PASSDEED · PRIVACY POLICY · UPDATED AUGUST 2026

Privacy, plainly.

1. What we collect

Your email address (when you start the free diagnostic, join the waitlist, or create an account) and your study activity: which questions you answered, what you chose, response times, and the ability estimates computed from them. That activity data is the product — it is what makes the practice adaptive.

2. How we use it

To run your sessions, compute your Readiness Score, save your records to your account, improve question quality through aggregate statistics, and email you about your results and about PassDeed itself. Every marketing email includes an unsubscribe link; service emails (like sign-in links) are sent only when you request them.

3. What we never do

We do not sell your personal data, and we do not share it with advertisers. Aggregate, de-identified statistics (for example, the percentage of candidates who miss a topic) may be published; they never identify you.

4. Where it lives

Data is stored with Supabase (managed PostgreSQL) in the United States, protected by row-level security so your records are readable only by you and by the service itself.

You can sign in with a one-time email link, an email address and password, Sign in with Google, or Sign in with Apple. Supabase Auth handles each method. Supabase Auth stores passwords only as salted hashes; PassDeed never sees or stores a plaintext password.

With Google sign-in, Google shares your basic profile — your name, email address, and profile picture — with our authentication provider, Supabase Auth. PassDeed itself uses only your email address — to create your account and sign you in. We do not use Google data for anything else, do not sell it, and do not share it with advertisers.

The same limits apply to Apple sign-in: PassDeed uses only the email address Supabase Auth provides, to create your account and sign you in. We do not use Apple data for anything else, do not sell it, and do not share it with advertisers. If you choose Apple's “Hide My Email,” we receive only the private relay address Apple generates (an @privaterelay.appleid.com address), never your real email.

5. Payments

Payments are processed by Stripe. Your card details go directly to Stripe and never touch PassDeed servers; we store only what we need to manage your access — a Stripe customer reference, what you bought, its status, and when access ends. Stripe's own privacy policy governs their processing.

6. Analytics

We always measure product usage with our own first-party event log: page views and product actions (for example “diagnostic started”), tied to a random identifier stored in your browser. The first-party analytics record does not store your raw IP address.

On the public website, Google Analytics 4 or Plausible may also receive page views and product event names and properties, but only when that provider is configured. Those providers process data under their own privacy policies. Their scripts are not loaded in the installed mobile app; the app still sends the same first-party events to PassDeed's /api/trackendpoint.

7. Data deletion & export

If you can sign in, the primary path is the in-app account-deletion control. Complete its security check and type DELETE to confirm. If you cannot sign in, or you only took the free diagnostic without an account, email support@passdeed.com from the address whose data you want deleted with the subject “Delete my data.” We complete verified email requests within 30 days and reply when the request has been handled. You can request a JSON export at the same address before deleting.

Your sign-in account, profile, preferences, and any diagnostic lead already claimed by this account are permanently deleted. Study sessions and question responses are retained only as anonymized learning data: all account and lead links are removed. This protects item statistics without identifying you. Analytics events lose their account, lead, and anonymous-device links. Support and review records are stripped of personal fields and account attribution, while non-identifying service and content metrics remain.

A restricted deletion audit retains your internal account UUID, timestamps, the actions taken, and Apple revocation status so operators can prove and follow up the deletion. It does not retain your name, email, password, or provider tokens. Subscription and Stripe-linked billing records are retained under a non-identifying deletion reference for legal and accounting obligations. Stripe keeps the corresponding billing records; PassDeed never stores your card details.

For an account linked to Sign in with Apple, the deletion control may require a fresh Apple sign-in. We also ask Apple to revoke PassDeed’s authorization. If Apple cannot accept it immediately, the revocation is recorded for follow-up and your PassDeed account is still deleted. See the full data-deletion explanation.

8. Cookies and local storage

PassDeed uses the first-party cookies required to keep you signed in and protect account actions. First-party browser storage holds limited product state such as the random analytics identifier and first marketing page seen in a browser session, your last selected state, incomplete-session recovery, and short checkout or app-link handoffs. In the installed app, your chosen local-notification time also stays on that device and is not sent to PassDeed.

We do not use advertising cookies. If Google Analytics 4 or Plausible is configured on the public website, that provider's own browser-storage practices apply under its privacy policy. Those third-party analytics scripts are not loaded in the installed mobile app.

Privacy Policy — PassDeed · PassDeed