EngX uses optional analytics to understand how the platform is used, measure performance, and improve the experience. Analytics may involve third-party service providers. You can change this at any time in Settings → Privacy. Privacy Policy
Version 1.0 — Effective 2026-08-24
This page describes what EngX actually collects and does today, based on the current product implementation. It is not a certification of legal compliance with any specific law or regulation. Sections marked LEGAL REVIEW REQUIRED have not yet been finalized by qualified legal counsel and should not be relied on as settled.
EngX ("EngX," "we," "us") operates an online platform for practicing engineering problems. EngX's exact legal/business entity name and mailing address are LEGAL REVIEW REQUIRED — see LEGAL REVIEW REQUIRED — EngX legal/business entity name not yet finalized. This policy describes the data practices of the EngX product regardless of final entity naming.
This policy covers information collected through the EngX website and application, including anonymous visitors, registered accounts, and paying subscribers. It does not cover third-party sites we link to.
We collect information in the following categories, and no others:
We do not directly log or store your IP address or browser user-agent string in our own database. Our hosting and analytics infrastructure providers may process this information as part of delivering the service or optional analytics — see §10 and §20.
Your account is created and authenticated through our authentication provider, Supabase. Your email address is managed there. In our own application database, we store a profile record linked to your account: display name, timezone, role, UI preferences, profile visibility settings, and notification preferences.
To provide the core product — practicing and being graded on engineering problems — we store your step-by-step answers and their correctness, which problems and steps you've completed, your daily completion counts, and your streak history. This data determines what EngX shows you (progress, streaks, resume position) and is not used for any purpose beyond delivering and improving that functionality.
If you subscribe to a paid tier, we store your subscription tier, status, billing period, and identifiers issued by Stripe. Stripe processes your payment method and card details directly — EngX's systems never receive or store raw card data. See §20 (Stripe) for the processor relationship.
Every decision you make about optional analytics or optional communications (grant or withdraw) is recorded in an append-only history tied to your account, along with when the decision was made and what triggered it. This history is never edited or deleted — a withdrawal is recorded as a new entry, not by erasing the earlier grant. See §26–28.
EngX uses OpenAI's API in one admin-only context: generating illustrative diagrams. This feature is restricted to EngX administrators and is not available to, or triggered by, regular user activity. In the normal course of using EngX as a learner, your account data is not sent to OpenAI. See §20 (AI processor) for detail, and our Tracking & Analytics Notice is not applicable here — this is a separate, non-analytics data flow.
EngX uses PostHog (behavioral analytics), Vercel Web Analytics, and Vercel Speed Insights (performance analytics). None of these run until you explicitly grant analytics consent — via the consent banner on your first visit, or later in Settings → Privacy. If you decline or never respond, no optional analytics of any kind collects data about you. Full detail, including exactly what each provider collects and how withdrawal works, is in our Tracking & Analytics Notice.
Our hosting provider, Vercel, necessarily processes standard web request metadata (such as IP address and request logs) to deliver the application and for its own infrastructure security — this happens for every request regardless of analytics consent, the same as with any web host. EngX's own application code does not separately collect or store this information. LEGAL REVIEW REQUIRED: the precise retention period and lawful basis for this hosting-level processing.
We use the information described above only for the following purposes:
We do not sell your personal information.
Your account and profile information is used to authenticate you and operate the platform.
See §22–25: you can access, correct, export, and delete your account data through self-service tools in Settings.
Your step attempts, progress, completions, and streaks are used exclusively to grade your work and display your own progress back to you.
Subscription and billing identifiers are used to determine your feature entitlements and to process payments through Stripe.
Grading records are used server-side to prevent replay of already-graded submissions. Authentication state is used to prevent one account from accessing or modifying another account's data.
See §9 and our Tracking & Analytics Notice. Analytics data, when you consent to it, is used only to understand feature usage and platform performance.
EngX defines three optional email categories a user may separately consent to: progress emails, product update emails, and marketing/promotional emails. As of this policy's effective date, EngX does not currently send any of these emails — no sender exists yet for any of the three categories. The consent, authorization, and unsubscribe architecture described in §28 exists so that if and when a sender is built, it cannot send to you without your current, specific consent. Transactional/service email (see §19) is separate and unaffected by these preferences.
We may use or disclose information where required to comply with applicable law, respond to lawful requests, or protect the rights, property, or safety of EngX, our users, or others.
The following third parties process data on EngX's behalf. Only currently-used providers are listed:
LEGAL REVIEW REQUIRED for every provider above: whether a data processing agreement is in place, and the applicable cross-border transfer mechanism. See §21.
Our service providers may process data in countries other than your own, including the United States. LEGAL REVIEW REQUIRED — the specific data residency of each provider and the applicable cross-border transfer mechanism have not been confirmed.
We keep most of your account and learning data for as long as your account is active. When you delete your account (§23), most data is deleted immediately. A limited set of records — billing identifiers and consent-decision evidence — is retained in a form disconnected from your identity for accounting and legal-evidence purposes. LEGAL REVIEW REQUIRED — the exact retention periods for these records have not been finalized; no specific period is claimed here. See our internal data retention documentation for the full per-category breakdown.
You can permanently delete your account from Settings → Privacy Centre → Danger Zone. This cancels any active subscription immediately, and deletes your profile, learning progress, streaks, and AI-feature usage records. Your consent-decision history and billing identifiers are retained in a de-identified form as described in §22, rather than tied to your account.
You can download a copy of your data — profile, learning progress, step attempts, streaks, subscription, and consent history — at any time from Settings → Privacy Centre.
You can edit your display name and timezone directly in your profile settings at any time. For corrections to information outside self-service tools (such as your account email), contact us at privacy@engx.app.
You can withdraw analytics or communications consent at any time from Settings → Privacy Centre. Withdrawal takes effect on your next relevant action — for analytics, no further events are captured from the moment you withdraw; for optional email, no future matching email may be sent (§28).
See §9 and the Tracking & Analytics Notice for exactly how analytics withdrawal works, including what is cleared from your browser.
Every optional email category carries its own unsubscribe link, which works without requiring you to be logged in and takes effect immediately in EngX's systems. Unsubscribing from one optional category (e.g. marketing) never affects transactional/service email, such as password resets or billing receipts, which are not optional and are not covered by this preference. LEGAL REVIEW REQUIRED: confirmation that "immediate effect" satisfies the exact statutory unsubscribe-processing timeframe applicable to EngX's jurisdiction.
Access to your data is restricted through database-level access controls scoped to your own account, and privileged operations (such as account deletion) are handled server-side using credentials never exposed to the browser. No security measure is perfect, and we cannot guarantee absolute security of information transmitted over the internet.
EngX does not currently implement age verification, a stated minimum age, or any minors-specific data handling. LEGAL REVIEW REQUIRED — minimum user age / minors policy has not been decided. We do not knowingly market EngX to children, but no COPPA, GDPR-K, or equivalent minors-protection compliance is claimed.
We may update this policy as EngX's practices change. Material changes will be reflected by incrementing the version number and effective date at the top of this page. LEGAL REVIEW REQUIRED — what constitutes a "material" change requiring direct user notice, as opposed to an update noted here, has not been defined.
For privacy questions or requests not covered by the self-service tools above, contact us at privacy@engx.app. This inbox is not yet staffed on a defined SLA — LEGAL REVIEW REQUIRED for the applicable response-time obligation in your jurisdiction.