Facebook Twitter Instagram LinkedIn

Privacy of Policy

Updated on May 1, 2023

PRS Review, LLC respects the privacy of people who use the website (https://www.prsreview.com) or other PRS Review services. This privacy statement ("policy") reflects the current information practices of PRS Review. Should there be any future changes to our privacy policy, we will continue to post them on this page.

In this policy, "you" and "your" refers to any person or entity subscribing to and/or using the Service ("Users"). “Service” refers to any current or future products (paid or free) offered by PRS Review. Unless otherwise stated, "PRS Review," "we," and "our" will refer collectively to PRS Review.

Information We Collect

We collect information when you access our website or use any of our services (including but not limited to our mobile applications).

We collect the following categories of personal information:

  1. Identifiers, such as your name, email address, IP address, or account name. 
  2. Personal information, such as your educational information, credit card number, or financial information. 
  3. Professional or employment-related information.
  4. Non-public education information (school attended and date of graduation).
  5. Classification characteristics, e.g., your age, race, national origin, or sex. 
  6. Commercial information, such as the products or services you’ve purchased, obtained or considered, and other purchasing or consumer histories or tendencies. 
  7. Internet activity, such as your browsing history, your search history, and information on your interaction with our website, our other services, and advertisements. 
  8. Geolocation data, e.g., your physical location or movements. 
  9. Inferences drawn from other personal information listed above, to create a profile reflecting your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitudes.

Information could be collected in any/all of the following ways. 

Information You Provide

When you register as a member or request information, we will use our registration and online enrollment forms to collect personally identifying information such as your full name, mailing address, email address, telephone number, educational background, professional information and credit card information ("personal data"). In addition, if you contact us via email or offline, we may collect the personal data that you voluntarily provide us at that time.

You may choose to voluntarily submit other information to us through our services that we do not request and, in such instances, you are solely responsible for such information.

Information Collected Automatically

For each visitor to our website, our server automatically records IP (Internet Protocol) address, browser type, operating system, domain name, access times, and referring website addresses.

For users interacting with our services, we may also collect various information using different types of technologies. This information includes:

  1. Type of subscription and your interactions with our Service.
  2. Details of the queries you make, and the date and time of your request.
  3. Any content (as defined previously) you post to the Service including answer responses, notes, flash cards, messages, and forum posts you send and/or receive via the Service.
  4. Technical data, which may include URL information, cookies, your IP address, the types of devices you are using to access or connect to our Service, unique device ID, device attributes, network and device performance, browser type, language, operating system, and PRS Review application version.
  5. Location data based on your IP address. PRS Review may use third-party applications to look up location based on your IP address. At no point will your personal or other identifying data (other than IP address) be used for such specific purpose. 

How We Use Collected Information

We may use any information collected, including personal information:

  1. To complete, perform, and support the activity for which the information was provided.
  2. To improve the content of our website or services.
  3. To develop new products and services, and analyze your use of the Service, including your interaction with applications, products, and services that are made available, linked to, or offered through the Service.
  4. To customize the content and/or layout of our website for you.
  5. To notify you about updates to our website, if you have consented to receive such information.
  6. To contact you for marketing purposes, if you have consented to receive such information.
  7. To process your payment or prevent or detect fraud.
  8. To contact you for employment opportunities.
  9. To enforce this Privacy Policy, the Terms and Conditions of Use, and any other terms to which you have agreed including to protect the rights, property, or safety of PRS Review, its users, or any other person, or the copyright-protected content of the Service.
  10. As otherwise stated in this Privacy Policy.

We may also use or disclose the personal information for its business purposes, including:

  1. Secure our network and our website.
  2. Conduct audits related to our current interactions with you
  3. Debug the site and service to identify and repair errors that impair existing intended functionality.
  4. Undertake activities to verify or maintain the quality or safety of a service or good that is owned, manufactured, manufactured for, or controlled by PRS Review, and to improve, enhance or update them.
  5. Perform services on behalf of PRS Review, including maintaining or servicing your account and providing customer service.

