Privacy Policy
This policy says, in plain language, what we collect, why we collect it, who processes it on our behalf, and the controls you have. The short version: we collect the data the product needs to work, we never sell your data, and optional advertising measurement is disabled unless you allow it.
1Who we are
The FE Exam AI Prep website and web member center are operated by Hangzhou Star Vision Technology Co., Ltd. We are responsible for the personal data described in this policy. You can reach us about anything in this policy at contact@xingshiyu.com.cn.
This policy covers the website, the web member center, and FE Exam AI Prep mobile apps available through the Apple App Store and Google Play. The same account and the same data described in this policy power the web service and supported mobile apps.
2What we collect
- Account information. Your email address, user ID, and authentication records. On the web you sign in by email link or password.
- Emails you choose to share. If you previously joined an app launch list, request a free study resource by email, or submit your name and email through a site form (for example, the plan-savings popup), we store what you submit and the page where you submitted it, and may send you occasional study emails you can unsubscribe from at any time.
- Your exam profile. The discipline you're preparing for, your exam date, and your weekly study-hours budget.
- Study activity. Questions attempted, answers and correctness, time spent per question, confidence ratings, mock-exam scores, topic mastery, streak days, wrong-answer review history, and video watch positions.
- Subscription and purchase records. Your plan, renewal or cancellation status, processor product and transaction identifiers, and receipt metadata needed to provide access and support. RevenueCat helps synchronize eligible Apple and Google entitlements. Creem processes supported web checkout and provides customer, order, subscription, and invoice identifiers. For eligible pay-over-time Max Annual purchases, Affirm receives the name, mobile number, email, and U.S. billing address you enter at checkout and returns checkout, transaction, capture, and refund identifiers. Affirm, not FE Exam AI Prep, collects loan-application and credit information. We do not receive or store your SSN or Affirm account credentials. For retired web purchases, we may retain PayPal or Paddle transaction identifiers and invoice metadata. We never receive or store your full payment-card details.
- Pass Guarantee records. If you use the annual-plan Pass Guarantee, we store your legal name, covered exam date, monthly effective-study or frozen content-completion ledger, selected refund-or-extension benefit, provider refund status, claim and review history, identity evidence, and NCEES-issued failed score report or diagnostic. You may redact unrelated identity-document fields.
- Web-session metadata. Which supported browser or device a practice session, mock exam, or video was last active on, so you can resume in the web member center. This is visible only to you.
- AI request content. Prompts you submit to optional live-AI features and the relevant study context listed on the consent screen for that request.
- AI response reports. If you choose to report a generated response, we store that response, its request ID, your issue category, and any optional note. The report does not store your original prompt.
- Abuse-prevention records for guest AI requests. Some AI features are free and usable before you create an account. Because a guest session can be created without limit, we record the IP address the request arrives from, an install identifier the app generates for itself, and a daily request count, so we can cap how much free AI generation any one source can consume. This applies only to guest requests: once you are signed in, your account is the limit and we do not record your address for this purpose.
- Which version of a page you were shown. We sometimes test two wordings of a button to learn which one people find more useful. So that you see the same version each time rather than a page that changes under you, the browser stores a first-party cookie named fe-hero-cta, kept for about 30 days. It holds one of two fixed labels and nothing about you — no identifier, no address, nothing that could single you out — it is never shared with an advertising platform, and it is deleted when the test ends. Where it appears alongside the measurement described in section 5, that measurement stays subject to your choice there.
- Trial-abuse-prevention device identifier. When you visit this website, the browser stores a random identifier (a first-party cookie named fe_device and a matching localStorage value, kept for about 13 months). We use it only to enforce the one free trial per device limit and to investigate trial abuse. It is not an advertising identifier, it is never used for advertising or analytics, it is not shared with advertising platforms, and it is separate from the consent-gated measurement described in section 5.
About the install identifier: it is a random value the app creates and stores on your device the first time it needs one. It is not your device's advertising ID, IDFV, or Android ID, it is not shared with anyone, and it cannot be matched to you in any other app. Uninstalling the app discards it.
What we deliberately do not collect: contact lists, photos, precise location, or mobile advertising identifiers. Our iOS and Android apps carry no advertising or analytics SDKs at all; the advertising measurement in section 5 exists only on this website.
3How we use it
- To run the product. Your activity updates your progress and readiness indicators, supports wrong-answer review and video recommendations, and keeps your records available in the web member center across supported browsers.
