BREAK·THE·TEST
Legal

Privacy policy

Effective May 27, 2026

Break the Test, formerly Break the Hidden Test ("we," "us"), respects your privacy. This policy explains what we collect, why, and what control you have. We wrote it in plain language. If anything is unclear, email [email protected].

1. Who we are

Break the Test is a test-prep web application that trains students to recognize wrong-answer patterns on the SAT, ACT, AP exams, and Common App essays. The service is operated from the United States.

2. What we collect when you sign in with Google

When you sign in with Google, we request the following OpenID Connect scopes:

  • openid: your Google account identifier.
  • email: your primary email address.
  • profile: your display name and profile picture.

We do not request, and we do not have access to, any other Google services. We never see your Gmail, Drive, Calendar, Contacts, Classroom, Photos, or any other Google product data. Our access is limited to confirming who you are and showing your name and picture inside the app.

3. What we collect when you use the product

Once you're signed in, we record your interactions with the service so we can show you your progress and personalize what you drill next. Specifically:

  • Which questions you've attempted, when, which answer you picked, whether it was correct, how long it took, and your self-reported confidence (low / medium / high).
  • Your test target (which exams you're preparing for and a target score band, if you set one during onboarding).
  • Aggregate per-skill progress data computed from your attempts.
  • Practice test sessions: your responses per item, the scaled scores we compute, and the time you spent.
  • Item flags: if you mark a question as confusing or unfair, we record the flag with your account.
  • Basic device information needed to deliver the app: browser user agent, IP address (for security and rate limiting), and the locale of your device.

We do not collect biometric data, location data more precise than country/region, contacts, or content from other apps.

4. How we use your data

  • Authenticate you when you sign in, and keep you signed in across devices.
  • Save your progress so your mastery, mistakes, and practice-test history persist between sessions.
  • Personalize what you drill next: we pick items that target your weaker skills.
  • Improve the product: aggregated, de-identified data helps us see which questions are too easy, too hard, or broken.
  • Respond to support requests if you email us for help.

We do not use your data for advertising. We do not build profiles for advertisers. We do not allow third parties to place tracking pixels or analytics scripts that share personally identifiable information.

5. What we share, and with whom

We do not sell, rent, or trade your personal information. We share data only with the service providers we need to run the product:

  • Google for sign-in and identity verification.
  • A cloud hosting provider that runs our application, stores account data, and serves the website to your device.

These providers act as data processors under our written instructions. They are not allowed to use your data for their own purposes.

We may disclose data if required by a valid legal process (subpoena, court order). We will tell you when we can and the law permits.

6. How we store and secure your data

Your data lives with our cloud hosting provider. Sign-in sessions use short-lived bearer tokens that expire automatically. All traffic between your device and our servers is encrypted in transit using TLS 1.2 or higher. At rest, data is encrypted by our provider per their standard practices.

No system is perfectly secure. If we discover a breach that affects your data, we will notify you within seventy-two hours of discovery, where the law requires it.

7. How long we keep your data

  • Account data (name, email, profile picture) for as long as your account is active.
  • Attempt history for as long as your account is active, since it powers your dashboard.
  • Session tokens expire automatically within thirty days of last use.
  • Inactive accounts: if you don't sign in for twenty-four months, we will email you a warning and then delete the account if you don't return.
  • Deleted accounts: when you delete your account, all personal data is removed within seven days, except where retention is legally required.

8. How to delete your data

Email [email protected] from the address you used to sign up and ask us to delete your account. We will confirm within two business days and complete the deletion within seven days. We will delete your identity, your attempts, your mastery, your practice-test history, and any item flags you submitted. We may retain aggregated, de-identified analytics that cannot be traced back to you.

9. How to export your data

Email [email protected] and we will send you a JSON file containing your account, your test target, and your full attempt history. We aim to deliver this within fourteen days of your request.

10. Children's privacy

You must be at least thirteen years old to use Break the Test. We do not knowingly collect personal information from children under thirteen. If we learn that we've collected data from someone under thirteen, we will delete it as quickly as we can. If you are a parent or guardian and believe your child under thirteen has signed up, please contact [email protected].

Students between thirteen and seventeen are welcome to use the service. Their data is treated the same as anyone else's, with the same protections.

11. Cookies and local storage

We use the following client-side storage:

  • A sign-in token stored locally in your browser so you don't have to sign in on every visit. Required for the service to work.
  • A local cache of the app's interface and images so it loads quickly on repeat visits. You can clear it from your browser settings at any time.
  • A theme preference (dark or light) stored locally so we don't have to ask each visit.

We do not use third-party tracking cookies. We do not use Google Analytics or similar analytics products that share personal identifiers with third parties.

12. Your rights

Depending on where you live, you have rights over your personal data:

  • Right to access: ask us what we hold about you and receive a copy.
  • Right to correction: ask us to fix inaccurate data.
  • Right to deletion: ask us to delete your account and data.
  • Right to portability: ask us to send your data in a portable format.
  • Right to object to certain processing.

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have these rights under the GDPR. You also have the right to complain to your local data protection authority. If you are in California, you have similar rights under the CCPA / CPRA, including the right to know what personal information we have and to ask us not to sell it (we don't sell it).

To exercise any of these rights, email [email protected].

13. International transfers

Our hosting provider may serve and process data from any country where it operates. We rely on standard contractual clauses or equivalent safeguards for transfers out of the European Economic Area or the United Kingdom.

14. Changes to this policy

If we change this policy in a meaningful way, we will email you and post a notice at the top of this page at least seven days before the change takes effect. The effective date below tracks when the current version went live.

15. Contact

Email [email protected]. We read every message and respond within two business days.