. The service runs on the provider's European route, which is where it is hosted rather than a promise that your data never leaves Europe. The safeguard covering any handling outside the European Economic Area is the European Commission's standard contractual clauses. We use the address for that one delivery and the follow-up it needs, and for nothing else: never marketing, never an account, never analytics or profiling, and it is stored apart from the table of attempts.

What we store, and for how long

Six kinds of record, and this is all of them.

A shared attemptThe summary described above. Kept 12 months from the day we received it.
The agreement recordThat you agreed, when, under which versions, and what you chose at the copy step, plus an email address only where you chose email. No name. Kept 3 years after your participation ends, because it is how we can show what we offered you.
A withdrawal statementThe name, contract reference and address the statutory form asks for, the statement, and when it was sent. Kept 3 years, apart from the table of attempts, and used for nothing else.
A record that you stoppedYour browser reference and the date. It exists to stop us collecting again and survives the deletion of your attempts, because losing it would let an old permission work. Kept 24 months after it stops applying.
A record that you paused our useThe same, for a pause you asked for rather than a stop. Kept 24 months after the pause ends.
A restriction we imposedWhere we suspended or excluded a browser from contributing under our Terms: the browser reference, the reason class and the dates. No attempt content. Kept 24 months after it stops applying.

A daily job deletes what has run out and records that it ran. While you have asked us to pause our use of your attempts, they wait rather than expiring, because deleting them would remove what you asked us to keep.

Deleting an attempt removes it from the live service immediately. A recovery copy may keep it for up to 366 days, but a deleted attempt will not return to the live service. Backblaze, Inc. (B2) stores those copies on our instructions. It and its subprocessors may process them outside the European Economic Area under the Controller-to-Processor Standard Contractual Clauses in its Data Processing Addendum; its subprocessor list is here.

The counts and error reports described above are a separate matter and are listed there; this section is about what you answered.

Advertising and third-party code

Last technically verified: 14 September 2026.

This site does not load advertising code and does not contact an advertising provider. It carries no sponsored content and no paid placement.

The two services above are the only third-party code the site loads: the measurement script, on ordinary pages, and the error reporter, after a failure. Neither writes to your device. Apart from them, the only code that reads or writes your browser is the trainer's own, and the table above is the whole of what it keeps. Our server receives ordinary request information, described further up.

The pages Google reads to check that this site is ours each carry one line in their source naming our own advertising account. It is a note in those pages and nothing more: it fetches nothing, contacts nobody, and puts nothing on your device. This notice is not one of them and does not carry that line; neither does the timed test. No advertising is shown on this site while it is there.

We will update this notice before advertising begins, or before anything else asks for access to your device that the service does not need to work. Where the law requires your permission, the code that needs it does not run until you have given it.

When you contact us

If you email us or call us, we keep what you send only as long as it takes to deal with it. An email sits in our mailbox; a call leaves the number you called from, the time, and any voicemail you record. We use it to answer you and for nothing else. The legal basis is our legitimate interest in replying to people who get in touch, under Article 6(1)(f) of the GDPR.

Our mailbox is run for us by a provider that handles the mail on our instructions, under a data-processing agreement signed on 13 August 2026. It stores the mail in the European Economic Area. The provider's group companies in India can reach that mail when they support the service or fix a fault, and the agreement requires a valid safeguard for that access, naming the European Commission's standard contractual clauses.

Our telephone service is run for us by a provider that handles calls and voicemail on our instructions, and keeps that data in the European Union (the provider's privacy policy, read 5 August 2026). We do not record calls, so the only recording that exists is a voicemail you chose to leave.

While we are dealing with a complaint, a rights request or a withdrawal, we keep a private record of it: what was asked, what we found, what we answered, and when. Two reminders sit beside it so the deadline is kept. Our workplace-tools provider holds that record and those reminders on our instructions. We delete our record 36 months after the case closes; the provider's own copies can take up to 180 days to go after that, which is its contract rather than our schedule. That provider's suppliers may handle the record outside the European Economic Area, so we make no claim that it stays in Europe. Two safeguards cover that: the EU-U.S. Data Privacy Framework for anything reaching the United States, and the European Commission's standard contractual clauses for any other country outside the Area.

Who else handles your data

Eight companies process personal data directly for us for the purposes described in this notice. Some use subprocessors, which are not included in this count.

Databricks, Inc. (Neon) stores the shared data and the records needed to manage it, on our instructions, for the periods stated above. It and its subprocessors may process those data outside the European Economic Area under the Controller-to-Processor Standard Contractual Clauses in its Data Processing Addendum; its subprocessor list is here.

Your rights

You can ask what we hold about you, ask us to correct or delete it, object to our use of it, or ask us to restrict that use. Write to info@testonome.eu. Your data is the fastest route for anything this browser sent: it lists those attempts, takes a copy of every one of them, pauses our use of them, objects to their use, and deletes them. We keep no account for you, and your practice history is on your device rather than ours. If you think we have handled your data wrongly, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

Two of those work differently here, and it is worth saying which. A shared attempt is a record of a test you took, so we cannot replace a score with a different one; where you think a record is wrong, pause our use of it on that page and write to us, and we check it, correct what is wrong on our side and tell you what we found. And the right to have data moved to another company covers data held because you agreed to it or because a contract needed it — we hold attempts on our own legitimate interest and the agreement records because the law requires it, so that right does not reach them. The copy you can take from Your data is a machine-readable file all the same.

What we hold about a shared attempt is tied to a random code kept in your browser. If you clear that browser, we may be unable to connect a stored row to you, and we will not ask you for an identity document to rebuild a link it could not prove. Where that happens we say so, and say what we tried.