Privacy Policy
Last updated: June 28, 2026
1. About this document
This Privacy Policy describes how ExamPass, developed by ExamPass (“we”, “our”, “us”), collects, uses and protects user information (“you”). By using the app, you agree to the practices described here.
This document complies with Brazil’s General Data Protection Law (LGPD — Law nº 13.709/2018), Apple App Store requirements, and Google Play requirements.
2. Data we collect
Data you provide us:
- Email address (used for authentication)
- Device preferred language
Data generated by app usage:
- Study session history (mode, date, score)
- Answers given to each question
- Verified purchase records (product ID, date)
- AI explanation usage (daily counter)
- Push notification token (FCM/APNs), if permission granted
Data we do NOT collect:
- Geographic location
- Contacts list
- Camera or microphone
- Biometric data
- Data from other installed apps
3. Purpose of processing
- Authenticate users and maintain active sessions
- Verify and record purchases made on app stores
- Personalize study history and progress
- Generate AI-powered explanations for exam questions
- Send study reminders via push notifications (with permission only)
- Fulfill legal obligations and prevent fraud
4. Data sharing
We do not sell or share your data with third parties for marketing purposes. We share only with:
- Apple Inc. / Google LLC— to verify purchases made on their respective stores. See Apple’s and Google’s privacy policies for details.
- Supabase Inc. — database and authentication platform where your data is stored, hosted in the us-east-1 region (AWS).
- Amazon Web Services (AWS) — AI explanation processing via Amazon Bedrock. Question text is sent to generate explanations and is not retained by AWS after processing.
5. Data retention
Your data is kept while your account is active. After account deletion, all personal data is removed from our systems within 30 days. Transaction records may be retained for additional periods as required by applicable tax law.
6. Your rights
Under applicable data protection law, you have the right to:
- Access: know what data we hold about you
- Correction: update incomplete or incorrect data
- Deletion: delete your account and all associated data — available directly in the app (Profile → Delete account)
- Portability: request your data in a structured format
- Revoke consent: disable push notifications at any time in your device settings
To exercise any of these rights, contact us at the email below or use the “Delete account” button in the app.
7. Security
We use TLS encryption for all communications. Passwords are not stored in plain text — we use Supabase’s authentication service with bcrypt hashing. Database access is protected by Row Level Security (RLS) policies.
8. Children
ExamPass is intended for users aged 13 and older. We do not knowingly collect data from children under 13. If we become aware of such collection, the data will be deleted immediately.
9. Changes to this policy
We may update this policy periodically. We will notify you of significant changes by email or in-app notification. The “last updated” date at the top reflects the most current version.
10. Contact
For questions, requests, or to exercise your data protection rights, contact our Data Protection Officer:
Email: privacidade@exampassapp.com