Privacy Policy

Last updated: September 4, 2026

This policy explains what ACami stores about you and your child, why we store it, and what we do not do with it. Like our Terms of Use, it is written in plain English, because the people who buy ACami are parents, not lawyers.

The short version: your child's dashboard - where they actually practice - runs no analytics, advertising, or tracking of any kind. Our public pages run Google Ads and Google Analytics, on by default, with a real opt-out. We do not sell your personal information, and we do not share it with anyone for advertising or marketing beyond those two Google tags. We do store the practice history your child generates, because the difficulty of the next question depends on how the last ones went.

1. Who this policy is for

ACami accounts belong to adults. A parent or guardian creates the account; children practice under it. That means everything described here — the account, the practice history, the analytics we show — sits under the adult's account and is controlled by that adult. Section 8 covers children's data specifically.

2. Account information

You sign up with an email address and a password, or by continuing with Google. Authentication is handled by Supabase, our database and auth provider, which stores your email address and, for a password account, a hashed version of your password. We never see or store your password itself.

If you continue with Google, Google tells us the email address on your Google account and whether it has been verified, and we never receive your Google password. Using that button also tells Google that you have an account here. If that email address already has a password account with us, continuing with Google signs you into that same account rather than creating a second one. There is no sign-in through Facebook or any other social account.

3. Practice data

This is the part worth reading carefully, because we do keep a fair amount of it. ACami adapts to the student, and adapting requires a record of how they have done. For each account we store:

  • Practice sessions — which section was practiced, when it started and finished, how many questions were asked, how many were right, how long the session took, and the points earned.
  • Individual answers — for every question: which option was chosen, whether it was correct, how many milliseconds it took, and the difficulty of the question at the time. We also store the explanation shown for a missed question, so the results page can show it again later without regenerating the item.
  • Per-question review state — how many times a question has come back, how well it went, and when it is due again. This is what drives spaced repetition.
  • Skill ratings — one difficulty rating per skill area, updated after every answer. This is how the system decides whether the next question should be harder or easier.

We use this to run the product: to pick the next question, to schedule reviews, and to draw the progress charts on the dashboard. We do not use it to build a profile of your child for any other purpose, and we do not share it with schools, districts, or test publishers.

4. The entry calculator

If you use the entry calculator while signed in, we save one row of the numbers you typed in: the four report-card grades, the neighborhood tier you selected, the schools you picked, and which year's cutoffs you were comparing against. That is the whole row. We save it so the calculator still has your inputs when you come back.

We do not ask for and do not store your home address, and we do not convert an address into a tier — you choose the tier yourself. The estimated score is not stored either; it is recalculated each time you look at it, against the current published cutoffs.

If you use the calculator without an account, your inputs stay in your own browser's local storage and are never sent to us. Clearing your browser data removes them.

5. Cookies and tracking

ACami sets a handful of cookies of its own. Every one of them is strictly necessary: each exists to make something on the site work, and none of them is advertising or analytics. This is the complete list.

  • Keeping you signed in - the cookies Supabase, our authentication provider, uses to sign you in and keep you signed in as you move between pages. Without them, every click would log you out.
  • Getting you back from Google - if you choose "continue with Google" on the sign-in page, we set a cookie called "oauth_redirect_to" that remembers the page you were on, so we can return you to it afterward. It lasts ten minutes, and it is cleared the moment you come back.
  • Which child you are looking at - if your account has more than one child, a cookie called "active_student" remembers whose practice you are currently viewing, so the dashboard does not jump back to your first child on every page. It lasts a year. This is the one cookie set inside the dashboard itself, and a family with a single child never gets it.
  • An unfinished practice test taken without an account - a cookie called "full_test_attempt" that remembers a full-length practice test in progress for someone who is not signed in, for seven days. Nothing sets it today: a full-length test now requires an account, so this one is switched off.
  • Preview builds only - a cookie called "program" that remembers which version of the site an internal preview build is showing, for one day. It is never set and never read on the live site: on any address we publish, the site works out which version to show from the address itself and does not consult this cookie at all. It exists for preview builds and for development on our own machines.

None of these is an advertising or analytics cookie. Your child's dashboard, the place they actually practice, loads no advertising tag, analytics tag, or third-party script of any kind; see section 6.

