ExamCite

Privacy Policy

Version 1.2 · Pre-Launch Beta — Effective date to be confirmed at public launch

ExamCite LLC (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains what personal information we collect when you use the ExamCite service (“the Service”), how we use it, with whom we share it, and the choices you have regarding your information.

By creating an account, by continuing as a guest where a module permits it, or by using any part of the Service, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, do not use the Service.

ExamCite is currently accessible via a web application at examcite.com, with native mobile apps planned for a future release. This Policy applies to every platform on which the Service is offered. Where a section below describes a practice that applies only to a future mobile release, it is marked as such.

1. Information We Collect

We collect information in the following categories:

1.1 Account Information

When you register for an account, we collect your email address. Passwords are managed securely by Firebase Authentication (Google) and are never stored in plain text by ExamCite.

Guest access without an account. Some exam modules may be used without registering. Where a module offers guest access, we create an anonymous identity for you through Firebase Anonymous Authentication. An anonymous identity has no email address, no name and no password, and we hold no information that identifies you personally — but it is a real, stored profile: your study activity (§1.2) is saved against it so your progress survives closing and reopening your browser. Anonymous progress is tied to the browser and device you used and does not survive clearing your browser storage or moving to another device.

Linking a guest identity to an account. If you later choose to register, we will ask you explicitly whether you want to keep your guest progress. If you say yes, your existing profile is linked to your new email address and password and continues as a registered account; from that point the account information described above applies to it. If you decline, you receive a new, separate account and the guest profile is not carried over. This linking never happens automatically.

Profile and preference information you provide. In addition to your email address, we store the following where you choose to supply it: a display name; your home state as a two-letter US state code, which is used only to resolve the small number of civics questions that ask about your own state's officials; your scheduled exam date and any reminder settings you configure against it, which are used to send the reminder emails you asked for; and, where applicable, an invitation code and beta-programme acceptance records. We also record the date and version of the Terms of Service you accepted, as a legal audit trail.

1.2 Exam & Study Data

When you use the Service, we collect data about your study activity, including:

  • Practice exam results, scores, and pass/fail outcomes
  • Exam session timestamps and duration
  • Per-topic performance and question response history
  • A per-question record of how many times you have answered each question correctly and incorrectly, with a timestamp for each attempt
  • Which questions you have already been shown, so that practice sets do not repeat
  • Progress over time (streaks, completion rates)

This data is stored in Google Cloud Firestore and is used to power your progress dashboard, to personalise your study experience, and to generate the study coaching described in §1.6. It is collected for registered and guest users alike.

1.3 Usage Analytics

We use Firebase Analytics to collect anonymised data about how the Service is used. Where Firebase Analytics is enabled, it automatically records standard interaction data such as page views, session starts, and session frequency and duration.

We send one event of our own: when a page of the Service fails to render, we record the error's type and a short diagnostic reference. We deliberately do not send the error's message text with it, because that text can contain details of your account's data.

This data is aggregated and does not identify you individually. It is used to improve the Service's design and functionality.

1.4 Device & Technical Information

We automatically collect certain technical information when you use the Service, including browser type and version; IP address; general geographic location derived from IP (country/state level only); and, on mobile apps only — not collected by the web application — device type, model, and operating system version, and application version.

1.5 Crash & Diagnostic Reports (planned — mobile apps only)

Firebase Crashlytics is not used by the web application and collects nothing from it. When native mobile apps are released, we intend to use Firebase Crashlytics to automatically collect crash reports when the Service experiences an error. Those reports may include the type and cause of the error, the device state at the time of the crash (memory, OS version, app version), and a stack trace identifying where in the code the error occurred. They will not include the content of your exam sessions or your AI assistant queries.

On the web, the only diagnostic information we collect when a page fails to render is the limited error event described in §1.3.

1.6 AI Study Assistant Queries

The Service offers three AI study assistants to signed-in users: the Handbook assistant, which answers questions about the official handbook; the Tutor, which explains material you are struggling with; and the Coach, which suggests what to study next. All three work the same way: the text of your question is sent to OpenAI, Inc. to be converted into a numeric representation, which is used to look up the relevant handbook passages in a vector index operated by Pinecone Systems, Inc.; those passages and your question are then sent to Anthropic, PBC via the Claude API, which generates the response. Your queries may be processed and retained by each of these providers in accordance with their own privacy policies and terms of service.

The Tutor and the Coach additionally receive a summary of your own study performance so that their answers can be specific to you — for the Tutor, the topics you are scoring poorly on; for the Coach, your recent scores, score trend, weak topics, and how many days remain until any exam date you have set.

What we store. We do not retain your conversations with the Handbook assistant or the Tutor between sessions. We do count how many assistant messages you have sent each day, in order to apply daily limits. We do store the output of two features that generate coaching content from your performance data rather than from anything you type: the coaching message shown after you finish an exam session, and the performance summary shown on your Progress page. These are stored so that re-opening the same page does not regenerate them, and they are associated with your account.

By using any of these assistants, you acknowledge that your queries will be processed by the systems described above. We recommend that you do not include personal or sensitive information in them.

1.7 Subscription & Payment Information

If you make a purchase, payment is processed by Stripe, Inc. ExamCite does not collect or store your credit card number, bank account details, or full payment card data.

We do receive and store transaction metadata, including your subscription tier, billing date, renewal status, and a transaction identifier from Stripe. This information is used to manage your entitlement and provide customer support. When native mobile apps are released, purchases made through the Apple App Store will be processed by Apple, and we will update this Policy before that happens.

