Privacy Policy
Last updated: August 26, 2026
This page explains what information PassPhysics ("the Service," "we," "us") collects, why, and what rights you have over it. The Service is free to use, carries no ads, and does not sell data to anyone.
What we collect
If you create an account, we store:
- Your email address — used to sign in and, if you ever request a password reset, to reach you.
- Your password — never in readable form. It's run through bcrypt, a one-way hashing function, immediately on our server; we cannot recover or view your actual password, even internally.
- Practice and exam history — which questions you've answered, whether you got them right, self-reported free-response scores, flashcard review scheduling, and which units you've marked complete. This is what powers the performance dashboard and spaced-repetition scheduling.
- A session cookie — a random token that keeps you signed in. It carries no personal information itself; it's just a lookup key tied to your account on our server.
If you use Timed Practice or a Practice Exam without an account, your answers during that session are stored temporarily so you can resume if you reload the page, but aren't linked to any identity and are automatically deleted after a short period.
We do not currently offer sign-in via Google or any other third party. If that changes, this policy will be updated first, and any data received from that provider will be described here.
What we don't do
- No advertising, and no ad networks embedded anywhere in the Service.
- No analytics or tracking scripts from third parties.
- No selling, renting, or sharing your data with third parties for their own marketing purposes.
Our hosting provider or reverse proxy may, as a standard operational matter, briefly log IP addresses for security and abuse prevention (this is infrastructure-level logging, not something the Service's own code does or has access to as personal data).
Why we process this data
For EU/EEA users, our legal basis under GDPR is: performance of a contract (creating and maintaining your account, keeping your progress) for the account and practice-history data, and legitimate interest (keeping the Service secure and functioning) for session cookies and infrastructure logs. We don't rely on consent as a basis for any of this, so there's nothing to opt in or out of beyond creating an account in the first place — and if you'd rather not create one, most of the Service's practice content works without one.
How long we keep it
For as long as your account exists. If you delete your account (available in Settings), the deletion is not cosmetic — it removes your user record and, by database-level cascading rules, every row tied to it: sessions, progress, practice history, and self-scored FRQ records, all in the same operation. Nothing lingers in an active table afterward. (Routine backups, if the operator keeps any, may retain a deleted account's data for a limited additional period until that backup cycles out — see the operator's specific backup retention policy, which should be stated here once configured.)
Your rights
Regardless of where you live, you can access, correct, or delete your data at any time through the account settings in the app. If you're in the EU/EEA, UK, or a jurisdiction with similar law, you additionally have the right to data portability (an export of your data in a readable format, available on request), the right to object to processing, and the right to lodge a complaint with your local data protection authority. If you're a California resident, similar rights (access, deletion, opt-out of sale — though we don't sell data regardless) apply under the CCPA/CPRA. To exercise any of these beyond what's self-service in the app, contact us at domainsellingservice@gmail.com.
If you're a student under 18
This Service is built for AP Physics and college-intro-physics students, who are very often minors. We ask for the minimum data needed to run the account features above and show no advertising to anyone, minor or not. We don't currently ask for or verify age at signup. If you're a parent or guardian and want to review, correct, or delete a minor's data, contact us at the address above and we'll handle it directly — you don't need the account's own login to request this.
If required by your local law (for example, GDPR Article 8 in some EU member states, which can require parental consent for users under 16), and you're below that age, please have a parent or guardian create or approve the account, or contact us and we'll assist directly.
Where your data lives
Data is stored on the server(s) the Service is hosted on. Servers are located in the EU. If that location differs from your own country, this may involve an international data transfer; for EU/EEA users this policy will name the safeguard relied on (e.g. an adequacy decision, or standard contractual clauses) once hosting is finalized.
Security
Passwords are hashed with bcrypt and never stored or logged in plain text. Login attempts are rate-limited to slow down automated guessing. The Service is only intended to be accessed over HTTPS; if you ever reach it over plain HTTP, that's a configuration issue on our end, not expected behavior, and we'd want to know about it.
Changes to this policy
If this policy changes in a way that meaningfully affects what we collect or how we use it, we'll update the date at the top and, for signed-in users, note it somewhere reasonably visible in the app.
Contact
domainsellingservice@gmail.com — reach out here with any question about this policy or your data.