Persons who supply us with their telephone numbers online will only receive telephone contact from us with information regarding orders they have placed online or with regard to technical, billing, or product-related issues when deemed necessary during our regular office hours.

How is the Information Shared

The information collected may be:

  1. Shared with our agents or contractors who assist in providing support for our internal operations.
  2. Used by all of our trading names and affiliated group companies, and transferred to other countries for processing. These countries may not have similar data privacy laws, but if we transfer your information in this way, we will take steps to ensure that your information continues to be protected.
  3. Disclosed when legally required to do so at the request of governmental authorities conducting an investigation, to verify or enforce compliance with the policies governing our website and applicable laws, or to protect against misuse or unauthorized use of our website, to a successor entity in connection with a corporate merger, consolidation, sale of assets, or other corporate change respecting the website.

The information will not be disclosed to third parties unless you have explicitly consented to do so. We are committed to protecting your personal information.

The categories of personal information that we used, transferred, exchanged, or disclosed  (including to third parties) about consumers during the preceding 12 months were: (a) identifiers; (b) personal information; (c) classification data; (d) commercial information; (e) internet activity; (f) geolocation data; and (g) inferences.

The categories of personal information that we disclosed about consumers for a business purpose during the preceding 12 months were:  (a) identifiers; (b) personal information; (c) classification data; (d) commercial information; (e) internet activity; (f) geolocation data; and (g) inferences.

Storage, Security and Transfer of Data

Cookies

We use cookies to store users’ preferences and record session information, such as items that users add to their shopping cart, record user-specific information on what pages users access or visit, alert users to new areas that might be of interest to them when they return to our site, record past activity at a site to provide better service when users return to our site, customize website content based on users' browser type, or other information that the user sends.

A cookie is a small piece of information that is sent by a website and stored on the visitor’s computer. Cookies are small files and will not pose any significant disk space concerns. Some cookies used by the PRS Review website may remain on the user's computer after they leave the website, but most are set to expire within 30-365 days. You can disable cookies using the settings on your web browser, but doing so will prevent you from taking advantage of customization and certain security features.

Tracking

Our Sites and Services do use analytics and advertising cookies and tags, including Google Analytics and Google Tag Manager, and these do collect information about how this Site is used. None of them run until you allow them: when you first arrive a banner asks you to choose, and if you choose “Reject all” no Google script is requested at all - your browser makes no request to googletagmanager.com, so no Google analytics or advertising cookie can be created. Ignoring the banner is not agreement. We do not act on the browser “do not track” header or on the Global Privacy Control signal, so setting one will not change what loads here; the choice you make in our cookie banner, or later under “Cookie Preferences”, is the one that governs, and you can change or withdraw it at any time. Full detail, including every cookie and its lifetime, is in the “Cookies and Similar Technologies” section below.   If you would like additional information about online tracking and various opt-out mechanisms, please see https://youradchoices.com/ 

Because we link to social media sites, and from time to time may include third-party advertisements, other parties may collect your personally identifiable information about your online activities over time and across different web sites when you visit this Site.

In addition, we use Google AdWords, so we are advertising the Site online through a form of tracking called remarketing, Third-party vendors, including Google, show our ads on various sites across the Internet, and use cookies to serve you ads based on your past visits to this Site.  You can opt out of Google's use of cookies by visiting Google's Ads Settings https://www.google.com/settings/ads/plugin . Alternatively, you can opt out of a third-party vendor's use of cookies by visiting the Network Advertising Initiative opt-out page. http://www.networkadvertising.org/choices/

Please note that not all tracking will stop even if you delete cookies.

Security

We use data hosting provider(s) in the United States to store your data. The provider(s) chosen employ a variety of security measures designed to ensure data protection and up-time. Although we are committed to employing safeguards to protect user information, due to the inherent nature of online and evolving technologies, it is not possible to completely secure any/all data. We cannot guarantee that data is absolutely safe and secure from intrusion.

How long is the data stored?

