Privacy Policy
Last updated: March 2026
1. Introduction
Welcome to Pass-IT ("we," "our," or "us"), operated by Pass-IT from Zurich, Switzerland. We are committed to protecting your privacy and ensuring you have a positive experience on our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered practice and exam platform.
We comply with the Swiss Federal Act on Data Protection (FADP/DSG), the EU General Data Protection Regulation (GDPR), and other applicable data protection laws.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, username, and securely hashed password (we never store passwords in plain text)
- Learning Content: Topics you create, study materials you upload (files and URLs), practice responses, and exam results
- Payment Information: Processed securely through Stripe and RevenueCat (we do not store full payment card details)
- Exam Outcomes: Certification exam results you report (pass/fail), exam dates, and proof images (score report screenshots) submitted with guarantee claims
- Guarantee Claims: Eligibility data, claim status, and admin review records related to our money-back guarantee program
2.2 Automatically Collected Information
- Usage Data: Session information, question responses, time spent, performance metrics, and study patterns
- Technical Data: IP address, browser type, device information, and access logs
- Cookies: Session cookies for authentication and functionality
- Referral Data: If you arrive via a partner referral link, we record the referral source for attribution purposes
3. How We Use Your Information
We use your information to:
- Provide and improve our AI-powered learning platform
- Generate personalized practice questions and exam simulations
- Track your learning progress and provide performance analytics
- Process subscription payments and manage your account
- Send important service notifications and updates
- Process money-back guarantee claims and verify eligibility
- Track partner referrals and calculate affiliate commissions
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. Third-Party Services
We use the following third-party services that may collect your data:
4.1 Anthropic (Claude AI)
We use Anthropic's Claude AI models to generate practice questions, provide explanations, and analyze your performance. Your learning content and responses are sent to Anthropic for processing. Anthropic's data usage is governed by their own privacy policy and data retention practices.
4.2 Stripe & RevenueCat
Payment processing is handled by Stripe (web) and RevenueCat (mobile). When you subscribe, these services collect and process your payment information. We receive only transaction confirmation and do not store full payment card details.
4.3 Cloudflare R2
Uploaded study materials (PDFs, documents) and exam proof images submitted with guarantee claims are stored securely on Cloudflare R2. Files are encrypted in transit and at rest.
4.4 PostHog
We use PostHog for product analytics and error tracking to understand how the platform is used and to quickly identify and fix issues. PostHog data is hosted in the EU (Frankfurt). Basic analytics (pageviews, clicks, error monitoring) run in cookieless mode without persistent identifiers under legitimate interest (Art. 6(1)(f) GDPR). Enhanced analytics (cross-session identification, session recording) are only activated after you accept cookies via our cookie banner.
4.5 Authentication
User authentication is managed through secure username/password login with bcrypt password hashing. Your passwords are never stored in plain text and are encrypted using industry-standard algorithms. Session management uses secure HTTP-only cookies.
4.6 Attio CRM
We use Attio as a customer relationship management tool. Account and subscription data may be synced to Attio for internal business operations such as customer support and engagement tracking.
5. Data Storage and Security
Your data is stored in secure PostgreSQL databases with encryption at rest and in transit. We implement industry-standard security measures including:
- Encrypted database connections
- Secure session management
- Regular security audits
- Access controls and authentication
- Daily encrypted backups with 14-day retention
6. Your Rights (Swiss DPA, GDPR & CCPA)
Under Swiss data protection law (FADP/DSG), EU GDPR, and depending on your location, you have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a structured format
- Opt-out: Opt-out of data processing (where applicable)
- Withdrawal: Withdraw consent at any time
To exercise these rights, please contact us at info@pass-it.ai. If you believe your data protection rights have been violated, you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local data protection authority.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide services. Specific retention periods:
- Account data is retained while your account is active
- Transaction records are kept for 10 years as required by Swiss commercial law
- Usage logs are retained for 90 days for security purposes
When you delete your account, we will delete or anonymize your personal data within 30 days, except where we must retain it for legal compliance.
8. Cookies
We use essential cookies for authentication and session management. These cookies are necessary for the platform to function and cannot be disabled. Our landing site runs analytics in cookieless mode (no tracking cookies) by default. If you accept cookies via our cookie banner, we enable enhanced analytics with cross-session identification and session recording. We do not use third-party advertising cookies.
9. Age Requirements
Our service is intended for users 16 years of age or older (in compliance with GDPR requirements). Users between 13-16 may use the service only with verifiable parental consent. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your own, including the United States (Anthropic, Stripe). For transfers from Switzerland/EU to the US, we rely on the EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs), or other approved transfer mechanisms. We ensure appropriate safeguards are in place for such transfers in compliance with Swiss FADP and EU GDPR requirements.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
Email: info@pass-it.ai