Privacy Policy
Last updated: March 8, 2026
Overview
CompTIA Prep ("we", "us", "our") operates the website comptiaprep.net. This policy explains what data we collect, how we use it, and your rights regarding that data.
Information We Collect
Account and Payment Data
When you purchase a plan, we collect your email address. Payments are processed securely by Stripe. We do not store credit card numbers or billing details on our servers — Stripe handles all payment data directly.
Feedback Submissions
When you submit feedback through our feedback form, we collect the category, message, and optionally your name and email address. We also record your IP address for rate-limiting purposes.
Quiz Usage and Study Progress
We sync your study progress to our servers, including mastery scores, learning pathway progress, and quiz history. This allows you to access your progress from any device. This data is tied to your account and is permanently deleted if you delete your account.
Chat messages with Professor Byte and visual preferences (theme, atmosphere) are always stored locally in your browser only.
Social Features
When you use social features, we store:
- Friend lists — your friend connections, pending requests, and friend relationships.
- Win/loss records — your head-to-head multiplayer results against friends.
- Notifications — friend requests and game invites (max 30 stored, tied to your account).
- Player reports — if you report another player, the report content and your email are stored.
All social data is deleted when you delete your account.
Automatically Collected Data
Our hosting provider (Netlify) may collect standard server logs including IP addresses, browser type, and pages visited. This data is used for security and performance monitoring.
How We Use Your Data
- Email addresses — to verify your identity, manage your subscription, and communicate about your account.
- Study progress — to sync your mastery, pathway, and quiz history across devices.
- Feedback submissions — to improve our service and respond to bug reports or feature requests.
- Server logs — for security monitoring, rate limiting, and service reliability.
Third-Party Services
We use the following third-party services that may process your data:
- Stripe — payment processing. See Stripe's Privacy Policy.
- Resend — transactional email delivery. See Resend's Privacy Policy.
- Netlify — website hosting and serverless functions. See Netlify's Privacy Policy.
- Google AdSense — advertising. Google may use cookies and tracking technologies to serve personalized ads. See Google's Privacy Policy. You can opt out of personalized ads at Google Ads Settings.
- Google Gemini API — AI-powered quiz generation. Quiz prompts (exam type, question count, difficulty) are sent to Google's API. No personal data is included in these requests.
Cookies and Local Storage
We use browser local storage (not cookies) to remember your login email, access expiry, and daily free question count. Google AdSense may set its own cookies for ad personalization.
Data Retention
- Account data — retained while your subscription is active. Expired accounts may be removed after 90 days.
- Feedback submissions — retained indefinitely to help improve the service.
Your Rights
You may request to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data from our systems ("right to be forgotten")
- Receive a copy of your data in a portable format (data portability)
- Restrict or object to certain processing of your data
To make a request, contact us at support@comptiaprep.net or use the feedback form. We will respond to requests within 30 days.
GDPR (European Users)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Legal basis for processing: We process your data based on (a) your consent when you provide your email for an account, (b) contractual necessity when processing payments, and (c) legitimate interest for security and service improvement.
- Data transfers: Your data may be transferred to and processed in the United States, where our hosting and service providers operate. These transfers are subject to appropriate safeguards.
- Data breach notification: In the event of a data breach that poses a risk to your rights, we will notify affected users and relevant supervisory authorities within 72 hours of becoming aware of the breach.
- Right to lodge a complaint: You have the right to lodge a complaint with your local data protection authority.
CCPA (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to know: You may request details about the personal information we collect and how it is used.
- Right to delete: You may request deletion of your personal information.
- Right to opt-out: We do not sell your personal information to third parties.
- Non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise any of these rights, contact us at support@comptiaprep.net.
Children's Privacy
CompTIA Prep is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last updated" date.
Contact
If you have questions about this privacy policy, contact us at support@comptiaprep.net.