The duration of data storage usually depends on the type of information as indicated below. After the indicated time, the data is either deleted or archived (backed up). In cases where the data is archived, we use reasonable efforts to continue to keep it secure until the time data is deemed safe for deletion.

Personal Information: This data is stored until the time you request to have it deleted. However, we may retain some personal information for a certain duration for us to meet certain legal and financial requirements, to resolve disputes, to enforce our agreements, and to support business operations.

Subscription data: Subscription-related data is stored until the subscription is no longer active. Once the subscription expires, the data is archived (backed up). As mentioned previously, we make all efforts to keep such data safe until it is deemed safe for deletion.

Service via organization: If the Service is provided to you through an organization, subscription-related data can be retained until the administrator of the organization gives approval for deletion or until the point the data is deemed irrelevant. After such time, the data can be either deleted or archived (backed up).

Transmission of Personal Data

The user acknowledges and agrees that by providing PRS Review any information through the website, the user automatically consents to the transmission of such personal or proprietary user information over international borders, as necessary, for processing in accordance with PRS Review standard business practices.

How to Control Your Information

You have the right:

  • To request access to the personal information we have about you.
  • To request that we delete personal information about you.
  • To opt-out of our use, transfer, exchange or disclosure (including to third parties) of personal information about you.
  • Not to be discriminated against based upon whether you decide to opt-out.

To exercise the access, deletion, and opt-out rights described above, please submit a verifiable consumer request using one of the following methods:

  • Email us at ajain@prsreview.com or use contact us using our contact us page.

Update Personal Information

You can review and update your personal information along with other preferences from the “Profile” section of the website at all times (subject to availability). Upon request, we offer users the ability to have inaccuracies corrected in contact information, financial information, unique identifiers, and transaction information. Users can have this information corrected by sending an email to ajain@prsreview.com or writing to us at PRS Review, 488 Cedar Grove Road, Pittsboro, NC 27312. You can also request to have any personal information, not relevant to the original purpose for which it was collected, removed by writing to us at the above address.

Opt Out of Email Notifications

You can opt out of receiving subscription/service-related notifications and marketing/promotional updates the “Unsubscribe” link included at the bottom of any email communication. Due to the technical failures and/or other unforeseen reasons, if the system fails to update your preferences, you can also write to us directly at ajain@prsreview.com.

Other Privacy Information

Maintaining Privacy 

As stated, PRS Review will maintain the confidentiality of all user communications that contain personal information transmitted directly to PRS Review. Postings by a user on any public arena, such as a message board or in a chat room, will not and cannot be protected as confidential.

Children

Our Services are not intended or directed toward individuals under age 13. If you fall under the age of 13, please do not use our Services or register on our website. We do not knowingly collect personal information from users under age 13. If it is brought to our attention that personal information has been collected from individuals under age 13, we will take required measures to delete such information. You can write to our support team at ajain@prsreview.com to address any concern you may have regarding such information.

Privacy Policy Changes 

We may periodically update our Privacy Policy. All policy changes will be posted on this website, and the date at the top will be updated to reflect that change. If there are any material changes to the policy, all users who have opted to receive communication will be notified via email. We may also show notifications/updates within our products/services to inform you about such changes. Continuing to use the product after the change is effective implies agreement with the Privacy Policy. If you disagree with any of the changes, you must cease using our services and write to us at ajain@prsreview.com or contact us at the address provided for deactivation. Any applicable refunds for paid services will be calculated as per our refund policy.   Any changes will be effective only after the effective date of the change and will not affect any dispute arising prior to the effective date of the change.

California Privacy Rights

This section describes your rights under California Consumer Privacy Act (CCPA).

PRS Review collects personal and other information as described in the “Information we collect” section. Information is collected for business and commercial purposes only as described in “How We Use Collected Information“ section. Collected information may be shared as per “How is the information shared”. PRS Review does not sell (as such term is defined in the CCPA) personal information. We do use cookies as per the policy outlined in “Cookies” and “Information we collect”.

