Privacy Policy
Last updated: May 17, 2026
This Privacy Policy explains how Cognify ("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our test preparation platform. By using Cognify, you agree to the practices described in this policy.
1. Information We Collect
Account Information
- Registration data: Name, email address, and authentication credentials (managed by Clerk).
- Profile data: Display name, preferred courses, and account preferences.
Study and Usage Data
- Practice data: Tests taken, questions answered, free-response submissions, scores, accuracy rates, XP, and study progress.
- Performance analytics: Unit-level accuracy, predicted scores, review history, and spaced repetition schedules.
- Usage logs: Pages visited, features used, session duration, and error logs for reliability and debugging.
Billing Information
- Payment processing: All payment data is handled directly by Stripe. We store only your Stripe customer ID, subscription status, and plan type. We never store credit card numbers, CVVs, or full payment details on our servers.
Technical Data
- Device information: Browser type, operating system, screen resolution, and device identifiers.
- Network data: IP address, approximate location (country/region), and referral source.
- Cookies: See our Cookie Policy for details on cookie usage.
2. How We Use Your Information
- Provide the Service: Generate practice questions, grade FRQs, track progress, calculate predicted scores, and deliver personalized study plans.
- Process payments: Bill you for Pro subscriptions and manage your subscription status.
- Send communications: Transactional emails (welcome, password reset, billing receipts), weekly progress reports, and important service updates.
- Improve the Service: Analyze usage patterns, diagnose bugs, improve question quality, and optimize AI grading accuracy.
- Ensure security: Detect and prevent fraud, abuse, and unauthorized access.
3. How We Share Your Information
We share your data only with the following categories of service providers, each for a specific purpose:
- Clerk -- Authentication and identity management.
- Stripe -- Payment processing and subscription billing.
- Cerebras / Groq -- AI inference providers. Free-response answers are sent to these providers for grading and question generation. They process data per their own privacy policies.
- Resend -- Transactional email delivery.
- Neon -- Managed PostgreSQL database hosting.
- Vercel -- Application hosting and edge delivery.
We do not sell your personal data. We do not share your data with advertisers or data brokers. We may disclose information if required by law, court order, or governmental request.
4. Data Retention
We retain your study data, scores, and progress for as long as your account is active. If you delete your account (available from Settings), we will remove your personal data within 30 days, except:
- Billing records, which are retained as required by tax and financial regulations.
- Anonymized, aggregated data that cannot identify you, which we may retain indefinitely for analytics.
5. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data.
- Portability: Request your data in a machine-readable format.
- Objection: Object to certain types of processing.
- Restriction: Request restriction of processing in certain circumstances.
If you are located in the European Union or United Kingdom (GDPR), California (CCPA/CPRA), or another jurisdiction with privacy legislation, we honor those rights. To exercise any of these rights, contact us at maestro.committee@gmail.com. We will respond within 30 days.
6. Children's Privacy
Cognify is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete that information promptly. If you believe a child under 13 has provided us with personal data, please contact us immediately.
7. Data Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit using TLS 1.2+.
- Data at rest is encrypted in our database.
- Authentication is managed by Clerk with secure session handling.
- Stripe webhook signatures are verified on every payment event.
- Access to production systems is restricted and logged.
No system is perfectly secure. If you discover a security vulnerability, please report it to maestro.committee@gmail.com with reproduction steps.
8. International Data Transfers
Cognify is hosted in the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US. By using the Service, you consent to this transfer. We rely on standard contractual clauses and other appropriate safeguards for international data transfers where required.
9. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them with your data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued use of the Service after changes means you accept the updated policy.
11. Contact Us
For privacy-related questions, data requests, or concerns, contact us at:
- Email: maestro.committee@gmail.com
- Contact form: /contact