Privacy Policy
Effective date: May 17, 2026
Last updated: May 17, 2026
This Privacy Policy explains how PREPSTR ("Prepstr", "we", "us") collects, uses, stores, and protects personal data when you use the Prepstr iOS application, the Prepstr web platform, the website available at www.getprepstr.com, and related services.
Prepstr is the data controller for the personal data described in this policy. Prepstr is a French simplified joint stock company (SAS), registered with the Paris Trade and Companies Register under SIREN 104108642, SIRET 10410864200018, VAT number FR03104108642, with registered office at 11 rue de Pommard, 75012 Paris, France.
Contact for privacy matters: contact@getprepstr.com.
1. Personal Data We Collect
1.1 Account and authentication data
We collect the information needed to create, secure, and manage your account, including your name, email address, authentication method, account identifiers, session information, and, when applicable, information provided by Apple Sign in or Google Sign-In.
1.2 Learning profile and app usage data
We collect information you provide during onboarding and while using Prepstr, such as your target exam, target score, current level, preparation timeline, learning preferences, answers to exercises and mock exams, scores, progress, reports, and activity history.
1.3 Writing, speaking, and audio data
Some TOEFL and TOEIC exercises require written answers or microphone recordings. When you use these features, we may collect your written responses, audio recordings, transcripts, evaluation scores, and feedback generated from those responses.
1.4 Payment and subscription data
For iOS subscriptions, Apple processes payment information. Prepstr receives limited subscription information from Apple and StoreKit, such as product identifier, transaction identifiers, subscription status, expiration date, and environment. We do not receive your full payment card details from Apple.
If you buy access through the web platform, Stripe may process your payment. Prepstr receives limited payment confirmation, customer, product, and access information from Stripe. Prepstr does not store full card numbers.
1.5 Support, contact, and administrative data
When you contact us, request support, report an issue, book a call, or ask for more tests or exercises, we may collect your name, email, message, phone number if provided, and related support history.
1.6 Technical, diagnostic, and analytics data
We may collect technical data such as IP address, device and app information, operating system version, browser type, log events, error reports, crash reports, security events, and product analytics to operate, secure, debug, and improve the service.
2. How We Use Personal Data
- To create, authenticate, secure, and manage user accounts.
- To provide the Prepstr app, learning platform, exercises, mock exams, scoring, corrections, progress tracking, and support.
- To process Apple in-app subscriptions, Stripe web payments, access rights, purchase restoration, and subscription status.
- To transcribe, evaluate, and provide feedback on writing and speaking exercises, including through AI-assisted correction tools.
- To troubleshoot bugs, detect abuse, prevent fraud, maintain security, and improve performance.
- To communicate with you about your account, service updates, support requests, and, where legally permitted, product news.
- To comply with legal, accounting, and tax obligations.
3. Legal Bases Under the GDPR
- Contract: to provide the app, platform, account, learning features, subscriptions, payments, and support you request.
- Legitimate interests: to secure, debug, improve, and measure the performance of the service, prevent abuse, and understand product usage.
- Legal obligations: to retain accounting, tax, invoice, and transaction records where required by law.
- Consent: where required for optional marketing, certain cookies or tracking technologies, or access to microphone permissions on your device.
4. AI, Transcription, and Automated Feedback
Prepstr uses automated tools to generate corrections, transcripts, scores, and learning feedback. Written responses, audio recordings, transcripts, and exercise context may be processed by AI, transcription, or infrastructure providers solely to provide and improve Prepstr services.
Prepstr feedback is educational and should not be treated as an official exam score or a guaranteed prediction of results on TOEIC, TOEFL, IELTS, or any other third-party test.
5. Processors and Third-Party Services
We rely on service providers that process data on our behalf or as independent providers for specific parts of the service. Depending on the feature used and the environment, these providers may include:
- Apple, for App Store subscriptions, StoreKit, and Sign in with Apple.
- Google, for Google Sign-In and cloud services used by Prepstr.
- Stripe, for web payments where applicable.
- Render and Neon/PostgreSQL, for backend hosting and database infrastructure.
- Vercel, for website hosting.
- Google Cloud Storage, for storage of certain generated or user audio files.
- OpenAI and Deepgram, for AI-assisted evaluation and speech transcription.
- Resend, for transactional email.
- Sentry, if enabled, for crash and error diagnostics.
- PostHog, Google Tag Manager, and Meta Pixel, where enabled, for web analytics and marketing measurement.
- Slack and Cal.com, where used, for internal notifications and booking workflows.
We do not sell your personal data. We do not allow processors to use personal data for their own advertising purposes unless you have given a valid consent where required.
6. International Transfers
Some providers may process personal data outside the European Union. Where this happens, we rely on appropriate safeguards under the GDPR, such as adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms.
7. Data Retention
- Account, learning, exercise, mock exam, writing, speaking, and audio data are kept while your account is active and for up to three years after your last meaningful activity, unless you request deletion earlier or we need to retain data for legal reasons.
- Payment, subscription, invoice, accounting, and tax records may be kept for up to ten years where required by law.
- Support messages and commercial contact history may be kept for up to three years after the last contact.
- Technical logs, diagnostics, and analytics are kept only as long as necessary for security, debugging, measurement, and legal compliance, generally no longer than thirteen months unless a security incident requires longer retention.
8. Account Deletion
You may request deletion of your Prepstr account and associated personal data from the iOS app account settings, or by contacting us at contact@getprepstr.com. We may ask you to confirm the request to protect your account.
If you have an active Apple subscription, deleting your Prepstr account does not automatically cancel billing by Apple. You must cancel or manage the subscription through your Apple ID subscription settings or the subscription management option in the Prepstr app.
After deletion, we delete or anonymize personal data unless retention is required for legal, accounting, tax, fraud prevention, dispute, or security reasons.
9. Your Rights
Under the GDPR and applicable privacy laws, you may have the right to access, rectify, delete, restrict, object to processing of, and receive a portable copy of your personal data. You may also withdraw consent where processing is based on consent.
To exercise your rights, contact us at contact@getprepstr.com. We will respond within the period required by applicable law. You may also lodge a complaint with the French data protection authority, the CNIL, at www.cnil.fr.
10. Security
We use technical and organizational measures designed to protect personal data, including HTTPS/TLS, access controls, authentication, logging, least-privilege access, and secure infrastructure practices. No online service can guarantee absolute security, but we work to reduce risks and respond to security issues promptly.
11. Children
Prepstr is intended for students and adults preparing for English certifications. If you are under the age required to create an account under local law, you must use Prepstr only with permission from a parent or legal guardian.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the date above and, where appropriate, notify users through the app, website, or email.
13. Contact
PREPSTR SAS
SIREN 104108642 - SIRET 10410864200018
VAT number FR03104108642
RCS Paris - APE 8559A
11 rue de Pommard, 75012 Paris, France
contact@getprepstr.com