Privacy Policy
Last updated: June 2026
1. Information We Collect
- Account information — your full name, email address, leaderboard display name, and school division (middle / high school).
- Quiz performance data — events practiced, questions answered, scores, time spent, and topic mastery scores.
- Payment information — subscription billing is handled entirely by Stripe. We never see or store your card number, expiration date, or CVV.
- Session data — authentication cookies required to keep you logged in across page loads.
2. How We Use Your Information
- To provide and improve the HOSA Practice service.
- To track quiz progress and display personalized analytics on your dashboard.
- To display your display name and score on the public leaderboard (only if you opt in — you can opt out at any time in Settings).
- To process subscription payments through Stripe.
- To send transactional emails (e.g., password reset, email verification) via Supabase Auth.
3. Third-Party Services
- Supabase (supabase.com) — stores your account data, quiz history, and manages authentication. Data is stored on AWS infrastructure in the United States. See Supabase's Privacy Policy.
- Stripe (stripe.com) — processes all subscription payments. Your card details go directly to Stripe — we never see them. See Stripe's Privacy Policy.
- Groq (groq.com) — generates AI quiz questions. We send only the HOSA event name, topic, and difficulty level to Groq. No personal information is transmitted to Groq.
- Vercel (vercel.com) — hosts this application. Request logs may be retained per Vercel's data retention policy. See Vercel's Privacy Policy.
4. Data Retention
- Account data (profile, quiz history) is retained until you request deletion.
- Individual quiz session records are retained for up to 2 years after each session.
- Upon account deletion, all personal data is removed within 30 days.
5. Your Rights
You may request access to or deletion of your personal data at any time by emailing shaunakacharya6@gmail.com. We will respond within 30 days.
6. COPPA — Children Under 13
This service is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If we discover that a user is under 13, we will immediately delete their account and all associated data. If you believe a child under 13 has registered, please contact us at shaunakacharya6@gmail.com.
7. CCPA — California Residents
California residents may request: (a) a copy of the personal information we hold about you, or (b) deletion of your personal information. To exercise these rights, email shaunakacharya6@gmail.com. We do not sell your personal information to third parties.
8. Cookies
We use only essential cookies required for authentication sessions (managed by Supabase Auth). We do not use tracking, analytics, or advertising cookies of any kind.
9. Contact
Questions about this Privacy Policy? Email us at shaunakacharya6@gmail.com.