DRAFT for legal review · last updated 2026-09-06
We never store login codes or passwords in readable form. We do not store payment details (there is no payment on the Service today). We do not use tracking cookies or third-party analytics.
All data is stored in Cloudflare's D1 database and KV storage in Cloudflare data centers, encrypted at rest and in transit (HTTPS only). Transactional e-mail (sign-in links, codes, score reports) is sent through Brevo; the e-mail address, subject, and message content pass through Brevo's servers for delivery.
Data is kept until the program deletes the event or organization, which removes it permanently. Programs can export a complete copy at any time. Login-link tokens expire within minutes to days and are deleted after use.
The Service uses only strictly necessary session cookies (signed, HttpOnly, Secure). Administrator sessions last 14 days; examiner and learner sessions last 24 hours.
Learners and examiners may ask their program administrator to correct or delete their information. Programs may contact the operator to delete an entire organization.