Privacy Policy
Last updated: March 2025 · Effective: March 1, 2025
Edvex, Inc. (“Edvex,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform at getedvex.com and app.getedvex.com (collectively, the “Service”).
Overview
We built Edvex to democratize access to excellent test preparation. Protecting student privacy is not an afterthought — it is central to who we are. We collect only the data needed to provide and improve our Service, and we do not sell your personal information to third parties under any circumstances.
This policy applies to all users of the Edvex platform, including students, guardians, and institutional users. By using the Service, you agree to the collection and use of information as described in this policy.
Key commitments at a glance:
- • We do not sell your personal data
- • We never show you ads
- • Student educational data is treated with FERPA-level protections
- • COPPA compliance for users under 13
- • You can request deletion of your data at any time
Data We Collect
1. Account Information
When you create an Edvex account, we collect your name, email address, and a hashed password. If you sign up through a third-party identity provider (e.g., Google), we receive only the basic profile information you authorize. We do not receive or store your third-party passwords.
2. Usage Data
We collect information about how you interact with the Service, including: pages visited, features used, session duration, practice sessions completed, questions answered, answers given (including incorrect answers), time spent on each question, and navigation patterns. This data is used to power our adaptive learning engine and improve the platform.
3. Exam Performance Data
All practice results, diagnostic scores, quiz performance, and full practice test results are collected and stored. This includes per-question accuracy, time-on-task per concept, and longitudinal performance trends. This data is the core of our personalization engine and is never shared with third parties in identifiable form.
4. Uploaded Study Materials
Elite and Max plan subscribers may upload study materials (PDFs, notes, documents). Uploaded content is stored securely and processed only for the purpose of powering the AI tutor experience for that specific user. We do not use uploaded materials to train our AI models on other users' behalf, and we do not share uploaded content with any third party.
5. Device and Technical Data
We automatically collect device type, browser type and version, operating system, IP address, and general location (country/region derived from IP). This information is used for security, fraud prevention, and improving compatibility.
6. Communications
If you contact us for support, we retain the content of your messages to resolve your issue and improve our service. AI tutor conversation logs are stored to enable context-aware tutoring sessions and are accessible only to you and authorized Edvex personnel for support purposes.
7. Payment Information
Payment processing is handled entirely by Stripe, Inc. Edvex does not store credit card numbers, CVV codes, or full payment details. We receive only a tokenized payment confirmation and the last four digits of your card for display purposes.
How We Use Your Data
We use the data we collect for the following purposes:
- Providing the Service: Running your account, authenticating your sessions, delivering practice questions, and enabling all core features.
- Personalization: Powering the adaptive engine that selects practice questions, calibrates difficulty, identifies knowledge gaps, and builds your personalized study plan.
- Score Prediction: Using your performance data to generate realistic score estimates and readiness predictions for your target exam.
- AI Tutor Context: Enabling Ed to remember your conversation history, understand your weak areas, and provide contextually relevant explanations without you having to repeat yourself.
- Product Improvement: Analyzing aggregated, anonymized usage data to improve our question bank, AI models, and platform features. Individual identifiable data is not used for model training without explicit consent.
- Communications: Sending transactional emails (account confirmations, receipts, password resets) and, if you opt in, product updates and study tips. You can opt out of non-transactional emails at any time.
- Security & Fraud Prevention: Detecting and preventing unauthorized access, abuse, and fraudulent activity on our platform.
- Legal Compliance: Complying with applicable laws, regulations, and court orders.
Data Sharing
We do not sell, rent, or trade your personal information to third parties for marketing or advertising purposes. Period.
We share data only in the following limited circumstances:
- Service Providers: We use trusted third-party vendors to operate our infrastructure: cloud hosting (AWS), payment processing (Stripe), email delivery (Postmark), and analytics (internal only). These vendors are contractually prohibited from using your data for any purpose beyond providing their services to us.
- AI Model Providers: To power the Ed AI tutor, we send conversation messages to our AI infrastructure partners under strict data processing agreements. These partners do not use your conversation data to train their own general-purpose models.
- Guardian Access: If you are a student who has linked a guardian account, your progress data and activity summaries are visible to your linked guardian as described in the Service.
- Institutional Accounts: If your account is provided by your school or institution, your performance data may be visible to authorized school administrators within the scope of their institutional license.
- Legal Requirements: We may disclose data when required by law, subpoena, court order, or other legal process, or to protect the rights, property, or safety of Edvex, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you and give you the opportunity to delete your account before such a transfer completes.
Data Security
We implement industry-standard technical and organizational measures to protect your personal information:
- All data is encrypted in transit using TLS 1.3
- Data at rest is encrypted using AES-256
- Access to production systems is restricted and logged
- Employee access to user data requires multi-factor authentication
- We conduct regular third-party security assessments
- Our infrastructure is SOC 2 aligned
- Passwords are hashed using bcrypt with work factors that exceed current NIST recommendations
No system is 100% secure. In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, email ariel@getedvex.com with your request and the email address associated with your account. We will respond within 30 days.
You may also delete your account directly from your account settings, which will initiate permanent deletion of your personal data within 30 days (except where we are required to retain it by law).
COPPA — Children Under 13
Edvex complies with the Children's Online Privacy Protection Act (“COPPA”). We do not knowingly collect personal information from children under 13 without verifiable parental consent.
If a user under 13 wishes to use Edvex, the registration process requires the entry of a parent or guardian's email address. We will send a consent request to that address, and the account will not be activated until consent is received and verified.
For accounts created for children under 13:
- We collect only the minimum information needed to provide the Service
- We do not use the child's data for marketing purposes
- Parents may review, correct, or delete their child's information at any time by contacting ariel@getedvex.com
- We will not condition participation in activities on providing more information than is reasonably necessary
If you believe we have inadvertently collected information from a child under 13 without proper consent, please contact us immediately at ariel@getedvex.com and we will take immediate steps to delete the information.
FERPA — Educational Records
The Family Educational Rights and Privacy Act (“FERPA”) protects the privacy of student education records. While Edvex is a direct-to-consumer platform (not a school-operated service), we treat educational data generated on our platform with the same level of protection as formal education records.
Specifically:
- Student performance data (practice results, diagnostic scores, progress metrics) is not disclosed to third parties without consent, except as necessary to provide the Service
- Institutional customers who access Edvex through a school or district license must comply with FERPA in their use of the platform
- We will cooperate with eligible educational institutions in meeting their FERPA obligations for data processed on their behalf
- Students 18 and older have full rights over their educational data under FERPA; for students under 18, these rights belong to their parents or guardians
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. When we make material changes, we will:
- Update the “Last updated” date at the top of this page
- Send a notification email to all registered users at least 14 days before the changes take effect
- Display a prominent notice on the platform
Your continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree, you may delete your account before the effective date.
Contact Us About Privacy
For privacy-related questions, data requests, or concerns, please contact our Privacy Team:
We will respond to all privacy inquiries within 30 days. For time-sensitive matters involving children's data or security incidents, please include “URGENT” in your subject line.
