Privacy preferences

EngX uses optional analytics to understand how the platform is used, measure performance, and improve the experience. Analytics may involve third-party service providers. You can change this at any time in Settings → Privacy. Privacy Policy

EngXHome

Privacy Policy

Version 1.0 — Effective 2026-08-24

This page describes what EngX actually collects and does today, based on the current product implementation. It is not a certification of legal compliance with any specific law or regulation. Sections marked LEGAL REVIEW REQUIRED have not yet been finalized by qualified legal counsel and should not be relied on as settled.

1. Who EngX is

EngX ("EngX," "we," "us") operates an online platform for practicing engineering problems. EngX's exact legal/business entity name and mailing address are LEGAL REVIEW REQUIRED — see LEGAL REVIEW REQUIRED — EngX legal/business entity name not yet finalized. This policy describes the data practices of the EngX product regardless of final entity naming.

2. Scope of this policy

This policy covers information collected through the EngX website and application, including anonymous visitors, registered accounts, and paying subscribers. It does not cover third-party sites we link to.

3. Information we collect

We collect information in the following categories, and no others:

  • Account/profile information: your email address (managed by our authentication provider), display name, timezone, and in-app appearance/notification preferences.
  • Learning/progress information: which problems and steps you've attempted or completed, your answers and their correctness, attempt counts, daily completion history, and streak data.
  • Subscription/billing information: your subscription tier and status, and identifiers issued by our payment processor, Stripe (Stripe Customer ID, Subscription ID, Price ID). We do not receive or store your raw payment card details — Stripe handles that directly.
  • Consent history/preferences: a record of the choices you make about optional analytics and optional communications (see §7 and §9).
  • Analytics/telemetry information (only after you opt in): page views, feature interactions, and performance metrics — see §9 and our Tracking & Analytics Notice for the full detail.

We do not directly log or store your IP address or browser user-agent string in our own database. Our hosting and analytics infrastructure providers may process this information as part of delivering the service or optional analytics — see §10 and §20.

4. Account/profile information

Your account is created and authenticated through our authentication provider, Supabase. Your email address is managed there. In our own application database, we store a profile record linked to your account: display name, timezone, role, UI preferences, profile visibility settings, and notification preferences.

5. Learning/progress information

To provide the core product — practicing and being graded on engineering problems — we store your step-by-step answers and their correctness, which problems and steps you've completed, your daily completion counts, and your streak history. This data determines what EngX shows you (progress, streaks, resume position) and is not used for any purpose beyond delivering and improving that functionality.

6. Subscription/billing information

If you subscribe to a paid tier, we store your subscription tier, status, billing period, and identifiers issued by Stripe. Stripe processes your payment method and card details directly — EngX's systems never receive or store raw card data. See §20 (Stripe) for the processor relationship.

7. Consent history/preferences

Every decision you make about optional analytics or optional communications (grant or withdraw) is recorded in an append-only history tied to your account, along with when the decision was made and what triggered it. This history is never edited or deleted — a withdrawal is recorded as a new entry, not by erasing the earlier grant. See §26–28.

8. AI usage information

EngX uses OpenAI's API in one admin-only context: generating illustrative diagrams. This feature is restricted to EngX administrators and is not available to, or triggered by, regular user activity. In the normal course of using EngX as a learner, your account data is not sent to OpenAI. See §20 (AI processor) for detail, and our Tracking & Analytics Notice is not applicable here — this is a separate, non-analytics data flow.

9. Analytics/telemetry information

EngX uses PostHog (behavioral analytics), Vercel Web Analytics, and Vercel Speed Insights (performance analytics). None of these run until you explicitly grant analytics consent — via the consent banner on your first visit, or later in Settings → Privacy. If you decline or never respond, no optional analytics of any kind collects data about you. Full detail, including exactly what each provider collects and how withdrawal works, is in our Tracking & Analytics Notice.

10. Technical/security logs

Our hosting provider, Vercel, necessarily processes standard web request metadata (such as IP address and request logs) to deliver the application and for its own infrastructure security — this happens for every request regardless of analytics consent, the same as with any web host. EngX's own application code does not separately collect or store this information. LEGAL REVIEW REQUIRED: the precise retention period and lawful basis for this hosting-level processing.

11. How we use information

We use the information described above only for the following purposes:

  • Service delivery (§12): operating your account, authenticating you, and running the core product.
  • Account management (§13): letting you view, correct, export, and delete your data.
  • Learning/progress functionality (§14): grading your work, tracking your progress and streaks, and showing you where you left off.
  • Billing (§15): processing subscription payments and determining your feature entitlements.
  • Security/fraud prevention (§16): preventing abuse of the grading system (e.g., replayed submissions) and unauthorized account access.
  • Analytics (§17): only with your explicit consent, understanding feature usage and performance to improve EngX.
  • Optional communications (§18): only with your explicit consent, per category.
  • Legal/compliance obligations (§19): where necessary to comply with applicable law.

We do not sell your personal information.

12. Service delivery

Your account and profile information is used to authenticate you and operate the platform.

13. Account management

See §22–25: you can access, correct, export, and delete your account data through self-service tools in Settings.

