Privacy Policy
This Privacy Policy describes how DS Bootstrap ("we", "us") collects, uses, and shares personal information when you use our Service. It applies to visitors, account holders, and purchasers.
1. Information we collect
Account information (via Clerk)
- Your email address.
- If you choose to sign in with Google: your name and profile picture from your Google account.
- Authentication tokens and session cookies.
- Account metadata we associate with you — plan status, purchase date, refund date, Stripe customer identifier, and billing activity history.
Payment information (via Stripe)
- Billing name, email, and address provided at checkout.
- The last four digits and card brand of your payment card, the transaction amount, and transaction status. We never receive or store your full card number or security code — Stripe handles those directly.
Study data (stored on your device only)
-
Question progress, self-rating, mastery state, and any private notes you
take in the Service are stored exclusively in your browser's
localStorage. This data never leaves your device and is not transmitted to our servers.
Technical information
- IP address, browser user agent, and request logs, via our hosting provider Vercel. These are used for security, abuse detection, and operational monitoring.
2. How we use your information
- To create and authenticate your account.
- To process your purchase, issue receipts, and handle refunds.
- To serve paid content only to accounts with active access.
- To detect and prevent abuse, fraud, account takeover, and security incidents.
- To communicate with you about purchases, refunds, account issues, and material changes to the Service.
We do not sell your personal information. We do not share it with advertisers or data brokers. We do not use it for targeted advertising or marketing profiling.
3. Third-party sub-processors
The following services process personal information on our behalf. Their own privacy practices apply to data they receive:
- Clerk — identity and authentication. See clerk.com/privacy.
- Stripe — payment processing. See stripe.com/privacy.
- Vercel — hosting, edge routing, and request logs. See vercel.com/legal/privacy-policy.
- Google — only if you choose to sign in with your Google account. See policies.google.com/privacy.
4. Data retention
- Account information: retained while your account is active. When you delete your account, your Clerk user record is deleted and your plan is revoked immediately. Operational logs containing IP and user-agent data are retained by Vercel per Vercel's own retention policy.
- Payment records: retained by Stripe per their retention policy (typically up to 7 years to satisfy tax and audit obligations). We cannot delete records on Stripe's behalf.
- Study data on your device: persists until you clear your browser storage, log out, or uninstall the browser.
5. Your rights
Depending on your state of residence, you may have the following rights:
- Access — you can see most of your account information on the Account page. For a full export, email us.
- Deletion — you can delete your account at any time via the Account page (the Delete account control on the Security tab). This removes your identity, plan, and billing metadata from our systems. Stripe billing records are retained by Stripe as required by law.
- Correction — you can update your email or profile on the Account page.
- Portability — on request we will provide your account information in a machine-readable format.
California residents (CCPA / CPRA)
If you are a California resident you additionally have the right to:
- Know what personal information we collect about you.
- Delete your personal information, subject to exceptions allowed by law.
- Opt out of the "sale" or "sharing" of your personal information — we do not sell or share personal information as those terms are defined by CCPA / CPRA, so there is nothing to opt out of.
- Correct inaccurate personal information.
- Non-discrimination for exercising any of these rights.
To exercise any right, email privacy@dsbootstrap.com. We may verify your request to prevent fraudulent access to another user's data.
6. Cookies and local storage
- Session cookies set by Clerk to keep you signed in.
- Browser localStorage for theme preference, font scale, question progress, notes, and self-rating. This data stays on your device.
We do not use advertising cookies, analytics cookies that identify you as an individual, or third-party marketing trackers.
7. Children
The Service is not directed to children under 18 and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, email privacy@dsbootstrap.com and we will delete it.
8. Security
We use industry-standard measures to protect your information in transit (TLS) and rely on the security controls of our sub-processors (Clerk, Stripe, Vercel). No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. International visitors
The Service is directed to and intended for users in the United States. It is not offered to or intended for users located outside the United States. Information we collect is processed and stored in the United States and in regions where our sub-processors operate.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced through the Service or by email. The "Last updated" date at the top of this page reflects the latest revision.
11. Contact
For privacy questions or to exercise any of the rights above, email privacy@dsbootstrap.com.
See also: Terms of Service.