Privacy

Preppsy

Privacy Policy

Last updated: January 2026

1. Introduction

Preppsy ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-native psychiatry academy platform.

By using Preppsy, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.

2. Information We Collect

2.1 Personal Information

  • Account Data: Name, email address, password (hashed), profile picture
  • Authentication Data: OAuth tokens (Google, Microsoft), session identifiers
  • Profile Data: Role (student/instructor), institution, target exam, preferences

2.2 Learning Data

  • Mastery Model: Per-concept retrieval strength, attempt history, accuracy
  • Session Data: Questions answered, time spent, response patterns
  • Misconceptions: Flagged misconceptions and remediation progress
  • Analytics: Study streaks, domain mastery, exam readiness scores

2.3 Uploaded Content

  • Documents you upload (textbooks, papers, notes)
  • Extracted text, embeddings, and generated teaching assets
  • Web articles and YouTube transcripts you choose to ingest

2.4 Technical Data

  • IP address, browser type, device information
  • Usage logs, error reports, performance metrics
  • Service worker and cache data for offline functionality

3. How We Use Your Information

  • Provide Core Service: Adaptive learning, spaced repetition scheduling, mastery tracking
  • Personalization: Tailor content difficulty, analogies, and teaching assets to your learning style
  • Generate Insights: Analytics dashboards, exam readiness predictions, study plans
  • Improve Service: Aggregate anonymized data to improve question quality and pedagogy
  • Communication: Send study reminders, streak notifications, important updates (opt-out available)
  • Security: Detect fraud, prevent abuse, enforce terms of service
  • Legal Compliance: Fulfill GDPR, FERPA, COPPA obligations

4. Data Sharing & Disclosure

We do not sell your personal data. We share information only in these circumstances:

  • With Your Consent: When you explicitly authorize sharing (e.g., with instructor)
  • Instructors/Institutions: If you join a class, your mastery data is shared with the instructor
  • Service Providers: Cloud hosting (PostgreSQL, Redis), authentication (Better Auth), AI providers (OpenRouter)
  • Legal Requirements: When required by law, court order, or to protect rights/safety
  • Business Transfers: In case of merger/acquisition (with notice and continued protection)

AI Processing: Your learning data and uploaded content may be processed by AI models (via OpenRouter) to generate explanations, questions, and teaching assets. We use zero-retention policies where available and never use your data to train shared models without explicit consent.

5. Data Retention & Deletion

  • Account Data: Retained while account is active; deleted within 30 days of account deletion request
  • Learning Data: Retained for longitudinal mastery tracking; anonymized after account deletion
  • Uploaded Documents: Deleted when you delete them or your account
  • Analytics/Logs: Aggregated data retained indefinitely; raw logs deleted after 90 days

6. Your Rights (GDPR, FERPA, CCPA)

You have the right to:

  • Access: Request a copy of your data via the dashboard or email
  • Rectification: Correct inaccurate data in your profile settings
  • Erasure: Delete your account and all associated data (Compliance → Delete Account)
  • Portability: Export your data in JSON/CSV format (Compliance → Export Data)
  • Restriction: Limit processing of your data
  • Objection: Object to processing for direct marketing or legitimate interests
  • Withdraw Consent: Revoke consent for optional processing at any time

To exercise these rights, use the Compliance Dashboard or email [email protected].

7. Security Measures

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • PostgreSQL with row-level security for multi-tenant isolation
  • Better Auth with secure session management, CSRF protection
  • Regular security audits and penetration testing
  • Incident response plan with 72-hour breach notification (GDPR Art. 33)
  • Subprocessor agreements with all vendors

8. International Transfers

Our servers are located in the EU/US. If data transfers outside your jurisdiction occur, we rely on:

  • EU Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Agreement (IDTA)
  • Adequacy decisions where applicable

9. Children's Privacy (COPPA)

Preppsy is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us immediately for deletion.

10. Changes to This Policy

We may update this policy. Material changes will be communicated via email and in-app notification 30 days before taking effect. Continued use constitutes acceptance.

11. Contact Us

Data Protection Officer: [email protected]

Postal Address: Preppsy Privacy Team, [Company Address]

EU Representative: [EU Rep Details if applicable]