Skip to content

Privacy Policy

Last updated: October 7, 2026

1. Information We Collect

Account information: When you sign up, we collect your email address to create and manage your account. We use email-based magic links (and optionally Google sign-in) for authentication — no passwords are stored.

Email you give us for practice results: If you ask for your practice-test results by email (no account needed), we store that email address with the test you took, your score, and your weakest area, and use it to send your results, a study plan, and two follow-up emails that week. Every one of those emails has an unsubscribe link, and you can ask us to delete the address by contacting us.

Payment information: Payment processing is handled entirely by Stripe. We do not store credit card numbers or banking details on our servers. Stripe's privacy policy governs how they handle your payment data.

Learning data: We store your training progress (competency scores, completed topics, learning phase, exam-simulation results) and your chat history with the instructor on our servers to provide continuity across sessions and to grade and adapt your training.

LLM API keys: If you save your API key, it is encrypted in your browser (AES-256-GCM with a passphrase-derived key) and the encrypted copy is stored locally in your browser's IndexedDB. We never store your key in our database. To generate a response, your key is transmitted over TLS to our server with each request and used solely to call the provider you selected on your behalf; it is held in server memory only while your request is being processed and, on our real-time connection, for at most 15 minutes of inactivity. We never log or persist it, and our error-monitoring service is configured to redact anything shaped like an API key.

Diagnostic information: If something goes wrong, our error-monitoring service records the error, the page or request involved, and technical details about your browser or our server. It does not record your chat content or your API key.

2. How We Use Your Information

  • To provide and maintain the training service
  • To process your subscription through Stripe
  • To send transactional emails (magic links, subscription confirmations, and study reminders you can opt out of in Settings)
  • To track your learning progress and adapt training content
  • To measure how the public site is used and to find and fix errors

We do not sell, rent, or share your personal information with third parties for marketing purposes.

3. Third-Party Services

We use the following services, each of which processes data on our behalf:

  • Stripe — payment processing and subscription management
  • Resend — transactional email delivery
  • Vercel — application hosting and request handling
  • Neon — database hosting
  • Sentry — error monitoring (see “Diagnostic information” above)
  • Google Analytics 4 — measurement of how the site and the study tools are used (see “Cookies” below)
  • LLM providers (Google, OpenAI, Anthropic, DeepSeek, or Groq) — by default the instructor's responses are generated by Google's Gemini API on our account. If you connect your own API key, your questions and answers go to that provider instead, under its terms.

4. Data Security

We implement appropriate security measures including HTTPS encryption in transit, encrypted database connections, Content Security Policy headers, same-origin checks on account changes, and secure authentication via Auth.js. Your saved API key is encrypted in your browser and is never written to our database or logs; see “LLM API keys” above for exactly how it is handled when you use the service.

5. Data Retention

Your account and learning data are retained until you delete your account, so that you can pause, cancel, and return without losing your progress. You can delete your account and all of its data yourself at any time from Settings (“Delete account”): this cancels any active subscription and permanently removes your account, sign-in methods, learning progress, and chat history. You can also request deletion by contacting us.

6. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Delete your account and data yourself, or request that we do so
  • Cancel your subscription at any time in Settings → Cancel subscription; access continues until the end of the period you paid for
  • Opt out of non-essential email in Settings

7. Cookies

We set one essential cookie: the session cookie that keeps you signed in. We also use Google Analytics 4, which sets analytics cookies to measure traffic in aggregate, and one first-party cookie (pb_attr, kept 90 days) that records how you first reached PhlebBot: the campaign tags on the link you followed, the referring website, and any ad click identifier. When you subscribe, that record is stored with your subscription, and each payment (amount, currency, and a pseudonymous ID, never your name or email) is reported to Google Analytics so we can see which channels lead to subscriptions. When you are signed in, usage of the study tools (for example practice scores, tutor response times, and whether an answer was graded correct, with its topic area) and subscription events (renewal, cancellation, failed payment) are reported under the same pseudonymous ID, a one-way hash of your internal account ID. Nothing you type, and never your name or email, is sent to Google Analytics. We do not use advertising cookies, and we do not set any tracking cookie when your browser sends Global Privacy Control. You can block these cookies in your browser without affecting the service.

8. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated date. Continued use of the service constitutes acceptance of the updated policy.

9. Contact

For privacy-related questions or data requests, contact us at support@phlebbot.com.