YOUR DATA, CLEARLY EXPLAINED

Privacy policy

Effective September 18, 2026.

Information used to provide the service

We use your email to send sign-in links and purchase messages and to look up purchased access in Stripe. Stripe processes payment details on its hosted checkout; CodeReady does not receive full payment-card numbers. Stripe stores customers, payments, and subscriptions. Resend processes email addresses and transactional email content for delivery.

Sign-in and essential cookies

A signed, httpOnly session cookie stores your email and access rights for up to seven days. It is sent only over HTTPS in production and is used for authentication, not advertising. Sign-in links contain signed tokens that expire after 15 minutes. Treat them as private; do not share them. Without a server-side token database, a link can be reused during its validity period.

Study progress

Practice answers, topic statistics, mock results, and an in-progress mock are saved in this browser’s localStorage, separately by sign-in email. They are not uploaded to a CodeReady progress database or synced automatically. Anyone with access to your browser profile may be able to read that data. Logout removes the session cookie but leaves local study data for your next visit.

Use dashboard export/import to move progress. Use Clear progress to clear answer history and scores. Browser site-data controls remove all local CodeReady data, including in-progress mock state and the session cookie.

Infrastructure and logs

Vercel hosts the application and may process IP addresses, request metadata, and operational logs. Stripe and Resend keep their own service records under their policies. Authentication links can contain credentials in the URL; we use no-referrer headers on verification responses and do not intentionally log tokens or email contents in application logs. Provider log handling is configured by the operator.

Use, sharing, and retention

We use information to provide access, process transactions, operate the service, prevent abuse, and answer support requests. We do not sell personal information or use advertising trackers in this version. Data is shared with the service providers needed to perform these functions and where legally required. Payment records may need to be retained for tax, accounting, fraud prevention, or legal obligations.

Your choices

You can stop using the service, cancel a subscription from the dashboard, remove local site data, or contact us about access, correction, or deletion requests. We may need to verify your request and retain records required by law. Transactional email is used for sign-in and purchases, not a marketing subscription.

Children and international processing

The service is intended for adults preparing for professional exams, not children under 13. Our providers may process data outside your country. Contact support if you believe a child has provided personal information or have questions about your applicable privacy rights.

Contact

Email hello@codereadyprep.com for privacy requests. This policy may be updated as the service changes; the effective date will be revised.