14. Learning/progress functionality

Your step attempts, progress, completions, and streaks are used exclusively to grade your work and display your own progress back to you.

15. Billing

Subscription and billing identifiers are used to determine your feature entitlements and to process payments through Stripe.

16. Security/fraud prevention

Grading records are used server-side to prevent replay of already-graded submissions. Authentication state is used to prevent one account from accessing or modifying another account's data.

17. Analytics

See §9 and our Tracking & Analytics Notice. Analytics data, when you consent to it, is used only to understand feature usage and platform performance.

18. Optional communications

EngX defines three optional email categories a user may separately consent to: progress emails, product update emails, and marketing/promotional emails. As of this policy's effective date, EngX does not currently send any of these emails — no sender exists yet for any of the three categories. The consent, authorization, and unsubscribe architecture described in §28 exists so that if and when a sender is built, it cannot send to you without your current, specific consent. Transactional/service email (see §19) is separate and unaffected by these preferences.

19. Legal/compliance obligations

We may use or disclose information where required to comply with applicable law, respond to lawful requests, or protect the rights, property, or safety of EngX, our users, or others.

20. Service providers / subprocessors

The following third parties process data on EngX's behalf. Only currently-used providers are listed:

  • Supabase — hosts our database, authentication, and file storage. Processes essentially all application data described in this policy.
  • Vercel — hosts the application and, when you consent, provides Vercel Analytics and Speed Insights.
  • Stripe — processes subscription payments. Receives your billing email and payment details directly; we never receive raw card data.
  • PostHog — provides behavioral analytics, only after explicit consent.
  • Cloudflare (R2) — stores files uploaded by administrators (such as problem diagrams and other content assets).
  • OpenAI — processes admin-submitted prompts for one admin-only feature (diagram generation). Not used to process regular user account data during normal platform use.

LEGAL REVIEW REQUIRED for every provider above: whether a data processing agreement is in place, and the applicable cross-border transfer mechanism. See §21.

21. International processing / transfers

Our service providers may process data in countries other than your own, including the United States. LEGAL REVIEW REQUIRED — the specific data residency of each provider and the applicable cross-border transfer mechanism have not been confirmed.

22. Retention

We keep most of your account and learning data for as long as your account is active. When you delete your account (§23), most data is deleted immediately. A limited set of records — billing identifiers and consent-decision evidence — is retained in a form disconnected from your identity for accounting and legal-evidence purposes. LEGAL REVIEW REQUIRED — the exact retention periods for these records have not been finalized; no specific period is claimed here. See our internal data retention documentation for the full per-category breakdown.

23. Account deletion

You can permanently delete your account from Settings → Privacy Centre → Danger Zone. This cancels any active subscription immediately, and deletes your profile, learning progress, streaks, and AI-feature usage records. Your consent-decision history and billing identifiers are retained in a de-identified form as described in §22, rather than tied to your account.

24. Data export / access

You can download a copy of your data — profile, learning progress, step attempts, streaks, subscription, and consent history — at any time from Settings → Privacy Centre.

25. Correction

You can edit your display name and timezone directly in your profile settings at any time. For corrections to information outside self-service tools (such as your account email), contact us at privacy@engx.app.

26. Consent withdrawal

You can withdraw analytics or communications consent at any time from Settings → Privacy Centre. Withdrawal takes effect on your next relevant action — for analytics, no further events are captured from the moment you withdraw; for optional email, no future matching email may be sent (§28).

27. Analytics withdrawal

See §9 and the Tracking & Analytics Notice for exactly how analytics withdrawal works, including what is cleared from your browser.

28. Email unsubscribe

Every optional email category carries its own unsubscribe link, which works without requiring you to be logged in and takes effect immediately in EngX's systems. Unsubscribing from one optional category (e.g. marketing) never affects transactional/service email, such as password resets or billing receipts, which are not optional and are not covered by this preference. LEGAL REVIEW REQUIRED: confirmation that "immediate effect" satisfies the exact statutory unsubscribe-processing timeframe applicable to EngX's jurisdiction.

29. Security safeguards

Access to your data is restricted through database-level access controls scoped to your own account, and privileged operations (such as account deletion) are handled server-side using credentials never exposed to the browser. No security measure is perfect, and we cannot guarantee absolute security of information transmitted over the internet.

30. Children / minors

EngX does not currently implement age verification, a stated minimum age, or any minors-specific data handling. LEGAL REVIEW REQUIRED — minimum user age / minors policy has not been decided. We do not knowingly market EngX to children, but no COPPA, GDPR-K, or equivalent minors-protection compliance is claimed.

31. Changes to this policy

We may update this policy as EngX's practices change. Material changes will be reflected by incrementing the version number and effective date at the top of this page. LEGAL REVIEW REQUIRED — what constitutes a "material" change requiring direct user notice, as opposed to an update noted here, has not been defined.

32. Contact / privacy requests

For privacy questions or requests not covered by the self-service tools above, contact us at privacy@engx.app. This inbox is not yet staffed on a defined SLA — LEGAL REVIEW REQUIRED for the applicable response-time obligation in your jurisdiction.

Privacy PolicyTerms of ServiceTracking & Analytics NoticePrivacy Centre