Privacy policy
Last updated: August 4, 2026
This policy explains what the operator of this ExamOps deployment ("we", "us") collects, why we collect it, who processes it, and what control you have. The current operator is identified through support@examopshq.com.
What we collect
| Data | Why we hold it |
|---|---|
| Your email address and authentication identity | To create your account, sign you in, and contact you about your account |
| Your study activity: which questions were served to you, the answer you selected, whether it was correct, and how long you took | To show your accuracy and progress, to avoid serving you the same question twice in a day, and to enforce daily question limits |
| Your subscription and payment records: plan, status, billing period, and identifiers issued by our payment processor | To give you the access you paid for, to handle refunds and disputes, and to meet financial and tax record-keeping obligations |
| Operational logs and security data | To keep the service running, to apply rate limits, and to investigate abuse |
What we do not collect
- We never see or store your card details. Payments are handled entirely by Stripe. Your card number does not pass through our servers.
- We do not sell your personal data, and we do not share it with advertisers.
- We do not use third-party advertising or cross-site tracking cookies. The cookies we set are the ones required to keep you signed in.
Who processes your data
These providers process data on our behalf, under contract:
| Provider | Role |
|---|---|
| Supabase | Account authentication and the application database |
| Cloudflare | Hosting, content delivery, and request rate limiting |
| Stripe | Payment processing, subscription billing, and refunds |
| GitHub or Google | OAuth identity, only if you choose that sign-in method |
| Google Fonts | Delivering the public site's typefaces; normal request data such as your IP address and browser metadata reaches the provider |
| Supabase Auth or the operator's configured SMTP provider | Sending account emails such as confirmations and password resets |
These providers may process data outside your country, including in the United States. Where required, transfers rely on the contractual and legal safeguards offered by each provider and configured by the operator.
Legal basis for processing
Where the GDPR or a similar regime applies, we rely on:
- Performance of a contract — to provide the account and the access you purchased.
- Legal obligation — to retain billing and tax records.
- Legitimate interests — to keep the service secure and prevent abuse.
How long we keep it
- Account and study data — for as long as your account exists. If you close your account, this is deleted or anonymized.
- Billing records — retained after account closure for the period required by applicable financial, tax, fraud, and dispute obligations. Our database deliberately prevents billing history from being erased by an ordinary account deletion, because we are required to keep it.
- Operational logs — for the hosting provider's configured operational window, and longer only when needed to investigate a security event or meet a legal obligation.
Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, object to or restrict processing, and receive a copy in a portable format. To exercise any of these, contact the operator and be prepared to verify the address on your account.
Two honest limits. First, if you have billing history we cannot delete the records we are legally required to keep; we will disable your account and minimize what remains. Second, we may need to verify your identity before acting on a request, so that someone else cannot use it against you.
We aim to respond within 30 days, or sooner when applicable law requires it. If you are in the EU or UK and are unhappy with our response, you may complain to your local supervisory authority.
Security
Access to your data is enforced at the database level: rows are readable only by the account that owns them. Answer keys are never sent to the browser. Payment secrets are held as encrypted platform secrets, never in client code. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority as required by law.
Children
ExamOps is intended for adults pursuing professional certification and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has created an account, contact the operator and we will remove it.
Changes
If we change this policy materially, we will update the date above and notify account holders by email before the change takes effect.