LEGAL · PRIVACY
Privacy policy for PrepAMT FAA A&P test prep
PrepAMT Academy, an independent A&P test prep service, holds your account, an email address and a way to prove it is yours, and it holds your studying: every question you answer, every gap you type into, every practice test you sit, and the test dates you are working towards. That is the whole of it, and section 02 lists it item by item. There are no analytics, no advertising trackers, and nothing is sold or shared for marketing. Everything below was written by reading the code and the database rather than from a template.
Version (rev 4). This replaces any earlier version.
The controller
PrepAMT Academy is operated by Ancestorii Ltd, a company registered in England and Wales (number 17224876), which is the data controller for everything described here.
Registered office: 41 Pentre Road, Maerdy, Ferndale, Wales, CF43 4DP.
Every question, request or complaint about this policy goes to support@prepamtacademy.com. One address, monitored by a person.
Which law this is written to. UK GDPR and the Data Protection Act 2018, because the controller is established in the United Kingdom and those obligations follow the controller rather than the customer. If you are a resident of a US state with its own comprehensive privacy statute, that statute may give you additional rights on top of the ones in section 07. Write to the address above and we will honor them.
The data this FAA A&P test prep actually holds
This is the complete list, and it is longer than it was: this policy was first written when the database held accounts and nothing else, and the study application has been built since. Everything below exists in the schema today and was read out of it rather than assumed.
Your account.
- Your email address. You give it when you create an account. It is how you sign in, how we send you a password reset, and how we would reach you about the service.
- Your password, hashed, if you set one. We never hold the password itself: Supabase Auth stores a one-way hash, which cannot be reversed into the password you chose, including by us. An account created through Google or Apple has no password at all until you add one.
- An identity record, if you signed in with Google or Apple. The provider, a stable identifier for you at that provider, and the email address and name it returned. Section 05 sets out exactly what is exchanged and what is not.
- Account timestamps. When the account was created, when the address was confirmed, and when you last signed in.
- Your sessions, and how each one started. Supabase Auth keeps a row per signed-in device holding the IP address and browser user-agent string the session was created from. It is a security record. It is what lets a session be recognised and revoked, and it is the only place anything like a location is stored about you.
- Your profile. The name you gave us or chose on your account screen, your time zone, the hour your study day rolls over, and your email preferences. There are four of those and nothing else in there: a countdown before a test date you have set, three weeks out and again a week out; the Sunday digest, which is off unless it is switched on; a note when a question you reported is ruled on; and a receipt when you file one. All four are yours to change, under Reminders on your account screen.
- That you agreed to these documents. When you ticked the box on the sign-up form, and the version date of the terms and this policy as they stood at that moment. A record of a consent that does not say what was consented to is not a record.
- A deletion request, if you have made one. That you asked for the account to be deleted, when, the date it takes effect, and whether you cancelled it. Section 07 describes the whole mechanism. The record itself is erased with the account it belongs to.
Your studying. This is the larger half, and it is the half the product is for.
- Every multiple-choice question you answer. Which question, which of the three options you picked, whether it was right, the subject it belongs to, the sitting it was part of, and the time you answered. Answers are permanent: the ledger has no edit and no delete, which is what makes the readiness figures worth looking at.
- Every fill-in-the-gap answer, word for word as you typed it, including a blank one, which the product records as a real “I don’t know” rather than a skip. Also which item it was for, whether the grader accepted it, and when.
- What the free plan served you, day by day. Which questions and gap items were handed to you and in what order, so the daily allowance can be metered and so coming back mid-day gives you the same set rather than a new one.
- Which of the three written tests you are studying for, and the date you have booked to sit each one. Taking a test off your bench keeps the date rather than losing it, so it is there when you put the test back.
- Every practice test you sit. Which test and which paper, when you started and finished, your percentage score, whether you passed, and your answer to every individual question on it, including which ones you left blank and which ones you flagged to come back to.
- What you are entitled to. Whether you are on the free plan or Pro, when that access started and expires, how it was granted, and any note a member of staff attached to the grant.
