AM Review · ce.arizval.com

Privacy Notice

Effective September 26, 2026 · Version 2026-09-26.1

AM Review is designed as a local-first educational platform. Most learner, study, assessment, certificate, CE Tutor conversation, and Gemini eligibility data stays in your browser. The optional CE Tutor uses a Gemini API key that you provide and sends only the bounded recent chat, explicit image attachments, and context categories you enable directly from your browser to Google.

1. Controller and scope

AM Review is an independently operated educational project available at ce.arizval.com. For personal data processed by or on behalf of AM Review, the operator acts as Personal Information Controller for purposes of Republic Act No. 10173, the Philippine Data Privacy Act of 2012, and applicable rules.

Privacy questions or requests may be sent to arizbmendoza@gmail.com. The project is operated from Baguio City, Philippines.

2. Data processed

CategoryExamples and usePrimary location
Learner profileFull name, nickname, school, program, year level, student number, optional profile image, certificate preference, and local identity metadata.Browser / device
Study and assessment activityProgress, quiz/mock-board responses, scores, timing, attempts, completed assessments, review state, and local recommendations.Primarily browser / device
Gemini 18+ eligibilityYour date of birth and current Gemini BYOK terms acknowledgement. The date is used locally to compute 18+ eligibility. It is not included in Gemini context and is excluded from normal learning-data backup/export.Browser / device only
Optional CE Tutor / Gemini BYOKLocally saved page-scoped tutor text conversations, separate context-sharing preferences, a learner-supplied Gemini key in dedicated browser secret storage, explicit image attachments for a current turn, and bounded request context when you explicitly use the Tutor.Text history saved locally; selected request data and attached images go directly to Google Gemini
Optional analyticsGoogle Analytics and Cloudflare Web Analytics page/interaction measurement when you expressly enable optional analytics.Analytics providers
Technical and communications dataOrdinary network/security request metadata and information you voluntarily send by email.Infrastructure providers / email records

3. Adult eligibility for Gemini BYOK

Google Gemini is exposed through CE Tutor only after the device has a valid date of birth showing the learner is at least 18 and the learner accepts the current Gemini BYOK eligibility notice. This 18+ eligibility check is local to the browser. AM Review does not send your date of birth to Google, include it in page/profile/analytics context, log it, or place it in normal learning-data backups.

Changing or clearing the date of birth or current Gemini eligibility acknowledgement invalidates the prior Tutor opt-in and tears down active Tutor work. The feature remains unavailable when the age is under 18, the date is missing/invalid, or the current eligibility acknowledgement is absent.

This self-entered DOB gate is an application eligibility control, not identity or age verification, and it does not override Google's separate restrictions on API Clients, intended audiences, or permitted professional/business use. AM Review therefore does not represent the local age gate by itself as proof of compliance with Google's provider terms.

4. CE Tutor transport, model routing, and context

CE Tutor uses Google Gemini through a pure bring-your-own-key architecture. CE ships with no platform-owned Gemini credential and no server-side Gemini proxy. Your Gemini API key is stored in a separate browser-only secrets database and requests use that key directly from your browser to Google only when you explicitly test the connection or ask a question.

For a Tutor question, CE uses direct Gemini generation only and attempts models in this order: Gemini 3.8 Flash, 3.7 Flash, 3.6 Flash, 3.5 Flash, then 3.5 Flash-Lite. CE does not use Antigravity or a Google-managed agent route for CE Tutor.

If Google identifies a model-scoped daily quota as exhausted, CE records only that model name, the current Pacific quota day, and the observation time in non-secret browser metadata, then continues to the next configured model. CE reads structured Google quota details when available so project-wide limits are not multiplied across the ladder. Temporary model-scoped limits and selected transient provider failures use bounded exponential backoff with jitter, honoring short provider retry hints when practical. Malformed requests, authentication, billing, permission, local-validation, consent, and protected-assessment failures do not silently cascade.

