Privacy policy
Last updated: August 18, 2026
This policy explains what the operator of this ExamOps deployment ("we", "us") collects, why we collect it, who processes it, and what control you have. The current operator is identified through support@examopshq.com.
What we collect
| Data | Why we hold it |
|---|---|
| Your email address and authentication identity | To create your account, sign you in, and contact you about your account |
| Your study activity: which questions were served to you, the answer you selected, whether it was correct, and how long you took | To show your accuracy and progress, to avoid serving you the same question twice in a day, and to enforce daily question limits |
| Your lab progress: the exam and exact lab version, identifiers of steps you completed or completed with a revealed reference answer, and timestamps for when progress began, changed, or completed | To resume your progress across sessions without retaining your entered responses, scratch work, or downloaded lab data |
| Your subscription and payment records: plan, status, billing period, and identifiers issued by our payment processor | To give you the access you paid for, to handle refunds and disputes, and to meet financial and tax record-keeping obligations |
| Operational logs and security data | To keep the service running, to apply rate limits, and to investigate abuse |
What we do not collect
- Your full card number and security code do not pass through our servers. Stripe collects them directly. Stripe may show us limited payment-method metadata—such as card brand, last four digits, expiration, and billing details—for transaction support, fraud review, refunds, and disputes.
- We do not sell your personal data, and we do not share it with advertisers.
- We do not use third-party advertising or cross-site tracking cookies. Authentication state, a short-lived pending-checkout choice, and lab completion identifiers may be kept in browser storage so you can remain signed in, resume the action you requested after authentication, and keep lab progress if the progress service is unavailable. Lab responses and scratch work are not written to browser storage.
Who processes your data
These providers process data on our behalf, under contract:
| Provider | Role |
|---|---|
| Supabase | Account authentication and the application database |
| Cloudflare | Hosting, content delivery, request rate limiting, and Turnstile abuse protection |
| Stripe | Payment processing, subscription billing, and refunds |
| Resend | Sending account confirmation, recovery, and other transactional emails through the configured SMTP service |
| GitHub or Google | OAuth identity, only if you choose that sign-in method |
| Google Fonts | Delivering the public site's typefaces; normal request data such as your IP address and browser metadata reaches the provider |
| Supabase Auth | Creating account-email events and handing them to the configured email service |
These providers may process data outside your country, including in the United States. Where required, transfers rely on the contractual and legal safeguards offered by each provider and configured by the operator.
Legal basis for processing
Where the GDPR or a similar regime applies, we rely on:
- Performance of a contract — to provide the account and the access you purchased.
- Legal obligation — to retain billing and tax records.
- Legitimate interests — to keep the service secure and prevent abuse.
How long we keep it
- Account and study data — for as long as your account exists. If you close your account, server-side question and lab progress is deleted or anonymized. You can reset a lab's browser-local completion from the lab workspace; clearing this site's browser storage also removes all local copies.
- Billing records — retained after account closure for the period required by applicable financial, tax, fraud, and dispute obligations. Our database deliberately prevents billing history from being erased by an ordinary account deletion, because we are required to keep it.
- Operational logs — for the hosting provider's configured operational window, and longer only when needed to investigate a security event or meet a legal obligation.
Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, object to or restrict processing, and receive a copy in a portable format. To exercise any of these, contact support and be prepared to verify the address on your account.
Two honest limits. First, if you have billing history we cannot delete the records we are legally required to keep; we will disable your account and minimize what remains. Second, we may need to verify your identity before acting on a request, so that someone else cannot use it against you.
We aim to respond within 30 days, or sooner when applicable law requires it. If you are in the EU or UK and are unhappy with our response, you may complain to your local supervisory authority.
Security
Client access to personal study rows is protected by database row-level security: a signed-in account can read only its own rows. Authorized server-side service access is limited to operating, securing, and supporting the service. Lab progress stores completion metadata and timestamps, not the response you entered. Correct question answers are returned only after you submit the matching question for grading; the browser cannot query or download the question answer-key table. Payment secrets are held as encrypted platform secrets, never in client code. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority as required by law.
Children
ExamOps is intended for adults pursuing professional certification and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has created an account, contact support and we will remove it.
Changes
If we change this policy materially, we will update the date above and notify account holders by email before the change takes effect.