Privacy Policy
Effective date: April 27, 2026 · Last updated: April 27, 2026
1. Introduction
2. Information We Collect
2.1 Information you provide directly:
- Full name and email address upon registration
- Profile information and study preferences
- Payment information (processed by Paddle — we never store card details)
- Communications you send to our support team
2.2 Information collected automatically:
- Practice session data: questions answered, time spent, accuracy rates, difficulty levels
- Score history and performance trends
- Feature usage patterns and navigation data
- Device type, browser, and operating system
- IP address and approximate location (country level)
2.3 Information from third parties:
- Authentication data if you sign in via third-party providers (Google OAuth)
3. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain the Service
- Generate personalized score predictions and study recommendations
- Process subscription payments via Paddle
- Send transactional emails (account confirmation, billing receipts, password resets)
- Send product updates and feature announcements (you may opt out at any time)
- Analyze usage patterns to improve the platform
- Detect and prevent fraudulent or abusive activity
- Comply with legal obligations
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area, we process your data under the following legal bases:
- Contract performance: to provide the Service you have subscribed to
- Legitimate interests: to improve our platform and prevent abuse
- Consent: for marketing communications
- Legal obligation: to comply with applicable law
5. Data Storage and Security
Your data is stored securely using Supabase (supabase.com), with servers located in the United States. We implement industry-standard security measures including:
- TLS encryption for all data in transit
- Encryption at rest for sensitive data
- Row-level security policies on all database tables
- Regular security audits and access controls
No method of transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data.
6. Data Sharing and Third Parties
We do not sell, rent, or trade your personal information. We share data only with:
- Paddle (paddle.com): payment processing
- Supabase (supabase.com): database and authentication infrastructure
- Vercel (vercel.com): hosting and deployment
All third-party processors are bound by data processing agreements and applicable privacy regulations.
7. Data Retention
8. Your Rights
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your personal data
- Export your practice history and account data
- Withdraw consent for marketing communications
- Lodge a complaint with your local data protection authority (EU users)
To exercise any of these rights, contact us at: multiprep.support@gmail.com. We will respond within 30 days.
9. Children's Privacy
10. Cookies
11. Changes to This Policy
12. Contact Us
For privacy-related questions or requests:
Email: multiprep.support@gmail.com
Website: multiprep.xyz