- Your subscription, if you have one. Stripe’s reference for your customer record and for the subscription itself, which plan you are on, the date the current month ends, and whether you have cancelled. That is what lets the account screen tell you when Pro renews without asking Stripe every time you open it. No card details are in this, and there is nowhere in our database that could hold any: not the number, not the last four digits, not the expiry, not a billing address.
- Which payments and cancellations we have already acted on. A list of the notifications Stripe has sent us and the billing emails we have sent you, each recorded once. It exists so that a notification arriving twice cannot charge your account twice over or send you the same receipt again, and it is the same kind of record as the email ledger below.
- Anything you report. If you tell us a question is wrong or that the grader refused a good answer, we keep the report: which item, the reason you chose, any note you typed, the answer of yours that was refused, and what our reviewer decided.
- A record of the emails we have sent you. Which one, when it went out, how many attempts it took, and the reference our email provider gave it. It is what stops the same message being sent twice.
What we do not hold. No card details of any kind. Pro is paid for on Stripe’s own pages, and what comes back to us is a reference and a renewal date. There is no column in our database that a card number could go in, which is a stronger statement than a promise not to look. No device records, no push tokens, no advertising or analytics identifier of any kind, and no location data. The time zone in your profile and the IP address on your session rows are the closest thing to it, and both are named above rather than denied. Nothing here profiles you or makes an automated decision with a legal or similarly significant effect: the readiness figures are arithmetic on your own answers, shown only to you.
And what happens when something new is added. This list is maintained by the same commit that changes the database. When a column that describes a person is created, the sentence describing it is written at the same time, not afterwards.
No analytics, no trackers, no sale of data
There is no Google Analytics, no Tag Manager, no Meta pixel, no Plausible, PostHog, Mixpanel, Segment, Hotjar, Clarity or Sentry, and no advertising or attribution script of any kind. This is not an aspiration: the site’s source and its dependency list were searched for every one of those names and none appears.
Nothing is sold. Nothing is shared with advertisers or data brokers. Your study history is yours: it is never sold, never published, never shown to another account, and never used to build a profile of you for anybody else’s purposes.
Because the only cookies we set are strictly necessary ones, there is no consent banner. If that ever stops being true, a banner arrives in the same change.
Processors
Five, and they do exactly what is described here.
- Supabase: authentication and the database. Everything in section 02 lives here.
- Vercel: hosting. It serves the pages and, like any web server, handles the network requests that reach them.
- Stripe: taking the payment, if you subscribe to Pro. Card details are entered on Stripe’s own pages and never reach our servers: we cannot see your card number and we do not store it. What we send Stripe is your email address and a reference for your account, so that a payment can be matched back to it; what we keep in return is Stripe’s reference for your customer record and your subscription, the plan you are on, the date it next renews, and whether you have cancelled. That is the whole of it. There is no card, no last four digits and no billing address on our side. Stripe is a controller in its own right for the fraud checks it runs on a payment, which is its own decision rather than ours and is covered by its policy. If you never subscribe, nothing about you is sent to Stripe at all.
- Resend: delivering the email we send you. Your address and your name pass through it, and so does whatever the message says: a welcome when you join, a reply when you report a question, a receipt when you subscribe and a notice when a subscription is cancelled, and, if you switch it on, a Sunday digest whose subject line and body carry that week’s figures, how many questions you answered and what share you got right. The receipt carries the amount you were charged and the date the subscription renews; neither it nor the cancellation notice can be switched off, because they are records of a payment rather than messages we chose to send you. The password reset is the one exception to all of it: it is sent by Supabase Auth rather than from our own code, over the same mail provider.
- Kickbox: checking, at sign-up only, that the address you gave has a mailbox behind it. Your address is sent to them once, at that moment, and the answer is not stored. It is there so that an account is not created against an address that could never receive a password reset.
Payments. This paragraph used to say there was no payment processor because there was nothing to buy, and that when there was, card details would be handled entirely by the processor and never reach our servers, and that this section would name it. It is named above. The rest of that sentence still holds: no card detail of yours is ever on our servers.
