Privacy Policy
This policy explains what data the CertMonk app and this website collect, why, who we share it with, how long we keep it, and how you can delete it. We have tried to keep it short and plain.
In short: we store your email address, your sign-in details, your study progress and any purchases, so the app works and your progress syncs. We do not show ads, we do not use third-party analytics, advertising or crash-reporting tools (we analyse usage on our own servers to power your progress features and improve questions), we do not collect your location, contacts, photos, camera or microphone, and we do not sell your data or share it for advertising.
1. Who we are
CertMonk is an IT certification practice app made by G3NO SYSTEMS LLC, a limited liability company in the United States ("we", "us"). We are responsible for the personal data described in this policy. This policy covers the CertMonk apps for Android and iPhone (systems.g3no.certmonk), the CertMonk web app at app.certmonk.app (also served at certmonk-web.web.app) and the websites at certmonk.app and g3nosystems.com/certmonk.
2. Data we collect
This is everything the app stores about you.
Your account
- Your email address.
- A hashed password, if you choose to sign in with a password. We never store your password in readable form. You can also sign in without a password using a 6-digit code we email to you.
- If you turn on two-step verification, the secret your authenticator app uses is stored by our sign-in provider (Supabase Auth) so it can check your codes. We never see your codes, and turning the feature off deletes the secret.
- Whether you have confirmed your email address. Email confirmation is required.
- If you choose Continue with Google or Continue with Microsoft, that company confirms who you are and sends us your email address, your name (if your account has one) and an account identifier. We never receive your Google or Microsoft password. If you already have a CertMonk account with the same verified email address, the two are linked.
- If you turn on fingerprint or face unlock, your phone checks your fingerprint or face on the device. We never receive or store fingerprint or face data; we only store, on your phone, that you turned the feature on.
Your study data
- Practice history and the answers you give.
- Practice test results.
- Flashcard progress (for spaced review).
- The exam you have selected.
- Daily usage counts (used for free-tier limits).
- Question reports you choose to submit: the category you pick and the message you write.
- The answer you chose for each question, how long you spent on each question during tests, and how often you changed an answer.
- Your readiness estimates and their history (calculated on our server from your practice).
- Your flashcard review history and your game results (scores, accuracy, levels reached).
- Your study plan and exam date, if you set one.
- A small, fixed set of in-app events (for example, when you open the app or view the plans screen), with your platform and app version. We do not record which screens you visit.
Practice limits and scraping checks
To protect our questions from bulk copying, if you own a Cert Pass we count, for each exam, how many full practice tests you start and how many new questions you are shown in a rolling 24 hours. If a limit is reached you'll see a message asking you to come back later. If use looks automated (for example very fast answers, most of a question pool seen in one day, or one account used from many different networks), we record a flag so a person can review it. Network addresses are stored only as scrambled values. A flag doesn't change your account by itself; if we confirm misuse we may contact you or limit access under our Terms.
Feedback you send
If you use "Send feedback" or report a problem, we store your message, the category you pick, the page you were on, your platform and app version, whether we may email you about it, and your account id.
How you found us (marketing links)
When you arrive from a CertMonk social post, profile link or ad, we record which post or ad it was, the page you landed on, and whether you then signed up or bought, to measure our marketing. We don't use cookies or third-party trackers for this, and we never store your IP address (only a scrambled value that changes every day, to prevent abuse). The web app keeps the link's tags in your browser's local storage for up to 30 days so a later signup or purchase can be matched to it. Our marketing reports only ever show totals, never individual people.
Promo codes
When you redeem a promo code, we keep a record of the code, your account and the time. Failed code attempts are logged against your account and a salted, one-way hash of your IP address (never the address itself) to stop code guessing.
Leaderboard (optional)
If you join a leaderboard, we store the display name you choose, which certifications you joined, and any reports or blocks you make. Other learners see only your display name, your rank, your readiness score used for ranking, and a "verified pass" mark if you have one. They never see your email, your real name or your account id. You can leave a leaderboard, or delete your leaderboard name, at any time.
