Privacy Policy
Last updated: April 4, 2025
1. Introduction
NCLEX Adaptive Prep (“we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and platform (collectively, the “Service”). By using the Service, you consent to the practices described in this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: When you create an account, we collect your name, email address, and password. If you sign in via Google OAuth, we receive your name and email from Google.
- Payment Information: When you purchase a subscription, payment is processed by Stripe. We do not store your full credit card number, CVV, or other sensitive payment details on our servers. Stripe handles all payment data in accordance with PCI DSS standards.
- Support Communications: If you contact us via email, we collect the content of your message and your contact information.
2.2 Information Collected Automatically
- Usage Data: We collect information about how you interact with the Service, including pages visited, questions answered, exam sessions, scores, time spent, and feature usage.
- Device & Browser Information: We collect your IP address, browser type, operating system, device type, and screen resolution.
- Cookies & Similar Technologies: We use cookies and local storage to maintain your session, remember preferences, and improve the user experience. See Section 7 for more details.
2.3 Information from Third Parties
- Authentication Providers: If you use Google Sign-In, we receive your name and email address from Google. We do not receive your Google password.
- Payment Provider: Stripe may provide us with limited transaction information such as payment status, subscription plan, and billing dates.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service.
- Create and manage your account.
- Process payments and manage subscriptions.
- Deliver adaptive question selection and personalized analytics (readiness scores, domain proficiency, CJMM analysis).
- Send transactional emails (account confirmation, password reset, payment receipts).
- Respond to your support requests and communications.
- Analyze usage patterns to improve platform performance and content quality.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers: We share data with third-party providers that help us operate the Service, including Supabase (database and authentication), Stripe (payment processing), and hosting providers. These providers are contractually obligated to protect your data and use it only for the purposes we specify.
- Legal Requirements: We may disclose your information if required by law, regulation, legal process, or governmental request.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change.
- With Your Consent: We may share your information for any other purpose with your explicit consent.
Aggregated or De-Identified Data: We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you (e.g., overall platform pass rates, average question accuracy) for research, marketing, or analytical purposes.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements).
Practice history, exam scores, and performance analytics are retained with your account to provide continuity of your learning experience. You may request deletion at any time.
6. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest.
- Secure authentication via Supabase with support for multi-factor authentication (MFA).
- Row-Level Security (RLS) policies on our database to ensure users can only access their own data.
- PCI DSS-compliant payment processing through Stripe.
- Regular security reviews and updates.
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
7. Cookies & Tracking Technologies
We use the following types of cookies and similar technologies:
- Essential Cookies: Required for the Service to function (authentication tokens, session management). These cannot be disabled.
- Preference Cookies: Store your settings and preferences (e.g., study mode settings, theme).
- Analytics Cookies: Help us understand how visitors use the Service so we can improve it. We may use privacy-focused analytics tools.
We do not use third-party advertising cookies or tracking pixels. We do not sell data to advertisers.
You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain features of the Service.
8. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete personal information.
- Deletion: Request deletion of your personal information and account.
- Portability: Request a copy of your data in a structured, machine-readable format.
- Opt-Out: Opt out of non-essential communications at any time by using the unsubscribe link in emails or contacting us.
- Restriction: Request that we limit the processing of your personal information under certain circumstances.
To exercise any of these rights, please contact us at support@nclexadaptiveprep.com. We will respond to your request within 30 days.
9. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected information from a child under 18, we will take steps to delete it promptly. If you believe a child has provided us with personal information, please contact us.
10. International Data Transfers
The Service is operated in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. By using the Service, you consent to such transfers. We take steps to ensure that your data receives an adequate level of protection wherever it is processed.
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information.
To submit a CCPA request, contact us at support@nclexadaptiveprep.com. We will verify your identity before processing the request.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. For material changes, we will provide notice through the Service or via email. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: support@nclexadaptiveprep.com