Privacy Policy
GREPrep is a personal GRE study application. It gives you a paced vocabulary curriculum with spaced repetition, quantitative and verbal practice questions, timed mock tests, and AI-assisted feedback on analytical writing essays.
This policy explains exactly what data GREPrep collects, why it collects it, who it is shared with, how long it is kept, and how to have it deleted. It covers the Google account information GREPrep receives when you sign in, and everything the application records as you study. GREPrep is operated by an individual developer, contact details in section 12.
In short: GREPrep asks Google only for your name, email address, profile picture and account ID, and uses them solely to identify your account and email you test reminders. It does not sell your data, does not show advertising, and runs no analytics or tracking of any kind.
1. Google account data GREPrep receives
Signing in with Google is the only way to create a GREPrep account. GREPrep uses the standard OAuth 2.0 authorization code flow and requests exactly three scopes. It requests no access to Gmail, Drive, Calendar, Contacts, Photos, or any other Google service, and it never receives or handles your Google password.
| Scope requested | What GREPrep receives | Why it is needed |
|---|---|---|
openid |
Your Google account identifier (the sub claim) |
The stable key that links you to your study record, so returning to the app brings back your own progress rather than a blank account. It is stored because an email address can change and this identifier cannot. |
email |
Your email address and whether Google has verified it | Shown to you as the account you are signed in as, and used as the delivery address for the reminder email sent before a test you have scheduled. GREPrep declines sign-in from an address Google reports as unverified. |
profile |
Your display name and profile picture URL | Displayed in the application so you can see which account is signed in. The picture is stored only as the URL Google provides; GREPrep does not copy the image itself. |
These values are read once from the ID token Google returns at sign-in and refreshed each time you sign in again. GREPrep requests offline access to nothing: no Google refresh token is issued to it, so it cannot reach your Google account when you are not actively signing in.
2. Google API Services Limited Use disclosure
GREPrep's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means GREPrep:
- uses Google user data only to provide and improve the study features described on this site and visible to you in the application;
- does not transfer Google user data to third parties except as needed to provide those features, for security purposes, or to comply with applicable law;
- does not use Google user data for advertising, and serves no ads of any kind;
- does not sell Google user data, and has no arrangement under which it could;
- does not allow humans to read Google user data, except where you have explicitly asked for support, where it is necessary for security or to comply with applicable law, or where the data has been aggregated and de-identified.
3. Other information GREPrep collects
Beyond the Google account data above, the application records what it needs in order to be a study tool. All of it is generated by your own use of the app โ none of it is bought, scraped, or obtained from any other source.
Study activity
- Which curriculum words you have been given, which you have marked as learned, and the spaced-repetition schedule derived from your reviews.
- Practice questions you have attempted, the answers you chose, whether they were correct, and how long you took.
- Tests you have scheduled or taken, your responses, and the resulting score reports.
- Analytical writing essays you submit, together with the feedback and scores generated for them.
Technical data
-
Session cookie. On sign-in, GREPrep sets one cookie named
greprep_sessioncontaining a random token. It isHttpOnly,SameSite=Laxand, over HTTPS,Secure. The server stores only a SHA-256 hash of the token, so a copy of the database does not hand anyone a set of live sessions. It expires after 30 days. -
Browser description. The
User-Agentstring of the browser that opened each session is stored alongside it, so a session you do not recognise can be identified. - Server logs. The web server records requested URLs, timestamps, response codes and originating IP addresses, as any web server does. These are used for debugging and to detect abuse.
GREPrep sets no advertising, analytics or tracking cookies, embeds no third-party trackers or social widgets, and does not track you across other websites.
4. How your information is used
- To create your account and keep you signed in.
- To store and show your study progress, and to decide what you should study next โ which words are due for review and which topics your practice should target.
- To generate practice questions, word explanations, essay feedback and spoken audio for the day's words (see section 5).
- To send you an email reminder a few days before a test you have scheduled. These are transactional messages tied to your own schedule; GREPrep sends no marketing email.
- To keep the service secure, diagnose faults, and prevent abuse.
GREPrep does not use your data to build advertising profiles, does not make automated decisions with legal effects about you, and does not use your essays or study data to train any machine-learning model of its own.
