Skip to main content
Legal

Privacy Policy

Last updated: April 2026 (template)

BoardPrep is a study tool. We collect what we need to run the service and nothing we can’t justify. This page explains exactly what that looks like.

1. What we collect

  • Account: your email address and a password hash (managed by Clerk, our authentication provider). We don’t store your password ourselves.
  • Subscription: Stripe customer ID, last 4 digits of your card (for display only), billing status. We don’t receive or store full card numbers.
  • Study activity: questions you’ve seen, answers you submitted, which exam you’re studying, and your dashboard state. This is what powers your miss-focused review.
  • Chatbot: messages you send to the grounded AI chatbot and the responses returned, stored per-user so you can scroll back through your own conversations.
  • Technical: device type, browser, IP address (for rate-limiting and fraud prevention only), and error logs.

2. What we don't collect

  • We don’t collect special-category health data about you. We’re a study tool, not a health app.
  • We don’t install advertising or behavioral tracking cookies.
  • We don’t sell, rent, or trade your data to third parties. There’s no ad business, no data broker relationship.

3. How we use what we collect

We use the data above to operate BoardPrep: authenticate you, bill you, show you your dashboard, serve your chatbot, stop abuse, and respond to support emails. We aggregate anonymized study activity to understand which questions are useful — we never share identified user activity with outside parties.

4. Service providers

BoardPrep runs on a small set of third-party providers. Each one has its own privacy policy:

  • Clerk — authentication (email, password hash, session cookies).
  • Convex — our database for study activity and chatbot history.
  • Stripe — payments, billing portal. Handles card data directly; we only see the last 4 digits + charge status.
  • Resend — transactional email (welcome, trial-ending, payment-failed).
  • Vercel — hosting and CDN.
  • Third-party medical-domain AI model — question verification. No user data is sent to this model; it sees only the question text during seed, not your identity or answers.
  • Mixlayer — inference for the grounded chatbot. Your messages are processed under the grounding scope described in the Terms; full retention policy depends on the provider’s terms at any given time.

5. Cookies

We use a first-party session cookie managed by Clerk so you stay signed in, a theme preference cookie (light/dark), and Stripe’s checkout cookies during payment flow. No advertising cookies, no third-party trackers.

6. Data retention

Active accounts keep all study and billing data while the account is open. Canceled subscriptions keep study data so you can re-subscribe and pick up where you left off. Account deletion (see section 8) purges everything associated with your account within 30 days.

7. Minors

BoardPrep is intended for board-exam candidates, which effectively means users 18+ in the United States. We don’t knowingly collect information from anyone under 13. If you believe a minor has signed up, email support@boardprep.guru and we’ll delete the account.

8. Your rights

You can:

  • Request a copy of your data by emailing support@boardprep.guru.
  • Correct inaccurate data through your account page or by emailing us.
  • Delete your account and all associated data by emailing support@boardprep.guru with the subject line "Delete my account". We’ll confirm within 5 business days.

BoardPrep is offered only in the United States at launch. California residents have additional rights under the CCPA / CPRA — exercise them via the same email address.

9. Changes

We’ll post changes here and, for material changes, email you at least 14 days before they take effect.

10. Contact

Email support@boardprep.guru for any privacy-related request.

Saved