Transfers. Processing may take place outside the United Kingdom. Where it does, transfers are made under the safeguards UK data protection law requires: an adequacy decision, or standard contractual clauses with the UK addendum. We name what each processor does rather than where it runs, because a hosting region changes without this document being touched, and a policy naming the wrong region is worse than one describing the safeguard.
If you use a provider instead of a password
The sign-in and sign-up pages offer “Continue with Google” and “Continue with Apple”. Using one is entirely optional (an email address and a password does everything the same account does) and it changes what is shared, so it gets its own section rather than a line in the one above.
Google and Apple are not our processors. That distinction is not pedantry, it decides who answers to you for what. A processor acts on our instructions; Google and Apple do neither. For the sign-in itself each acts as its own controller under its own privacy policy, which is the one that governs what they do with the fact that you signed in. We are the controller only for what they hand back and we then keep.
What they learn. Choosing a provider sends you to that company, and it necessarily tells them that you are signing in to PrepAMT Academy and when. We never see your provider password, and they never see ours.
What we receive. Only what identifies the account. We ask for the default sign-in scopes and nothing else, so we get no access to your mail, your files, your contacts or your calendar, and could not read them if we wanted to:
- A stable identifier for you at that provider. It is how we recognize you on the next sign-in, and it is meaningless anywhere else.
- Your email address, and whether the provider has verified it.
- Your name, and from Google a link to your profile picture, where the provider supplies them. The name is what the workspace greets you by, and you can change it on your account screen at any time.
That is stored alongside your account as an identity record, so the provider is linked to it and you can sign in the same way again. An account created this way has no password (there is nothing to hash and nothing to steal) until you set one.
Two things specific to Apple, both worth knowing before you choose it. Apple lets you hide your email address, and if you do we receive a @privaterelay.appleid.com address that forwards to you instead of your real one. That works perfectly well here and we treat it exactly like any other address. And Apple releases your name only on the first authorization. If you remove PrepAMT Academy from your Apple ID and come back, that is a first authorization again, and anything you changed in between is not resent.
The lawful basis is the contract, the same as for a password. You asked to sign in this way; receiving an identifier and an email address is how that request is carried out.
You can stop. Revoking our access from your Google or Apple account settings ends the connection at their end. It does not delete your account here. Write to support@prepamtacademy.com for that, and see section 07.
Lawful basis and retention
Performance of a contract covers everything needed to give you an account and run the product you asked for: holding an email address and a password hash so you can sign in, and recording what you have studied so that the next screen can show you where you are. A study tool that forgets your answers is not a study tool, so keeping them is not incidental to the service. It is the service. It also covers your subscription record, if you have one: we cannot give you a paid plan without knowing that you are on one and when it renews.
Legitimate interests covers the session records in section 02, which exist so a compromised account can be investigated and a session revoked; the address check at sign-up, which exists so accounts are not created against mailboxes that do not exist; and the mail ledgers, which exist so the same message is not sent to you twice; and the record of which Stripe notifications we have already acted on, which exists so that one arriving twice cannot charge or credit an account twice over. In each case the interest is a working, secure service and the data is the minimum that serves it.
Consent covers the Sunday digest, and nothing else. It is off on every account unless it is switched on, and every one that goes out carries an unsubscribe address. The other two emails (a reply when a question you reported is ruled on, and a receipt when you file one) are answers to something you deliberately did, and they stop when you ask us to stop them. The subscription receipt and the cancellation notice are not on consent and are not switchable: they are records of a payment, in the same class as the password-reset email, and a customer is entitled to have been told what they were charged.
Retention. Almost everything is kept while the account exists, because almost all of it is what the account is for. The one exception is the free plan’s daily serving log, which is only ever read for the current day and is purged after ninety days. Delete the account and the rest goes with it (the record, any provider identity, the sessions, your answers, your practice tests, your reports, the per-account mail ledgers and the link to your Stripe customer record), really deleted, not flagged as deleted. We do not keep a shadow copy for analytics, because there are no analytics. Email that has already been delivered is in your inbox and in our provider’s sending records, and cannot be recalled from either.