1.8 Public Handbook Assistant (ask.examcite.com)

ExamCite operates a free public handbook assistant at ask.examcite.com that requires no account and no sign-in. Questions asked there are processed exactly as described in §1.6, by the same three providers.

To stop any one visitor from exhausting a shared resource, we limit how many questions may be asked from a single internet connection each day. To do this without holding anyone's IP address, we convert the IP address into an irreversible one-way value (a SHA-256 hash) and use that value alone as the key for a counter. No raw IP address is stored. The only information held against that key is a count of questions asked and the date the count applies to; the count returns to zero at midnight UTC. The limit is currently five questions per connection per day and may be adjusted.

No account is created, and no profile, study data or exam history is collected, when you use ask.examcite.com.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide, operate, and maintain the Service and its features
  • Authenticate you and manage your account, including guest identities where a module permits them
  • Process payments and manage your entitlement
  • Power the AI study assistants described in §1.6 and the public handbook assistant described in §1.8
  • Track and display your exam progress and performance
  • Generate personalised study coaching from your performance history
  • Show the small number of civics questions that depend on your home state with the correct answer for your state
  • Send the exam-date reminder emails you have configured, and account, subscription and support correspondence
  • Analyse usage patterns to improve the Service's design and content
  • Identify and fix technical errors
  • Detect and prevent fraud, abuse, or violations of our Terms of Service, including limiting how many questions may be asked from a single connection on the public handbook assistant
  • Comply with applicable laws and legal obligations

We do not use your information for advertising purposes and we do not serve ads within the Service.

3. Third-Party Services

ExamCite relies on the following third-party services to operate. Each has access to your data only as necessary to perform their function.

ServiceProviderPurposePrivacy Policy
Firebase AuthenticationGoogleUser login & identity management, including anonymous guest identitiespolicies.google.com/privacy
Cloud FirestoreGoogleUser data & exam session storagepolicies.google.com/privacy
Firebase AnalyticsGoogleUsage analytics & error reportingpolicies.google.com/privacy
Firebase Crashlytics (planned — mobile apps only)GoogleCrash reporting & diagnostics on future native mobile apps; not used by the web applicationpolicies.google.com/privacy
StripeStripe, Inc.Payment processingstripe.com/privacy
Claude APIAnthropic, PBCAI study assistant responsesanthropic.com/privacy
OpenAIOpenAI, Inc.Converts assistant queries into the numeric form used for handbook searchopenai.com/policies/privacy-policy
PineconePinecone Systems, Inc.AI vector search for the study assistantspinecone.io/privacy
RevenueCat (planned — mobile apps only)RevenueCat, Inc.iOS subscription management on a future native mobile app; receives no data todayrevenuecat.com/privacy

4. Data Sharing

We do not sell your personal information to third parties. We do not share your data with advertisers. We may share your information in the following limited circumstances:

  • With the third-party service providers listed in §3 above, solely to operate the Service
  • If required to do so by law, court order, or lawful government request
  • To protect the rights, property, or safety of ExamCite LLC, our users, or the public
  • In connection with a merger, acquisition, or sale of all or substantially all of our assets — in which case we will notify you via email or in-app notification

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service.

  • Account and study data: retained while your account is active. When you ask us to delete your account, we delete your account profile, your exam sessions and study history, and any feedback, problem reports, feature requests, contact messages or early-access requests you submitted, and we remove your login record so that your email address can be registered again. What we keep after that is a minimal record containing only an internal account identifier and two dates — when the deletion happened, and when that record is itself due to be removed. It contains no email address, no name and no study data. That record is deleted automatically thirty (30) days later. We may retain information for longer only where the law requires it.
  • Analytics data: retained per Google's Firebase Analytics retention settings (typically up to 14 months).
  • Crash reports (mobile apps only — see §1.5): retained per Google's Crashlytics settings (typically 90 days).
  • Payment records: retained as required by applicable financial regulations (typically 7 years).

To delete your account and data, use the deletion option in your Account settings. You may also contact us at support@examcite.com.

6. Security

We take reasonable technical and organizational measures to protect your personal information, including:

  • All data transmitted between the Service and our servers is encrypted in transit using HTTPS/TLS
  • Firebase Authentication manages password security — passwords are never stored in plain text
  • Firestore Security Rules restrict data access so users can only read and write their own data
  • API keys and service credentials are stored in server-side environment variables and are never exposed in client code

While we implement these safeguards, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.

7. Your Privacy Rights

7.1 All Users

Regardless of your location, you may:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Opt out of non-essential analytics (contact us to request this)

To exercise any of these rights, email us at support@examcite.com. We will respond within 30 days.

7.2 California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You may request a report of the categories and specific pieces of personal information we have collected about you in the past 12 months, and the purposes for which it was collected.
  • Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions.
  • Right to Opt Out of Sale: We do not sell your personal information. You do not need to take any action to opt out.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To submit a CCPA request, email us at support@examcite.com with the subject line “CCPA Request” and include your name and the email address associated with your account. We will verify your identity and respond within 45 days.

8. Children's Privacy

ExamCite is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you are under 18, you may not use the Service.

If we become aware that we have inadvertently collected personal information from a person under 18, we will take steps to delete that information as quickly as possible. If you believe we may have collected information from a minor, please contact us at support@examcite.com.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification or by email to the address on your account at least 14 days before the changes take effect. The updated Privacy Policy will be posted at examcite.com/privacy and, where you have an account, notified to you as described above. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

10. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

Developer: ExamCite LLC

Email: support@examcite.com

Website: examcite.com

ExamCite Privacy Policy · Version 1.2 · Pre-Launch Beta

Effective date and contact email will be updated at public launch. Our Terms of Service are available at /terms.