Privacy policy
What is stored, where, who can see it, and how to get rid of it.
Last updated 13 August 2026
Short version: your practice history stays in your browser, and the copy we keep is a score and a made-up name — never an email address, unless you give us one to protect a purchase. There is no advertising, no third-party analytics, no tracking pixels, and nothing here is sold or shared for marketing.
1. What stays on your device
Your answers, scores, streaks, attempt history, topic mastery, subject preference, theme, and companion settings are kept in your browser's local storage. They are not uploaded, not backed up, and not visible to us.
The consequence is worth stating plainly: clearing your browser data, using private browsing, or switching to another device loses that history, and we cannot restore it because we never had it.
2. What we collect, and why
When you start your first test
An account is created for you automatically. You are not asked for anything and you do not sign up — there is no form, and we do not know who you are. It holds:
- A made-up name, generated by us, like
SwiftFalcon-7K2M. This is what appears on the leaderboard. It is not derived from anything about you. - A session cookie named
cds_sid. It is httpOnly — script on the page cannot read it — and its only job is to recognise this browser next time. It is not an advertising or tracking cookie, and there are no others. - The date it was created, and your finished tests: for each one the subject, the number right, wrong and skipped, and the score. Not your individual answers.
The daily test works even if you block cookies — you simply get no account, no leaderboard row and no saved scores. Random tests need the cookie, because that is how the free ones each day are counted.
An account created this way is deleted automatically after ninety days without a visit. The ninety days restart every time you come back, so an account in use is never reaped, and a completed purchase removes that expiry altogether. Binding an email removes it too — which is the honest reason we ask for an address after a purchase rather than a marketing one: it is what lets you reach what you bought from a different browser or a new phone.
If you add an email
The only reason to, and the only time we ask, is to stop a purchase being lost when you clear your browser or change phone. It is optional, and free practice never requires it.
- Your email address — so the account can be recovered and so we can reach you about it. It is stored, and it is also indexed under a one-way SHA-256 hash so the list of accounts cannot be read back into a list of addresses.
- A six-digit code, stored hashed and for ten minutes, to confirm the address is really yours before anything is attached to it.
Your full address is never shown on the leaderboard, and what is shown depends on how old your account is. Every account created since sign-up became automatic carries a generated name, and that is all the board ever displays for it. Accounts from before that — when an email was the only way in — may have no name to show, and for those the board shows the address masked: the first character, then dots, then the domain, so sagar@gmail.com appears as s••••@gmail.com. The masking is deliberate, so you can recognise your own row without the address being readable by anyone else. The consequence to be plain about: the domain is visible on those rows, and the length of the hidden part is approximated rather than exact. The whole address is never shown.
When you finish a test
- The result is saved to your account as described above, and for the daily test your score and display name go on that week's public leaderboard — one board per subject, Sunday to Saturday, holding your best score of the week rather than your latest. Both are visible to anyone who opens it.
- A marker recording that your account has completed that day's test, so one attempt cannot be posted twice.
- For the daily test, answers are sent to the server to be scored there rather than in your browser. They are used for that and are not kept as a per-question record against your name.
Automatically, on any request
- Your IP address, used for rate limiting — to stop one client hammering an endpoint — and, separately, recorded in the ordinary access log our web server keeps for every request, as any web server does.
- A visit summary built from those logs. We read them back on our internal page to see how the site is being found and used, and that reading is grouped by address: for each one it works out which of our pages were requested and which came first, when it arrived, how far through landing → home → test → results → pricing it got, whether the device is a phone, tablet or desktop, which browser, and which site referred it. What the page then shows is counts built from those groups — how many came from Instagram, how many reached the test, how many saw one page and left — not a row per address and not a list of addresses. We say "grouped by address" rather than "per person" because it is not the same thing: everyone behind one coaching-centre or hostel router looks like a single visitor here, and one person moving from wifi to mobile data looks like two.
- Error reports, if a page crashes: the error message, the stack trace, the route it happened on, and a coarse timestamp. These carry no email, no cookie, and no test answers, and they are deleted automatically after three days.
What the visit summary is notis as much the point as what it is. It is not joined to your account, your email, your session cookie or your test results — nothing anywhere links an address to a person's row on the leaderboard — and we make no attempt to work out whose address it is. We keep no separate copy of it either: it is recomputed from whatever the server's own access logs still hold and held in memory for a few minutes at a time, so deleting the logs deletes it. It exists so we can tell whether money spent bringing people here brought anyone who then took a test. There are still no third-party analytics and no tracking scripts of any kind.
3. Payments
Payments are handled by a third-party payment gateway. Your card, UPI, or bank details go to them and never reach our servers — we receive only the fact that a payment succeeded, its amount, and a reference number, which we keep as long as tax law requires. The gateway has its own privacy policy governing what it does with those details.
4. Who else can see it
- Anyone, for the leaderboard — the display name described in section 2 and your score, by design. Nothing else on it is public: not your email, not your other results, and not whether you are on a paid plan. Rank is the score and nothing else.
- Upstash, which provides the Redis database that holds accounts, sessions, leaderboard entries, test results, payment records and error reports.
