Privacy Policy

Last Updated: April 13, 2026

1. Scope and Applicable Law

This Privacy Policy applies to all users of Preppath, including organization Admins, Members, and visitors to our website. It covers personal information we collect through the platform and through related communications.

We are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law. We are committed to complying with PIPEDA's ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance.

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with local privacy laws that apply to you, those laws may provide you with additional rights. We will make reasonable efforts to honour requests made under those frameworks.

2. Personal Information We Collect

When you sign up for Preppath, we collect information necessary to create and manage your account, including your full name and email address (provided through Clerk), organization name and details, your role within your organization, and profile information you choose to provide.

If your organization subscribes to a paid plan, billing information is collected and processed by Stripe through Clerk's billing integration. We do not store your full credit card number, card verification code, or full bank account details on our servers.

We also collect information about how you use the Service, including exam content you create or submit, exam session data, progress data, and analytics associated with exam attempts. When you access the platform, we automatically collect technical information such as your IP address, browser type, and log data. When you use the AI question generation feature, the content you submit is transmitted to Anthropic's API.

3. How We Use Your Personal Information

We use the personal information we collect to create and manage your account, provide and improve the Preppath platform, manage subscriptions and process payments, enable exam creation and delivery, power the AI question generation feature, communicate with you about your account, respond to support requests, monitor for security incidents, and comply with applicable legal obligations.

We do not use your personal information for advertising, and we do not sell your personal information to third parties.

4. Legal Basis for Processing (PIPEDA)

Under PIPEDA, we rely on contractual necessity (processing required to provide the Service), legitimate interests (security, platform improvement, and fraud prevention), legal compliance (obligations under Canadian law), and consent (where required by law, with the ability to withdraw at any time).

5. AI-Powered Features and Third-Party Processing

Preppath's AI question generation feature is powered by Claude, an AI model provided by Anthropic, PBC. When you use this feature, the content you submit is sent to Anthropic's API for processing. Under Anthropic's Commercial Terms of Service: content you submit is not used to train AI models; API inputs and outputs are retained by Anthropic for a maximum of 7 days by default; and Anthropic does not sell content you submit.

We strongly recommend that you do not submit the following through the AI feature: full names of identifiable individuals, sensitive personal data (health, financial, or legal information), confidential business data, or any content you do not have the legal right to share with a third-party AI service.

6. Disclosure of Personal Information

We do not sell, rent, or trade your personal information. We share data with the following third-party service providers: Clerk (United States) for authentication and identity management; Stripe, Inc. (United States) for payment processing; Supabase, Inc. (United States) for cloud database and file storage; and Anthropic, PBC (United States) for AI model API processing.

We may also disclose personal information if required by applicable law, regulation, or court order; in the event of a business merger or acquisition (with prior notice to users); or with your prior written consent.

7. Data Retention

We retain personal information for as long as necessary to provide the Service and meet our legal obligations. Account data is retained for the duration of your account and up to 2 years after deletion. Exam content and responses are retained for the duration of the organization's subscription, and deleted or anonymized within 90 days of account deletion. Billing records are retained for 7 years to comply with Canadian tax requirements. Server and security logs are retained for up to 90 days. AI feature inputs are subject to Anthropic's 7-day retention policy.

8. Data Security

We implement appropriate technical and organizational safeguards including TLS encryption in transit and at rest, Row Level Security (RLS) at the database level for complete data isolation between organizations, JWT-based authentication tokens managed by Clerk, and access controls restricting employee access to personal information on a need-to-know basis.

Despite these measures, no internet transmission or electronic storage system is completely secure. If you become aware of any security vulnerability or suspected unauthorized access involving your account, please contact us immediately.

9. International Transfers

Preppath is operated from Canada. However, our service providers (Clerk, Supabase, Stripe, and Anthropic) are based in the United States and may process and store personal information on servers located in the United States or other countries. By using the Service, you acknowledge that your personal information may be transferred to and processed in countries outside Canada, which may have different data protection laws than your country of residence. We take steps to ensure that transfers of personal information outside Canada are subject to appropriate safeguards.

10. Your Privacy Rights

Under PIPEDA and applicable provincial privacy laws, you have the following rights: the right to request a copy of the personal information we hold about you (we will respond within 30 days); the right to request correction of inaccurate or incomplete information; the right to withdraw consent at any time (where processing is consent-based); the right to request deletion of your personal information where we are not legally required to retain it; and the right to file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca).

To exercise any of these rights, please contact us using the details in Section 14. We will acknowledge your request within 5 business days and respond in full within 30 days.

11. Cookies and Tracking

Preppath uses essential cookies and session tokens necessary for authentication and platform functionality, including session tokens issued by Clerk to maintain your logged-in state. We do not use third-party advertising cookies or cross-site tracking technologies. If we introduce analytics or non-essential cookies in the future, we will update this Policy and obtain your consent where required.

12. Children's Privacy

Preppath is designed for use by organizations, educators, and adult learners. The Service is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If your organization uses Preppath to administer exams to minors, the organization is responsible for obtaining any parental or guardian consent required under applicable law.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by prominent notice within the platform at least 14 days before the changes take effect. Your continued use of the Service after the effective date of the updated Policy constitutes your acceptance of the changes.

14. Contact Us and Privacy Officer

For questions, access requests, correction requests, or complaints regarding our privacy practices, please contact Curious Bear Solutions Limited (operating as Preppath) through the support form at preppath.app/contact.

If you are not satisfied with our response, you may escalate your concern to the Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec, K1A 1H3. Toll-free: 1-800-282-1376. Website: priv.gc.ca.