Security
Your account holds your study history, and for some of you, a subscription. Here is how it is protected — stated plainly, including the limits.
Your account
- Passwords are never stored — only a secure hash of them.
- New accounts confirm their email address before they can sign in.
- Two-factor authentication is available in Settings.
- Changing a password requires signing in again and a six-digit code sent to your email.
- Sign-up, sign-in and password resets are protected against automated bots.
- An account can be active on a limited number of devices at once.
Your data
- All traffic is encrypted in transit (HTTPS, with HSTS enforced).
- Every database table is locked down so that each account can read and change only its own records.
- Administration tools are not on the public website.
- Your practice data is never sold.
Payments
Payments are processed by Stripe. Your card number goes straight to Stripe and never touches our servers.
Every release is tested
A release reaches the site only after an automated gate runs the app end to end, including security checks on who can read and change what. If any check fails, nothing ships.
The honest limit
No online service can promise it will never be attacked. What we can promise is that we build to make attacks hard, limit what any single failure could expose, and tell affected users promptly if their data is ever involved in a breach.
Reporting a vulnerability
If you believe you have found a security issue, please email [email protected] with the details. Please give us a reasonable chance to fix it before disclosing it publicly. We will not take action against good-faith research that avoids harming users or their data.
Home · How our questions are made · Security · Privacy · Terms