Privacy Policy
What we collect, why we collect it, and who else sees it. This describes what the product actually does today. Where something is not settled yet, we say so rather than guess.
- Effective date:
- 2 September 2026
- Last updated:
- 2 September 2026
Who we are
TabTheCode is an independent study aid for the NICET Fire Alarm Systems Level II certification and the NERC System Operator certifications. We are the controller of the personal data described here.
TODO(legal): legal entity name and registered address.
What we collect
Your account. An email address, a password (stored only as an argon2id hash, never as text we can read), and whether you have verified your email. If you turn on two-step login we also store your authenticator secret, encrypted, and hashes of your recovery codes. You can add a display name; it is optional.
What you tell us during setup. Which certification you are studying for, your exam date if you have one, your experience level, why you are studying, and your time zone. The time zone is used so streaks and daily plans roll over at midnight where you are rather than in UTC.
Your study activity. This is the bulk of what we hold, and it is what makes the product work:
- Every question you answer: which question, which options you selected, whether it was correct, and how many seconds you spent on it.
- Your drill, exam and glossary sessions, including in-progress state so you can resume.
- Your review deck and its spaced-repetition schedule.
- Navigation-trainer sprints and individual lookups.
- Per-topic ability estimates and daily readiness snapshots, which are derived from the answers above.
Purchases. Which plan you bought, whether it is active, when your access window ends, and identifiers that link the purchase to Stripe.
Email records. Your email preferences, and a log of which transactional emails we sent you and when.
Payment details never reach us
Card payments are handled entirely by Stripe, on Stripe’s own checkout pages. Your card number does not pass through our servers and is not stored in our database. We hold no card numbers, no last four digits, no expiry dates, and no billing addresses.
What we do store is a Stripe customer identifier, the checkout session identifier for each purchase, the plan you bought, and when your access ends. We send Stripe your email address so it can identify the customer, and the plan code you selected.
All purchases are one-time. There is no subscription and no auto-renewal, and we do not keep a payment method on file to charge you again.
Who else sees your data
We do not sell your data, and we do not share it for advertising. We use a small number of providers to run the service:
- Render: hosting and our database, in their US Oregon region.
- Stripe: payments. Receives your email address and the plan you are buying, and handles your card details directly.
- Sentry: server-side error and performance monitoring, so we find out when something breaks. It receives error reports and a sample of performance traces. We have not enabled its option to attach personal data to those reports.
- Our email provider sends the transactional messages listed below. TODO(legal): name the email provider.
We also use Anthropic’s API to help draft candidate exam questions before a human reviews them. It is sent reference material and question drafts only. No student account or study data is sent to it, ever.
Email we send you
Transactional email: confirming your address, resetting your password, and a receipt when you buy something. You cannot opt out of these while you have an account, because they are how the account works.
Study reminders: occasional nudges when you have review cards due, a streak about to lapse, or an exam approaching. These are optional. You can turn them off in Settings or from the unsubscribe link in any of them, and turning them back on is the same switch.
IP addresses
We use your IP address in memory to rate-limit sign-in attempts and other sensitive requests, which is how we make brute-force attacks impractical. It is not written to our database and not retained.
How long we keep it
Your account and study history are kept while your account exists, so your progress, review deck and readiness history remain intact between sessions and between purchases. Access to paid content ends when your window ends; your history does not disappear with it.
TODO(legal): retention windows for inactive accounts, email-send logs, and purchase records, plus a job that enforces them.
Your rights, and one honest limit
You can see and correct most of what we hold from Settings, and you can download everything at any time: Settings has a “Download my data” export that produces a JSON file containing your profile, every answer, your review deck, exam history, readiness over time, your email preferences and your purchase records.
Self-service account deletion is not built yet. We would rather tell you that than pretend otherwise. If you want your account and data removed, email us and we will do it by hand. We are working on making it a button.
Depending on where you live you may also have the right to object to or restrict processing, to data portability, and to complain to your local data protection authority. TODO(legal): confirm lawful bases and name the supervisory authority for EU/UK visitors.
Security
Passwords are hashed with argon2id. Two-step login secrets are encrypted at rest with a key held only in the server environment, and recovery codes are stored as hashes. Sessions are stored server-side and can be revoked; changing your password signs out every other session.
No system is perfectly secure, and we are not going to claim otherwise.
Children
These are professional certification exams. The service is not directed at children, and we do not knowingly collect data from anyone under 16.
Changes to this policy
If we change this policy we will update the dates at the top. If a change materially affects what we do with your data, we will tell you by email rather than quietly editing this page.
Contact
Questions about any of this, or a request about your data, go to our contact page.