ExamLark

ExamLark / Privacy & your account

Privacy policy

An explanation of the information used to run ExamLark, the choices you have, and how to get in touch.

Last updated

At a glance

ExamLark uses account information to sign you in and manage access to exam preparation content. Social sign-in is optional. Study progress is stored on your device and synced to your account within each app when connected. You can contact us to request access, correction or deletion of your personal information.

01. Who we are

ExamLark is a product of Pravaralife Limited (www.pravaralife.com). This policy applies to the ExamLark website at examlark.com, its management workspace and its exam preparation apps. It covers information processed by ExamLark when you create an account, sign in, obtain content, manage a subscription or contact us.

Contact ExamLark

For privacy questions, requests about your personal information or account-deletion requests, contact the ExamLark team:

contactus@examlark.com

You can contact us without signing in. For the information to include in a deletion request, see our data-deletion instructions.

02. Information we handle

  • Account information: your name, email address, internal account identifier, account role, account status and registration date. For password accounts, we store a password hash rather than your readable password.
  • Authentication information: linked sign-in provider identifiers, verified email information, sessions, sign-in events and security information needed to protect your account.
  • Content access and subscriptions: exam selections, free-access allocations, trial dates, download grants and failures, purchase platform, product identifiers, subscription status and expiry, invoices, amounts paid and refunded, and billing verification records. Website and direct Android payments use Stripe; store purchases, where available, use Apple or Google. ExamLark does not collect your full payment-card details.
  • Referral rewards: invitation codes, which account invited a new account, verification status, earned credits, and exam reward redemptions. The inviting learner sees referral counts rather than invited learners' email addresses.
  • Study information: answers and attempts, bookmarks, study review state, study goals, activity and completed practice or mock summaries. Progress is stored on your device and synced to your account within the app. Downloaded questions and unfinished mock exams remain on the device.
  • Technical and service information: request and error logs, IP addresses and request metadata processed by our hosting and authentication services, plus records of account and administrative actions.
  • Information you provide: support correspondence and, for staff accounts, content and changes submitted through the management workspace.

03. Google, Microsoft, Apple & Facebook sign-in

If you choose an available social sign-in option, the provider authenticates you and sends information through Supabase Auth. Depending on the provider and your settings, this can include your name, email address, email-verification status, profile image and a provider-specific identifier. ExamLark uses the verified identity to create or connect your account and establish an ExamLark session.

For Facebook Login, we request basic profile and email permissions. We use that information for sign-in and account management. We do not request access to your Facebook posts, messages or friends list, or permission to publish to Facebook. Your Facebook password is entered with Facebook, not ExamLark.

Apple may provide a private relay email address if you choose to hide your email. Supabase may retain provider profile information as part of your authentication record even if it is not displayed in ExamLark.

You can manage provider access in that provider’s account settings. Removing access there does not by itself delete information already held by ExamLark. Follow our account and data-deletion instructions to request its removal.

04. How we use information

We use personal information to operate your account, authenticate access, deliver exam content, verify purchases, support offline learning, respond to requests and protect the service against misuse.

We also use registration, sign-in, purchase and referral records to administer rewards and provide service reports to administrators, including accounts with expiring access or unused credits. Reports also include synced learning activity, such as attempts, practice accuracy and completed sessions. Offline activity appears after a device syncs. Invitation sharing is initiated by the learner.

Where data-protection law requires a legal basis, these activities rely on:

  • Providing the service you request: account management, content access and subscription administration necessary to fulfil our agreement with you.
  • Legitimate interests: securing accounts, preventing fraud, resolving technical problems and maintaining reliable operations, taking your rights and reasonable expectations into account.
  • Legal obligations: records or disclosures required by applicable law, including handling privacy requests.
  • Consent, where required: optional processing for which we ask your permission. You can withdraw that consent without affecting earlier lawful processing.

Providing the account details required for registration and sign-in is necessary to use account-based features. We do not use Facebook sign-in data to serve advertising.

