Privacy Policy

Effective date: July 9, 2026 · Last updated: July 9, 2026

In plain terms. We collect only what we need to run your courses: your account details, what you read and practice, the work and notes you create, and your answers to short in-course questions. We never sell your personal information, never use it for advertising, and never see your card number. We hold no demographic data, and our learning-activity records never contain the text of your work. You can export or delete your data at any time in Settings, and when your school uses Prepara for a class, your records are protected under FERPA. The sections below have the detail; questions go to admin@preparacourse.com.

This Policy explains what Prepara LLC (“we,” “us”), which operates and publishes the Prepara courseware platform and its books (the “Service,” reached at app.preparacourse.com), collects about you, how we use it, and the choices you have. We collect only what we need to run the Service, we never sell your personal information, and we never use it for advertising. It applies to students, instructors, and anyone who uses the Service.

What we collect

What we do not collect

How we use your information

We use your information to sign you in, to grant and protect your course access, to process purchases, to provide support, to keep the Service secure, to show your progress, to help your instructor support the class, and to measure and improve how well the course teaches. We do not sell personal information or use it for advertising.

How we measure and improve your learning

To show your progress, to help your instructor support the class, and to measure whether the course actually works, we record how you read and practice: which chapters and lessons you open, how far you scroll, how much active time you spend, which learning widgets you use, and how you answer in-chapter checks. This record is tied to a pseudonymous id and stores counts, timings, and short labels. It never stores the text of your notes, your answers, or your tutor messages.

Program evaluation and experiments. We use this record to measure what teaches well and change what does not. As part of it, we may assign students to different versions of a lesson, a layout, or a study feature and compare how each version works, using an automatic and consistent method that does not depend on who you are. A version may add material or present it differently, but it never removes material you were assigned, so every student always keeps the full educational content of the course. This is evaluation of the product, not research on you as a named individual, and we can end any comparison and return every student to the standard version.

Coarse location. So we can see how a course is used across different regions, we record a coarse, county-level location with your learning activity. We work it out from your general connection details at the moment you read, keep only the county, the wider region, and a coarse country, and never store your street address or your exact location. The connection detail we use for the lookup is used for that and then discarded. When we report by place, any county, region, or school with fewer than ten students is shown as “fewer than 10” so no small group can be singled out.

Two copies of your learning activity. We keep this record in two forms. A recent working copy in our main database shows your progress and your instructor's class view, and it is deleted automatically after about 180 days (your summarized progress is kept so you do not lose your place). A long-term evaluation copy, which we call the event lake, is a pseudonymous record kept for program evaluation; it holds only counts, timings, and short labels, never the text of your work and no demographic data. We do not delete the evaluation copy on a schedule, but you can ask us to remove your records from it at any time, as described under “How long we keep your information.”

AI features and your input

The Service includes AI features that process text or audio you provide: an AI tutor you can ask questions, an AI support assistant, voice notes you record for us to transcribe, and in-chapter learning widgets. Each is labeled as AI, so you know when you are working with an automated system.

Most of these features run on Cloudflare Workers AI, which processes your input inside our provider's network using open-weight models. The AI tutor and the AI support assistant run there by default, and a voice note you record is transcribed to text on Cloudflare's edge rather than sent to an outside transcription service. Text-to-speech reading of content uses Cloudflare Workers AI by default. The in-chapter learning widgets are served by Anthropic (Claude) through a separate proxy, and the AI tutor also uses Anthropic when a Claude model is chosen for it. In some books the in-chapter AI moments are pre-recorded and send no input to any live model; where a widget does send your input, it goes to Anthropic through the proxy.

Your input to these AI features is not used to train any outside AI model. Anthropic processes input under its commercial API terms, which do not train models on API inputs. AI output can be wrong or incomplete, so treat it as a study aid and check anything important.

When you ask the AI tutor a question, we also sort each question into a general category (for example, asking for help to do the work yourself, or asking the tutor to do it for you) so we can measure how a class uses the tutor. This category is a short label; the text of your question is not copied into our learning-activity records. Your tutor conversations themselves are stored in your account and, for a section you are enrolled in, are visible to your instructor along with the rest of your coursework.

Surveys and confidence check-ins

From time to time the Service asks short, optional questions inside the reader: a brief confidence or AI-literacy survey at the start and end of a course, and one-question check-ins after some chapters. These are voluntary and skippable, each is one screen or one question, and each states what it is for. Your answers are rating-scale and short responses, kept as part of your record so your school can use them as learning evidence and so we can improve the course. We label each questionnaire with a version, so if we reword one, older answers are never mixed up with new ones.

