Privacy Policy
Last updated: 30 August 2026.
This policy explains how PrepRun processes personal data and how its limited internal Google Ads API tool uses Google account data.
1. Google Ads API and Google user data
PrepRun uses the Google Ads API only through an internal first-party tool operated by authorised staff of the data controller. The OAuth grant is used to access the controller's own Google Ads account. The tool reads campaign identifiers, configuration, status and bounded cost information for one pre-created Search campaign, and may change only that campaign's status between enabled and paused.
- No PrepRun customer data, email addresses, CVs, interview answers, contact lists or audiences are uploaded to Google Ads.
- The tool does not use Customer Match, remarketing, conversion uploads or app-conversion tracking.
- Operational storage is limited to Google Ads resource identifiers, configuration/status, bounded cost records and cryptographic audit receipts.
- OAuth refresh credentials, client credentials and the developer token are stored as protected operational secrets. They are not stored in the PrepRun application database, browser storage or logs.
- Google Ads API data is not sold, shared for advertising by third parties or used to create profiles of PrepRun users.
The authorised Google account holder can revoke access through their Google Account security settings. The controller can also delete the internal OAuth credentials. Requests may be sent to preprun@outlook.com. The tool is described at PrepRun Google Ads API Internal Tool.
2. Other data PrepRun processes
- Account: email address and basic Google profile details if Google sign-in is selected.
- Progress and usage: game type, mode, level, accuracy, streak and focus-drill results needed to provide and improve the service.
- Interview practice: vacancy text for up to 90 days; CV text for up to 30 days only when optional retention is actively selected. Answer audio and transcripts are processed only for the requested transcription or coaching.
- EPSO practice and AI Tutor: paid and free practice sessions, selected answers, completion state and entitlement checks are stored in Supabase so access limits and retakes work consistently. When you explicitly ask the AI Tutor for help, PrepRun sends OpenAI a bounded learning snapshot and, where relevant, the current question, answer options, your selected answer, the canonical answer and rationale. Provider-side response storage is disabled. Tutor event logs contain only account ID, action, section, token counts and latency—not question text, answers or Tutor output—and are deleted after 30 days.
- Marketing preference: consent status, statement version, source, language and timestamp. Marketing is sent only after explicit opt-in and can be withdrawn at any time.
- Security and aggregate visit integrity: short-lived, non-reversible token/network hashes are used to prevent abuse and deduplicate the approximate daily visit counter. Raw IP addresses and user-agent strings are not stored in these receipts.
- Payments: Stripe supplies customer/subscription references and status; PrepRun never stores full card details.
- Optional advertising measurement: consent choice, consent-statement version and timestamp are stored in your browser. Only after you choose “Allow measurement”, the Google Ads tag may process an advertising click identifier and a pseudonymous Stripe Checkout session ID to count an ad-attributed purchase. No email, account ID, CV, vacancy or interview content is sent.
- Aggregate intelligence: non-personal counts, conversion/cost metrics, rating bands and bounded public-source metadata used for reversible product decisions.
3. Purposes and legal bases
We process data to provide accounts and services (contract), secure and improve PrepRun through bounded aggregate analysis (legitimate interests), send marketing and perform optional Google Ads purchase measurement only after the relevant explicit consent, and meet accounting or legal duties. Automated tools do not make legal or similarly significant decisions about individuals.
4. Processors
We use Supabase for authentication/database/server functions, OpenAI for requested AI functionality and bounded analysis, Stripe for payments, Resend for email, Cloudflare for hosting and cookieless analytics, and Google Ads for the internal campaign-control purpose described above and, only after explicit opt-in, purchase conversion measurement. Providers process data under their applicable contractual and data-protection terms.
5. Cookies and local storage
PrepRun uses essential browser storage for sign-in, settings, progress and security tokens, plus cookieless analytics. The Google Ads tag is not requested and no Google Ads measurement data is sent before you explicitly opt in. If you opt in, Google may set or read advertising-measurement storage to attribute a purchase; personalised advertising, customer-list targeting, remarketing and lookalike audiences remain disabled. You can refuse without losing any PrepRun functionality and withdraw later in Settings.
6. Retention and security
Account and selected progress records are kept while the account is active. Expired or abandoned EPSO practice sessions are deleted after 30 days and completed EPSO sessions after 365 days; EPSO Tutor metadata-only events are deleted after 30 days. Temporary security hashes are deleted within 36–48 hours; anonymous candidate-demand data within 90 days; public-community discovery metadata within 30 days; interview vacancy text within 90 days; and optionally retained CV text within 30 days. Non-personal security, reconciliation and audit receipts may be retained to prove safe operation. Access is restricted according to role and protected in transit and at rest.
7. Your rights
Under the GDPR you may request access, correction, deletion, portability or restriction, and object where applicable. You may withdraw consent at any time and complain to the Polish UODO or the supervisory authority in your EU country. Contact preprun@outlook.com.
8. Changes
Material changes will be communicated in the application or by email where appropriate. The current version and update date remain available on this page.