Privacy Policy
Last updatedSeptember 7, 2026
SecPlus Mastery ("we", "us", or "our") operates a study platform for the CompTIA Security+ (SY0-701) exam from Michigan, United States. This Privacy Policy explains what personal information we collect, how and why we use it, who we share it with, how we protect it, and the choices and rights you have. By using the Service you agree to this Policy and to our Terms of Service. This Policy covers the website and your account on it. Our free browser add-ons run on your own machine and are covered separately, by the policies published on the extensions page.
01Information we collect
- Account information. Your email address and display name, and a password that is hashed and stored by our authentication provider (Supabase Auth). We never store your password in plain text. You can sign in with Google or GitHub instead of a password, in which case we receive the email address and name on that account and hold no password for you at all; you can connect or disconnect Google at any time from Settings. If you enable two-factor authentication, we store the associated factor metadata, not your one-time codes, and any recovery codes you generate are stored only as one-way hashes. If you ask us to trust a browser for two-step verification, we store a one-way hash of a random identifier for that browser, a short description of it (for example "Chrome on Windows"), and the dates it was trusted, last used, and expires. Trust lasts 30 days, and you can revoke every trusted browser from Settings.
- Profile information. An optional avatar (a URL you provide or an image you upload) and study preferences such as daily goal, questions per quiz, theme, reminder time and days, your time zone, the days of the week you rest, how many reviews you want in a day, how you prefer reviews to be scheduled, which emails you want from us, your chosen exam date (or that you have none yet), and whether you have told us you have already sat the exam and how it went. Your preferences, exam date, and exam result are saved to your account, so the app works the same on every device you sign in on. The exam result is a setting you can change or clear at any time in Settings; it decides how the app talks to you, and it is separate from the outcome report described below.
- Study activity. Quiz attempts and scores, objective mastery, the days you studied and the streak they add up to, timed sittings and the questions each one dealt you (mock exams, and the one free sample sitting from a locked domain, including any questions you left unanswered, so a later mock can serve you fresh ones), spaced-repetition schedules, and a record of each question you answer: which question and objective it was, whether you got it right, and how long you spent on it. Your flashcard progress, meaning which acronyms you have marked as known, and your best score on each Learn deck are kept with your account as well. All of it is tied to your account, so your study stats and your place in the material are the same on every device you sign in on.
- Study planning. Figures the app works out from the study above and keeps with your account so every device shows you the same plan: the daily practice target we recommend for a given day, a daily snapshot of your readiness score (the 0 to 100 measure that draws your trend chart), and your result from the free readiness check if you take it while signed in. These are calculated from activity you already do in the app; we do not ask you for anything extra to produce them.
- Exam outcomes you report. If you choose to tell us how your real CompTIA Security+ exam went, we store that outcome with your account: whether you passed, your scaled score if you enter it, and your readiness level at the time (a 0 to 100 measure derived from your study in the app). We use it only to calibrate the pass-likelihood estimate we show learners. It is read back across users only in aggregate, by readiness band, and we never publish or share an individual result. Reporting an outcome is optional, and it is deleted along with the rest of your data when you delete your account.
- Class seats. If your school licenses seats and you join its class with a class code, we store your membership: the class, your role (student or instructor), the roster name you enter, the date you joined, and the date your seat was ended, if it was. Your instructor can see the roster name, the date you joined, how many days you have studied, the date you were last active and whether that was in the past week, your mastery of each exam domain, and your best mock exam score, and can download that list. They do not see your email address, your answers, or your settings. The class view stays open to them for 30 days after the license ends and then closes. We also hold the institution's own record: its name, a contact email, the number of seats, the license dates, the class code, and any notes we keep on the account.
- Seat license enquiries. If you ask for a seat-license quote on the schools page, we store the school, your name and email, your role, the number of seats, the start month, and your message, together with a one-way hash of your IP address that we use only to limit repeat submissions. The same details reach us by email so we can reply.
- Payment information. If you buy a paid plan, payment is handled by Stripe. Stripe collects your card or payment details directly; we do not see or store full card numbers. Our paid plans are one-time purchases, not subscriptions. We receive and store limited billing metadata such as a Stripe customer ID, payment or charge identifiers, the plan you bought, your access status, and the date your access expires.
- Technical and usage data. Limited data such as IP address, browser type, device, pages viewed, and aggregate usage, collected by our hosting provider (Netlify), our privacy-focused analytics (Plausible), and our error-monitoring tool (Sentry) to keep the Service running, secure, and reliable.
- Sign-in and security records. When your account is signed into, we record in our security log a one-way hash of a random identifier the app keeps in that browser, along with the IP address and browser description of the request, so we can tell a new browser from a familiar one. Other security events, such as a recovery code being used, a data export, or an account deletion, are logged the same way. For the paid video lessons, the playback link we issue is tied to the network you requested it from and expires shortly after.