- To power optional AI features. Before the first request, the web service names Google Gemini as the primary AI Coach and score-diagnosis provider and DeepSeek as its fallback, lists the prompt and study fields required for that feature, and asks for permission. Only after you consent and make a request are those fields sent through our server to Gemini, or to DeepSeek after an eligible Gemini retry failure. Product Support uses a separate DeepSeek assistant for account and billing questions. With permission off, no prompt or study context is sent and deterministic local recommendations remain available.
- To review reported AI responses. We use the generated response, request ID, issue category, and optional note to investigate accuracy, safety, privacy, and quality issues.
- To administer Pass Guarantee claims. We use the server-recorded study ledger and submitted evidence to verify eligibility, match identity to the NCEES-issued failed result, prevent duplicate or fraudulent claims, and issue the approved three-month access extension or qualifying Max Annual refund.
- To run free trials. We use your account email (in normalized form), the device identifier described in section 2, and your trial and order history to decide free-trial eligibility. For a historical card-backed trial we retain the price, trial end date, consent time, IP address, browser user agent, and lifecycle records needed to evidence the terms you accepted, manage billing, and resolve disputes; the card itself is held by Creem and we never receive its full number. For the current registration no-card trial, we record the selected plan and exam, campaign, reservation, activation and end times, and status — no card or payment method is collected and none is charged.
- To keep free AI features available. We use the IP address and install identifier attached to a guest AI request only to enforce a daily cap and to investigate abuse. We do not use them to build a profile, to advertise, or to identify you, and they are never combined with your study data.
- To email you. Sign-in links you request, any one-time app launch notice you previously requested, and study resources you explicitly ask us to send.
We do not sell your data or share it with data brokers, and we never use your study data — your answers, scores, readiness, or practice history — for advertising. We do measure whether an ad we paid for led to a visit or a sign-up, which is described in section 5. We may use aggregated, de-identified statistics (for example, “typical readiness at the start of prep”) to improve the product; those never identify you.
Readiness indicators summarize your own practice activity only for study planning. They do not determine exam eligibility, admission, employment, professional licensure, or any other consequential decision, and we do not provide them to NCEES, licensing boards, schools, or employers for those purposes.
4Who processes data on our behalf
- Supabase — account, authentication, sync, and storage for your study data.
- Vercel — website hosting, performance measurements, and anonymous aggregate web analytics.
- Resend — delivery of sign-in, launch-list, and requested study-resource emails.
- Apple and Google — mobile app distribution, in-app billing, subscriptions, receipts, cancellation, and refund processing.
- RevenueCat — app-store purchase validation, entitlement synchronization, and aggregate subscription reporting.
- Creem — merchant of record for supported web checkout. Creem is the seller for those transactions and handles tax calculation, payment, subscription management, receipts, fraud prevention, disputes, and refunds.
- PayPal and Paddle — retention and support for retired web transaction, invoice, subscription, fraud-prevention, and dispute records. The website no longer initiates payments through either provider.
- Google Gemini — primary provider for optional AI Coach and score-diagnosis requests, only after explicit consent.
- DeepSeek — fallback provider for an eligible Gemini failure, and the separate Product Support assistant for account and billing questions.
- Google — optional Google Ads conversion measurement on this website after you allow measurement. We do not use Enhanced Conversions or send Google your email address.
- Reddit — advertising measurement on this website only, and unlike the providers above, Reddit also uses what it receives for its own advertising purposes. What it receives is described in section 5.
- FirstPromoter — referral-program measurement on this website only. Its tag loads only after you select “Allow measurement,” records that you arrived through a referral link, and — unlike the advertising tags — receives your account email at sign-up, solely so the person who referred you is credited. It does not run on signed-in member-center pages.
The advertising providers may process measurement data under their own terms. Section 5 explains when they load and what we do and do not send.
5Cookies, analytics & advertising measurement
The website uses browser storage to keep you signed in and remember your light/dark theme choice. We use Vercel Web Analytics to understand aggregate page visits, referral sources, device types, and general location, and Speed Insights to measure page performance. These services do not use advertising cookies, do not identify you by email, and do not track you across other websites. Member-center routes are excluded from our Web Analytics page-view collection, and the only query-string values we pass to analytics are campaign labels (utm_source and similar) — never tokens, codes, or anything identifying.
