Privacy Policy

Last updated: February 9, 2026

1. Introduction

NECexam ("we", "us", or "our") operates the NECexam web application ("the Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name, email address, and authentication credentials. If you sign in with Google, we receive your name, email address, and profile picture from Google.

2.2 Study Data

We collect data about your use of the Service, including:

  • Quiz and exam answers, scores, and completion times
  • Flashcard review history and spaced-repetition data
  • Sections read, bookmarks, and highlights
  • Study streaks and progress metrics
  • Study group participation and messages

2.3 Payment Information

Payment processing is handled by Stripe. We do not store your credit card number, CVV, or full card details on our servers. We receive from Stripe your customer ID, subscription status, and billing period information. See Stripe's Privacy Policy for details on how Stripe handles your payment data.

2.4 Usage Data

We automatically collect standard server logs including IP address, browser type, device type, pages visited, and timestamps. This data is used for security, performance monitoring, and improving the Service.

3. How We Use Your Information

We use your information to:

  • Provide and maintain the Service
  • Personalize your study experience (difficulty levels, spaced repetition scheduling, progress tracking)
  • Process payments and manage subscriptions
  • Display leaderboards and group study features (using your display name and avatar)
  • Send important account notifications
  • Improve the Service based on usage patterns
  • Prevent fraud and enforce our Terms of Service

4. How We Share Your Information

We do not sell your personal information. We share data only:

  • With Supabase — our database and authentication provider. See Supabase's Privacy Policy.
  • With Stripe — for payment processing.
  • With other users — your display name, avatar, and study stats may be visible on leaderboards and within study groups you join.
  • As required by law — to comply with legal obligations, enforce our terms, or protect rights and safety.

5. Data Storage and Security

Your data is stored on servers managed by Supabase (hosted on Amazon Web Services). We use industry-standard security measures including encryption in transit (TLS), row-level security policies, and secure authentication tokens. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

6. Data Retention

We retain your account and study data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or legitimate business purposes (such as fraud prevention or financial record-keeping).

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Opt out of marketing communications
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact us at the email listed below.

8. Cookies and Local Storage

We use essential cookies for authentication and session management. We use browser local storage to save your study preferences and theme settings. We do not use third-party advertising cookies or tracking pixels.

9. Children's Privacy

The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on the Service or sending you an email. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect and how it is used, the right to request deletion, and the right not to be discriminated against for exercising your rights. Contact us to exercise these rights.

12. Contact

If you have questions about this Privacy Policy or your data, contact us at privacy@necexam.com.