Data Policy

Last updated October 3, 2026 · Version 2026-10-03.2

What stays on this device

Your profile, answers, editable Canvas drafts, saved versions, progress, rewards and preferences are stored locally. The app uses iOS file protection and excludes practice storage from system backup. This is not a cross-device account or backup service. Keep your own copies of work you need to preserve.

History controls

History retains up to five editable versions per question in each category: Drafts, Successful submissions, Unsuccessful submissions and Cleared. Your current draft counts toward the Drafts limit. Clearing the Canvas saves a recoverable version in Cleared history. Clear saved history removes older saved versions and detailed activity while retaining current drafts, progress, streaks, badges and the small submission records needed to preserve progress and avoid duplicate rewards.

Reset and online deletion

In Settings → Account & Data, Delete account & data removes local answers, drafts, history, progress and preferences and starts a new local identity. Only an aggregate count of used free Smart Hints carries forward; old hint contents and submission identifiers are removed. Resetting does not restore free hint allowances or cancel Apple subscriptions. Use Manage subscription for cancellation. Online account deletion covers the linked Firebase guest account and identifiable Firebase milestone records. The app stops collection for the old identity and clears its local analytics queue. Local erasure and online account deletion are separate stages; the app displays pending or failed states and offers retry/status controls. A completed online-account deletion status confirms the Firebase account workflow, not erasure of every service provider's records.

Offline and interrupted deletion

If online deletion cannot be authorized or started, local practice remains and you can retry or contact support. Once the Firebase account has been removed, local reset can finish. Unfinished Firebase account deletion is retried on our server, including when the app is closed after the request is recorded. Unresolved requests are flagged for follow-up rather than treated as complete. A device-only receipt survives local reset for status and retry; completed local receipts may remain until replaced. Server-side completed receipts are scheduled for deletion after 30 days, and the hashed prior authentication identifier after seven days following removal of the authentication account. Unfinished requests retain the information needed for resolution. Aggregate counts without a profile link are not used to reconstruct deleted profiles.

Information sent for online features

Smart Hints sends the selected question, answer and relevant context through Google Cloud to OpenAI. PostHog receives the manual product events and pseudonymous identifiers described in the Privacy Policy; Firebase receives limited milestones and authentication information. Support emails contain what you choose to send. Question illustrations are bundled locally and do not generate image-host requests. None of these services provides cloud backup of your practice.

Retention limits and requests

Provider processing is not instantaneous, and security, legal and backup retention can differ from live-record deletion. PostHog events follow the retention practices described in the Privacy Policy. We do not promise deletion of Apple billing records, messages held by your email provider, or OpenAI request records we cannot locate by your app identity. Ask contact@faangcodingprep.com for access, correction, deletion or processing objections, including requests concerning retained analytics. We will assess those requests under applicable requirements and explain any limitation rather than reporting unfinished deletion as complete.