Last updated: April 2026
Privacy Policy
1. Information We Collect
When you create an account and use Cernova, we collect the following information:
- Email address — used for authentication and account communications.
- Authentication data — session tokens and OAuth identifiers (e.g., Google account ID if you sign in with Google).
- Exam performance data — your answers, scores, time spent per question, and exam session history. This data is used to calculate your readiness score and generate analytics.
- Display name — optionally provided during account setup.
We do not collect payment information directly. If payment functionality is added in the future, it will be processed through a third-party payment provider.
2. How We Use Your Information
- To provide the Cernova service — deliver practice exams, track your progress, and generate your readiness score.
- To improve question quality — aggregate (anonymous) performance data helps us identify questions that may be poorly worded or incorrectly scored.
- To communicate with you — we may send account-related emails such as password resets. We do not send marketing emails without your consent.
- To enforce our Terms of Service and protect the integrity of the platform.
3. Data Storage and Security
Your data is stored in Supabase, a hosted PostgreSQL database service. Supabase enforces row-level security (RLS) on all tables, meaning your data is only accessible to your own authenticated session. Data is encrypted in transit (HTTPS/TLS) and at rest.
We follow security best practices and periodically review our data handling procedures. That said, no system is 100% secure. If you believe your account has been compromised, contact us immediately at support@cernova.io.
4. Third-Party Services
Cernova uses the following third-party services:
- Supabase — authentication and database hosting. Supabase's privacy policy applies to data stored on their infrastructure.
- Vercel — web hosting and edge network. Vercel processes requests and may log IP addresses and request metadata per their standard infrastructure practices.
- Google OAuth — if you choose to sign in with Google, Google will authenticate your identity per Google's privacy policy. We receive only your email address and profile name from Google.
We do not sell your data to any third party, and we do not use your data for advertising purposes.
5. Cookies
Cernova uses session cookies solely for authentication — to keep you signed in during your session. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. If you disable cookies, you will not be able to sign in.
6. Data Retention
Your account data (email, exam history, performance data) is retained for as long as your account exists. If you request account deletion, we will permanently delete your personal data within 30 days of receiving the request.
7. Your Rights
You have the right to:
- Access your data — request a copy of the personal data we hold about you.
- Correct your data — request corrections to inaccurate personal information.
- Delete your data — request complete deletion of your account and associated data.
- Export your data — request an export of your exam history and performance data in a machine-readable format.
To exercise any of these rights, email us at support@cernova.io.
8. Children's Privacy
Cernova is not intended for users under the age of 13. We do not knowingly collect personal information from children. If you believe a child has created an account, please contact us and we will delete the account promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Continued use of Cernova after changes are posted constitutes your acceptance of the updated policy. For significant changes, we may notify you by email.
10. Contact
If you have questions about this Privacy Policy or how we handle your data, contact us at support@cernova.io.