Diagnostic session and answer data
Session ids, answer selections, scoring evidence, result artifacts, remediation attempts, and timestamps used to produce the readiness result and return the learner to the right state later.
Privacy
Examber should only use the data needed to run the diagnostic, browser-save, result, and remediation-access flows. Optional account sign-in can reconnect saved progress across browsers.
Last updated: 2026-09-05
Privacy promise
This notice covers the current diagnostic, browser-save, result, remediation, optional account sign-in, optional analytics, and deferred-billing access flows. It is written for the public product, not as launch-prep placeholder copy.
At a glance
Details
Controller: Jack Tam. Privacy contact: privacy@examber.com.
Use this inbox for access, correction, deletion, export, or privacy questions. Respond without undue delay and within one calendar month unless a lawful extension is recorded.
Session ids, answer selections, scoring evidence, result artifacts, remediation attempts, and timestamps used to produce the readiness result and return the learner to the right state later.
If someone saves progress in this browser, the app stores a learner public id, internal browser-save identifier, membership state, and saved return paths. Browser-only save does not collect an email address and cannot recover progress on another browser by itself.
When account sign-in is offered and you choose it, Amazon Cognito authenticates your account. Google is also available where that option is enabled. Examber stores the provider and account identifier, email address and its verification status, verified recovery email when supplied, and the time the account was linked. Your password is handled by the identity provider, not stored in the Examber app database. Signing into the same linked account can reopen its saved progress on another browser.
Sign-in uses essential security cookies and does not enable optional analytics. The link timestamp records your account connection; it is separate from analytics consent.
No live checkout runs in the current deferred-billing path. The app may store learner membership state, temporary remediation access records, and future billing placeholder fields needed to restore access without pretending a payment has happened.
If someone opts in, the app records pseudonymous funnel events using a visitor id cookie plus session ids where the product already has them. These events can be linked to saved learner sessions for export and deletion. The app does not use third-party ad-tech or client SDKs.
The diagnostic, learner-access, focused-remediation, and remediation-access restore flows use data to provide the service the user asked for.
Security, service integrity, and abuse prevention use limited data so the product can remain reliable and trustworthy.
Analytics cookies and analytics-event collection should run only after an explicit opt-in.
Amazon Cognito authenticates learners when account sign-in is offered, including optional Google federation. Data handled: Provider subject, source provider, email and verification status, account-link timestamp, and authentication request data. The app stores verified recovery email when supplied.
Authenticate a learner who chooses Continue with Google, when that option is enabled. Data handled: Google authenticates the learner and supplies identity and email claims through Cognito. Examber retains the mapped identity fields, not the Google password.
Serve the Next.js app, route handlers, and server actions. Data handled: Diagnostic/session identifiers, request metadata, and rendered app responses.
Store sessions, answers, results, remediation state, learner access, and audit records. Data handled: Learner-linked diagnostic records, browser-save identifiers, linked provider subjects and email/recovery metadata when account sign-in is used, funnel events, and admin audit events.
Monitor production failures and route operational alerts. Data handled: Structured server logs, DB/error summaries, and operational event labels.
Receive privacy, support, and data-rights requests. Data handled: Requester contact details, verification evidence summaries, and case correspondence.
Measure the proof-of-concept funnel after analytics opt-in. Data handled: Pseudonymous visitor ids, session ids where already present, page keys, event names, and allow-listed metadata.
Data may be processed outside the UK or EEA when a necessary provider operates infrastructure there. Examber requires an appropriate transfer mechanism, such as a data-processing agreement and standard contractual clauses where needed.
Window: 180 days. Enforcement: Browser cookie expiry.
Window: 365 days. Enforcement: npm run privacy:retention -- --apply clears stale funnel visitor ids.
Window: 30 days by default. Enforcement: npm run privacy:retention -- --apply deletes stale anonymous assessment sessions and strips linked analytics identifiers.
Window: 24 months after the learner's last activity, or 24 months after grace/premium access expiry, whichever is later.. Enforcement: Earlier deletion or anonymization is allowed for verified erasure requests when no legal, security, dispute, audit, or active support reason requires retention. Scheduled broad enforcement still needs implementation.
Window: Retained for accountability while admin tooling exists, subject to legal review.. Enforcement: Audit rows are retained with a documented exemption rationale rather than erased with learner records.
Owner: Privacy inbox owner. SLA: Open the case the same working day when practical. Evidence: Record request channel, request type, requester contact, received date, deadline, and assigned owner.
Owner: Privacy inbox owner. SLA: Verify before releasing export data or anonymizing records. Evidence: Match learner public id, email, saved-browser context, or anonymous session id. Store only a minimal verification summary.
Owner: Admin operator. SLA: Respond without undue delay and within one calendar month unless a lawful extension is recorded. Evidence: Use /admin/privacy to export learner or anonymous-session data before erasure when the requester asks for access or when the case file needs proof.
Owner: Privacy inbox owner with engineering support. SLA: Respond without undue delay and within one calendar month unless a lawful extension is recorded. Evidence: Confirm the field to correct, apply a targeted database/admin change, and record what changed without rewriting result evidence.
Owner: Admin operator. SLA: Respond without undue delay and within one calendar month unless a lawful extension is recorded. Evidence: Use exact confirmation in /admin/privacy after verification; preserve aggregate analytics by stripping identifiers rather than deleting aggregate event rows.
Owner: Privacy inbox owner. SLA: Close after response, appeal path, and retained-record rationale are documented. Evidence: Keep minimal admin audit events for accountability, fraud prevention, and rights-request evidence; do not erase audit rows unless legal review confirms deletion is required.