Privacy Policy
Last updated: July 2026
Overview
Getting to Aced ("we", "the app") helps bar exam students log and analyze multiple-choice questions they answered incorrectly. This policy applies to the website and the Chrome extension.
Data we collect
- Account: email address, first and last name (optional), and authentication credentials (stored by Supabase Auth).
- Study data: wrong-answer logs you enter (subject, source, subtopic, rules, notes, dates, and reason tags).
- Technical: standard server logs from our host (Netlify) and database provider (Supabase) for security and reliability.
- Contact form: if you use our contact page, we receive your name, email, and message so we can respond.
Security
Data is transmitted over HTTPS (TLS). Passwords are hashed by Supabase Auth. Database storage is encrypted at rest by Supabase. Row Level Security ensures each user can only access their own data. We do not sell your personal information.
How we use data
Your data is used only to provide the service: saving your entries, showing your dashboard, enforcing access, syncing between the website and Chrome extension, and responding to support messages you send us.
Data retention
Your log entries are kept when you stop using the service — you may delete individual entries in the app or request full account deletion.
Free access (July 2026 bar exam)
Free for the July 2026 bar exam. Unlimited logging, analytics, and the Chrome extension — no payment required. Paid plans may return after the July 2026 bar exam period; we will update this policy before any change, including describing any payment processor we use at that time.
Chrome extension
The extension stores your sign-in session locally in the browser until you sign out or your session expires per Supabase Auth settings. It communicates with Supabase over HTTPS using the same account as the website. It does not read the content of other websites you visit.
Third parties
- Supabase — authentication and database hosting
- Netlify — website hosting
- Resend — transactional email (verification messages and contact form delivery)
Your choices
You may delete individual log entries in the app, delete custom sources/subtopics on the Account page, or contact us to request account deletion.
Changes to this policy
We may update this policy from time to time. When we make a significant change, we'll post the new version here with an updated date and, where practical, let you know. The "last updated" date at the top always shows the most recent revision.
Contact
Questions about your privacy, or to request account deletion: admin@gettingtoaced.com or our contact form.