Privacy policy
Last updated 17 September 2026
This policy describes what Preptics collects and why. It is written to be specific rather than generic — where we collect something unusual, such as behavioural signals during an exam, we say so plainly rather than hiding it under "usage data".
The data controller is an independent business. A US limited liability company is being formed; this page will name it as soon as registration completes. Contact: support@preptics.com. Once the US LLC is registered it becomes the controller and this page will name it and its registered address.
What we collect
Account
- Email address and a hashed password. There is no sign-in through Google, Apple or any other account.
- A display name, which defaults to a pseudonym derived from your email. We never ask for your real name.
- Optional country code, used for country leaderboards.
- Accessibility settings, such as an extended-time accommodation.
Exam activity
- Which exams you started and submitted, and when.
- Your answers, and the time between a question being served and answered.
- Your first answer to a question, where you later changed it. This is what lets us tell you whether changing your mind tends to help you or cost you — a thing no study guide can tell you about you.
- Your scores, domain breakdowns and leaderboard placement.
How you work through a question
So that the analytics can describe how you study rather than only whether you got it right, we record a small set of counts about how you use the tools on screen:
- Which answer options you crossed out, and whether you later chose one of them.
- How many highlights you made and how long they were — never the text you highlighted, or anything you wrote. What we keep here is a count and a length, nothing else. (Your working itself is saved, separately and only for you — see Your own working below.)
- When you opened the question list, and which flagged questions you returned to.
- Whether you skipped a question and came back to it, and how long it took before you made your first move on it.
- In Maths: how often you opened the graphing calculator and the reference sheet, and how many expressions and graphs you made — never what you typed into it.
- In lessons and drills: how long you spent on a card, which practice simulations you adjusted, and which linked resources you opened.
- In drills and untimed practice only: how confident you said you were before answering, if you choose to say. Timed mock exams do not ask — test day does not, either.
Your own working
The exam tools let you highlight a passage, cross out options, sketch on a scratchpad and leave yourself a note on a question. All of that is saved, because otherwise a refresh — or a phone that drops the tab — would destroy forty minutes of reading in the middle of a module you cannot restart.
It is saved for one reason: to give it back to you. Your working is stored against your own answer to that question, it is shown to you and to nobody else, it is never read for analytics, never pooled with anyone else’s, and it is deleted with your account. The counts described above — how many highlights, how long — are a separate thing and never include what you actually wrote or drew.
This is the same footing as a word processor saving your draft. If it helps to have the test: data you get back is a feature; data we merely observe about you is something else, and we hold ourselves to that line rather than to what we could argue for.
What we work out from it
From your answers and timings, our software estimates how well you know each skill, how hard each question is, which answers were probably rushed guesses, and when a topic is due for review. Your study plan updates itself automatically from those estimates as you practise, sit mocks and work through lessons.
Estimates are shown as ranges, with how confident we are in them. A rushed guess never changes your score — a right answer is a right answer, as it is on test day. It only stops a lucky or unlucky click from distorting your skill estimates. None of this is used for anything except your own studying. How Preptics works explains each calculation in plain language.
Recalibrating the models. Once a week, a scheduled job re-estimates how hard each question is and how quickly each skill tends to be learned, from everyone’s answers together. It reads those answers without names, email addresses or account numbers: each practice test is treated as an anonymous occasion, and a student’s run of answers within a skill is keyed by a one-way hash. What it writes back describes questions and skills, not people.
One part of that job does concern an individual. Once you have completed 1,000 spaced reviews, it can compute review timing fitted to your own history, which means reading your review record — which question, when, and how it went — against an internal account number. Those settings are stored against your account and deleted with it. Until you reach 1,000 reviews, everyone’s reviews are timed by the same published defaults.
What we deliberately do not collect
A list of what a study tool could collect is worth as much as a list of what it does. We have decided against all of the following, and we are not planning to revisit them:
- No mouse movement, cursor paths, or click rhythm. No keystroke timing or typing cadence. These are behavioural biometrics, and most of our users are school-age.