Optional advertising measurement. We may buy ads on Google and Reddit. If you select “Allow measurement,” the website loads their conversion tags. They can receive page visits and a small set of conversion events such as completing the free diagnostic, creating an account, viewing plans, or following an App Store or Google Play link. Those tags may set advertising cookies and their providers may use the data under their own advertising terms.
What the advertising tags never receive from us: your name, email, diagnostic answers, scores, readiness, or other study activity. We do not use Google Enhanced Conversions, Reddit Advanced Matching, or send hashed email for ad matching. Advertising tags do not run on signed-in member-center pages.
Referral-program measurement. The FirstPromoter tag follows the same “Allow measurement” switch and the same browser privacy signals as the advertising tags. It is the one measurement tag that can receive your account email: once, at sign-up, solely to credit the referrer whose link brought you here. If you never allow measurement, it does not load and receives nothing.
Your control. Advertising measurement starts disabled everywhere. Choose “Allow measurement” in the website prompt to enable it, choose “Necessary only” or “No measurement” to keep it off, or reopen “Cookie settings” in the footer at any time. The same choice also turns our own usage records off. We honor Global Privacy Control and Do Not Track for both. Your choice does not affect your account or study data.
Our own usage records. Separately from the advertising tags, we keep a private first-party record of how the site is used, so we can see which steps people get stuck on. It may include campaign labels, Google or Reddit click IDs, page path, coarse country/region, device category, and a random browser/session ID. We do not store the raw IP address or full browser user-agent in it, it is never shared with an advertising platform, and it is not readable through public or member APIs.
This record is not the same decision as the advertising tags, so it does not follow the same rule. In the EEA, the UK and Switzerland it waits for you to choose, exactly as the advertising tags do. Elsewhere it starts on and you can switch it off, which is the standard those countries’ own privacy laws set. Either way, Global Privacy Control and Do Not Track turn it off, and choosing “No measurement” or “Necessary only” turns it off. Until you say yes, the random ID behind it is stored only for as long as the browser tab is open, so it cannot recognise you on a later visit; saying yes is what lets it last longer and connect a return visit to the ad that first brought you here.
Counting ad arrivals. When a link carries a campaign label such as utm_source or an advertising click ID, our server adds one to a running daily total so we can tell how many visits an ad actually produced. That total is a bucket count only — the date, the campaign label, the page the link pointed at, whether a click ID was present, a broad device category, and a country code. It sets no cookie, stores no ID of any kind, keeps neither your IP address nor your browser user-agent, and cannot be traced back to a visit or a person, so it does not change with your measurement choice. It is never shared with an advertising platform.
6Retention & deletion
- Delete your account from Settings on the web — deletion starts immediately, including cleanup requests to connected identity providers, and removes your account, progress, and account-linked AI response reports from active systems promptly. Backup and security-log copies age out within 30 days. Transaction, invoice, tax, fraud-prevention, and subscription records may be retained by us, Apple, Google, RevenueCat, Creem, PayPal, or Paddle where required for legal, accounting, dispute, or security purposes. Deleting your account does not cancel billing; cancel separately in Apple, Google, or the Creem customer portal. Historical Paddle purchases can still use the Paddle portal.
- Guest abuse-prevention records — the IP address, install identifier, and daily count described in section 2 — are deleted automatically once they are more than 7 days old. They are not readable through any public or member API.
- Pass Guarantee documents are kept in private storage and scheduled for deletion 90 days after a final approval or rejection. We may retain the non-document eligibility snapshot, decision, and refund or extension audit record as needed to administer repeat claims, prevent fraud, resolve disputes, and comply with legal obligations.
- Access or correct your data by emailing contact@xingshiyu.com.cn. We'll respond within 30 days.
- Launch-list emails are kept until we send the requested availability notice, then deleted within 90 days unless you separately create an account or ask to receive something else. You can ask us to remove your address at any time.
- We keep your data while your account exists so your progress and readiness history keep working.
7Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. We honor these requests for everyone, not just where the law requires it — email contact@xingshiyu.com.cn and we'll take care of it. You can also withdraw third-party AI permission at any time under Settings → Privacy & AI.
8Children
The product is for engineering-exam candidates and is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We don't knowingly collect data from children; if you believe a child has created an account, contact us and we'll delete it.
9Changes to this policy
If we change this policy in a way that matters, we'll update the effective date above and, for significant changes, tell you in the web service or by email before the change takes effect.