Your Privacy Matters

We're committed to protecting your personal information and being transparent about how we use it.

Last updated: August 2025

Information We Collect

Personal Information

  • Email address (for account creation and communication)
  • Full name (optional, for personalization)
  • Profile picture (optional, via OAuth providers)
  • Payment information (processed securely through Stripe)

Usage Information

  • Questions you've viewed and completed
  • Study progress and performance metrics
How We Use Your Information

Service Delivery

  • Provide access to interview questions
  • Track your learning progress
  • Personalize your experience
  • Process payments securely

Communication

  • Send account verification emails
  • Notify you of important updates
  • Respond to your support requests
How We Protect Your Data
  • Encryption: All data is encrypted in transit and at rest
  • Secure Infrastructure: We use industry-standard cloud providers (Supabase, Vercel)
  • Payment Security: Payment data is processed by Stripe, not stored on our servers
  • Access Controls: Limited access to personal data on a need-to-know basis
  • Regular Updates: We keep our security measures up to date
Your Rights

Access & Portability

Request a copy of your personal data

Correction

Update or correct your information

Deletion

Request deletion of your account and data

Opt-out

Unsubscribe from marketing communications

Cookies & Tracking Technologies

We use cookies, web beacons, and similar tracking technologies to enhance your experience and analyze usage patterns.

Essential Cookies

  • Authentication and session management
  • Security and fraud prevention
  • Basic site functionality
  • User preference storage

Analytics Cookies

  • Site traffic and usage measurement
  • Performance optimization
  • Feature usage analysis
  • Error tracking and debugging

Cookie Control: You can manage cookie preferences through your browser settings. However, disabling certain cookies may limit functionality. Most browsers allow you to refuse cookies, delete existing cookies, or receive notifications when cookies are being used.

Third-Party Service Providers

We partner with trusted third-party services to deliver our platform. Each provider adheres to strict data protection standards:

Payment & Security

  • Stripe: PCI DSS compliant payment processing. We never store your full payment information on our servers.
  • Supabase: SOC 2 Type II certified database and authentication services with end-to-end encryption.

Infrastructure & Analytics

  • Vercel: ISO 27001 certified hosting with global CDN and DDoS protection.
  • Analytics Providers: Anonymized traffic analysis to improve user experience and performance.

Data Processing Agreements: All third-party providers are bound by data processing agreements that ensure your information is handled according to applicable privacy laws and our privacy standards.

Data Retention & Deletion

We retain your personal data only as long as necessary for legitimate business purposes and legal compliance.

Account Data

Retained while your account is active and for up to 30 days after deletion request to allow for account recovery.

Usage Analytics

Anonymized usage data retained for up to 2 years for service improvement and security purposes.

Legal Requirements

Some data may be retained longer if required by law, regulation, or for legitimate legal purposes.

Secure Deletion: When data is deleted, we use industry-standard secure deletion methods to ensure it cannot be recovered. Backups containing your data are also securely purged according to our retention schedule.

Children's Privacy Protection

COPPA Compliance

Our Service is not intended for children under 13 years of age. We do not knowingly collect, use, or disclose personal information from children under 13 without verifiable parental consent.

  • We do not knowingly solicit data from children under 13
  • We do not knowingly market to children under 13
  • If we learn we have collected data from a child under 13, we will delete it immediately
  • Parents can contact us to review, delete, or stop collection of their child's information

Parental Rights: If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at codexprepteam@gmail.com. We will take steps to verify your identity and remove the information.

International Data Transfers

As a global service, your information may be transferred to and processed in countries other than your own.

Data Locations

  • Primary servers located in secure data centers
  • Backup systems in geographically distributed locations
  • CDN nodes worldwide for performance optimization
  • All locations meet international security standards

Transfer Safeguards

  • Standard Contractual Clauses (SCCs) with all processors
  • Adequacy decisions where applicable
  • Encryption in transit and at rest
  • Regular security audits and compliance reviews

Your Consent: By using our Service, you acknowledge and consent to the transfer of your information to countries that may have different data protection laws than your country of residence. We ensure appropriate safeguards are in place regardless of location.

Legal Framework & Dispute Resolution

Governing Law

This Privacy Policy and any disputes arising from it are governed by the laws of Singapore, without regard to conflict of law principles. This choice of law does not affect your rights under the data protection laws of your country of residence.

Dispute Resolution

We encourage you to contact us first to resolve any privacy concerns. If needed, disputes may be resolved through binding arbitration in Singapore, or in your local jurisdiction where permitted by law.

Regulatory Compliance: We comply with applicable data protection regulations including GDPR, CCPA, PDPA, and other relevant privacy laws. You may also have the right to lodge a complaint with your local data protection authority.

Contact Us

Have questions about this Privacy Policy or want to exercise your rights?

codexprepteam@gmail.com

This Privacy Policy is effective as of August 2025 and may be updated from time to time.