Exam results (optional)
If you tell us your exam result, we store the result, the exam date, any score you enter (marked as self-reported), and, if you give us a badge link, the link, the issuer, the credential name and the issue and expiry dates. To check the badge, we request it once from Credly or Microsoft Learn, only when you ask us to. We do not keep the name or email shown on the badge.
Your purchases
Each purchase is a one-time purchase that gives your account access to a certification for the exam version you bought (see the Terms). We store which certifications your account owns, where the purchase came from, the Google Play order number and product, a one-way hash of the purchase token (not the token itself), whether it was a test purchase, and the relevant dates (the purchase date, when we confirmed it with Google, and a refund date if the purchase is refunded). When you buy, the app gives Google Play your CertMonk account ID (a random identifier, not your email) so the purchase stays tied to your account and cannot be moved to another one. Access lasts for that exam version as described in the Terms. If a purchase is refunded or charged back, we record that and remove the access it paid for. Purchases are made through Google Play Billing, the Apple App Store, or on our website through our payment provider. On the website, payments are handled by Stripe, which may act as the reseller (merchant of record) and collects tax where required; we store the Stripe payment reference, the certifications and exam versions bought, the price tier and any discount code used, but never your card number. In the apps, Google or Apple handle payment details. We never see or store your full card number or other payment details.
Server logs
Like almost every online service, our hosting provider keeps routine server logs, such as your IP address and the time of each request. These are used for security and to keep the service running.
Emails you send us
If you email support or privacy, we receive your email address and whatever you include in your message.
3. What we do not collect
- No ads and no advertising ID.
- No third-party analytics or crash-reporting tools, and no analytics or advertising SDKs in the apps or the web app.
- No location, contacts, photos, camera or microphone access. The app only asks for internet access, Google Play billing (for purchases) and, if you turn on fingerprint or face unlock, your phone's biometric check.
- We do not sell your data, and we do not share it for advertising.
- The certmonk.app and g3nosystems.com pages have no cookies, no scripts and no trackers. The web app stores your sign-in session and a few settings (for example dark mode and keyboard shortcuts) in your browser's local storage so you stay signed in; it also keeps, for up to 30 days, the tags of the CertMonk marketing link you arrived from (see "How you found us"). It uses no advertising or tracking cookies.
4. How we use your data
- To create and run your account, including signing you in.
- To save your progress and sync it across your devices.
- To grade your practice and practice tests on our server.
- To send account emails: sign-up confirmation and sign-in codes.
- To answer support requests and review questions you report.
- To check which certifications you have purchased.
- To keep the service secure and prevent abuse, for example by rate limiting and by detecting automated scraping of questions.
- To calculate your readiness and study insights, and to show the leaderboard if you join it.
- To publish anonymous, aggregated statistics, for example pass rates by readiness band. We publish a figure only for groups of at least 30 learners, and never in a way that identifies anyone.
- To find and fix poor questions from answer patterns, and to act on feedback you send.
- To measure which of our own posts and ads bring people to CertMonk, reported only as totals. We do not build advertising profiles or share this with ad networks.
- To apply promo codes and prevent code guessing.
We do not use your data for advertising or profiling, and we do not make automated decisions about you that have legal or similarly significant effects.
5. Legal bases
Where laws such as the EU or UK GDPR apply, we rely on these legal bases:
- Contract: to provide the account, sync, grading, study analytics, purchases and account emails you ask for.
- Consent: the leaderboard, which is optional and which you can leave at any time.
- Legitimate interests: to keep the service secure, prevent abuse, improve our questions and the app, measure our own marketing, and produce anonymous aggregate statistics.
- Legal obligation: where we must keep or disclose information by law.