Subject to certain limitations and exceptions as applicable under the law, you have the right to request that we disclose to you what personal Information we collect, use and disclose, including the right to request specific pieces of personal information we have collected about you in the prior 12 months. You also have the right to request to delete personal information, to opt out of any “sales” that may be occurring, and to not be discriminated against for exercising these rights.

You may choose to exercise your right(s) by submitting your request as described in “How to Control Your Information” section.  In order to verify the authenticity of the request, we may use the information your account (including your email address) and/or request a government supplied identification. You have the right to designate an authorized agent to exercise the rights on your behalf. We may require sufficient proof (as applicable under law) to establish the authenticity of the designated agent. In case we are unable to verify the authenticity of designated agent, we may deny requests originating from the said agent.

Contact Us

If you have any questions about our Privacy Policy or suggestions on how to improve our privacy to all users, you may contact us at any time at ajain@prsreview.com or write to us at the address provided below.

PRS Review

488 Cedar Grove Road

Pittsboro, NC 27312

Cookies and Similar Technologies

This section lists the cookies, the browser storage and the requests to other companies that this Site uses, in four categories, with the lifetime each one is actually given. Not everything below is a cookie: several items are entries in your browser’s own local or session storage, and two are requests to another company that store nothing on your device at all. Each entry says which it is, because calling them all cookies would be inaccurate. Only the strictly necessary category is used without asking you. Nothing in the functional, analytics or advertising categories is loaded until you allow that category, and for analytics and advertising that means no Google tag and no video player script is requested at all, not merely that their cookies are suppressed.

Strictly necessary

These are needed for the Site to work, to keep you signed in, to take payment and to defend the Site against abuse. The settings panel offers no switch for them, and they cannot be refused while you use the Site.

    \t
  • prs_consent_id (cookie) – a random identifier containing no personal information, which links your cookie choice to our record of it. It is written only at the moment you make a choice, never on page load and never before you answer, and it is never replaced afterwards. Lifetime: 397 days, about 13 months. Because it is the only handle we have for a visitor who is not signed in, if you clear your cookies we can no longer connect you to your own consent record.
  • \t
  • prs_consent (cookie) – your choice itself, category by category, together with the version label of the banner and of this policy, so that each page knows what it is allowed to load. Lifetime: 397 days, about 13 months.
  • \t
  • .AspNetCore.Session (cookie) – keeps you signed in and holds your progress through a test. It is issued only once there is something to keep, and answering the cookie banner does not create one. Lifetime: the cookie is deleted when you close your browser, and the session it refers to expires on our servers after 25 minutes without activity.
  • \t
  • .AspNetCore.Mvc.CookieTempDataProvider (cookie) – carries a single short-lived value from one page to the next in the test and oral board sections, such as a note telling the next page it is being opened for the first time. Lifetime: seconds.
  • \t
  • ckCsrfToken (cookie) – protects the content editor in our administrative area against cross-site request forgery. It is set only in that administrative area, and never on the pages a subscriber uses. Lifetime: the browser session.
  • \t
  • Cloudflare Turnstile (challenges.cloudflare.com, set by Cloudflare) – distinguishes people from automated traffic. The Turnstile script is loaded on every page that uses our main site layout, not only where a form appears; the challenge itself runs on the contact and scholarship forms. It is not loaded on the subscriber dashboard, within the test and oral board screens, or on the sign-in, sign-up and password-reset pages. Lifetime: as set by Cloudflare.
  • \t
  • Google Fonts (fonts.googleapis.com, fonts.gstatic.com) – the typefaces the Site is set in. These are requested in the head of every page, before you answer the cookie banner and whatever you answer, and the settings panel does not control them and cannot. No cookie is set and nothing about your use of the Site is measured, but the request itself discloses your IP address, your browser and operating system, and the address of the page you are viewing to Google. Lifetime: no cookie; the font files are cached by your browser.
  • \t
  • Stripe (js.stripe.com, set by Stripe) – takes payment and screens the transaction for fraud. It is loaded on the two checkout pages only, and on no other page of the Site. Lifetime: as set by Stripe.
  • \t
  • Microsoft Azure Speech (set by Microsoft) – recognizes your spoken answers. It is loaded on the two oral board practice pages only, and on no other page of the Site. Lifetime: as set by Microsoft.
  • \t
  • Service worker (/sw.js) (browser storage, not a cookie) – a small background script your browser keeps so that notifications can be delivered. It is registered only where we have browser notifications switched on for the Site; where we do not, nothing is registered at all. It is not controlled by the cookie banner, and it stores nothing about you or about what you do here. Lifetime: until you clear the Site’s data in your browser.
  • \t
  • prsAnalytics.txn.* (session storage, not a cookie) – a note that a completed purchase has already been counted, so that reloading a confirmation page does not count it twice. It is written by a first-party script of our own that is present whatever you choose; that script makes no network request, sets no cookie and sends nothing to Google, and what it prepares is only ever reported if you have allowed analytics. Lifetime: discarded when you close the tab.

