Privacy Policy
Last updated: September 24, 2026
Who we are
ATP Quest (“ATP Quest”, “we”, “us”) is operated by Griffin Blue, 124 Langdon St, Madison, WI, USA. For the purposes of data protection law we are the controller of the personal data described here. You can reach us at privacy@atpquest.com.
The short version
- You can study without an account. Your progress then stays in your browser and never reaches us.
- With an account we store your email, your study progress and your answer history, so it syncs across devices.
- Payments are handled by Stripe. We never see or store your card number.
- We use no advertising or tracking cookies, and we don’t sell or share your data for advertising.
- We keep only what the service needs, and delete everything else on a fixed schedule.
- You can download everything we hold about you, or delete your account, from the Account page at any time.
What we collect
If you study without an account
Nothing that identifies you. We set one random identifier in a cookie (atpq_guest) so we can apply the free tier’s daily allowance and protect the service from abuse, and we record which questions that identifier was shown on which day.
If you create an account
- Account details: your email address, an optional display name, and your password, which our authentication provider stores only as a salted hash. If you sign in with Google we receive your Google email address and an account identifier.
- Study data: your spaced-repetition schedule for each question, the questions you answered, whether you were right, how long you took, your test date if you set one, badges, and in-app currency and upgrades.
- Billing: your Stripe customer identifier, plan, and subscription status. Your name, card and billing address are collected and held by Stripe, not by us.
- Messages you send us: support messages and bug reports. A bug report includes technical details about your browser, the screen you were on and any errors, so we can reproduce the problem.
Automatically
Our hosting provider logs requests (IP address, browser, the page requested, time) to operate and secure the service. To stop abuse we count requests per visitor for short periods, which can involve your IP address. Our analytics are cookieless and aggregate: we see counts of page views and sign-ups, never an individual visitor. If the app crashes, an error report (the error, the page, your browser and operating system) is sent to our error-monitoring provider, without your IP address.
Cookies and browser storage
We use only storage that is strictly necessary for a service you asked for, or that remembers a choice you made. Because of that, we don’t show a cookie banner.
| Name | What it’s for | How long |
|---|---|---|
sb-…-auth-token | keeps you signed in | your session |
atpq_guest | the free tier’s daily allowance and abuse protection for visitors without an account | 1 year |
atpquest.v1, atpquest.session.v1, atpquest.owner | your progress and an unfinished session, stored in your browser | until cleared or you sign out |
atp-theme | your light or dark theme choice | until changed |
How we use it, and on what basis
- To provide the service you signed up for (performance of a contract): accounts, syncing progress, scheduling reviews, the free tier and paid plans.
- To keep it secure and working (legitimate interests): rate limiting, fraud prevention, fixing errors, and aggregate usage statistics.
- To meet legal obligations: keeping payment records as tax law requires.
We send only email you need: confirming your address, sign-in links, password resets, and notices about your account or subscription. We send no marketing email. We do not make decisions about you by automated means that have legal or similarly significant effects; the scheduler only decides when to show you a question again.
Who processes it
We use these service providers, each bound by a data processing agreement:
| Provider | What for | Where |
|---|---|---|
| Vercel | hosting | United States, with a global network that serves pages near you |
| Supabase | database and sign-in | United States |
| Stripe | payments | United States |
| Resend | account email | United States |
| Plausible | cookieless, aggregate analytics | EU |
| Sentry | error monitoring | United States |
| sign-in, only if you choose it |
We don’t sell personal data or share it for cross-context behavioural advertising. We disclose data to authorities only when the law requires it.
Your rights
Depending on where you live, you have rights to access, correct, export, delete and restrict or object to the processing of your personal data, and to withdraw consent where we rely on it. Most of these you can exercise yourself:
- Export: Account → Download my data gives you every record we hold about you, as JSON.
- Correct: change your name and email on the Account page.
- Delete: Account → Delete account removes your account and all your study data immediately, after cancelling any subscription.
For anything else, write to privacy@atpquest.com. We answer within 30 days. You may also complain to the data protection authority where you live. California residents: we do not sell or share personal information, and you have the rights to know, delete and correct described above.
How long we keep it
We keep personal data only as long as the service needs it. Records we no longer need are deleted automatically, every day:
| Record | Kept for |
|---|---|
| Your account and study data | until you delete your account; deletion is immediate |
| Free-tier records for visitors without an account | deleted after a year with no activity |
| Bug reports and support messages | 90 days; if you delete your account sooner, your link to them is removed at once |
| Abuse-prevention request counts (which can include your IP address) | 1 day |
| Hosting request logs | about 1 day, under our hosting provider’s retention |
| Error reports | up to 90 days, under our error-monitoring provider’s retention |
| Payment records | held by Stripe for as long as tax and financial law requires |
Our analytics store no personal data, so there is nothing of yours there to keep.
Security
Data is encrypted in transit. Every table holding your data enforces row-level security, so an account can read only its own records. Passwords are hashed by our authentication provider and never visible to us. No system is perfectly secure; if a breach affects your data, we will tell you and the relevant authorities as the law requires.
International transfers
ATP Quest is run from the United States, and our providers process data there and in other countries. Where personal data from the EU, UK or Switzerland is transferred, we rely on the Standard Contractual Clauses (with the UK Addendum) in our providers’ data processing agreements, or on the EU–US Data Privacy Framework where a provider is certified under it.
Children
ATP Quest is for people preparing for the MCAT and is not directed to children. You must be at least 13 to create an account, or older if the law where you live sets a higher age for using online services without a parent’s consent (up to 16 in some EU countries). We do not knowingly collect personal data from anyone below that age. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
If we change this policy in a way that matters, we will say so on this page and, for significant changes, email account holders before the change takes effect.
Contact
Griffin Blue, 124 Langdon St, Madison, WI, USA, privacy@atpquest.com. Or use the contact form.