- No analysis of what you highlighted, sketched, wrote or typed into the calculator. Your working is saved so you can have it back, and that is the whole of it — we do not read it, mine it, score it, train on it or show it to anyone. What you thought was worth marking is your thinking, and reading it back is not something a study tool should do.
- No tracking after you leave. If you open a linked resource we record that you opened it. We do not follow you or time you off our site.
- No guesses about your state of mind. We will not score your focus, estimate your burnout risk, or infer your mood or attention from how you clicked. Those numbers sound scientific, would be built from a handful of sessions, and would be wrong about real people.
- No camera, microphone, screen recording, or clipboard contents. We record that a paste happened during an exam, never what was pasted.
Exam integrity signals
This is the part most policies leave vague, so here it is in full. While an exam is in progress we record: when the exam tab loses focus, when full-screen mode is exited, copy and paste events on the question area, whether the same exam is open in more than one tab, and whether your device's reported timing diverges from our server's.
This exists to keep the leaderboard meaningful. It is not used for advertising, profiling, or anything outside exam integrity. A flagged exam still gets its score, explanations and analytics — the only consequence is that it may not appear on the public leaderboard.
Device and network
- A device identifier stored as a first-party cookie and hashed before it is stored. We do not use browser fingerprinting.
- Your browser family (for example "Chrome"), not a full user-agent string.
- A truncated IP address only — the /24 network prefix for IPv4 or /48 for IPv6. We do not store full IP addresses.
When something breaks
If a page or our server fails with an error, we record what failed so we can fix it: the error message and where in our code it happened, the page’s address with anything after a ? or # removed and ids replaced, your browser family, which version of the site you were using, and — if you were signed in — your account. It never includes what was on the page, your answers, or anything you typed. We record this ourselves; no error tracking company receives it.
Visits to our public pages
On the public pages — home, guides, help, pricing, sign-up and sign-in — we count visits with Umami, so we can see which pages help people and how they found us. It sets no cookies, stores nothing in your browser, and is never told your name, email address or account. For each page view it receives the page’s address with everything after a ? removed except campaign tags such as utm_source, and nothing after a #; the page title; the site you came from, reduced to its address; and your screen size and browser language. Like any web request it also carries your IP address and browser details, which Umami uses to estimate your country and device type and to tell one visitor from another without cookies.
Your dashboard, settings and exams never load it, and if you move to one of them from a public page, nothing is sent from there — not the page, and not the page you left.
Payments
Payments are handled by our payment provider acting as merchant of record. We never see or store your card details. We keep a record of the amount, currency, date and provider order reference. If you buy the optional Founder’s Pass, we also keep your supporter number and the date, which is what your Early Supporter Certificate shows.
Things you send us
Feature requests, contact messages and question error reports, plus any email address you choose to include.
How AI is used
Two things you see are written by an AI model today: the written debrief on a practice test’s results page, and the one-sentence explanation you can ask for in lessons, drills and review. A weekly summary and the reasons behind your study plan are planned; when they ship they follow the same rules. This is exactly how it works, and how we use AI goes further.
- The AI writes words, not numbers. Every score range, percentage, skill estimate and count you see is calculated by our own software. The AI is only allowed to explain those figures; if it returns a number of its own, we discard it.
- What is sent: a summary our software has already worked out — your score ranges, accuracy by difficulty, which skills cost you points, your pacing, the kinds of mistake you made, and what is due for review. It carries no identifier at all: not your name, email address, username, account number, or any reference we could use to link it back to you.
- What is never sent: the questions or passages you saw, your answers to them, anything you highlighted, sketched, wrote or typed into the calculator, your exam integrity signals, or your device and network details.
- The one exception is something you ask for. Outside timed exams, you can select a phrase in a lesson, a drill or a post-exam review and ask what it means. That phrase is sent, answered, and not kept by us. It is never available during a timed exam.