6. Who we share it with
We share data only with the service providers we need to run CertMonk. They process it on our behalf.
| Provider | What it does | Data involved |
|---|---|---|
| Supabase | Hosting, database, authentication, server functions and storage | All the data described above |
| Resend | Sends account emails from noreply@mail.certmonk.app | Your email address and the email content (such as a sign-in code) |
| Microsoft 365 | Hosts our support@ and privacy@ mailboxes | Emails you send us: your email address and what you write |
| Stripe | Web payments; may act as merchant of record (reseller) and handle sales tax | Your email address, billing country and postal code, payment details (held by Stripe, not us), and the items bought |
| Google Firebase Hosting | Serves the web app and the certmonk.app pages | Routine request data such as your IP address, for delivering the pages |
| Credly (Pearson) and Microsoft Learn | Checked at your request to verify a badge link you give us | Only the badge link, requested from our server |
| Google Play | App distribution and payment processing for in-app purchases | Google handles your payment details under its own privacy policy. We receive purchase information, not card numbers. |
| Google (sign-in) | Continue with Google, if you choose it | Your email address, name and a Google account identifier |
| Microsoft (sign-in) | Continue with Microsoft, if you choose it | Your email address, name and a Microsoft account identifier |
We may also disclose data if required by law, to protect the rights and safety of our users or others, or as part of a merger or sale of the business, in which case this policy would continue to apply to your data.
7. Where it is stored
Your data is stored with Supabase in the United States (Amazon Web Services, us-east-1 region). If you use CertMonk from outside the United States, your data is transferred to and processed in the United States.
8. How long we keep it
- Account, study data, purchase records and question reports: kept while your account exists. When you delete your account, they are deleted immediately and permanently from our live database.
- Backups: our hosting provider's backups roll off within about 7 days.
- Server logs: kept by our hosting provider for a limited period for security and operation.
- Support emails and feedback: kept as long as we need them to answer you, then up to 12 months after the issue is resolved; feedback is deleted with your account.
- In-app events: 13 months, then deleted automatically.
- Practice-limit counts: 7 days. Scraping flags: until they are reviewed; a record of confirmed misuse is kept as long as we need it to enforce our Terms.
- Marketing link visits: about 13 months, then deleted automatically. The link your account arrived from is deleted with your account.
- Promo codes: redemptions are kept with your purchase records; failed code attempts are deleted automatically after 1 day.
- Anonymous aggregate statistics (for example how often a question is answered correctly) are kept after an account is deleted, because they cannot identify anyone.
- Stripe payment records: kept by Stripe and by us as long as tax and accounting law requires.
- Google Play purchase records: kept by Google under its own policy.
9. Deleting your account
You can delete your account at any time:
- In the app: Study tab → Settings (gear) → Delete account… → type DELETE → confirm.
- By email: email privacy@certmonk.app from your account's email address with the subject "Delete my CertMonk account". We delete it within 30 days and reply to confirm.
Deletion removes everything, including your purchase records, so purchases cannot be restored to a new account afterward. Deleting your account does not cancel or refund Google Play purchases; refunds follow Google Play's refund policy. Uninstalling the app does not delete your account. If you signed in with Google or Microsoft, you can also remove CertMonk's access from that account's security settings. See Delete your CertMonk account for details.
10. Security
Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider. Passwords are stored only as hashes, and we use rate limiting to help prevent abuse. No system is perfectly secure, but we work to protect your data and will act promptly if something goes wrong.
11. Your rights
You can ask us to:
- give you access to your data,
- correct it,
- delete it, or
- give you a copy of it.
Email privacy@certmonk.app from your account's email address. We may ask you to confirm the request from that address.
Depending on where you live (for example the EU, the UK or California), you may have additional rights, such as objecting to or restricting some processing, or complaining to your local data protection authority. We honor those requests. We do not sell or share personal information for cross-context behavioral advertising, and we will not treat you differently for exercising your rights.
12. Children
CertMonk is not directed to children under 13, and we do not knowingly collect data from children under 13. If you believe a child under 13 has given us data, email privacy@certmonk.app and we will delete it.
13. Changes to this policy
If we change this policy, we will update the effective date on this page. If a change is significant, we will also tell you in the app or by email before it takes effect.
14. Contact
G3NO SYSTEMS LLC
Privacy: privacy@certmonk.app
Support: support@certmonk.app