The short version
We store your email, a hashed password, and your practice history so you can resume on any device. We never store voice recordings or transcripts. We do not sell data, run advertising, or send your answers to analytics.
What we collect
| Data | Why | Kept |
|---|---|---|
| Email address | Your account and sign-in | Until you delete your account |
| Password | Sign-in. Stored only as a salted PBKDF2 hash | Until you delete your account |
| Google account ID | Only if you choose "Continue with Google": Google's permanent ID for your account, so it can sign you in. We ask Google for your email address and nothing else: no name, photo or contacts | Until you delete your account |
| Contact messages | Answering what you sent through the contact page: your name, organization if given, email and message | 12 months |
| Session records | Keeping you signed in. The cookie holds a random token; we store only its hash | 60 days at most, 14 days idle |
| One-time codes | Email verification and password reset. Stored only as a hash | 10-minute validity; removed with your account |
| Onboarding answers | Exam date, experience and goal, to shape your plan | Until you change or delete them |
| Attempts and answers | Scores, review queue, resume across devices | Until you delete your account |
| Voice and typed scenario results | Which checklist points you covered, the score, the model used, the date. No audio, no transcript | Until you delete your account |
| Purchase records | Access period and refunds, once paid access opens | As long as tax law requires |
| Consent record | Which policy version you accepted, and when | Until you delete your account |
| Credits | A ledger of free-tier credits granted and spent, so the balance is correct | Until you delete your account |
| Ratings | Your score and the reason you wrote, to improve the product. Read by a person | Until you delete your account |
| Founding Access list | The email you entered, that you accepted the terms, and whether you opted in to promotional email (with the time you did) | Until you delete your account or ask to be removed |
Counting visits
We count page views on our own server, without cookies and without third-party trackers. Each visit adds one to a counter for that day, page and referring site. To count unique visitors, we store a short one-way digest made from the day, a secret, your network address and your browser; it cannot be turned back into an address and is useless the next day. We also record your country (from Cloudflare) and whether you are on a phone, tablet or computer. Digests older than 60 days are deleted.
Sometimes we test two wordings of a page to see which one helps more people. Which one you see is worked out from the same daily digest, so no cookie is set, and we record only which wording that digest saw and whether it went on to the free sample or to sign up that day. Those records are deleted after 60 days with the digests.
Promotional email
Joining the Founding Access list means we may contact you once about Founding Access opening. We send promotional email only if you tick the separate, optional box, and every such email will include a way to unsubscribe.
Voice recordings
When you record an answer, your browser asks for the microphone only when you press record. The audio is sent to our server and passed to Cloudflare Workers AI for transcription, then discarded. It is not written to a database, file storage, logs or analytics. The transcript is shown to you so you can correct it, sent once for checklist matching, and then discarded too.
Who processes data for us
- Cloudflare hosts the site, the database, the visit counters and the AI models used for transcription and checklist matching.
- Google signs you in if you choose "Continue with Google". Google tells us your email address and that it is verified; we do not receive your Google password.
- Stripe will process payments once paid access opens. Card details go to Stripe's hosted checkout and never reach us.
- No third-party analytics or advertising scripts run on this site.
Export and deletion
From the account page you can download everything we hold about you as a JSON file, and delete your account. Deletion removes your learning history and signs out every session immediately. We keep a record that a deletion happened and when, with no personal details.
Operational logs
Server logs record a request ID, the route, the status, the duration and an error type. They do not contain your answers, email, questions or transcripts.
Changes
If this policy changes in a way that affects what we store, we will ask you to accept the new version.