Functional

These remember small preferences so that the Site behaves the way you left it. None of it is sent to an advertiser or used to measure you. If you refuse this category, the two items we can remove from here – lnkFrSignup and prsTestFontSize – are deleted at that moment. We should be straightforward about the limits of that. The parts of the Site that write those two values do not yet check your answer before writing, so after a refusal one of them may be written again later in the same visit, and is deleted again the next time you refuse. The other two items in this category are not removed by refusing here: prs.push.* and prs.a2hs.* stay in your browser storage until you clear it, and a web push subscription ends when you turn notifications off for this Site. You can remove all of them at any time by clearing this site’s cookies and storage in your browser.

    \t
  • Web push subscription (browser storage) – an address at your browser vendor’s notification service, so that a study reminder can reach you. This one is governed by your browser’s own permission prompt, and by whether we have notifications switched on for the Site, rather than by our cookie panel. Lifetime: until you turn notifications off for this Site.
  • \t
  • prs.push.*, prs.a2hs.* (local storage, not cookies) – records that you have already been asked about notifications and about adding the Site to your home screen, so that you are not asked again on every visit. Lifetime: until you clear your browser storage.
  • \t
  • lnkFrSignup (cookie) – which link brought you to the sign-up page, so that the plan you were looking at is the plan pre-selected at checkout. It is read by our own server; it is not used for advertising and is not shared. Lifetime: 7 days.
  • \t
  • prsTestFontSize (local storage, not a cookie) – the text size you chose in the test engine, so that it is the same the next time you sit a test. It stays in your browser and is never sent to us. Lifetime: until you clear your browser storage.

Analytics

These tell us how the Site is used, so that we can see which material is working. Nothing here is loaded unless you allow the analytics category: until you do, your browser makes no request to googletagmanager.com and no Google analytics script is placed on the page.

    \t
  • Google Analytics (_ga, _ga_*, and the short-lived _gid and _gat cookies, set by Google) – visit counts, pages viewed and general usage patterns, reported both for the site you are on and in a combined view covering all six of our board review sites. Lifetime: up to 2 years for _ga and _ga_*; _gid expires after about a day and _gat after about a minute.
  • \t
  • Google Tag Manager (googletagmanager.com, set by Google) – the container we use to manage the tags above. It is worth being exact about this one: the container is loaded under the analytics permission and has no separate switch of its own, so if you allow analytics and refuse advertising the container is still loaded, and any tag we deliver through the container is delivered on your analytics permission. Lifetime: the container sets no cookie of its own; any cookies come from the tags it delivers.

Advertising

These tell us whether an advertisement led to a sign-up, allow us to provide our video. Nothing here is loaded unless you allow the advertising category. We do not run any advertising or conversion-measurement tag on this Site, and nothing in this category is shared with an advertising network.

    \t \t
  • JW Player (content.jwplatform.com, set by JW Player) – the video on our home, question bank and oral board pages. JW Player stores its own playback and measurement data. Until you allow advertising, those pages show a message in place of the video together with a button that reopens the cookie settings, and no player script is requested. Lifetime: as set by JW Player.

