Legal

Privacy Policy

Effective date: April 5, 2026

This Privacy Policy explains how Exam.gg ("we," "us," or "our") collects, uses, and protects information about you when you use our service ("the Service"). We are committed to handling your data with transparency and care.

1. Introduction

Exam.gg is a course-aware exam preparation tool. To provide the Service, we need to collect and process certain information about you. This policy describes what we collect, why we collect it, and the controls you have over your data. By using the Service, you agree to the practices described here.

2. Information We Collect

We collect the following categories of information:

  • Account information: When you sign up, we collect your email address and, if you use Google sign-in, your name and profile photo as provided by Google.
  • User Content: Files you upload (PDFs, DOCX, PPTX, etc.), course names, professor names, exam dates, and any other content you enter into the Service.
  • Usage data: Information about how you interact with the Service, including pages visited, features used, and actions taken. This is collected via our analytics provider (PostHog).
  • Technical data: Your IP address, browser type, device type, operating system, and referring URL, collected automatically when you access the Service.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service.
  • Authenticate your identity and secure your account.
  • Process your uploaded files to generate topic heatmaps and mock exam questions.
  • Understand how the Service is used so we can improve it.
  • Send you service-related emails (e.g. account confirmation, password reset). We do not send marketing emails without your explicit opt-in.
  • Comply with legal obligations.

We do not sell your personal data to third parties. We do not use your User Content to train AI models without your explicit consent.

4. Data Storage and Security

Your data is stored using Supabase, a managed database and storage platform. Supabase stores data in secure, access- controlled environments. Data in transit is encrypted using TLS.

While we take reasonable technical and organisational measures to protect your data, no system is completely secure. We cannot guarantee the absolute security of information transmitted to or stored by the Service.

We retain your data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law.

5. Third-Party Services

We use the following third-party services to operate Exam.gg:

  • Supabase: Authentication, database, and file storage. Your account credentials and uploaded files are processed through Supabase. See Supabase's Privacy Policy.
  • PostHog: Product analytics. PostHog collects anonymised usage data to help us understand how the Service is used. See PostHog's Privacy Policy.
  • Google (OAuth): If you choose to sign in with Google, we receive your name, email address, and profile picture from Google. We do not receive access to any other Google account data.

These providers act as data processors on our behalf and are contractually required to handle your data only as instructed.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request that inaccurate personal data be corrected.
  • Deletion: Request that your personal data be deleted.
  • Portability: Request that your data be provided in a portable format.
  • Objection: Object to certain processing activities.

To exercise any of these rights, contact us at support@exam.gg. We will respond within 30 days.

7. Cookies and Analytics

We use cookies and similar technologies to:

  • Keep you signed in across sessions (authentication cookies managed by Supabase).
  • Remember your theme preference (dark or light mode).
  • Collect anonymous analytics via PostHog to understand usage patterns.

We do not use third-party advertising cookies or sell browsing data to advertisers. Most browsers allow you to control or disable cookies in settings, though disabling authentication cookies will prevent you from staying signed in.

8. Changes to This Policy

We may update this Privacy Policy from time to time. The effective date at the top of this page will reflect when the policy was last revised. For material changes we will make reasonable efforts to notify you before they take effect. Your continued use of the Service after the updated policy takes effect constitutes your acceptance of the revised policy.

9. Contact

If you have questions or concerns about this Privacy Policy or how we handle your data, please contact us at support@exam.gg.