Introduction
This Privacy Policy explains what data PrepLab collects when you use the service, why we collect it, who we share it with, and what you can ask us to do with it.
Who Is Responsible For Your Data
PrepLab is operated from Ukraine by the two teachers who write the lessons. Each of us is registered separately as an individual entrepreneur (ФОП), and for the purposes of this policy we act as joint controllers: we decide together what data is collected, why, and how long it is kept.
Being joint controllers means you can exercise any of the rights described below against either of us, and it makes no difference which one you write to — the request reaches both. Whichever of us receives it is responsible for answering it.
Contact for anything to do with your data: [email protected]. Both of us read that inbox and we usually reply within a few business days. Our full registration details — registered names and entrepreneur registration numbers — are available on request to the same address.
We have not appointed a Data Protection Officer and are not required to at our size.
Data We Collect
We collect only what the service needs to work:
- Account data — your email address; an Argon2 hash of your password, never the password itself; a Google account identifier, the stable subject identifier Google returns, if you sign in with Google; whether your email is verified and whether the account is disabled; the date and time you accepted the Terms of Service and this Privacy Policy, if you created your account with an email address and a password; and the times the account was created and last changed.
- What we do not collect — your full name, your phone number, or your postal address. PrepLab has no fields for them and never asks you for them.
- Purchase and subscription records — which lessons and plans you bought and when, together with our internal order reference, the amount and currency, the transaction status, the plan you chose (Monthly, 6-Month or 12-Month), the subscription status and price, the start, expiry and cancellation dates, and an append-only log of billing events.
- Payment references — the WayForPay order references, the transaction outcomes, and the recurring-payment token WayForPay returns for a Monthly subscription. We never receive your card number, CVV or expiry date.
- Technical data — session cookies and standard server logs needed to keep you signed in and to keep the service secure. Logs record your IP address, your browser’s user-agent string and the time of each request. Signing in also creates short-lived server-side records: your active sessions, and single-use email-verification and password-reset tokens, of which we store only a SHA-256 hash and never the token itself.
- Content access records — the set of lessons and lesson sets your purchases and subscription currently give you access to.
How We Use Your Data
We use your data to give you access to what you paid for, to keep your account secure, to send transactional email such as verification and password-reset links, and to answer your support messages.
We do not sell your data, and we do not use it for third-party advertising. We use no third-party analytics — no Google Analytics, no PostHog, no Plausible, no Mixpanel, no Segment. We embed no advertising trackers and no marketing pixels.
Payment Data and WayForPay
All payments are processed by WayForPay, a Ukrainian payment processor. Your card details go directly to WayForPay during checkout — PrepLab never sees or stores your card number, CVV, expiry date, or billing address. We keep only the order references, the transaction outcomes, and the recurring-payment token WayForPay returns for a Monthly subscription, so we can match a payment to your lesson or subscription.
Your card data is subject to WayForPay's own privacy practices. WayForPay is our sole payment processor — we do not use Stripe, PayPal, or any other.
Data Retention
We keep your account and purchase records for as long as your account exists, because they are what proves your access to the lessons you bought. Server logs are retained for a limited period for security and debugging. Auth tokens are short-lived: email-verification and password-reset tokens expire on a timer and stop working after a single use.
Commerce records — purchases, subscriptions and billing events — outlive the account. When an account is closed we anonymise it rather than delete the row, because those records point at it, and we keep them for accounting, tax and dispute-resolution purposes for the periods applicable law requires, which for digital-goods commerce typically spans several years.
Your Rights Over Your Data
You can ask us for any of the following at any time by writing to [email protected]. We usually reply within a few business days and act on the request within 30 days.
- Access — a copy of the personal data we hold about you.
- Correction — have anything inaccurate fixed. You can also change your email yourself from the Profile tab in your Dashboard.
- Erasure — have your account closed and your personal data erased. You can do this yourself: Dashboard, Profile tab, Delete account. It is permanent and ends your access to everything you bought, so download anything you want to keep first. We anonymise the account rather than deleting the record outright, because your payment records point at it and are kept for accounting and tax — see Data Retention above. We can also close an account ourselves — if you ask us to, or if we have to for a policy reason. It does the same thing to the account, and we keep a permanent record of who did it: that record names the person on our side who acted, and holds nothing further about you.
- Export — your data in a portable, machine-readable format.
- Objection and restriction — ask us to stop or limit a particular use of your data.
- Withdraw consent — where we rely on consent, you can withdraw it without affecting anything done before you did.
Why We Are Allowed To Hold It
Account and purchase records: to perform the contract you entered into when you bought a lesson or took a subscription. Without them we cannot prove what you have access to.
Transactional email such as verification links, password resets and receipts: also contract performance.
The record of when you accepted the Terms of Service and this Privacy Policy: our legitimate interest in being able to show that you agreed to them before the account was created.
Support messages and the reCAPTCHA check on the contact form: our legitimate interest in answering you and in keeping the form free of automated abuse.
Server logs: our legitimate interest in keeping the service secure and working.
If You Are Not Happy With Our Answer
Write to us first at [email protected] — it reaches both joint controllers. If we cannot resolve it, you have the right to complain to a data protection authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU or the UK, the supervisory authority for the country you live in.
Security
Passwords are stored hashed with Argon2, never in plain text, so we never see or store the password itself. Signing in uses an HttpOnly session cookie, which browser JavaScript cannot read. Content files are served through short-lived signed S3 URLs rather than public links, so a lesson file cannot be shared by copying its address — only a signed-in user with valid access is issued a fresh URL. All traffic to PrepLab is secured by HTTPS at the ingress. If you believe your account has been compromised, contact us and we can disable it on request.
Children's Privacy
PrepLab is intended for tutors and other adult educators, and is not directed to children under 13, or the applicable local age of digital consent where that is higher. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
Third-Party Services
PrepLab relies on a small number of third-party services, each of which has its own privacy policy:
- WayForPay — payment processing and checkout. Receives the card-payment data you enter at checkout, and returns transaction outcomes and recurring-payment tokens to us.
- Google — optional sign-in, and reCAPTCHA on the contact form. When you sign in with Google, Google returns your email and a stable subject identifier to us.
- Our object-storage provider — hosts lesson PDFs and lesson thumbnails. PDFs are served only through short-lived signed URLs.
- Our email delivery provider — sends transactional email: verification, password reset, purchase confirmation and subscription notices.
- Miro and Canva — board and design templates linked from lessons. Opening one is subject to that platform’s own terms.
We do not embed any third-party analytics, advertising, or marketing SDKs in the PrepLab frontend.
Changes to This Policy
We may update this policy from time to time. The version published on this page is always the one in force. For material changes we will make reasonable efforts to notify you by email or an in-product notice before they take effect. Continued use of the service after a change constitutes acceptance of the revised policy.
Contact Us
Questions about your data or this policy? Reach us at [email protected].
Questions about this document? Reach us at [email protected].