Guest data handling
Answers, scores, mastery, reviews, applications and profile preferences are stored in browser local storage for guest users. Clearing site data removes this local progress.
Optional accounts
When a user creates an account or signs in, Supabase Auth handles email, password or magic-link authentication. QuantPrep never implements custom password cryptography. Synced progress is protected by row-level security so an authenticated user can access only their own private records.
Completed verbal rehearsal notes and self-reviews are also part of your saved progress. Owner-only operational reports aggregate synced learning activity, such as training days, question counts and observed return rates after signup; these reports do not display your answers, notes or email address. Unsynced activity is not observed in those aggregates. No AI or voice provider is enabled.
Data choices
The profile page provides a JSON data export, local data deletion and permanent account deletion for configured cloud accounts.
First-party analytics
QuantPrep records limited first-party events such as page views, training starts, completed sessions and account conversions. The browser keeps random analytics identifiers in session storage for navigation within a browser session (renewed after 30 minutes of inactivity). The Netlify function hashes those identifiers before storage; it does not derive identity from IP address or user-agent; the application does not store the raw IP address, advertising identifiers or cross-site profiles. Analytics does not set a cookie or persistent browser identifier, honors the browser’s Do Not Track and Global Privacy Control settings and removes event records after approximately 400 days. These aggregate statistics help operate and improve the service.
Infrastructure and external resources
Netlify hosts the website and server functions, Supabase provides optional authentication and cloud data storage, and Google serves the site’s web fonts. These providers may process standard request and account information under their respective terms and privacy policies.
Payments
Billing and the paywall remain disabled. This policy and the terms will be updated with the payment provider, purposes, retention and user choices before payments are enabled.
Changes
The effective date of this policy is 8 September 2026. Material changes will be reflected in the changelog and on this page.