Our public pages — the ones anyone can read without signing in, such as the home page, the pricing page, checkout, and the interactive sample at /try-it — also run two Google tags: a Google Ads conversion tag and Google Analytics (GA4). The Ads tag tells us when a visit that started from an ad led to a purchase; Analytics tells us, in aggregate, how people use the public site. Both are Google's tags, and Google's own cookies come with them, including a doubleclick.net cookie the Ads tag uses to attribute a purchase to an ad. /try-it renders the same dashboard interface a purchaser's child would use, with invented sample data — but it is still a public page, so these two tags load there like anywhere else on the public site. The moment your child signs in and starts practicing for real, they leave every one of these tags behind.

These two tags are on by default. You can turn them off at any time — use the "Turn off tracking" button the first time the cookie notice shows, or the control below. Your choice is stored in this browser and respected on every visit after, and turning tracking off stops both tags from setting a cookie on your next page load.

6. What we do not do

There is no tracking inside your child's dashboard.

No Google Analytics, no advertising pixels, and no session recording or replay tools run anywhere your child signs in and practices. Section 5 names exactly what runs on the public pages instead, on which pages, and how to turn it off. We do not sell your personal information, and we do not share it with anyone for advertising or marketing beyond the two Google tags described there.

Where the dashboard says "analytics", it means charts about your child's own practice, computed from the data in section 3 and shown only to you. It is not a tracking product.

7. Service providers

We use a small number of companies to run the service, and they process data on our behalf rather than for their own purposes:

  • Supabase — hosts our database and handles sign-in. Your account and all the practice data in section 3 live there.
  • Google — only if you choose "Continue with Google". Google confirms your email address to us, and learns that you have an account here. If you sign up with an email address and password instead, nothing about you goes to Google.
  • Vercel — hosts and serves the site. Like any web host, it processes the requests your browser makes, which includes an IP address, and keeps operational logs of them.
  • Stripe — takes payment for a pass. Section 9 covers what reaches them and what does not.

8. Children's data

Children do not have their own ACami accounts. A child practices under the account of the adult who created it, and the practice data described in section 3 belongs to that account. The account-owning adult can see all of it, export it, and ask us to delete it.

We do not ask for a child's name, date of birth, school, photograph, or contact details, and none of those has a place to be stored. Please do not put a child's personal details into feedback or bug reports either.

9. Payments

Payments are handled by Stripe. When you buy a pass we send you to Stripe's own checkout page to pay, so your card number, expiry and security code are entered on Stripe's site and never reach our servers or our database — there is no card field anywhere on ACami.

We give Stripe your email address and an internal reference to your account, so the payment can be matched back to the right pass. Stripe tells us in return which pass was bought, how much was paid, and its own identifiers for the payment; we store those to grant your access and to keep a record of the purchase. Stripe handles your card details under its own privacy policy, as the party actually processing the payment.

10. How long we keep things

We keep your account and its practice history for as long as your account exists, because that history is what the adaptive difficulty and the progress charts are built from — deleting it resets the student to square one.

If you close your account, or if we shut the service down, we keep the practice history available for export for at least 30 days from that date, and may delete it permanently afterward. That is the same commitment section 12 of the Terms of Use makes. Export anything you want to keep as soon as you know you need it.

You can also ask us to delete your data sooner. Email tfmcmahon@gmail.com from the address on the account and we will do it.

11. Security

Traffic to the site is encrypted in transit. Passwords are stored hashed by our auth provider, not in plain text, and access to a row of practice data is restricted to the account it belongs to. No system is perfectly secure, but we do not keep data we do not need, which is the most reliable protection there is.

Keep your own password private — anyone who has it can see your child's practice history. Tell us at tfmcmahon@gmail.com if you think someone else has got into your account.

12. Your choices

You can see your practice data any time on the dashboard, change or clear your calculator inputs on the calculator page, and close your account whenever you like. For a copy of your data, a correction, or a deletion, email tfmcmahon@gmail.com from the address on the account.

13. Changes to this policy

If we change what we collect or what we do with it, we will update this page and move the "Last updated" date at the top. For significant changes we also email the address on your account.

14. Contact

Questions about this policy, or a request about your data, go to tfmcmahon@gmail.com.

ACami, 3841 N Southport Ave Apt 1, Chicago, IL 60613