Privacy Policy
Last updated: September 10, 2026
ExamOven ("ExamOven," "we," "us," or "our") is an independent, individually-operated exam-practice service. This Privacy Policy explains what information we collect, why we collect it, how it's used, and the choices you have.
We designed ExamOven to be privacy-first: your exam attempts and results are stored on your own device by default, and we collect the minimum amount of additional information needed to run and protect the service.
1. Information We Collect
1.1 Information You Provide Directly
We collect information you actively choose to give us:
- Contact and support requests — such as your name, email address, the topic of your message, and the message itself, when you use our contact form or in-app chat/feedback tools.
- Feedback submissions — such as whether you found what you were looking for, and an exam name if you tell us one is missing.
- Contributed content — if you voluntarily share a custom practice-question set or other material with us (for example, to suggest it be added to our public question library), we receive whatever you choose to send.
- Community contribution forms — links to external forms (for contributing past exam papers, etc.) are governed by the privacy policy of the form provider once you leave our site.
We never ask for sensitive information (such as government ID numbers, financial account details, or precise location) through these channels, and you should avoid including such details in free-text messages to us.
1.2 Information We Collect Automatically
While you use the app. Like most web services, we automatically collect limited, aggregated usage information to understand how the service is used and to keep it working correctly — for example, which pages/features are used, session counts, and basic error events. This is collected via a privacy-conscious analytics tool, is not linked to your name or email, and is only collected after you've had the opportunity to accept or decline it through our cookie/consent banner (see Section 4).
When you submit a form to us (planned). We do not currently do this, but we may, in the near future, begin automatically capturing a small set of technical metadata alongside form submissions:
- IP address
- Browser and device type (user-agent string), including general operating system information
- Screen resolution
- The web page you submitted the form from, and the referring page (if any)
- Date and time of submission
- Basic, non-precise session/device information (e.g., a randomly generated session identifier)
This information would not be displayed as a field on the form itself — it would be captured automatically as part of standard, routine web request handling. We're disclosing this possibility here in advance so this policy stays accurate. If and when this is enabled, we will update the "Last updated" date above; no separate re-consent is required for this category, since it is collected for security/anti-abuse purposes rather than analytics or advertising (see Section 4).
Why we would collect this, and why only this. In line with the data-minimization principle (see, e.g., GDPR Article 5(1)(c)), this automatic collection would be limited strictly to what is useful for:
- Detecting and preventing spam, automated abuse, and fraudulent submissions;
- Applying basic rate limits so the service isn't overwhelmed or misused;
- Diagnosing delivery problems if a message doesn't reach us; and
- Maintaining the general security and integrity of the service.
We would not use this technical metadata to build advertising profiles, to track you across other websites, or to determine your precise physical location. Any IP addresses and device metadata collected for these purposes would be retained only as long as reasonably necessary for spam/abuse review and security purposes, and then deleted or aggregated into a form that no longer identifies you.
1.3 Exam Attempt Data (Stored Locally on Your Device)
When you take an exam, the following information is generated and stored locally on your device (in your browser's IndexedDB):
- Your selected answers for each question.
- The calculated score and maximum possible score.
- Counts of correct, incorrect, and unattempted questions.
- Total time taken for the attempt and time spent per question.
- The specific settings used for that attempt (time limit, marking scheme).
This data is used to provide you with results, allow answer review, and populate your attempt history. We do not transmit your individual question responses to our servers.
1.4 User-Uploaded, Pasted, or Shared Content
If you upload or paste a custom JSON question set for practice, ExamOven processes this data locally in your browser to deliver the exam simulation. We do not upload or store your custom question content on our servers unless you explicitly share it with us via our support chat (see Section 1.1).
Custom Exam Sharing: If you use the "Share this exam" feature to generate a link for a custom exam, the question data is end-to-end encrypted in your browser before being temporarily stored on our servers. The decryption key is included only in the final URL and is never transmitted to us, meaning we cannot read or access your shared questions. These encrypted records automatically expire and are deleted after a limited time.
1.5 What We Deliberately Do Not Collect
To be clear about the boundaries of what we gather, ExamOven does not:
- Collect precise (GPS-level) geolocation data;
- Collect or process payment card details or bank information (see Section 8 on donations);
- Require an account, email, or login to use the core service;
- Use browser fingerprinting or persistent cross-site advertising identifiers;
- Sell, rent, or trade your personal information to third parties, ever.
2. How We Use Information
We use the information described above to:
- Operate, maintain, and improve ExamOven;
- Provide core exam simulation functionality and display your results;
- Respond to your questions, bug reports, and feedback;
- Detect, investigate, and prevent spam, abuse, and security incidents, and to apply reasonable rate limits;
- Understand aggregate usage patterns so we can prioritize improvements;
- Comply with applicable legal obligations.