  • Page context is off by default and, when enabled, is bounded rendered/visible text rather than unrestricted raw page source.
  • Learning analytics sharing is off by default and sends aggregate completed-session metrics rather than raw assessment rows or exact session identifiers.
  • Profile sharing is off by default and is limited to display name, school, program, and year level. Student number, identity IDs, profile images, and date of birth are not sent as profile context.
  • Images are sent only when you explicitly attach them to the current Tutor message. CE accepts bounded JPEG, PNG, and WebP attachments and sends them inline to Google for that turn.
  • Consent and 18+ eligibility are re-evaluated at the transport boundary before every direct-model request, retry, and fallback request.
  • CE Tutor is blocked on integrity-protected assessment surfaces.

5. Local-first storage and backups

A substantial part of AM Review uses localStorage, IndexedDB, and application caches. Clearing site data, private-browsing behavior, browser storage eviction, device loss, or browser reset can permanently remove locally stored information for which AM Review has no server copy.

The Gemini credential, DOB-backed Gemini eligibility record, and locally saved Tutor conversations are intentionally not included in AM Review backup exports. Import validation also rejects those sensitive/control entries from a portable learning-data package.

Attached image bytes are intentionally not written to the local Tutor chat database or learning-data backups. They exist only in the active browser memory needed to preview/send the current turn and are transferred to Google when you send that message. A locally restored text thread therefore does not restore prior image bytes.

6. Tutor conversation retention

page-scoped tutor conversations are saved locally in a dedicated browser database so they can be restored on the same canonical pathname/query. The application retains at most 60 messages and 200,000 logical characters per thread and at most 50 recently updated page threads. Local retained history is larger than, and separate from, the bounded recent text history sent with a Gemini request. Image bytes are not part of the persisted thread.

Clear conversation deletes the current page thread. Disabling the Tutor or removing only the API key keeps local chat history. Remove AI chat deletes all locally saved Tutor threads, the saved Gemini credential, DOB/eligibility record, and AI-sharing preferences while preserving unrelated learning, assessment, bookmark, certificate, and profile data.

7. Third parties

Google Gemini processes requests under Google's applicable Gemini API terms, privacy practices, project settings, and infrastructure. Depending on your selected controls and the message you send, a request may contain your question, bounded recent chat, explicit image attachments, bounded page context, aggregate learning analytics, and limited profile fields. Provider-side handling after transfer is controlled by Google, not AM Review.

Cloudflare may process technical request/security metadata necessary to deliver and protect the site. Google Analytics and Cloudflare Web Analytics are loaded as optional analytics only after your analytics preference enables them; advertising storage remains denied in AM Review's analytics consent configuration.

AM Review does not sell personal data and does not provide the learner's Gemini key or local Tutor database to an AM Review server.

8. Purposes, choices, and deletion

  • Requested educational features: process local profile, progress, assessments, certificates, offline resources, settings, and Tutor state needed for features you choose.
  • Gemini eligibility: use DOB locally to determine whether the 18+ gate is satisfied before provider access is possible.
  • CE Tutor requests: transfer only request data, explicit image attachments, and enabled context needed for the question using your own Gemini credential.
  • Optional analytics: process analytics only after the corresponding optional analytics preference is enabled.
  • Security/service delivery: process ordinary network metadata needed to deliver and protect the service.

You can disable CE Tutor, hide the global AI chat, remove the Gemini key, revoke any context-sharing category, clear the current conversation, or use Remove AI chat. You can also change optional analytics through Privacy preferences.

9. Security and device responsibility

AM Review separates the Gemini credential from normal settings/learning data and never repopulates a persisted key into the Settings input. Browser-only storage is nevertheless not equivalent to hardware-backed secret storage; someone with sufficient access to the browser profile or a compromised page may be able to access locally stored information. Use appropriately restricted provider credentials and protect your device/browser profile.

10. Your Philippine privacy rights

Subject to the Data Privacy Act of 2012 and applicable rules, you may have rights to be informed, object, access, correct, erase/block, obtain data portability where applicable, lodge a complaint, and seek damages where the legal requirements are met. Some local-only data exists solely on your device and can be controlled directly there.

For AM Review-controlled data or privacy questions, contact arizbmendoza@gmail.com. You may also contact the National Privacy Commission where applicable.

11. Changes to this notice

The effective date and version identify this notice. Material changes, including the September 4, 2026 adult-gated Gemini BYOK release and later same-day agentic/multimodal routing update, update the version and may require a fresh policy acknowledgement.