Privacy Policy & Cookie Policy

This Privacy Policy & Cookie Policy describes how TestLessons ("we", "our", or "us") collects, uses, and discloses your information when you use our website testlessons.com (the "Service").

Summary

  • Core experience requires no account and tracks nothing externally. You copy prompts and use them in your AI tool of choice. We don't see what you paste into ChatGPT, Grok, or any other model. No study-session analytics, no prompt logging.
  • Optional accounts (first-party auth on Cloudflare) unlock saved prompts, progress tracking, and personalized study plans. You choose what to save. Account data is encrypted and protected.
  • Cookies are used for analytics (Google Analytics / GA4) and advertising (Google AdSense). You control them via our consent banner — reject non-essential, or customize per category.
  • We don't sell your data. We share only with processors (Google, Cloudflare, Resend) under contractual safeguards (DPAs, SCCs).
  • Contact: jim@testlessons.com | Contact Form

1. Information We Collect

1.1 Personal Data You Provide

We collect information you voluntarily provide when you:

  • Create an account (optional): email address, password (hashed with PBKDF2-SHA256 on our Cloudflare backend), optional display name.
  • Subscribe to our newsletter: email address.
  • Contact us via the contact form: name, email, message.
  • Use account features (if you create an account): saved prompts you choose to store, progress/quiz data from practice sessions, study preferences for personalized plans.

1.2 Account Data (Optional Features)

If you create an account, we process the following additional data to provide membership features:

Data Category Purpose Legal Basis (GDPR Art. 6)
Account credentials (email, hashed password)Authentication, account securityContract (Art. 6(1)(b))
Saved prompts & favoritesYour personal prompt libraryContract (Art. 6(1)(b))
Progress tracking (quiz scores, completion rates, time spent)Progress dashboards, study analyticsContract (Art. 6(1)(b)) / Consent (Art. 6(1)(a))
Study preferences (target tests, weak areas, timing, difficulty)Personalized study plansContract (Art. 6(1)(b)) / Consent (Art. 6(1)(a))
Display name (optional)Account personalizationConsent (Art. 6(1)(a))

Key distinction: Core prompt access is free and account-free. We do not track which prompts you copy or how you use them in external AI tools. Account features only store data you explicitly save or generate within the TestLessons platform.

1.3 Automatic Data Collection (Cookies & Similar Technologies)

When you visit our site, we automatically collect certain information using cookies and similar technologies (pixels, local storage). See Section 5: Cookies & Similar Technologies for full details.

2. How We Use Your Information

We use your information for the following purposes:

Purpose Legal Basis (GDPR Art. 6) Data Categories
Provide and maintain the Service (core prompts, account features)Contract (Art. 6(1)(b))Contact form, newsletter, account data, saved prompts, progress data
Communicate updates, educational content, newsletterLegitimate Interest (Art. 6(1)(f)) / Consent (Art. 6(1)(a))Email, name
Analytics & performance improvement (GA4)Consent (Art. 6(1)(a))IP address (anonymized), device, browser, usage data
Personalized advertising (AdSense)Consent (Art. 6(1)(a))IP address, browsing behavior, ad interaction
Security, fraud prevention, CAPTCHA (Cloudflare Turnstile)Legitimate Interest (Art. 6(1)(f))IP address, request metadata, device signals
Legal complianceLegal Obligation (Art. 6(1)(c))As required by law
Account authentication & management (Cloudflare D1)Contract (Art. 6(1)(b))Email, hashed password, session tokens

3. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Encryption in transit: All traffic uses HTTPS/TLS 1.2+ (enforced via Cloudflare).
  • Encryption at rest: Account and progress data are stored in Cloudflare D1. Account passwords are hashed with PBKDF2-SHA256 (never stored in plaintext). Session tokens are stored only as SHA-256 hashes.
  • Access controls: Least-privilege principle. Application service keys are scoped; admin access is restricted and logged.
  • Infrastructure: Hosted entirely on Cloudflare Pages (static assets + Functions) with Cloudflare D1 for account data. Cloudflare maintains SOC 2 Type II compliance and undergoes regular third-party audits.
  • CAPTCHA / bot protection: Cloudflare Turnstile protects auth endpoints without tracking users across sites.
  • Incident response: We maintain an incident response plan. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and affected users without undue delay (GDPR Art. 34).