- Where it goes: requests are routed through OpenRouter and restricted to providers that have committed to zero data retention — they do not store what we send, and they do not train on it. The model is DeepSeek’s, run by those providers rather than by DeepSeek. If no provider meeting that standard is available, you see our standard wording instead; the request is never sent anywhere else. Each provider is named on third-party services.
- What we keep: the summary and the written explanation, for up to 90 days, so a page you reopen does not need a new request. The explanation is stored as a template whose figures are filled in from your own results each time it is shown, so it contains nothing about you and may be reused for another student whose results look similar. The summary it was written from is linked to your account and is deleted with it.
Separately, and never involving anything about you: we use models from Anthropic to help write and check our questions and lessons before a person reviews them, and we send our own published explanations, lessons and help articles to OpenAI’s embedding model, through the same zero-data-retention routing, so that material can be searched by meaning.
Why we are allowed to hold it
- Contract — your account, purchases and exam results, and the study records described above. The analytics built from those records are the service you are paying for; we cannot provide it without them.
- Legitimate interests — integrity signals, device records and abuse controls. Our interest is keeping exams fair and preventing fraud; the data is minimised (hashes and truncated IPs), and the consequences are limited to leaderboard eligibility. Error reports, too: our interest is finding and fixing what breaks, and they hold only what is listed under “When something breaks”. And visit counts on the public pages: our interest is knowing which pages help people and how they find us, with no cookies, nothing linked to your account, and nothing from inside the app.
- Legal obligation — transaction records retained for tax and accounting.
- Consent — optional analytics cookies, if and when we enable them. See our cookie policy.
How long we keep it
- Account and exam history: until you delete your account.
- Integrity and risk signals: 12 months, then aggregated.
- The question-by-question study records above: 12 months in detail, the same window as integrity signals. After that we keep only the summarised version — the counts and averages your analytics are built from — and the detail is discarded.
- AI-written analysis, and the summary it was written from: 90 days, or until you delete your account if that is sooner.
- Your skill estimates, review schedule and, if you have reached 1,000 reviews, your personal review timing: until you delete your account. They are recalculated from your answers as you practise, so they never outlive the records they come from.
- Signup abuse records: 30 days.
- Error reports: 30 days after the error was last seen.
- Visit counts on the public pages: held by Umami for the retention period of our plan with it. They are not linked to your account, so there is nothing of yours in them to delete when you delete it.
- Transaction records: as long as tax law requires, but detached from you when you delete your account.
Who else sees it
We do not sell your data and we do not share it for advertising. We use processors to run the service, each acting on our instructions only: Supabase (database and sign-in), Vercel (hosting), Cloudflare (DNS, scheduling and the sign-up bot check), Lemon Squeezy (payments, as merchant of record), Zoho (email), your browser’s push service if you turn on notifications, OpenRouter and the zero-data-retention providers it routes to (AI), GitHub (the weekly recalibration job), and Umami (visit counts on the public pages). Third-party services says exactly what each one receives and links to its own policy.
Other students never see your answers, your study records or your skill estimates. If you are on the public leaderboard, it shows your display name, your country if you set one, your rank and the score of your ranked attempt. You can leave it at any time in settings.
Your rights
You can export everything we hold about you, or delete your account outright, from settings — both are immediate and self-serve. For the full list of rights and how to exercise them, see your data rights.
Children
Preptics is not intended for children under 13, and we do not knowingly create accounts for them. If you believe a child has an account, contact us and we will remove it.
Changes
If we change this policy materially we say so on this page, the app asks you to read and accept the new version the next time you use it, and we record which version you accepted. Where the change affects how we use data you have already given us, we also tell you by email.
Preptics is operated by an independent business. A US limited liability company is being formed; this page will name it as soon as registration completes.
Questions about this document: support@preptics.com