- Referral link clicks. If you arrive through an affiliate or referral link (a link beginning with /r/, or a page address carrying ?ref= and a code), we log the click with limited technical data: your IP address, approximate country, browser and user-agent, and the referring page. We use it only to credit the referrer and to detect click fraud. We do not use it to build advertising profiles or track you across other sites.
- Anonymous signup counts. When an account is created we write one row that records how the signup arrived: the promotion code on the link, if there was one; which sign-in method was used; the page of this site that was first opened in that browsing session, reduced to a route (for example /security-plus-pbq or /glossary, never a search term or anything after the question mark); and the bare website address that sent the visit (for example google.com), never the full referring link. It carries no account identifier, no email address, no IP address, and nothing derived from any of them, so it cannot be traced back to a person or to your account. We use it only to count how many people sign up from each page and each channel.
- The referral code on your account. If you arrived through a referral or affiliate link and then create an account, we keep that code on the account so the partner who referred you is credited if you later buy, whichever device you buy on. It is the code alone, never anything about who else used the link, and it is deleted with the account.
- Sign-ups made while our email is down. If you sign up by email on a day we cannot send a confirmation code, we still create your account and mark the address as not yet verified. Until you verify it from Settings, we keep on the account the date it was created, a one-way hash of the last verification code we sent you, when that code went out, and how many guesses were made. Verifying clears the code; the note that you verified stays with the account, and all of it is deleted with the account.
- Reviews you submit. If you leave a review, we store the star rating and any written note, linked to your account. Approved reviews may be published on the site anonymously, attributed to "Verified learner" with no name or other identifier shown.
- Diagnostic results email (results gate). If you take the free readiness check without an account and ask for your results by email, we store the email address you enter, a snapshot of those results (your score, estimated readiness, per-domain accuracy, and the recommended starting objective), which version of this Policy the consent notice referenced, and when you asked. We use this to send you those results and a short Security+ study email series; see "How we use information" below. Entering an email there does not create an account, and the address is never shared with our analytics.
- Communications. If you email us, or send a message from the contact page or the in-app bug and idea buttons, we receive your message, the category you picked, the reply address you give us (optional for in-app reports), and the page you sent it from, so we can reproduce a problem. Those messages arrive in our support mailbox as email; the app itself stores none of them. We keep them to respond and to maintain records.
02How we use information
- provide, operate, personalize, and improve the study platform;
- calibrate the pass-likelihood estimate we show, using reported exam outcomes only in aggregate;
- authenticate you and enforce access to free and paid features;
- run class seat licenses for schools, including showing an instructor the study summary described above;
- process payments and send receipts and billing notices;
- send service messages, including a notice when your account is signed into from a browser we have not seen before (on by default; you can turn it off in Settings);
- send study reminders. For a new account the daily review reminder and a warning when a streak is about to lapse are on by default, and you can turn them off, or change their time and days, in Settings. If you set an exam date, we send a short countdown email 30, 14, 7, and 1 days before it, which you can also turn off. A weekly progress summary is sent only if you turn it on. In your first week we may send two short emails about your study plan, unless reminders or product updates are off;
- send the diagnostic results you request by email, followed by a short Security+ study email series (six emails in all; one of them describes what the paid tier adds and two others mention it in passing); every email in the series carries a one-click unsubscribe link, and unsubscribing stops it immediately;
- occasionally email registered users about the Service itself, such as a new feature, a sale on our plans, or an invitation to leave a review; the product updates switch in Settings controls these, every such email carries an unsubscribe link, and once you unsubscribe we keep a do-not-email record and stop;
- diagnose and fix errors, prevent fraud and abuse, and secure our systems;
- comply with legal obligations and enforce our Terms.
03Legal bases (for users in the EU/UK)
Where the GDPR or UK GDPR applies, we rely on a legal basis for each purpose:
- Contract. Creating and authenticating your account, providing the free and paid features, processing payments, and, for a class seat, running the class under your school's license.
- Legitimate interests. Securing, maintaining, and improving the Service, preventing fraud and abuse, and keeping the Service reliable, including the sign-in notice described above. Also, for registered users, the study reminders that are on by default and the occasional email about our own features and offers; you can turn each of these off in Settings or via the unsubscribe link, and we honor it immediately.
- Consent. The weekly progress summary and any other email you turn on yourself, the diagnostic results email and its study series, and any non-essential cookies, where required. You can withdraw consent at any time (for the study series, via the unsubscribe link in every email) without affecting processing already carried out.
- Legal obligation. Keeping tax, payment, and other records the law requires us to retain.
05Service providers (sub-processors)
We share personal information with vetted providers only as needed to run the Service:
- Supabase - authentication and database storage.
- Stripe - payment processing.
- Netlify - website hosting and serverless functions.
- Cloudflare - DNS, content delivery, video hosting and streaming (Cloudflare Stream, for the Domain 2 to 5 video lessons), and email routing.