What “not loaded” means here

For the analytics and advertising categories, refusing is not a matter of blocking cookies after the fact. The script is never requested: choosing “Reject all” produces no request to googletagmanager.com and none to the video library, so no identifier is created and nothing is sent, not even a measurement without cookies. Alongside that, this Site publishes Google’s own consent settings on every page, whether or not any Google tag is ever loaded, denying advertising storage, advertising user data, advertising personalization, analytics storage and personalization storage and allowing only functionality and security, and updates them the moment you change your choice.

The one request to another company that your choice does not govern is the typeface. Google Fonts is requested in the head of every page, before the banner is answered and whatever the answer is. It sets no cookie and measures nothing, but the request itself discloses your IP address, the address of the page you are viewing and your browser and operating system to Google, and no setting in the panel can prevent it.

What we record when you make a choice

When you answer the banner or change your settings, we write one row in our own database, so that we can show what you were asked and what you answered. That row contains the random identifier from the prs_consent_id cookie; your user account identifier, but only if you were signed in when you answered; whether you accepted all, rejected all, or chose your own combination; the resulting on or off state of each of the four categories above; the version label of the banner, and the version label of this policy where one has been set, both taken from our own configuration and never from your browser; which control you used to answer, being the banner, the settings panel or the footer link; your IP address and your browser’s user agent string; and the date and time.

Each decision adds a new row, and no row is altered or deleted, so the history of your choices is preserved rather than overwritten. We keep the decision itself indefinitely, because it is our evidence that permission was asked for and was given or refused. The IP address and the user agent are the only personal information in the row, and they are kept as evidence for 400 days and then erased from it outright rather than masked, leaving the decision behind and the row marked as cleared. To be accurate about the mechanics, that erasure is carried out while a later consent submission is being handled rather than at a fixed hour, so a row becomes eligible at 400 days and is cleared the next time the routine runs. We do not use this record to build a profile of you, it is not used to advertise to you, and it is not shared with any advertiser.

Because the prs_consent_id value is random and is written only at the moment you choose, it is the only link between a visitor who is not signed in and that visitor’s rows. If you clear your cookies, that link is gone and we cannot connect you to your earlier record; if you were signed in when you answered, your account identifier is in the row and we can.

Changing or withdrawing your choice

Withdrawing takes the same single step that giving it took. A “Cookie Preferences” link in the footer of our main pages reopens the settings panel at any time, and every category except strictly necessary can be turned on or off there, individually or all at once. On the signed-in dashboard the same control sits in your account menu. On the pages that have neither – the test engine, the oral board screens, and the sign-in and sign-up pages – a “Cookie Preferences” link is placed at the end of the page instead, so the panel is reachable from wherever you are. If you choose “Withdraw all consent” and a tag or the video player was already running on the page you are viewing, that page reloads once your new choice has been recorded, so that what was running stops; if nothing had been loaded on that page, the change is confirmed without a reload. If instead you turn a single category off and save, your choice takes effect at once and nothing further in that category is loaded, but a script that had already started on that page continues to run until you leave that page or reload it. Withdrawing does not undo what was already collected while the permission was in force.

You can also delete everything listed above through your browser’s own settings, which removes your recorded choice and causes the banner to ask you again; because the identifier is created only at the moment you answer, we will then have no way to connect you to the answer you gave before. The strictly necessary items will be created again as you use the Site, and blocking them will stop parts of it working. Finally, and worth repeating here: this Site does not read or act on a “do not track” header, on the Global Privacy Control signal, or on any other automatic browser signal, so setting one will not change what loads here. The choice you make in the banner or in the settings panel is the one that governs.

Draft for legal review — not yet in force. The sections below describe how this site handles email, notification preferences, cookies and analytics. They were drafted on 18 September 2026 and are published here so they can be reviewed in place. They have not been approved and do not yet form part of the policy above.

Email we send you

We send two kinds of email, and they are handled differently.