4. Sharing Your Information

We do not sell, rent, or trade your personal information. We may share data with the following categories of service providers (subprocessors), each under a Data Processing Agreement (DPA) with Standard Contractual Clauses (SCCs) for international transfers:

Provider Services Data Categories Safeguards
Google LLCAnalytics (GA4), Advertising (AdSense)IP (anonymized), device, usage, ad interactionGoogle DPA + SCCs; EU-U.S. DPF certified
Cloudflare, Inc.CDN, Pages hosting, Functions, D1 database, Turnstile CAPTCHA, DNS, WAFIP, request metadata, device signals (Turnstile), account email, hashed passwords, saved prompts, progress dataCloudflare DPA + SCCs; EU-U.S. DPF certified; SOC 2 Type II
Resend (via Cloudflare Email Workers)Transactional email (contact form, newsletter confirmations, password resets)Email, name, message contentResend DPA + SCCs

We may also disclose information to legal authorities when required by law, court order, or to protect our rights, property, or safety.

5. Cookies & Similar Technologies

We use cookies categorized as follows. You can manage preferences anytime via the cookie banner (bottom of page) or your browser settings.

Category Purpose Consent Required
Essential / Strictly NecessaryEnable core functionality: session management, security (CSRF), cookie consent storage, CAPTCHA verification, authentication sessions.No (always active)
Analytics / PerformanceMeasure site traffic, user behavior, content popularity (Google Analytics / GA4).Yes
Advertising / TargetingServe personalized ads, measure ad effectiveness, limit frequency (Google AdSense).Yes

Essential Cookies (Always Active)

NameProviderPurposeExpiry
tl_consentTestLessonsStores your cookie consent preferences1 year
tl_session (localStorage)TestLessonsAuthentication session token for optional account features14–30 days (or until sign-out)
cf_clearance / __cf_bmCloudflareBot protection, Turnstile CAPTCHA verification, WAF30 min – 1 year

Analytics Cookies (Require Consent)

NameProviderPurposeExpiry
_gaGoogleDistinguishes unique users26 months
_ga_GooglePersists session state26 months
_gidGoogleDistinguishes users24 hours
_gatGoogleThrottles request rate1 minute

Advertising Cookies (Require Consent)

NameProviderPurposeExpiry
__gadsGoogleShows relevant ads, limits frequency13 months
__gpiGoogleAd delivery & measurement13 months
FCNECGoogleFraud detection, ad personalization13 months
IDEGoogle (DoubleClick)Ad targeting & reporting13 months

We implement Google Consent Mode v2 to respect your choices before consent is granted. By default:

  • analytics_storage: 'denied' — GA4 does not set cookies or collect data
  • ad_storage: 'denied' — AdSense does not set cookies or personalize ads
  • ad_user_data: 'denied' — No user data sent to Google for ads
  • ad_personalization: 'denied' — No personalized ads

When you grant consent via the banner, these signals update to 'granted' and the respective scripts load. You can withdraw consent anytime via the banner.

5.4 Managing Cookies

  • Our banner: Click "Customize" on the cookie banner (bottom of page) to toggle categories.
  • Browser settings: Block/delete cookies via your browser (may break essential features).
  • Google opt-outs: GA Opt-out Browser Add-on | Google Ads Settings

6. Data Retention

Data TypeRetention Period
Newsletter emailUntil you unsubscribe (or 2 years inactivity)
Contact form submissions1 year after resolution
Account credentials (email, hashed password)Until account deletion + 30 days grace
Saved prompts, progress data, preferencesUntil account deletion (or 2 years account inactivity)
GA4 analytics data26 months (default, configurable)
AdSense cookiesUp to 13 months
Cookie consent log1 year
Security / access logs (Cloudflare)Per Cloudflare retention (typically 30–90 days)

7. Your Rights

Depending on your location, you may have the following rights:

  • Access (Art. 15 GDPR / CCPA §1798.100) — Request a copy of your personal data.
  • Rectification (Art. 16 GDPR) — Correct inaccurate data.
  • Erasure / "Right to be Forgotten" (Art. 17 GDPR / CCPA §1798.105) — Request deletion. For accounts: email us and we'll process within 30 days (GDPR) / 45 days (CCPA), except where legal retention applies.
  • Restriction (Art. 18 GDPR) — Limit processing.
  • Portability (Art. 20 GDPR) — Receive your data in a structured, machine-readable format (JSON/CSV for account data).
  • Object (Art. 21 GDPR) — Object to processing based on legitimate interest (e.g., direct marketing, analytics).
  • Withdraw Consent (Art. 7(3) GDPR) — Withdraw cookie consent anytime via the banner; withdraw marketing consent via unsubscribe link in any email.
  • Do Not Sell / Share (CCPA/CPRA §1798.120) — We do not sell or share personal information for cross-context behavioral advertising. For ad personalization opt-out, use Google Ads Settings.
  • Limit Sensitive Data (CPRA §1798.121) — Limit use of sensitive personal information (we do not collect sensitive data as defined by CPRA).