Your research choice

Separately from the measurement above, which applies to every account so the Service can run and improve, you may choose whether your learning data is included, anonymously, in published education research. We ask you this once, on a card shown when you first sign in, worded “My learning data may be included anonymously in education research.” The setting defaults to off, so your data is included in published research only if you turn it on. Published results report groups, never individuals. Your choice does not affect your access or your grade, and you can change it at any time in Settings; if you turn it off, we stop using your records for research going forward.

How we measure website traffic

To understand how many people visit our public pages and where they come from, we use a method that counts visits without identifying people, and we store nothing that could re-identify you. We do not use tracking cookies for this, and nothing is stored in your browser. For each visit we create a one-way value from a secret that changes every day plus general request details (the page, a coarse country, the device type). Because that daily secret is deleted, the same visitor becomes a new, unlinkable value the next day, and we never store your IP address or your full browser details. Since this method uses no cookies and cannot follow you across days or across other websites, it does not require a cookie consent banner.

Cookies

The only cookie we set is a strictly necessary sign-in cookie that keeps you logged in. We do not use advertising or cross-site tracking cookies, and we do not store analytics identifiers in your browser.

Who can see your information

Service providers we use

We use a small set of vetted providers to run the Service. Each one processes only the data it needs for its function, under confidentiality and security obligations, and we never sell your personal information to any of them.

Your school and FERPA

When your school uses the Service for a class, the records we keep about you in that class (such as your enrollment, your progress, your quiz scores, your assignment submissions, and your tutor conversations for that section) can be education records under FERPA, the federal student-privacy law. In that case we act as a school official with a legitimate educational interest, which means we handle those records only to provide the Service for your school, under your school's control, and we do not use them for anything else or share them except as your school directs or the law requires. Your instructor and teaching staff for a section can see the coursework and learning activity of the students enrolled in that section, the same way they would in any class. We will sign a data processing agreement with your school on request, and your school keeps control of its students' records. If you have questions about your education records, you can also ask your school.

Learning-management systems (LTI)

If your instructor connects a course section to your school's learning-management system (LMS), such as Canvas, using the LTI 1.3 standard, we exchange data with that LMS to make the connection work. When you launch the Service from your LMS, your LMS identity (such as your name, email, and role in the course) is shared with us so we can sign you in to the right section, and your grades and completion for that section flow only to your school's own gradebook. This happens only for sections an instructor has connected and only with your own school's LMS. Your school's own privacy policy governs the data once it is in your LMS.

Security

Data is encrypted in transit and at rest, and passwords are hashed. Two-factor authentication is available. Access to course content is gated and carries a per-user visible and invisible watermark. We use least-privilege access and keep an audit log of access and administrative actions. To report a security issue, email admin@preparacourse.com; our security contact and disclosure policy are also published at /.well-known/security.txt. If a breach affecting your personal data happens, we will tell you and any required authorities without undue delay and as the law requires; where a school's data is involved, we will notify the school promptly, within 72 hours of becoming aware, so it can meet its own obligations.

How long we keep your information

We keep your account data for as long as your account is active. For other kinds of data we keep only what we still need:

When you delete your account, we remove your personal data, your notes, highlights, voice notes, boards, and the activity records tied to your account in our main database within 30 days, except the order, payment, security, and audit records we must keep for legal reasons. Deleting your account also stops any further use of your records for research. The long-term evaluation copy holds only pseudonymous counts and labels and never the text of your work; we do not delete it automatically, but if you want it removed, email admin@preparacourse.com and we will delete your records from it. Records we hold on behalf of a school are returned or deleted on the school's instruction, or within 30 days after that school's contract with us ends.

Your privacy rights

You can access, correct, export, or delete your personal information. Update your profile and password or delete your account in Settings, use Download my data for a full export, ask us to remove your records from the long-term evaluation copy, or contact us to make any request. We do not sell your personal information, ever, do not share it for advertising, and will not treat you differently for using your rights. These rights apply to everyone, wherever you live. Where you use the Service through your school, that school relationship and FERPA govern your class records. Email admin@preparacourse.com and we will honor your rights as the law requires.

Younger users

You must be at least 13 years old to have an account. The Service is built for college and university coursework and is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Children's privacy laws such as COPPA apply to children under 13 and do not apply to college students, but we still hold to a 13-and-over rule and will delete any account we learn belongs to a younger child.

Changes to this Policy

We may update this Policy. When we make a material change, we will update the date at the top and, where appropriate, give notice through the Service. Using the Service after a change takes effect means you accept it.

Contact

Questions about this document? Email admin@preparacourse.com.