Account and service email is sent because you have an account or have asked us for something: sign-in and verification codes, password resets, purchase receipts, subscription notices, and replies to messages you send us through the contact form. This email is part of the service. It carries no unsubscribe link and it continues whatever your marketing preferences are, because switching off a password reset is not something we can offer. If you want it to stop, write to us and we will talk through what is possible for your account.

Marketing email is everything else, and you can switch all of it off at any time. It is organised into categories, each of which you can turn on or off on its own. We do not list those categories here on purpose: they can be added to or renamed, and a list printed in this policy would quietly go out of date. The live list is always the one on your email preferences page, which names every category and describes what each one covers, including the ones that are only ever sent as a notification on the site or your device rather than as an email. One further category, Institutional report, is the quarterly usage report we send to the administrator of an institution about their own programme; it is sent because of that administrative relationship rather than as marketing, so it is shown to you but cannot be switched off. Study reminders are a service reminder rather than marketing: unsubscribing from marketing does not stop them, and they have their own switch on the preferences page.

When you create an account, the signup form tells you that clicking “Start Learning” means you agree to our Terms of Use and this Privacy Policy, and we record that as your starting position for marketing email. There is no separate marketing tick box at signup. You can change it immediately and at any time afterwards.

Changing what you receive

Every marketing email carries a link to a preferences page for the address it was sent to. That page opens without a login: the link itself is the permission, so we do not sign you in, we do not set a cookie, and the page can do exactly one thing – manage marketing preferences for that one address. It cannot be pointed at anybody else’s address, and the address is taken from the link rather than from anything typed into the page.

On that page you can unsubscribe from all marketing email and browser notifications at once, turn individual categories on or off for email and, where your browser is registered for them, for notifications, and switch off all browser notifications while leaving your devices registered. Marketing emails also carry the standard one-click unsubscribe headers, so your mail provider can offer its own unsubscribe button; that route only ever removes you, and it keeps working however old the email is.

Turning marketing back on from a link in an email works for 30 days from the date that link was issued. After that the link will still unsubscribe you, but to opt back in you will be asked to sign in and use the notification settings in your account, because a sign-in is better proof of who is asking than a link in an old email.

When you unsubscribe we keep a record of the address, so that we do not send to it again. That record is not deleted when you resubscribe – it is marked inactive instead, because it is the evidence that your request was honoured while it stood. We also add an address to that list when mail to it hard bounces, when a spam complaint is reported to us, or when our email provider tells us the address should not be mailed. Whether you can reverse it yourself depends on why it was added: an unsubscribe you can undo, a bounce or a complaint you cannot. Your preferences are checked at the moment each message is sent, not when the mailing list was drawn up, so unsubscribing after a campaign has been prepared still stops it reaching you.

What we record about the email itself

Our email is delivered by Postmark, and their systems process the message in order to send it. For every message we attempt, we keep a record of the address we sent to, the subject line, which campaign and template it came from, when we sent it, and whether the provider accepted it. We keep those records indefinitely, because they are how we can answer later whether a particular message was sent.

Our provider then reports back what happened to the message, and we store what they tell us: that it was delivered, that it was opened, that a link in it was clicked, that it bounced, or that it was reported as spam – each with the recipient address and the time. We deliberately do not store the contents of these reports wholesale: we rebuild each record from a fixed list of fields we have decided to keep, so the original message body, the subject line, and the location and device information that a bounce or complaint report can carry are not retained by us.

Links in marketing emails are tagged with four standard campaign parameters – the source, the medium, the campaign and which link in the message it was. They carry no identifier for you personally, so a click tells us that someone who received a particular campaign arrived, not which recipient it was. Account and service emails are not tagged at all.

