Privacy
What we store, and what you can do about it
This page says exactly what the product keeps about you and how to get rid of it. Last updated 10 August 2026.
You can use most of it without an account
The study notes and the free practice questions work signed out. Nothing about a signed-out visit is stored against a person by default: no account, no profile, no record of which answers were picked. The one exception is if you choose to save your result, described below; that is something you type in, not something collected by visiting.
If you sign in
Signing in creates one row about you, holding:
- your email address, as your sign-in provider reports it;
- an identifier from that provider, so we recognise you next time;
- the date the account was created.
Sign-in is handled by Supabase Auth, either with Google or with an emailed sign-in link. We never see or store a password, because there is no password to see. Signing in with Google does not give us your Google contacts, files, or anything beyond your email address, name and profile picture.
If you answer questions
Each attempt stores which questions were served, which option you picked, whether it was right, how long you spent on it, and a copy of the question as it was shown to you. That copy exists so an attempt you review later still makes sense after the question bank changes.
This is what makes the dashboard and review pages possible. It is also the most personal thing here, since it is a record of what you did not know on a given day. It is visible only to you: the database enforces that with row-level security, not with application code that could be bypassed.
If you save your result
At the end of the free practice questions, and on a locked page, there is a form to save your result: your email, and optionally the date you are taking the exam. It says plainly what it is for before you type anything, and it is opt-in every time, never pre-filled or pre-ticked.
That row also carries which certification it was captured against, which of the two places it was captured from, the moment you consented, and the same random visitor identifier described below, so that if you later create an account we can recognise it is you. We use it to keep your result and to email you when access opens. Nothing else, and no third party sees it: it is not synced to a mailing list yet, and when it is, that will not change what this page says about removing it.
Where it lives
- The database and sign-in are both Supabase, hosted in the EU (eu-west-1, Ireland). Signing in with Google also involves Google as the identity provider.
- The site itself is served from within the EU, behind Cloudflare, which sees request metadata such as your IP address in the course of routing traffic.
- Sign-in link emails and other account emails go out through Resend, which sees your email address and the content of that one email in order to deliver it.
- Payments are taken by Polar (Polar Software, Inc.), which is the seller and merchant of record for anything bought here, not a processor acting for us. Paying means leaving this site for Polar's own checkout, where they collect your card details, your billing address and your email in order to charge you and to work out the tax. Your card details never reach our servers and we never see them: what comes back to us is that a payment succeeded, for which account, and for how much.
There is no analytics script, no advertising pixel, and no third-party tracker on any page. Nothing about you is sold or shared with anyone for marketing.
We do count our own funnel, in our own database, and it is worth being exact about what that means. Two first-party cookies are set: a random identifier this site generates, and a short label for how you arrived, such as a link from a forum post or a search engine. Against those we record which pages were seen and whether the free practice questions were started and finished. We do not store your IP address, your browser fingerprint, or the full address of the page you came from, and none of it leaves our database. It exists so we can tell how many people tried the product and where they found it.
How long it is kept
For as long as the account exists. Attempt history is the product, so deleting it on a schedule would defeat the point, but it goes when you go, and you can ask for that at any time.
Getting a copy, or getting rid of it
Email [email protected] from the address you signed in with, or the address you saved a result under, and ask for either. A copy comes back as a JSON file with your profile, attempts and answers, and any saved-result row under that email. Deletion removes the account row and everything that references it, which includes every attempt and answer, plus any saved-result row matched by that email; none of it is recoverable afterwards.
Both are done by hand within a few days, by one person, checking every place your data could be held rather than relying on memory each time. A self-serve button replaces this before the product starts charging for anything. Under GDPR you can also object to processing, ask for a correction, or complain to the Dutch DPA (Autoriteit Persoonsgegevens).
Changes
If this page changes in a way that affects what is stored about you, the date at the top changes with it.
Questions about any of this: [email protected]