Skip to main content

Privacy policy

Last updated September 11, 2026

We store your account and study progress, plus feedback you choose to send. We do not sell your personal data.

What we store

  • Your email address. It is how you sign in and the only way we can reach you.
  • Sign-in records. Supabase Auth keeps the account, the one-time codes it issued, and when sessions were created.
  • Your practice. Every exam session you start, every answer you give, and when you gave it. This is what the score and readiness are computed from — without it the product does nothing.
  • Your purchase. Whether you have an active pass, when it was granted, and the Stripe checkout session id it came from. We do not store your card number, and we never see it.

We do not ask for your name, address, phone number, or date of birth, and you should leave those details out of feedback messages.

Study tools and feedback

We store your optional answer confidence, exam date, study days, daily target, and time zone to schedule reviews and show your study plan. These settings are removed with your account. We also store your question bookmarks, saved practice answers, and whether you dismissed the study check-in with your account. These let you resume studying and choose what to review next.

If you send feedback, including an optional post-exam result, we store your message, its category, an optional reply email, and any question reference you chose to include. Signed-in feedback is linked to your account. We use it to investigate issues and improve the product; it is not public. Account-linked bookmarks, check-in preferences, and feedback are removed when you delete your account. For feedback sent without an account, contact support if you want it removed.

Who else processes it

Five companies handle your data on our behalf. Each does one job and gets only what that job needs.

  • Supabase — the database and the sign-in system. Your account, your answers and your pass live here.
  • Stripe — payments. Stripe takes your card details directly; they never pass through us. We receive a confirmation and an id, nothing more.
  • Resend — delivers our email: the sign-in codes, and the messages about your pass such as the purchase confirmation, the notice before it expires, and the confirmation if you are refunded. It sees your email address and the contents of those messages.
  • Google — Google Analytics, a second count of visits to the public pages, used to connect them to Google Search Console. It records a page address, a referrer, a country and a device type, and it does not run on the signed-in app. It sets cookies — see the cookie section below. We have not enabled Google Signals, which is the setting that would let Google combine this with your activity elsewhere for advertising.
  • Plausible — counts visits to the public pages, so we know which ones are worth writing. It is cookieless and records no personal data and no identifier that can be traced back to you: a page address, a referrer, a country, and the type of device. It does not run on the signed-in app at all, only on the public pages.

We do not use advertising trackers, and we do not sell or rent your data to anyone.

Cookies

Two of ours are strictly necessary: one that keeps you signed in, and one that remembers which state exam you are studying for. Plausible sets none at all.

Google Analytics sets two more, and they are analytics cookies rather than necessary ones:

  • _ga — a random identifier for your browser, so a second visit can be recognized as the same visitor rather than a new one. It does not carry your name or your email. It lasts two years unless you clear it.
  • _ga_<id> — the same thing scoped to this specific Analytics property, holding the state of your current visit: when it started, and how you arrived. Also two years.

Neither is used for advertising, and we have not enabled the Google setting that would allow that. You can remove them at any time by clearing cookies for this site in your browser, or block them with any content blocker; nothing on the site stops working if you do.

How long we keep it

For as long as you have an account, because your history is the product. When you delete your account it goes with it. Payment records are kept by Stripe under their own retention rules, which we do not control and which exist because payment processors are legally required to keep them.

Deleting your data

Go to your account page and delete your account. That removes the account itself, every exam session, every answer, and your entitlement record. It happens immediately and cannot be undone.

If you would rather we did it, or you want a copy of what we hold on you first, email support@statelicenseprep.com from the address on the account and we will do it by hand.

Deleting your account is not a refund. If you want your money back, read the refund policy and ask before you delete — once the account is gone we can no longer connect you to the purchase.

Changes

If we start collecting something new or add a processor, this page changes and the date at the top changes with it.

Contact

Anything about your data, including a request to see or delete it, goes to support@statelicenseprep.com.