Cookies and similar storage

The first time you visit, a banner asks you to choose. It offers “Accept all”, “Reject all” and “Manage preferences”, and it lists every cookie and third-party script the site uses, what each is for, and how long it lasts. There are four categories:

  • Strictly necessary – always on, and not something we can offer to switch off. These sign you in, hold your place while you work through a test, take payment, block automated abuse, and record the cookie choice you have just made.
  • Analytics – counts visits and shows us which pages and features are used. If you say no, no analytics script is loaded at all and no analytics cookie is written.
  • Advertising – today this covers only the video player, which is a third-party product that stores its own playback and measurement data on your device. We do not run any advertising or conversion-measurement tag on this site. If you say no, the player is not loaded and the videos show a short message instead.
  • Functional – small preferences such as the text size you chose in the test engine, which link brought you to the signup page, and whether you have already been asked about notifications.

Nothing in the three optional categories is loaded until you allow it. This is a decision about whether the script runs at all, not a setting passed to a script that has already loaded. Saying no to functional storage also deletes what is already stored under it; being straight about the limit, two of those items are written by other parts of the site, so one may be written again later in your visit until those parts are changed to ask first.

Two things reach third parties on every page whatever you choose here, and both are named in the banner’s own list. The site’s typeface is requested from Google Fonts, which sets no cookie and is not an analytics or advertising tag, but does mean Google sees your IP address and browser on every page view. Cloudflare Turnstile, which tells a person from an automated script, is loaded on every page of the main site even though the challenge itself only runs on the contact and scholarship forms.

Closing the banner without choosing is not consent: nothing optional is loaded, nothing is recorded, and the banner comes back. You can change or withdraw your choice at any time from the “Cookie preferences” link in the footer.

Analytics

If you allow analytics, we load Google Analytics and, where it is configured, a Google Tag Manager container. We send product-usage events – that a pricing page was viewed, that a signup started, that a test was created or completed, that a flashcard was reviewed, that a purchase happened, that an error page was shown, and similar. Each event carries whether the visitor was signed in or not, as one of two words, and never a user id, a name or an email address.

Page addresses are cleaned before they are sent: only a short list of parameters is kept – the selected tab and the standard campaign parameters – and everything else in the address is dropped from the page address we report. Google's own tag separately records the address shown in your browser at the time, which is a part of its own behaviour rather than something this site sends.

The record of your choices

We keep a record of the consent choices themselves, separately from the cookie on your device, because a choice that exists only in your browser cannot be produced later if you ask us what you agreed to.

For cookie choices, we record a random identifier for the browser, your account if you were signed in, which of the four categories you allowed, the version of the policy and of the banner you were shown, where on the site you answered, your IP address and your browser’s user-agent string, and the time. Each decision is a new record; we never overwrite an earlier one. The random identifier is generated for this purpose alone, is not derived from anything you typed, and identifies a browser rather than a person. The two cookies that carry it and your choice last 13 months and are written only once you have made a choice. Cookie decisions from known search-engine crawlers are applied but not recorded.

For marketing choices, we record the email address, your account if there is one, what changed and on which channel, the version of the policy in force, the route you used, which campaign the link came from where it came from one, your IP address and user-agent string, and the time.

The IP address and user-agent string in these records are the part that identifies you rather than your choice, so they are deleted on a clock: 400 days after a cookie decision, and 90 days after a marketing choice. The record of the decision itself is kept, marked to show the identifying details have been removed. Both periods are settings, and if either is changed this paragraph will change with it.

When you make a cookie choice, it is applied on your device first and then sent to us. If that fails, your choice still stands on your device but we will have no record of it.

Browser notifications

If you accept your browser’s own notification prompt, your browser gives us an address at its push service so that we can send notifications to that device. We store that address, a fingerprint of it, the two keys your browser supplies so the message can be encrypted, which push service it belongs to, and the account it is for. That subscription is created only by accepting the browser’s prompt, and it is that prompt and your browser’s settings – not the cookie banner – that control it. Unsubscribing from marketing also stops marketing notifications.

Surveys, reviews and feedback

We sometimes email a link asking you to answer a survey, leave a review, or react to a feature. Those links work the same way as the preferences page: the link is the permission, no login is involved, and it expires. We store what you submit – star ratings, the options you chose, and any free text you write – against your account. A review is held for moderation before it is used. If a moderator edits a review, the edit is stored alongside your original words rather than replacing them, and the change is logged.