05. Service providers & disclosures

We share information needed to operate the service with providers that perform the relevant functions:

  • Supabase: database hosting and social authentication, including identity and session records. Supabase privacy policy.
  • RevenueCat: purchase and subscription verification, using an ExamLark account identifier and subscription-related information. RevenueCat privacy policy.
  • Stripe: website and direct Android subscription checkout, billing management and payment verification. Stripe processes checkout and payment information; ExamLark stores payment references, amounts, status and access periods. Stripe privacy policy.
  • Apple and Google: app distribution, store payments and subscriptions; and social authentication if selected. Apple privacy policy · Google privacy policy.
  • Microsoft and Meta: authentication if you choose Microsoft or Facebook sign-in. Microsoft privacy statement · Meta privacy policy.
  • Infrastructure and communications providers: website/API hosting, backups and delivery of support correspondence. The management workspace also loads fonts from Google, which receives the connection information needed to deliver them. These policy pages use local assets.

Authorised staff access information when needed for their responsibilities. We may also disclose information where required by law or necessary to address fraud, security incidents or legal claims.

Providers may process information in countries other than your own. Where applicable law restricts international transfers, appropriate transfer safeguards are required. Contact us for information about the arrangements relevant to your data. Providers’ own policies govern information they independently collect through their services.

06. Cookies & device storage

The management website uses a session cookie to keep you signed in. Social sign-in uses temporary browser storage and authentication information to complete the redirect securely. Providers may use their own cookies when you visit their sign-in pages.

Support tickets store your messages, account and optional exam/question references so authorised support staff can respond. Staff may record internal notes. Announcement read records store which version you marked as read. In-app messages are not sent automatically by email.

Study goals, bookmarks, review state, answers and completed practice summaries sync per account, app and exam. A durable device queue holds offline changes until a connection is available. The account-data download includes synced learning records; it excludes unsynced device records. Privacy requests submitted through Support are reviewed by staff; they do not automatically delete an account or cancel billing.

The mobile apps use device storage for sign-in credentials, downloaded content and study progress. Signing out or deleting a server account does not necessarily erase downloaded content or local history from every device. See how to remove device-local information.

These public privacy and deletion pages do not set application cookies or load analytics, social widgets or advertising scripts. Hosting services still process the requests needed to deliver the pages.

Optional emails and performance measurements

Study reminders and weekly summaries are off by default. When enabled, we use your verified email, per-app preferences, timezone and quiet hours. Every study email includes an unsubscribe link. Delivery status records are retained for up to 90 days. Account recovery and security verification emails are separate from study-email preferences.

Signed-in web and mobile clients may send page responsiveness, layout stability, startup or question-download timings to improve reliability. Measurement records contain the app, platform, metric, value and time; they do not contain account identifiers, page URLs, question content or payment details. Measurements are retained for up to 30 days.

07. Retention & security

Account and access records are kept while needed to provide your account and services. Subscription and billing records may also be needed to verify entitlements, address disputes and meet record-keeping obligations. Security logs and support correspondence are retained according to their operational purpose and any applicable legal requirements.

When you request deletion, we assess which information can be erased or anonymised and which limited records must be retained. We will explain any exception that applies to your request. Backup copies may remain until the applicable backup rotation removes them; deletion from live systems does not imply immediate removal from every backup.

We use access controls, protected authentication and encrypted connections to reduce the risk of unauthorised access. No system can guarantee absolute security. Device-local information and device backups remain subject to your device and backup settings.

08. Your privacy choices

Depending on the law that applies to you, you may have rights to access or obtain a copy of your information, correct it, request deletion, restrict or object to processing, request portability, and withdraw consent where processing relies on consent.

Contact us using the details above. You do not need to sign in to send a request. We may need proportionate information to verify that the request concerns your own account. Never send us a password, authentication code or access token.

For account closure or removal of social-provider data, use our data-deletion instructions. Where UK or EU data-protection rules apply, requests normally require a response within one month, subject to the rules on verification and extensions.

You can also raise a concern with the data-protection authority in your country. In the UK, this is the Information Commissioner’s Office (ICO).

09. Younger users

ExamLark provides exam preparation resources. If you are a parent or guardian and believe a child has provided personal information without the permission required by applicable law, contact us so we can review the account and any deletion request.

10. Changes to this policy

We may update this policy as the service or our practices change. The date above identifies the latest revision. Where required, we will provide additional notice of material changes.

Account & data-deletion instructions →