PASSDEED · PRIVACY POLICY · UPDATED JUNE 2026
Privacy, plainly.
1. What we collect
Your email address (when you start the free diagnostic, join the waitlist, or create an account) and your study activity: which questions you answered, what you chose, response times, and the ability estimates computed from them. That activity data is the product — it is what makes the practice adaptive.
2. How we use it
To run your sessions, compute your Readiness Score, save your records to your account, improve question quality through aggregate statistics, and email you about your results and about PassDeed itself. Every marketing email includes an unsubscribe link; service emails (like sign-in links) are sent only when you request them.
3. What we never do
We do not sell your personal data, and we do not share it with advertisers. Aggregate, de-identified statistics (for example, the percentage of candidates who miss a topic) may be published; they never identify you.
4. Where it lives
Data is stored with Supabase (managed PostgreSQL) in the United States, protected by row-level security so your records are readable only by you and by the service itself. Authentication is handled by Supabase Auth via one-time email links — we never see or store a password.
5. Payments
Payments are processed by Stripe. Your card details go directly to Stripe and never touch PassDeed servers; we store only what we need to manage your access — a Stripe customer reference, what you bought, its status, and when access ends. Stripe's own privacy policy governs their processing.
6. Analytics
We measure product usage with our own first-party event log: page views and product actions (for example “diagnostic started”), tied to a random identifier stored in your browser. We do not record IP addresses in analytics, do not use third-party trackers, and do not share analytics with anyone.
7. Data deletion & export
Email support@passdeed.com from your account address to export or permanently delete your data. Deletion removes your account, profile, sessions, responses, subscription records, and analytics tied to your account within 30 days; we confirm by email when it completes. Anonymous diagnostic records tied only to an email are deleted on the same request. Records we must keep for tax or accounting (for example Stripe invoices) are retained as the law requires.
8. Cookies
PassDeed sets only the cookies required to keep you signed in, plus one localStorage value holding the random analytics identifier described above. There are no third-party advertising or analytics cookies.