Privacy Policy
Last updated: September 2, 2026
This Privacy Policy explains what personal data ExamCertAI ("we", "us") collects, why we collect it, how we use it, and the choices you have. By using ExamCertAI you agree to the practices described here. If you don't agree, please don't use the service.
1. Data we collect
Account data
- Email address, display name, password hash (bcrypt — we never store plaintext passwords).
- OAuth identifiers when you sign in with Google, GitHub, or Microsoft — we receive your email and a provider-specific user ID, nothing more.
- Subscription plan (Sandbox / Lite / On-Demand / Reserved) and Stripe customer ID.
Usage data
- Exams you've unlocked, questions you've answered, scores, study-plan progress.
- AI-generated explanations and tutor conversations linked to your account.
- Feature-usage counters (daily AI-call quotas, practice-question counts).
Device and sign-in data (for fraud detection)
For each successful sign-in we record a timestamp, the IP address, a hashed device fingerprint (User-Agent + accepted languages + platform hint), and a unique token ID. We do not use canvas, WebGL, or similar covert fingerprinting techniques. See the Terms of Service for the full account-sharing detection policy.
Payment data
Payments are processed by Stripe. We never see or store your full card number — Stripe sends us a customer ID, a subscription ID, and the last 4 digits of the card for display purposes.
2. How we use your data
- To deliver the service: sign you in, track progress, gate paid features.
- To personalise study plans and AI-generated content.
- To detect and prevent account sharing, abuse, and fraud.
- To measure product usage and the performance of our advertising (see Section 6).
- To send transactional emails (verification, password reset, billing receipts, ban notices, subscription changes).
- To comply with legal obligations (tax, accounting, law-enforcement requests with valid legal process).
3. Who we share data with
We don't sell your personal data. We share it only with the processors we rely on to run the service:
- Stripe — payment processing and subscription management.
- Microsoft Azure — application hosting and the production SQL database (region: East Asia).
- Cloudflare — DNS, CDN, DDoS protection, and the AI Gateway proxy.
- OpenAI — the model that generates explanations and tutor answers. Prompts contain the question text and your message; we do not send your name, email, or payment details.
- Google / GitHub / Microsoft — only when you choose to sign in with that provider.
- Google — Google Tag Manager, Google Analytics 4, and Google Ads, for product analytics and advertising measurement (see Section 6).
- Meta (Facebook) — the Meta Pixel, for advertising measurement (see Section 6).
- Email delivery provider — to send transactional email.
4. How long we keep your data
- Account and usage data: for as long as your account exists.
- Raw IP addresses: 90 days, then truncated to the network prefix.
- Deleted accounts: soft-deleted for 30 days, then purged.
- Billing records: 7 years, as required by tax law.
5. Your rights
You can, at any time:
- Access your data — Settings → Export my data downloads everything we have on you, including a
login-history.csv. - Correct your email, display name, or password in Settings.
- Delete your account — Settings → Danger Zone. We confirm by email and purge after 30 days.
- Object to specific processing or restrict it — email support@examcert.app and we'll action the request within 30 days.
- Opt out of marketing email (we don't run marketing email today, but if we ever do, every message will carry a one-click unsubscribe).
6. Cookies, analytics, and advertising
We use two kinds of browser storage:
- Essential cookies and local-storage keys — a sign-in token, a hashed device fingerprint, your theme preference, and your cookie-banner choice. The service can't work without these, so they are always set.
- Analytics and advertising tags — we load Google Tag Manager, which in turn runs Google Analytics 4, Google Ads conversion measurement, and the Meta (Facebook) Pixel. These set their own cookies and report usage events (which pages you visit, the referring page) to Google and Meta so we can understand product usage and measure our advertising. They never receive your password or payment details, and we don't sell your data.
You can limit or block the analytics and advertising tags with your browser's cookie and tracking controls, a Global Privacy Control or Do-Not-Track signal, an ad-blocker, or the providers' own opt-outs — the Google Analytics Opt-out Browser Add-on and your Google and Meta ad-preference settings. Blocking them does not affect your ability to use ExamCertAI.
7. Children
ExamCertAI is not directed at children under 16. If we learn we've collected data from a child under 16, we will delete it.
8. International transfers
Our primary infrastructure is in Microsoft Azure East Asia. If you access ExamCertAI from outside that region your data is transferred there to deliver the service. We rely on the standard contractual clauses Azure, Stripe, OpenAI, and Cloudflare publish for cross-border transfers.
9. Security
Passwords are hashed with bcrypt. All traffic is encrypted in transit (TLS 1.2+). Database backups are encrypted at rest. Access to the production database is restricted to a small set of administrator accounts with logged actions. If we ever discover a breach affecting your personal data, we will notify you by email within 72 hours of confirmation.
10. Changes to this Policy
We may update this Policy when we ship material changes. We'll notify you by email or in-app banner at least 14 days before the change takes effect.
11. Contact
Questions about your privacy or this Policy? Email support@examcert.app and we'll respond within 3 business days.