Legal

Privacy Policy

Effective date: 3 April 2026

1. About This Policy

PrepPath (“we”, “us”, “our”) operates the website preppath.com.au and the PrepPath application (together, the “Service”). We are committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Policy explains what information we collect, why we collect it, how we use and store it, and your rights regarding that information. By using the Service you agree to the practices described in this Policy.

2. Information We Collect

Account information. When you create an account we collect your email address and a hashed password. We do not store your password in plain text.

Practice data. When you complete a quiz we record your score, the subject and year level practised, the difficulty level, and a timestamp. For logged-in users we also record which individual questions were answered and whether each was answered correctly, so the Service can personalise future sessions.

Usage data. Our hosting infrastructure (Amazon Web Services) may automatically log standard technical information such as your IP address, browser type, and pages visited. This data is used solely for security monitoring and service reliability and is not used to identify you personally.

Communications. If you contact us by email we retain that correspondence to respond to your enquiry and to improve the Service.

We do not collect payment card details directly. If payment processing is introduced, it will be handled by a PCI-compliant third-party provider (such as Stripe) and we will never see or store your card number.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Personalise practice sessions — skipping questions you have already mastered and repeating questions you found difficult
  • Display your session history and progress
  • Respond to your support enquiries
  • Send you transactional emails (e.g. password reset) — we do not send marketing emails without your explicit consent
  • Detect and prevent fraud, abuse, or security incidents

We do not sell your personal information to third parties. We do not use your data for advertising purposes.

4. Children's Privacy

PrepPath is designed to be used by school-age children under parental or guardian supervision. We do not knowingly collect personal information from children under 13 without verifiable parental consent.

If you are a parent or guardian and believe your child under 13 has created an account without your consent, please contact us at preppathwebapp@gmail.com and we will promptly delete the account and all associated data.

We recommend that parents create accounts on behalf of younger children and supervise their use of the Service.

5. Data Storage and Security

All data is stored on Amazon Web Services infrastructure located in Sydney, Australia (ap-southeast-2 region). Your data does not leave Australia.

We implement reasonable technical and organisational security measures including encrypted data transmission (HTTPS/TLS), hashed password storage via Amazon Cognito, and access controls limiting who can view your data.

No method of transmission over the internet is completely secure. While we take reasonable steps to protect your information, we cannot guarantee absolute security.

6. Data Retention

We retain your account and practice data for as long as your account is active. If you request deletion of your account, we will delete or anonymise your personal information within 30 days, except where we are required to retain it by law.

7. Disclosure to Third Parties

We may share your information only in the following limited circumstances:

  • Service providers. Amazon Web Services (hosting and authentication). These providers process data on our behalf and are bound by confidentiality obligations.
  • Legal requirements. If required by law, court order, or government authority.
  • Business transfer. In the event of a merger or acquisition, your data may transfer to the new owner, who will be bound by this Policy.

8. Your Rights

Under the Privacy Act 1988 you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your account and personal data
  • Complain about a breach of the APPs

To exercise any of these rights, email us at preppathwebapp@gmail.com. We will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

9. Cookies and Local Storage

PrepPath uses browser localStorage to remember your quiz settings and, for guest users, which questions you have already seen. We do not use third-party tracking cookies or advertising cookies. We do not use Google Analytics or any similar analytics service.

10. Changes to This Policy

We may update this Policy from time to time. When we do, we will update the effective date at the top of this page. For significant changes we will notify registered users by email. Continued use of the Service after changes are posted constitutes acceptance of the updated Policy.

11. Contact Us

For any privacy-related questions or requests, please contact us at:

PrepPath
New South Wales, Australia
PrepPath is an independent service and is not affiliated with, endorsed by, or associated with ACARA, the NSW Department of Education, or any government body. NAPLAN is a registered trademark of ACARA. OC and Selective are programs of the NSW Department of Education.