Privacy Policy

Last updated: September 26, 2026

1. Scope and contact

Testara is a practice-test service operated by an individual based in Spain. This policy covers accounts, practice activity, purchases, website analytics and support.

For privacy questions or requests, email support@testara.app. You do not need a separate rights portal or a paid account to contact us.

2. Data and purposes

  • Accounts: name, email, account identifier and authentication information. Supabase handles authentication. We use these data to provide your account and purchased access.
  • Practice: answers, scores, saved attempts, timing, notes and study progress. We use these data to provide practice, reviews and performance analysis.
  • Purchases: payment references, status, selected certification and access expiry. Stripe collects payment details. Testara does not store full card numbers.
  • Contributions: comments, likes, question reports and optional survey answers. We use these data to provide discussions and address reported problems.
  • Support: your contact details and the information you send us. We use these data to answer questions and resolve account or purchase issues.
  • Technical data: request information, browser details and error logs support delivery, security and debugging. Hosting providers receive network information, including IP addresses.
  • Optional analytics: after consent, analytics providers receive information about visits, browser/device characteristics and site performance.

Data come from your use of the service, your contributions and payment confirmations from Stripe. Do not include sensitive personal information in comments or support messages.

Your display name and comments are visible to people who can access the relevant discussion. Guest demo attempts are not saved as account history.

3. Legal bases

  • Contract: account management, purchased access, practice records, requested support and service communications.
  • Legal obligation: records and disclosures required for tax, accounting, consumer rights and valid legal requests.
  • Legitimate interests: protection against abuse, service security, error investigation and handling legal claims, subject to your rights.
  • Consent: optional website analytics. Refusing analytics does not prevent access to the service.

Study scores and recommendations help you review answers. They do not grant a qualification or make decisions with legal or similarly significant effects.

4. Cookies and browser storage

Essential storage supports sign-in, security, preferences and practice sessions. Optional analytics stay off until you accept them.

  • Supabase authentication: session cookies keep you signed in. Their expiry follows the authentication session and token refresh process.
  • Preferences: local storage records your theme and cookie choice. It remains until you change it or clear browser data.
  • Practice: session storage keeps temporary configuration and questions in the current browser tab. It is separate from saved account attempts.
  • Google Analytics: after consent, cookies such as _ga and _ga_* distinguish visits. Google documents a default expiry of two years, subject to configuration and browser limits.
  • Vercel Analytics and Speed Insights: after consent, these tools measure visits and performance. They are designed to operate without analytics cookies.

Use Cookie preferences in the footer to accept or reject optional analytics. You can change your choice at any time.

Withdrawing consent stops optional analytics on subsequent use and clears known first-party analytics cookies. The page reloads to stop scripts already loaded.

If browser storage prevents saving your choice, we stop optional analytics on the current page and show an error. Clear site data or allow storage and save your rejection before further visits.

Withdrawal does not invalidate earlier processing or automatically erase data already sent. Contact support to request deletion where applicable.

Stripe can use its own cookies and security technologies during payment. Its privacy and cookie notices apply to its payment interface.

5. Service providers

  • Supabase: authentication, database and storage.
  • Stripe: payment processing, fraud prevention and associated payment records.
  • Resend: service email delivery.
  • Vercel: hosting and, with consent, website analytics and performance measurements.
  • Google Analytics: optional website audience measurement.
  • Sentry: error reporting when configured. The application disables default personal-information collection and performance tracing.

Providers receive data needed for their respective services. Some, including payment providers, also process data for their own legal and security responsibilities.

We can disclose relevant data to authorities when legally required, or to establish, exercise or defend legal claims.

6. International processing

Providers operate internationally. Data processing locations depend on the service and its configuration. Provider privacy notices explain their international operations.

Contact support for information about the locations and transfer safeguards applicable to your data, or to request a copy of applicable safeguards.

7. Retention and deletion

Your account and learning records remain associated with your account while it exists. Expiry of purchased access does not delete the account.

You can request account deletion in Settings. The deletion process removes associated account and learning records and attempts to replace your comment text.

Discussion threads can retain a deleted-comment entry. If your text remains visible after deletion, contact support so we can address it.

Deleting a Testara account does not automatically erase payment-provider records, correspondence, backups or technical logs. Retention depends on their purpose and applicable legal requirements.

Transaction records can remain where tax, accounting or legal obligations require them. Contact support for retention information or a deletion request concerning these records.

8. Your rights

Under applicable data protection law, you can request access, correction, deletion, restriction, portability and objection. You can withdraw consent at any time.

Email support@testara.app with your request. We can request information needed to verify identity. Do not send identity documents unless requested securely.

For GDPR requests, we respond without undue delay and normally within one month. If a permitted extension is necessary, we explain it within that month.

You can complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.

Other jurisdictions can provide additional rights and response deadlines. Contact the same address to exercise applicable rights, including through an authorized representative.

9. Age requirements and changes

Testara is not intended for people under 16. Higher local age or parental-authorization requirements still apply. The Terms of Service explain eligibility.

If you believe a child provided data without the required authorization, contact support. We will review the account and the request.

We update this page when our practices change. Where required, we provide additional notice or obtain new consent before a change takes effect.