Legal Basis for Processing (EU/UK Users)
Where applicable data protection law requires a stated legal basis, we rely on:
- Consent — for optional analytics-related cookies, which are off by default until you accept our consent banner;
- Legitimate interests — for automatically collected technical metadata used for spam prevention, rate limiting, and security, which we've limited to the minimum necessary for those purposes;
- Performance of a request you initiate — for information you submit through forms, used to respond to you;
- Legal obligation, where applicable.
3. Local Storage on Your Device
Your exam attempts, scores, answer history, and app preferences are stored locally in your browser (using IndexedDB and Local Storage) by default. This data is not transmitted to us or to any server we control. Clearing your browser's site data will remove this local history unless you have enabled optional cloud sync (Section 5).
We provide in-app tools to export your local history as a file you control, and to delete individual entries or your entire local history at any time.
4. Cookies and Consent
We use a small number of cookies/local-storage flags for:
- Essential functions — such as remembering your cookie preference and basic app settings. These are always active, since the app can't function properly without them.
- Analytics — anonymized/aggregated usage measurement via Google Analytics, active only if you accept our consent banner. Analytics-related consent defaults to denied until you actively opt in, and you can change your choice at any time.
- Authentication — Google OAuth cookies to securely manage your session if you use the Google Drive Sync feature.
We currently do not run advertising on ExamOven. If that changes in the future, we will update this policy in advance and extend the relevant consent categories accordingly.
5. Optional Cloud Sync (Google Drive)
If you choose to enable cloud sync, ExamOven will ask you to sign in with your Google account and grant a narrow, app-specific storage permission. This permission only allows the app to read and write files inside a private, application-specific storage area associated with your own Google account — it does not grant access to your general Google Drive files, and no one at ExamOven can see this data.
If enabled, your exam history and related settings are copied to this private storage area so you can access them across devices. You can disconnect this feature and delete the associated cloud data at any time from within the app. Deleted records are automatically and permanently purged from cloud storage after a limited retention window.
Our use of Google user data through this integration is limited strictly to providing the sync feature you've requested, consistent with Google's API Services User Data Policy, including its Limited Use requirements.
6. Third-Party Services
ExamOven relies on a small number of third-party service providers to operate:
- Website hosting and analytics infrastructure — to serve the app and measure aggregate usage (including Google Analytics);
- Form-processing services — to receive and route contact/feedback submissions (including Google Forms);
- Optional account and storage services — for the Google Drive sync feature described above;
- Publicly hosted content repositories — from which our (non-personal) practice question content is served;
- Standard web infrastructure providers — such as font and QR-code generation services used to render parts of the interface;
- Client-side rendering libraries — including Recharts (charts), KaTeX, and React Markdown (math/text rendering), which operate locally in your browser and do not send data externally.
Each of these providers processes data under their own privacy policy and terms, and may be located in a different country than you. We select providers that meet reasonable industry security and privacy standards, and we do not share more information with them than is necessary for them to perform their function.
7. Data Retention
- Local device data persists until you delete it or clear your browser's site data.
- Cloud-synced data (if enabled) persists until you delete it in-app or disconnect the sync feature; deleted-item records are automatically purged from cloud storage after a limited retention window.
- Support/feedback submissions are retained only as long as reasonably necessary to address your request and for a limited period afterward for record-keeping.
- Automatically collected technical metadata (Section 1.2), if and when that capability is enabled, will be retained only as long as necessary for spam-prevention and security purposes, then deleted or anonymized.
8. Donations
We may offer an optional way for users to voluntarily support the project (for example, via a third-party payment app). We do not process, collect, or store any payment card, bank, or transaction details ourselves — any such payment happens directly between you and your payment provider, subject to that provider's own terms. Making or not making a donation has no effect on your access to the service.
9. Data Security
We take reasonable technical and organizational measures to protect the information we do handle. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Your Rights and Choices
Depending on your location, you may have rights to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent at any time. In practice, for most ExamOven users this means you can:
- Export your local exam history at any time from within the app;
- Delete individual records, your entire local history, or your cloud-synced data at any time from within the app;
- Opt out of analytics by declining or later withdrawing consent via the cookie banner;
- Contact us (Section 13) for anything not covered by the in-app controls, including requests relating to information submitted through our contact/feedback forms.
We will respond to legitimate requests within a reasonable timeframe as required by applicable law.
11. Children's Privacy
ExamOven is intended for general audiences preparing for academic and competitive exams and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will take steps to remove it.
12. International Users
ExamOven is accessible globally. Where we or our service providers process information outside your home country (for example, through providers based in the United States), that information may be subject to the laws of those jurisdictions, which may differ from the data protection laws of your own country.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal or operational reasons. We'll update the "Last updated" date above, and where changes are significant, we'll make reasonable efforts to give notice within the app before they take effect.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your information, please reach out via our Contact page.
This policy is intended to give you a clear, accurate picture of our data practices and is drafted with common data-protection principles (including GDPR data minimization) in mind.