Privacy

Privacy Policy

We built PractiqAI to respect your privacy from day one. Review the data we collect, why we process it, and the safeguards that keep your workspace secure.

Last updated

Highlights

What you can expect from PractiqAI

Your data stays yours

We never sell prompts, telemetry, or course progress. Access is limited to the teams that operate PractiqAI and provide support.

No surprises

Every processing activity is documented in plain language so legal and compliance teams understand how we protect learner data.

Easy controls

Download, delete, or update account data directly from settings or by emailing our legal team - no extra portals needed.

Human support

Reach the people behind PractiqAI for data questions, security incidents, or contract reviews at any time.

01Section

Who we are & scope

This Privacy Policy explains how PractiqAI handles personal information across our website, app, and related services.

PractiqAI is the controller for information collected through our web properties and learning platform. This Policy covers visitors, registered users, and organizational accounts that access PractiqAI content and features.

Some functionality depends on trusted service providers (for hosting, analytics, payments, authentication, and email). Where they act as processors, they handle data only under our written instructions.

02Section

Information we collect

We limit collection to the data required to run the platform, troubleshoot issues, and comply with the law.

When you interact with PractiqAI we capture a mix of account information, usage telemetry, and the prompts or submissions you voluntarily provide. Anonymous users only generate transient session identifiers while registered members share a small set of profile details.

We do not ingest contact books, payment card numbers, or documents you do not intentionally upload to the service.

Account details

Name, email address, organization, role, timezone, and authentication metadata collected when you register or connect a federated login provider.

  • Password hashes (never the plaintext password)
  • Multi-factor and device trust settings when enabled
  • Course enrollments and certifications you choose to display

Usage metrics

Product analytics describing how you navigate the app, which tasks you attempt, performance scores, completion timestamps, and feature flags that help us debug issues.

  • IP address, country/region, and browser version for fraud and abuse prevention
  • Audit logs showing significant account actions (login, subscription changes, exports)
  • Crash reports with truncated stack traces when the client encounters an error

Content you submit

Prompts, completions, file uploads, and feedback that you intentionally send to the service. These artifacts power scoring, coaching, and moderation workflows.

  • We automatically redact secrets found in task submissions before they reach long-term storage
  • Team workspaces may expose submissions to organization admins for review

You stay in control

Profile → Privacy contains download and deletion flows. Contact legal@practiqai.com if you need offline attestations or a custom retention schedule.

03Section

How we use information

Processing focuses on delivering the product experience, securing the platform, and improving learning outcomes.

We process data to authenticate you, personalize course recommendations, surface relevant notifications, and maintain accurate billing. Usage trends also inform product decisions so we can improve the curriculum and reduce friction in workflows.

Product delivery

Operate the core learning environment, synchronize progress across devices, and provide AI-generated feedback during practice sessions.

Security and compliance

Detect fraud, enforce rate limits, respond to legal requests, and log administrator actions for audit purposes.

Research & improvement

Aggregate trends (never individual submissions) to evaluate content difficulty, build benchmarks, and tune heuristics that drive evaluations.

  • We anonymize analytics before sharing them with internal research partners
  • Humans only review submissions when you request support or a moderation trigger fires
04Section

Legal bases for processing

When required (e.g., under GDPR), we rely on specific legal bases to process personal data.

Contract

To create and administer your account, deliver coursework, evaluate submissions, and provide support you request.

Legitimate interests

To secure the platform, prevent abuse, understand usage trends, and improve content, provided these interests are not overridden by your rights.

Consent

For optional activities (e.g., certain analytics, marketing communications). You can withdraw consent at any time.

Legal obligations

To comply with tax, accounting, and regulatory requirements or respond to lawful requests.

05Section

When we share information

We only share data with trusted vendors or when the law requires it, and every vendor is bound by a written agreement.

PractiqAI relies on infrastructure, analytics, and payment providers to offer a reliable experience. Each processor undergoes security due diligence and signs a Data Processing Agreement that limits their use of your information.

Vendors and subprocessors

Cloud hosting, authentication, email delivery, billing, and analytics providers that help us operate the product. They only receive the minimum data needed to perform their service.