- Google - sign-in, if you choose to sign in with Google, and YouTube, which hosts the free Domain 1 video lessons and the case-study videos. A page holding one of those videos loads its still image from YouTube, and starting a video loads YouTube's no-cookie player, so Google receives technical data such as your IP address even if you never press play. Google also hosts our support mailbox (Gmail), so any message you send us, and any form submission that reaches us by email, is stored there.
- GitHub - sign-in, if you choose to sign in with GitHub. We receive the email address and name on your GitHub account and nothing else from it.
- Plausible - privacy-respecting, cookieless analytics.
- Sentry - error monitoring, configured to minimize personal data: we do not send your authentication tokens, cookies, or full request contents, and reports carry only what we need to diagnose a problem, such as the affected feature and, where necessary, an internal account identifier.
- Resend - transactional, reminder, digest, exam countdown, sign-in notice, and policy-update notice emails, plus the diagnostic results email and its study series, and the messages our own forms send us.
Each provider has its own privacy policy and processes data on our behalf under appropriate terms.
07Data retention
We keep account and study data while your account is active and for a reasonable period afterward to honor refund windows, keep tax and transaction records, resolve disputes, and maintain security logs. When you delete your account, we delete or de-identify your personal data within a reasonable time. A few records outlive the account on purpose: payment and tax records that we or Stripe must keep by law; security and audit events, which can include an account identifier, an IP address, a browser description, and a hashed browser identifier; and any referral or affiliate sale attached to a purchase. We keep the last two to investigate fraud and abuse, to keep our security log trustworthy, and to settle what an affiliate is owed. None of them hold your study history, and we do not use them to rebuild it.
A few other records have their own lifetimes. We keep a note of which reminder, digest, countdown, and policy notice emails we sent you and when, so we never send one twice; the reminder notes are kept only for recent days. If you leave or are removed from a class, your membership is marked ended rather than deleted, so the school's seat count stays right, and it is deleted along with your account. Seat-license enquiries are kept until you ask us to remove them, or until an account with that email is deleted. Addresses tied to abuse may be kept on a blocklist our security tooling uses, with or without an expiry; that list is not connected to any account.
If you requested your diagnostic results by email without an account, we keep that email address and results snapshot while the study series is active and until you unsubscribe or ask us to delete it. After you unsubscribe, we keep only the address itself as a do-not-email record, so we never mail it again; the same record is kept for any other address that unsubscribes from our emails. Email us at support@secplusmastery.com if you want even that record removed.
08Security and breach notification
We protect your data with measures including encryption in transit (HTTPS/TLS), row-level security so each account can access only its own records, server-side verification of paid access, minimized error logging, optional two-factor authentication (with the choice to trust a browser for 30 days), and an email when your account is signed into from a browser we have not seen before. No method of transmission or storage is perfectly secure. If a security breach involving your personal information occurs, we will notify you and any authorities without unreasonable delay, in the way and within the time that applicable law requires.
09Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of the personal information we hold about you, and to object to or restrict certain processing. Residents of California (under the CCPA/CPRA) have the right to know, delete, correct, and to opt out of "sale" or "sharing" of personal information, and as noted above, we do not sell or share personal information for those purposes. Residents of the EU/UK have rights under the GDPR, including the right to lodge a complaint with a supervisory authority. You can exercise the two most common rights yourself at any time from Settings > Your data: download a complete, portable copy of the personal information we hold about you, or permanently delete your account and its data. From the same page you can also clear your study record without deleting the account; your account, purchases, exam date, reviews, and any class seat stay, and what an instructor sees of you resets with it. Settings also lets you choose which emails you receive, revoke trusted browsers, sign out your other devices, and open your receipts and payment history in the billing portal that Stripe hosts. For any other request, or if you cannot sign in, email us at support@secplusmastery.com; we will verify your request and respond within the time required by law. We will not discriminate against you for exercising your rights.
10Children's privacy
The Service is intended for users 13 and older, including students using a seat licensed by their school, and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us information, contact us and we will delete it.
11Where your data is processed
We operate from the United States, and our providers may process and store data in the United States and other countries. If you access the Service from outside the United States, you understand your information may be transferred to and processed in the United States, where data-protection laws may differ from those in your location.
12Michigan and other US states
We operate from Michigan and apply the practices described in this Policy to everyone, wherever they live. If the law of your state gives you rights beyond the ones described above, email us and we will honor them as that law requires.
13Changes to this Policy
We may update this Policy as the product and the law evolve. When we make a material change, we publish the new version here with a new "Last updated" date, and we email every registered user a plain-language summary of what changed, at the address on their account. Those emails go out in daily batches that start within a day of the change, so everyone hears within a few days. These change notifications are service messages about your account and these documents, not marketing, so they are sent whether or not you have opted into other emails.
14Contact
Questions about this Policy or your data, or to exercise your rights: support@secplusmastery.com.
Written notices can be mailed to SecPlus Mastery, 23211 Ryan Rd, Ste E, Warren, MI 48091, United States. Email is the faster route, and it is the only one that lets us verify a rights request without asking you for more information than we already hold.