Three of our records survive a deletion, and all three are named rather than glossed. The list of Stripe notifications we have already acted on keeps its rows, with the link to your account removed. It is what stops a notification that arrives after the deletion being processed as if it were new, and without your account attached it says nothing about you. The record of what Stripe told us about each subscription (the plan, the renewal dates, the cancellation) keeps its rows the same way, reference removed, because it is the business’s account of a paid arrangement rather than a description of you. And the one-line ledger of report emails already sent keeps its rows likewise, so “was this sent twice?” stays answerable; the reports themselves, and everything you wrote in them, are deleted with the account. Beyond our records entirely, the payment itself is Stripe’s: a company that has taken money has to keep an account of it for tax and anti-fraud purposes for as long as the law requires, and deleting your PrepAMT Academy account does not and cannot reach into that. Stripe’s own policy governs it.
What you can make us do
Write to support@prepamtacademy.com from the address on the account. We answer within one month, which is the statutory deadline rather than a target.
- Access. A copy of what we hold about you: the account, the profile, and your study history as described in section 02.
- Rectification. Correct anything wrong. Your name, time zone and day boundary you can change yourself on your account screen; anything else, write to us and we will.
- Erasure. Delete the account and everything attached to it, yourself, from your account screen: the Leaving section asks you to type the address on the account, then opens a fourteen-day window. During those fourteen days you can sign back in and cancel from the same card, and the switchable emails are paused; at the end of them the account is erased: a real deletion of every record listed in section 02, not a flag, with the three named survivors in section 06 keeping their rows with the link to you removed. One rule sits in front of it: if a paid subscription is still renewing, you are asked to cancel it first, under Manage billing, because deleting the account cannot reach into Stripe and would not have stopped the charges. Writing to us instead still works, and is answered within the same month it always was.
- Portability. Your data in a machine-readable format.
- Objection and restriction. Object to processing based on legitimate interests, or ask us to hold rather than use the data while a dispute is resolved.
- Withdraw consent. Reply to the unsubscribe address on the Sunday digest, or write to us, and it stops. Withdrawing does not undo what was sent before.
- Complaint. To the UK Information Commissioner’s Office, at ico.org.uk. You do not have to come to us first, though we would rather you did.
The cookies, named
Only strictly necessary ones, and they exist for a single purpose: keeping you signed in, for as long as you asked to be kept signed in.
- The session cookies, set by Supabase Auth and named
sb-…. They carry your session, an access token and a refresh token, and the server swaps an expiring token for a fresh one on each page request. They are cleared when you sign out. - Two cookies of our own, named
amt_, written only if you clear “keep me signed in on this device” before signing in. One remembers that you asked; the other is set to expire when the browser closes. When the first survives and the second does not, we know the browser has been restarted and we sign this device out. That is the entire mechanism, and it works per device: signing out here never signs you out anywhere else.
There is no analytics cookie, no advertising cookie and no third-party cookie of any kind. Block them and the site still reads; you simply cannot stay signed in, which is what the cookie is for.
Who this is for
PrepAMT Academy is for people preparing for a professional certificate and is not directed at children. You must be 16 or over to create an account, and the sign-up form asks you to confirm it in the same sentence that asks you to accept the terms and this policy. (The certificate itself requires you to be 18 before the FAA will issue it, though there is no minimum age for the knowledge tests: see the eligibility page.) If you believe a child has created an account, write to us and we will remove it.
Changes to this policy
This policy is versioned by date, and the version above is the one in force. When it changes materially (a new processor, a new category of data, a new purpose), the new version goes up here before the change takes effect, not after, and the version date above moves with it. So that date is how you tell whether anything has changed since you last read this.
The version you agreed to when you created your account is recorded against it, so “which one did I accept?” is a question with an answer rather than a guess.