Compliance disclosures

We may share data when responding to lawful requests from public authorities, subpoenas, court orders, or to enforce our agreements and protect users.

Business transfers

If we explore a merger, financing, or acquisition, we may share necessary information under NDA and will notify you if ownership changes.

Public verification pages

If you share a certificate verification link or ID, anyone with that link may view certificate metadata (e.g., recipient name, course, and highlights) to confirm authenticity. You control if and when you share such links.

No advertising sales

We do not sell learner data to advertisers or allow advertising networks to track you across PractiqAI properties.

06Section

Cookies & similar technologies

We use strictly necessary cookies and local storage to operate the service, plus privacy‑respecting analytics to understand usage.

Authentication and session management rely on browser storage. We set a first‑party anonymous token in localStorage and a cookie to prevent abuse and correlate attempts across tabs. These are scoped to PractiqAI domains, use SameSite protections, and are not shared with advertisers.

We use first‑party analytics to measure feature usage and reliability. On some pages we also dispatch events to a tag API if you have permitted analytics. You can block non‑essential analytics in your browser or via extensions without losing access to core functionality.

Strictly necessary

Anonymous token cookie and localStorage entry used for rate‑limit enforcement, session bootstrap, and fraud prevention.

  • Cookie attributes: SameSite=Strict; Secure on HTTPS; typical lifespan up to 12 months
  • Not used for cross‑site tracking or advertising

Analytics

First‑party, aggregated analytics (e.g., Vercel Analytics) and optional event tags to understand performance and content engagement.

  • No sale of personal information
  • IP addresses may be transiently processed for geolocation and abuse prevention
07Section

Security & retention

We align with industry security practices and keep data only as long as we have a documented business reason.

Data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Production access follows the principle of least privilege with enforced multi-factor authentication.

We retain submissions for the lifetime of your account to maintain evaluation history. Backups are removed within 35 days. If you delete your account, most records purge within 30 days except for billing logs we must preserve for tax and fraud prevention.

Technical controls

Role-based access, automated patching, security monitoring, and regular recovery drills safeguard your information.

Incident response

We notify affected users and regulators of a data breach without undue delay and provide post-incident summaries upon request.

08Section

Your rights & choices

Depending on where you live, you may have additional rights over your personal information. We honor verified requests globally.

You can access, update, or delete your personal data from account settings. Email legal@practiqai.com if you represent a team or need help authenticating a request.

Residents protected by GDPR, CCPA/CPRA, LGPD, and other privacy laws can object to processing, request portability, or appeal an automated decision. We respond within 30 days unless regulations require a faster SLA.

Requests we support

Access copies of your data, transfer it to another provider, restrict specific processing activities, or close your account entirely.

Verification

For security we may ask you to confirm recent activity or provide contract details before fulfilling a request. Authorized agents must include a signed permission letter.

Need a custom agreement?

Email legal@practiqai.com to request a DPA, SCCs, or bespoke privacy commitments for enterprise deployments.

09Section

International data transfers

We may process data in the United States and other countries where we or our providers operate.

When transferring personal data from the EEA, UK, or Switzerland, we use approved transfer mechanisms such as Standard Contractual Clauses (and, where applicable, the UK Addendum). We assess providers for security posture and require contractual commitments limiting their use of personal information.

10Section

Children’s privacy

PractiqAI is intended for users at least 16 years old or the age required in your jurisdiction.

We do not knowingly collect personal information from children under applicable age thresholds. If you believe a child provided information to us, contact legal@practiqai.com and we will delete it.

11Section

Changes to this policy

We will post any changes on this page and update the 'Last updated' date.

If we make material changes, we will provide additional notice (for example, by email or prominent in‑app messaging) at least 30 days before they take effect, when required by law.

Contact

Any legal questions?

Reach our legal and support team directly. We aim to respond within two business days.

Keep building

Courses to keep your skills sharp

Legal reviews done? Jump back into the hands-on work that justifies the contract.

Resources

Operational guides to share internally

Pricing breakdowns and release notes help teammates understand PractiqAI’s cadence.

Trust

Compliance-friendly references

Certificates, privacy, and terms are always one click away for future reviews.