Skip to main content

Updated 2026

Privacy Policy

We collect the minimum data needed to run a DECA practice platform, and we are explicit about who touches that data. This policy explains exactly what we store, why we store it, and your rights over it.

1. What we collect

We collect (a) your name and email via Google OAuth when you create an account; (b) practice test data, including the questions you attempt, your answers, scores, and roleplay submissions; and (c) Stripe billing tokens to process subscriptions. We never see or store raw credit card details — Stripe handles payment information directly.

2. How we use it

We use your data to deliver the product: serve practice tests, score your responses, generate cluster-level analytics, and (for Pro members) generate leaderboards. We do not sell your data, and we do not use it for advertising.

3. Third-party processors

We rely on a small set of trusted vendors to operate the Service: Google OAuth for authentication, Stripe for billing, Neon (Postgres) for database storage, Vercel for hosting and edge delivery, and Groq for AI inference. Each processor receives only the data needed to perform its function.

4. Cookies and tracking

We use a single auth-session cookie set via Google OAuth so you stay signed in, and basic analytics cookies to improve the product. We do not run advertising or third-party marketing trackers.

5. Data retention

Your account and practice test history are retained while your subscription is active. When you close your account, we delete your personal data and test history within 30 days, except where retention is required by law (e.g., billing records).

6. Your rights

You can export your test data and delete your account at any time from your settings page. If you would like a copy of your data in a portable format, or want to correct inaccurate information, email maestro.committee@gmail.com and we will respond within 30 days.

7. Children's privacy

Users under 13 require verifiable parental or guardian consent before creating an account. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has signed up without consent, contact us and we will delete the account.

8. Security

All data is encrypted in transit via TLS and encrypted at rest in our database. Access to production systems is limited to authorized engineers and audited. No system is perfectly secure, but we apply industry-standard practices and review them regularly.

9. Changes to this policy

We may update this policy as the Service evolves. Material changes will be announced in-product or via email at least 14 days before they take effect. The “Updated” date at the top of this page reflects the most recent revision.

10. Contact

Privacy questions or requests? Email maestro.committee@gmail.com.