- Our hosting provider, which serves the site and keeps ordinary access logs.
- A payment gateway, once billing is live, for payments only.
- Us — CDS Prep has one password-protected internal page, used to run the service and to check that people who paid actually received what they paid for. It carries more than accounts and payments, so it is listed in full below.
What the internal page shows
- Accounts — display name, when it was created, whether an email is bound and whether it has been confirmed, and whether a plan is live. Email addresses are hidden by default and shown one at a time only when deliberately revealed, and no other column is derived from an address, so revealing is the only way one appears.
- Results— one account's saved attempts when opened, and a feed of the most recent finished tests by anybody, each with its score and the name that would appear on the board.
- Money — payments taken, and checkouts started and never finished, with the plan, the amount, the reference number and the account each belongs to.
- The visit summarydescribed in section 2, read from the server's access logs.
- Server and database health — uptime, memory, disk, load, certificate expiry, which build is running, and how many keys the database holds and how much memory they occupy. Nothing in this part concerns any individual.
- Crash reports from the last three days — the same ones described in section 2, with their message, stack trace and route.
That is the whole list. We do not sell personal data, we do not share it with advertisers or data brokers, and there are no third-party analytics or tracking scripts on any page — no Google Analytics, no advertising pixels, nothing that follows you to another site. We do keep our own counts, described in the next section. We would disclose data if a law or a valid court order required it, and not otherwise.
5. Counts we keep
Three different things, kept apart here because they are not equally thin and one paragraph covering all three would flatter two of them.
Daily totals
We count how many people arrive each day, how many accounts are created, how many tests are finished, and how many payments succeed. These are daily totals and nothing else — a number per day, with no name, no address, no device details and nothing tying any of it back to a person. They tell us that eleven tests were finished yesterday, not who finished them. They are kept for about thirteen months.
The visit summary
This is the one described in section 2, and it is not just a number per day. It is read from our web server's access logs and grouped by network address before it is counted, so along the way it knows the pages one address requested, the one it landed on, when it arrived, the referring site, the device class and the browser. It holds no name, no email and no link to any account, the page it feeds shows totals rather than addresses, and we keep no copy beyond the logs it is read from — but it is a fuller picture than the totals above, and it would be misleading to let it sit under the sentence written for them.
The free-tier check
Separately again, to stop one person taking unlimited free random tests by clearing their browser, we keep a daily count of free random tests started per network address. The address itself is not stored — only a one-way fingerprint of it — and the count is deleted after two days.
6. How long it is kept
- Accounts with no email bound: ninety days after your last visit, then deleted automatically along with their saved results. The ninety days restart on every visit.
- Accounts with an email bound: until you ask us to delete them.
- Accounts that have bought a plan: never deleted for inactivity while that plan is live, and the ninety-day expiry is dropped the moment the purchase is granted, so the account is kept until you ask us to delete it. The payment record itself — separate from the account — is kept for about thirteen months so a purchase can be traced and put back by hand, which is what to write to us about if a plan you paid for is not showing.
- Saved test results: the most recent fifty per account.
- The internal recent-results feed: the last five hundred finished tests by anybody, each holding the account it belongs to, the name that appears on the board and the score. It is trimmed by count rather than by age, so an entry can outlive the account it came from until five hundred more tests push it out. It is never public.
- Sessions: until they expire or you sign out.
- Daily counts: about thirteen months. They name nobody.
- Leaderboard entries: one board per subject per week, running Sunday to Saturday and deleted about nine days after the week it belongs to opens. Last week's board is not the public board.
- The visit summary: not stored at all — it lives as long as the web server's own access logs do, and is recomputed from them.
- Error reports: three days, then deleted automatically.
- Payment records, once billing is live: as long as Indian tax and accounting law requires.
7. Your choices
- Delete everything on your device — clear site data for prepcadet.in in your browser. That removes all of it at once, is immediate, and does not involve us. Settings can reset your topic history on its own if that is all you want gone.
- Delete your account — if you bound an email, write to support@prepcadet.in from that address and we will remove the account, its email, its saved results and its leaderboard entries. One thing we will not claim to remove instantly is the internal recent-results feed in section 6: it is trimmed by count, so an entry there carrying a display name and a score rotates out as new tests arrive rather than on the day you ask. If you never bound an address, clearing site data is enough: what is left holds no email and nothing that names you, and it deletes itself after ninety days.
- See a copy, or correct something — same address, same way.
- Stay off the leaderboard — simply do not create an account. The daily test works without one.
8. Security
The site is served over HTTPS. Session cookies are httpOnly and SameSite-restricted, sessions are stored as hashes rather than as the token itself, and API endpoints are rate limited. Email ownership is not yet verified at sign-up — we say so rather than implying an address has been confirmed when it has not. No system is perfectly secure, and we do not claim otherwise.
9. Children
CDS Prep is meant for candidates aged 18 and over and is not directed at children. If you believe a child has created an account, write to support@prepcadet.in and we will remove it.
10. Changes
If this policy changes, the date at the top of the page changes with it. A change that materially affects what we collect will be announced in the app rather than made quietly.
11. Contact
Privacy questions and deletion requests: support@prepcadet.in. Full details on the contact page.