This policy explains what OpenAptitude collects, why, and the control you have over it. Our starting point is to collect as little as possible and never sell your data.
What we collect
- From your sign-in provider (e.g. Google or Facebook): your name, email address, profile picture, and the provider’s account identifier. We never receive your provider password.
- From you: your age band, optional country, and your consent choices.
- From your use of the tests: your answers, scores, per-domain results, and integrity/proctoring events (e.g. counts of copy/paste actions or leaving the test window).
- Automatically: a hashed (pseudonymized) form of your IP address, your browser’s user-agent string, and timestamps — used for security and abuse-prevention.
What we do NOT collect
- No passwords — sign-in is handled entirely by your provider.
- No payment card details — donations are handled by Stripe. We store only that a donation succeeded, its amount, and Stripe's reference for it.
- No screen contents or files. Proctoring only counts browser events (like copy/paste or tab-switching); it cannot see your screen, camera, or files.
- No advertising or cross-site tracking cookies.
How we use it
- To run the Service and score your tests.
- To build and improve our scoring norms using aggregated, screened data (not your identity).
- To keep tests fair — detecting cheating, bots, and abuse.
- To secure the Service and comply with legal obligations.
Legal bases (GDPR)
Where GDPR applies, we rely on: your consent (to create an account and process your results); our legitimate interests (securing the Service, preventing abuse, and improving the test); and legal obligations where they apply. You can withdraw consent at any time by deleting your account.
Cookies and local storage
We use one essential, HttpOnly session cookie to keep you signed in. Your light/dark theme preference is stored locally in your browser. We do not use third-party advertising or analytics trackers.
Who we share it with
We do not sell your personal data. We share it only with service providers that help us run the Service:
- Cloudflare — hosting, database, and storage on their global network.
- Your sign-in provider (Google/Facebook) — governed by their own privacy policies.
- Stripe, if you donate — they handle the payment and hold your card details; we never see them.
- Where required by law, or to protect the rights and safety of our users and the Service.
International transfers
Our infrastructure runs on a global network, so your data may be processed in countries other than your own. Where required, we rely on appropriate safeguards for such transfers. [Specific mechanisms to be confirmed by counsel.]
How long we keep it
We keep your data while your account is active. When you delete your account we remove your profile, sign-ins, attempts, scores, and answers. We may retain minimal, limited-time security logs where necessary for fraud-prevention or legal reasons.
Your rights
Depending on where you live, you may have the right to:
- Access and export your data — download everything we hold about you as a JSON file from your account page.
- Delete your account and data — one click from the same page, no email required.
- Correct inaccurate information, object to or restrict certain processing, and withdraw consent.
- Complain to your local data-protection authority.
Security
Sign-in is delegated to your provider (no passwords stored for members), traffic is encrypted in transit, session cookies are HttpOnly and Secure, and IP addresses are stored only in hashed form. No system is perfectly secure, but we design to minimize what we hold and how it can be misused.
Children
The Service is for adults 18 and older and is not directed at children. We do not knowingly collect data from anyone under 18.
Changes and contact
If we change this policy we’ll update the “last updated” date. To exercise your rights or ask a question, use your account page or contact [privacy@openaptitude.com]. [Data controller identity and any DPO/representative to be confirmed by counsel.]