To exercise any right, email jim@testlessons.com or use our Contact Form. We respond within 30 days (GDPR) / 45 days (CCPA). Identity verification may be required.

8. Do Not Track (DNT)

We respect the DNT: 1 browser signal. When DNT is enabled, we treat it as a signal to not enable analytics or advertising cookies (equivalent to "Reject All" in our banner). The consent banner will still appear for explicit consent management, but non-essential cookies will not load if DNT is detected. You can also manage preferences manually via the banner.

9. Automated Decision-Making & Profiling

We do not make solely automated decisions that produce legal or similarly significant effects (GDPR Art. 22). Personalized study plans and progress insights are generated algorithmically based on data you explicitly save (quiz results, preferences). These are recommendations only — you control your study path. No profiling with legal consequences occurs.

10. Children's Privacy & Minors (13–18)

Our Service is not directed to children under 13 (or 16 in the EEA/UK). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us for deletion.

For users aged 13–18 (common in test prep): we recommend parental involvement for account creation. Account features store only data the user explicitly saves (prompts, progress). We do not collect sensitive data (health, biometrics, precise geolocation) from minors.

11. International Data Transfers

Our subprocessors (Google, Cloudflare, Resend) process data in the United States and other countries. We rely on:

  • Standard Contractual Clauses (SCCs) — included in each provider's DPA.
  • EU-U.S. Data Privacy Framework (DPF) — all listed providers are certified (as of 2024).
  • UK International Data Transfer Agreement (IDTA) — via UK Addendum to SCCs.

12. California Privacy Rights (CCPA/CPRA)

  • We do not sell or share personal information for cross-context behavioral advertising.
  • Categories collected: Identifiers (email, IP), Internet activity (usage data, cookies), Account data (saved prompts, progress, preferences — if you create an account), Inferences (study recommendations).
  • Categories shared with service providers: Identifiers, Internet activity, Account data (with Cloudflare, Google, Resend).
  • Right to Opt-Out of Sale/Sharing: Not applicable (we don't sell). For ad personalization opt-out, use Google Ads Settings.
  • Right to Limit Sensitive Data: Not applicable (no sensitive data collected).
  • Authorized Agent: You may designate an authorized agent to submit requests on your behalf with written permission.

13. Newsletter & Marketing Communications

The newsletter signup form uses explicit opt-in (you must enter your email and click Subscribe). We do not use pre-checked boxes. Every email includes a one-click unsubscribe link. We process newsletter emails under Consent (Art. 6(1)(a) GDPR) and Legitimate Interest for existing customers (soft opt-in where permitted). Contact jim@testlessons.com to update preferences.

14. Changes to This Policy

We may update this policy. The "Last updated" date at the top reflects the latest revision. Material changes will be announced via the website banner or email (if subscribed). Continued use after changes constitutes acceptance.

15. Version History

DateVersionSummary
July 30, 20262.1Replaced Supabase with first-party Cloudflare D1 auth; updated subprocessors, cookies/localStorage, and security wording.
July 13, 20262.0Major rewrite: added account/membership data, security section, expanded subprocessors (Supabase, Cloudflare), DNT, automated decision-making, minors 13–18, newsletter consent, version history. Fixed "no accounts" inaccuracy.
June 25, 20261.0Initial policy (account-free model only).

16. Governing Law & Dispute Resolution

This policy is governed by the laws of the State of Connecticut, United States (consistent with our Terms of Service). For EEA/UK users, GDPR rights are unaffected by choice-of-law provisions. Disputes may be resolved in accordance with applicable consumer protection laws in your jurisdiction.

17. Contact Us

Questions, concerns, or requests? Contact our Data Protection contact:

TestLessons
jim@testlessons.com
Contact Form