Legal

Privacy policy

Last updated August 8, 2026

What we collect

We collect the account information you provide, your profile details, practice submissions, assessment results, and actions you take in the application tracker. We use this information to operate your account, grade work, calculate rankings, and issue credentials.

How your answers are graded

To grade a written answer we send the text you submit, together with the question and its reference answer, to Google’s Gemini API. Google processes this text to return a score and written feedback. We do not send your name, email address, or any other account identifier with it, so the request is not linked to you at Google. Google handles that text under its own API terms, which set out whether submitted content may be used to improve Google’s services. Where no grading key is configured, or the request fails, grading falls back to an offline rubric that runs entirely on our own servers and sends nothing anywhere.

Public credentials

When you earn a credential, its holder name, credential title, score, issue date, serial, and verification status are public at its verification URL. Do not earn a credential under a name you do not want a recruiter to see.

Cookies and similar technologies

We set a cookie to keep you signed in. It is required for the site to work and cannot be turned off while you hold an account. We store your theme preference and a small number of interface settings in your browser’s local storage; these never reach our servers. We use Vercel Analytics and Speed Insights, which measure page views and loading performance in aggregate and set no cookies and no cross-site identifiers.

Advertising

Advertising is currently switched off and no advertising scripts are loaded. If we enable it, we will show it only in designated non-assessment placements, never during a practice attempt or an examination, and we will ask for consent before loading any personalised advertising where consent is required.

Where your data is held

Account and practice data is stored in a Postgres database hosted by Supabase in the United States, and the application runs on Vercel. If you use Prepalyst from outside the United States, your information is transferred there and handled under this policy. Grading requests to Google may be processed in other regions.

Your choices

You may request access, correction, or deletion of your account data by contacting the Prepalyst team at [email protected]. Some credential records may remain resolvable as revoked to preserve the integrity of a verification record.

Contact

Prepalyst is operated from New Jersey, United States. Privacy questions and data requests can be sent to [email protected].