Privacy policy
Effective: August 5, 2026 · Last updated: August 5, 2026
This policy explains how ExamNinja handles information when you use examninja.io, the ExamNinja Chrome extension, email-code accounts, AI study features, support, and subscriptions. “ExamNinja,” “we,” and “us” refer to the operator of these services.
Information we handle
Website visits, free tools, and security
- Basic request data. Cloudflare and our server infrastructure process information such as IP address, browser or device details, requested path, timestamps, and security signals to deliver and protect the service.
- Free-tool usage. The website stores a random installation identifier in local storage. For signed-out limits, the backend sets a signed, HttpOnly guest cookie and creates rotating one-way identifiers derived from that cookie and the network address. The application database is designed not to retain the raw IP address.
- Operational records. We may store request ID, tool type, completion status, a one-way content hash, provider and model, latency, error class, and token-usage totals. We do not store the submitted question or generated answer in our application database.
- Human verification. Free-tool pages use Cloudflare Turnstile. Cloudflare receives the challenge token, network address, and browser or device signals needed to identify automated abuse.
- Website analytics. Public pages load DataFast to measure visits and product interactions such as tool use and install or pricing clicks. DataFast may receive page, referrer, device, and network information under its own privacy terms.
Accounts, email, and support
When you sign in, we process your email address, a random installation identifier, one-time-code challenge details, session records, account ID, usage totals, and account status. Raw one-time codes and refresh tokens are stored by our backend only as one-way hashes. Resend processes the recipient address and email content to deliver login and service messages. If you contact hello@examninja.io, we process the message and contact details needed to respond.
Billing
Stripe hosts checkout and the customer portal and processes payment method, billing, tax, fraud-prevention, and transaction information. ExamNinja stores Stripe customer, subscription, price, status, renewal, and event identifiers needed to provide paid access. We do not receive or store full card numbers.
Chrome extension access and local storage
The extension is limited to the learning and practice sites listed in its Chrome manifest. Its permissions allow it to store settings and session data, work with the active tab, and run ExamNinja code on supported pages. When you activate ExamNinja, it can read the relevant page or question content, send it to the ExamNinja backend, and—only after you choose the available apply action—interact with supported page controls. It does not change learning-platform logs, proctoring systems, secure browsers, or school policies.
Chrome local storage may contain the random installation ID, account email and ID, access and refresh tokens, billing status, onboarding stage, shortcut-related preferences, and visibility setting. Educational screens do not separately save the email you type or the one-time code. Signing out removes the local account, token, and billing values; uninstalling removes the extension’s local storage.
Questions and AI processing
When you request help, the minimum content needed for the feature is sent to our backend and then to the configured AI provider. Depending on the feature, this can include question text, answer choices, your proposed answer, selected page HTML, a page URL used for page analysis, and limited context. When configured, OpenAI is tried first; Google Gemini can be configured as a fallback.
ExamNinja requests non-persistent processing where the provider supports it and does not use submitted content to train its own models. Provider processing and temporary abuse-monitoring retention remain governed by the provider account configuration and terms. Do not submit names, student IDs, grades, access codes, private instructor feedback, health or financial information, restricted assessments, or content you are not allowed to share.
Limited product measurement
The extension records only allowlisted onboarding and authentication events used to improve setup: onboarding started, how-to viewed, skipped, completed, code requested, signup completed, and returning sign-in completed. A record can include a random event ID, pseudonymous installation ID, onboarding and extension versions, optional account ID after sign-in, and timestamp. It does not include email, raw IP address, page URL, question, answer, or arbitrary event metadata.
How we use information
We use information to operate accounts and sessions; deliver AI explanations; enforce free and paid limits; provide subscriptions and support; prevent abuse and fraud; debug failures; understand onboarding and website performance; secure the service; and meet legal obligations. We do not sell personal information or use submitted questions for targeted advertising.
Service providers and disclosures
We disclose information only as needed to operate the service, respond to lawful requests, protect users and the service, or complete a business transfer subject to appropriate safeguards. Current providers include:
- Cloudflare for website and Worker hosting, network security, Hyperdrive, and Turnstile;
- Supabase for PostgreSQL database infrastructure;
- OpenAI and, if enabled, Google Gemini for AI processing;
- Stripe for checkout, subscriptions, billing portal, tax, and payment fraud prevention;
- Resend for transactional email; and
- DataFast for website analytics.
These providers may process information in countries other than your own under their applicable contracts and legal safeguards.
How long we keep information
- Expired one-time-code challenges and expired sessions are removed by scheduled cleanup.
- AI provider-attempt logs, email-delivery events, free web-tool request records, and extension product events are scheduled for deletion after 90 days.
- Account, subscription, daily usage, and core AI request records—including content hashes but not raw submitted content—are kept while the account is active and removed through account deletion, except where billing, fraud, security, or legal records must be retained longer.
- Stripe and other processors retain information under their own policies and legal obligations.
Security
We use encrypted connections, restricted backend access, signed sessions, one-way hashes for security-sensitive values, database access controls, request validation, and limited operational logging. No online service can guarantee absolute security.
Your choices and rights
You can sign out, manage a subscription in Stripe’s customer portal, or delete your account from extension settings. Account deletion attempts to cancel the active Stripe subscription and then removes the ExamNinja account and associated application data. Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to processing and to appeal or complain to a regulator.
Email hello@examninja.io to make a privacy request. We may need to verify that you control the relevant account before fulfilling it.
Children and school-managed use
ExamNinja is not directed to anyone who cannot legally consent to the service. If local law requires parental, guardian, or school authorization, that authorization is required before use. Contact us if you believe a child provided personal information without the required permission.
Changes and contact
We may update this policy when the product, providers, or law changes. We will post the revised policy here and update the date above. Privacy and data questions can be sent to hello@examninja.io.