Privacy Policy

Last updated: June 4, 2026

1. Who we are

PassADC ("we", "us") operates passadc.com and the related study platform. Contact: hello@passadc.com.

2. Information we collect

We collect the minimum information needed to run the Service:

  • Account data: email, name, password (hashed), country, native language, exam date, university (optional).
  • Usage data: questions answered, accuracy, study streak, mock exam results, AI chat history. Stored to power your personalised dashboard.
  • Payment data: processed by Stripe. We never see or store your card number.
  • Login events: IP address, user-agent, timestamp — used for "new device" security alerts.
  • Marketing leads: if you take our public diagnostic and provide an email, we may add you to our marketing list (managed via VBOUT).

3. How we use it

  • To provide the Service, including personalised study plans and AI feedback.
  • To send transactional emails (password reset, payment receipts, trial-ending reminders).
  • To send marketing emails if you opt in. You can unsubscribe anytime.
  • To improve the Service and detect abuse.

4. Sharing & sub-processors

We share data only with sub-processors needed to deliver the Service:

  • Stripe — payment processing
  • OpenAI — AI tutor, OSCE role-play, doubt solver
  • ElevenLabs — voice generation for OSCE
  • VBOUT — email marketing & CRM
  • MongoDB Atlas — database hosting

We do not sell your personal data.

5. Your rights

You can access, correct, export or delete your data at any time from your Account page or by emailing hello@passadc.com. Under GDPR / Australian Privacy Principles you also have the right to lodge a complaint with a supervisory authority.

6. Cookies

We use a single httpOnly authentication cookie to keep you signed in. No third-party advertising cookies. We may use first-party analytics to measure aggregate usage.

7. Data retention

We retain your account data for as long as your account is active and for up to 12 months after closure, unless a longer period is required by law (e.g. financial records).

8. International transfers

Our sub-processors (Stripe, OpenAI, VBOUT, etc.) are located in the United States and Europe. Where applicable we rely on standard contractual clauses or equivalent safeguards.

9. Security

Passwords are stored hashed (bcrypt). Sessions use signed JWTs in httpOnly cookies. Single-active-session per account. TLS in transit. While we follow industry-standard practice, no system is perfectly secure.

10. Children

PassADC is not directed to children under 18. We do not knowingly collect data from minors.

11. Updates

We may update this Privacy Policy. Material changes will be notified in-app or by email.