Effective August 17, 2026 · Draft for launch review
Privacy Policy
What this policy covers
This policy explains how CCAT Sim handles data for the website, account service, and future compatible mobile clients.
Data we collect
Firebase Authentication holds your email address and account identifier. If you save practice, we store the question type, generated content hash, selected answer, accuracy, response time, generator version, and attempt time. We do not need your employer, actual assessment questions, date of birth, camera, microphone, contacts, or precise location.
Age screen
We use birth month and year one time to select an account flow. We do not store those values. The account service in this MVP is for adults. A person under 18 can use free local practice but cannot use cloud storage.
Local practice
Anonymous practice stays on the device and is not attached to an account. You can clear local practice data from the dashboard.
Why we use data
We use account data to authenticate you, sync saved attempts, show access, provide support, prevent abuse, and process deletion requests. We use practice data to show your history. We do not use it to make employment decisions.
Service providers
Google Firebase provides authentication, database, and server functions. No checkout is currently active. Stripe may retain records for a legacy or future web payment; Stripe, not CCAT Sim, handles card numbers and security codes.
Analytics and advertising
The MVP does not include advertising, session replay, Firebase Analytics, or sale of personal information. We do not share personal information for cross-context behavioral advertising.
Retention
We delete profile, settings, practice, served-item, progress, and access records when confirmed account deletion processing completes. If a financial record must remain for tax, accounting, refunds, disputes, fraud defense, or legal claims, we retain only its transaction reference, amount, currency, transaction date, refund or dispute status, and a deletion reference. Retention is measured from the transaction date; confirming deletion does not restart the clock. The launch schedule must use the shortest period required for the operating entity and market and still requires tax and legal approval. The deletion reference is the SHA-256 hash of a random receipt. The service shows the user both values once; the reference is not derived from an email address or Firebase UID. Stripe controls its separate payment records and generally states that it retains end-customer information for five or more years. Firebase states that provider-side deletion can take up to 180 days unless law requires storage.
Your controls
You can clear device data, delete saved attempts, request an export, and request account deletion. The deletion page remains available on the web for future app-store requirements.
Tracking signals
The MVP does not track users across other services. It does not respond differently to Do Not Track because it does not use cross-service tracking. We will honor Global Privacy Control if a later feature creates a use for that signal.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information. You can use the dashboard for export and deletion. The final privacy contact and any required appeal process must be added before launch.
Changes and contact
We will show a new effective date for material changes. Add the legal entity name, postal address, launch jurisdictions, and final privacy email before launch.