5. Who your information is shared with
GREPrep does not sell, rent or trade personal information. It is shared only with the service providers the application needs in order to work:
| Provider | What it receives | Purpose |
|---|---|---|
| Groq, Inc. | The text of an essay you submit for feedback, and the study content being generated (a word, a topic, a question). Your name, email address, Google account ID and profile picture are not sent. | Runs the AI models that score essays, produce practice questions and word explanations, and read the day's words aloud. |
| Google LLC (Gmail SMTP) | Your email address and the content of the reminder message, at the time one is sent. | Delivers scheduled test-reminder emails. |
| Amazon Web Services, Inc. | Hosts the server and its database, and so holds all stored data at rest as infrastructure provider. | Hosting and storage. |
Each provider is bound by its own terms and privacy commitments and may process data only to deliver the service above. Beyond these, information is disclosed only where required by law, or where necessary to establish or defend legal claims or to protect the safety of users. If GREPrep is ever transferred to another operator, you will be told before your data moves and given the opportunity to delete your account first.
6. Where and how your data is stored
Your data lives in a SQLite database on a single server run by the developer on Amazon Web Services infrastructure. It is not replicated to third-party analytics platforms or data warehouses. Protections in place:
- All traffic is served over HTTPS with a certificate renewed automatically.
-
Session tokens are stored only as SHA-256 hashes, never in plain text; session cookies
are
HttpOnly, so page scripts cannot read them. - Every request for personal data is bound to the signed-in account before any query runs, so one account's data cannot be returned to another.
- Administrative access to the server is by SSH key only, and is limited to the developer.
- The application never receives, stores or transmits any password.
No system is perfectly secure, and GREPrep is a personal project rather than an enterprise service. Please bear that in mind and do not put sensitive personal information into essay text or other free-text fields. If a breach affecting your data occurs, you will be notified at your account email address without undue delay.
The server is located in, and data is stored in, the United States or India depending on the hosting region in use. If you are accessing GREPrep from elsewhere, your data will be transferred to and processed in those countries.
7. How long data is kept
- Account and study data are kept for as long as your account exists, because their whole purpose is to be a long-running record of your preparation.
- Sessions expire 30 days after sign-in, and are deleted from the database when they expire or when you sign out.
- Sign-in state tokens used during the OAuth exchange are deleted as soon as they are used, and in any case within 10 minutes.
- Server logs are rotated and retained only for a short period for debugging and abuse detection.
- Deleted accounts are removed along with their study history, essays and sessions within 30 days of the request.
8. Your choices and rights
- Revoke access. You can remove GREPrep's access to your Google account at any time at myaccount.google.com/permissions. You will simply be unable to sign in again until you re-authorise it.
- Sign out. Signing out of the application deletes that session from the server immediately.
- Access and portability. Email the address in section 12 and you will be sent a copy of the data held about your account.
- Correction. Name, email address and picture are refreshed from Google on each sign-in, so correcting them in your Google account corrects them here. Ask by email for anything else.
- Deletion. Email the address in section 12 from the address you signed in with, asking for deletion, and your account and all associated study data will be erased within 30 days.
- Objection and complaint. Depending on where you live, you may have the right to object to or restrict processing, and to complain to your local data-protection authority.
Requests are answered within 30 days and cost nothing. Where processing needs a legal basis, GREPrep relies on performance of a contract for running your account and study record, on its legitimate interest in keeping the service secure and working, and on your consent for the Google data you grant at sign-in โ consent you can withdraw at any time by revoking access as described above.
9. Children
GREPrep is intended for people preparing for graduate admission and is not directed at children under 13 (or under 16 in the EEA and UK). Accounts are not knowingly created for them. If you believe a child has created an account, write to the address below and it will be deleted.
10. Links to other sites
The application links to third-party sites such as Google's account pages and reference material. This policy does not cover them; their own policies apply once you leave GREPrep.
11. Changes to this policy
This policy may be updated as the application changes. The "last updated" date at the top always reflects the current version. If a change materially affects how your data is used, you will be notified at your account email address before it takes effect, and continued use of GREPrep after that point means you accept the revised policy.
12. Contact
For any question about this policy, to request a copy of your data, or to have your account deleted, write to:
GREPrep โ Privacy
sachinyadav20031101@gmail.com
Please send deletion requests from the email address associated with your account, so the request can be verified before anything is erased.