Privacy Policy
This policy describes what Prep collects, what it is used for, and what we deliberately cannot see. It is written to be checkable against the software rather than to be reassuring.
Who we are
Prep is operated by Circuvent Technologies. For any privacy question, or to exercise the rights described below, contact support@circuvent.com.
What we collect
| Data | Why | Required? |
|---|---|---|
| Email address | To identify your account and let you sign in | Yes |
| Name | Shown in the app and on documents you generate | No |
| Password | Stored only as a scrypt hash. We never hold the password itself | Only for password sign-in |
| Session records | IP address, browser or device description, and times, so you can review and revoke the devices signed into your account | Yes |
| Your app data | Applications, skills, habits, goals, notes and similar — whatever you enter. Synced so it survives a lost device | No, sync can be avoided by not signing in |
| Documents | Encrypted on your device before upload. We store ciphertext only | No |
| Community profile and posts | Visible to other members. Only created if you opt in | No |
| Activity log | Sign-ins, failed sign-ins, administrative actions — for security and abuse investigation | Yes |
What we cannot read
Documents stored in the vault are encrypted in your browser using AES-256-GCM, with a key derived from a passphrase that is never transmitted. The server receives only ciphertext. Filenames and descriptions are encrypted too, because a filename alone can reveal what a document is.
This is a technical guarantee rather than a promise of good behaviour: there is no mechanism by which we could decrypt your documents, and the administration interface has no route to them.
Where your data goes
Infrastructure
- Vercel — hosting and content delivery (United States)
- Neon — the database (United States)
- Vercel Blob — encrypted document storage, where enabled
Optional features you switch on
- AI assistance. If you use an AI feature, the text you submit for that request is sent to OpenAI to generate a response. Only what you submit for that feature is sent — never your documents, your vault, or your data as a whole. Each use is labelled in the interface at the point of use.
- Google sign-in. If you sign in with Google we receive your email address, name and profile picture.
- Gmail (separate, explicit consent). If you connect it, Prep reads job-search-related messages to classify them and prepare reply drafts. Prep cannot send email. Drafts are written to your Gmail drafts folder for you to review and send yourself. You can disconnect at any time, which revokes our access and deletes the stored credential.
What we do not do
- We do not sell your data.
- We do not share it with advertisers or data brokers.
- We do not use advertising or tracking SDKs.
- We do not track you across other apps or websites.
- We do not collect your location or your contacts.
Visitor statistics
We count page views so we can tell whether anyone is finding the site and which pages are useful. This is measured by us, on our own servers. There is no Google Analytics, no third-party script, and nothing is shared with anyone.
No cookie or identifier is stored on your device for this, which is why the site has no cookie banner — there is nothing to consent to. We also do not store your IP address. Instead, each day a random secret is generated and used to turn your connection into a short code. That code lets us tell two visits apart on the same day without knowing who either of you is, and the secret is deleted after two days, after which the codes cannot be linked back to anyone at all — by us, by anyone who obtained our database, or by a court order.
For each view we record:
- Which page was viewed, chosen from a fixed list of our own pages. Inside the app we record the section only — never anything you typed, and never the name of a document, goal or journal entry.
- The website that linked you to us, as a bare domain name. We deliberately drop the rest of the address, because a full referring URL can contain your search terms.
- Your country, and whether you were on a phone, tablet or computer.
- The date and time.
Nothing here is connected to your account. There is no user identifier in this data and no way to add one, so it cannot be used to see what any particular person looked at. That is a deliberate limit on what we are able to do, not only on what we promise to do.
If your browser sends a Do Not Track or Global Privacy Control signal, we record nothing at all for your visit.
Notifications and two-factor authentication
If you turn on push notifications, your browser gives us an address to deliver to, plus two keys that belong to your device. We store those so we can send you a notification, and nothing else — they cannot be used to read anything from your device or to identify you elsewhere. Turning push off, or clearing your browser data, removes the address. We also delete it automatically as soon as the push service tells us it has stopped working.
If you turn on two-factor authentication, we store the shared secret your authenticator app uses, encrypted, along with hashes of your recovery codes. Recovery codes are hashed the same way passwords are, so nobody can read them out of the database — which is also why we can only show them to you once.
Quiet hours need to know your timezone to be any use, so your browser's timezone is saved with your notification preferences. It is used for that and nothing else.
Taking your data with you
You can download everything we hold about your account at any time from the Account page, without asking us. It includes your profile, everything you entered in the app, your own community posts, your notification history and the security log.
Two things are worth knowing about that file. Your vault documents are included but stay encrypted, because that is the only form we have — download readable copies from the Documents page instead. And other people's messages are excluded, even from conversations you took part in: those are their words, not your data.
The recovery module
Prep includes optional support for people reducing or stopping a compulsive behaviour. Anything you record there — journal entries, triggers, progress — is part of your synced app data and is not visible to administrators through the administration interface, which deliberately shows counts and sizes only.
This module is not a medical service. It does not diagnose or treat anything and does not replace professional care.
How long we keep it
- Account and app data — until you delete your account.
- Sessions — until they expire or you revoke them; expired records are cleared after 30 days.
- Activity log — retained for security investigation. Entries identify accounts by address, so deleting your account removes the link.
- Community posts — when you delete your account, your posts are emptied of content and marked removed, so conversations others are reading keep their shape without retaining what you wrote.
- Visitor statistics — kept for at most 400 days, then deleted. The daily secret that makes them linkable at all is deleted after two days, so older rows are already anonymous.
Deleting your account
Open Settings → Account → Delete account, in the app or on the web. You will be asked for your password and to type your email address, because it cannot be undone.
This removes your account, your synced data, your encrypted documents and the files behind them, your community profile, your linked Google account and all active sessions.
If you cannot access your account, email support@circuvent.com from the address you registered with and we will delete it for you.
Your rights
Depending on where you live, you may have the right to access, correct, export or erase your data, and to object to or restrict its processing. Export and erasure are available in the app; for anything else, contact us at the address above. You also have the right to complain to your local data protection authority.
Security
- All traffic is served over HTTPS.
- Passwords are hashed with scrypt, which is memory-hard by design.
- Session tokens are stored as hashes, so a database copy yields no usable sessions.
- Google credentials, where stored, are encrypted at rest with AES-256-GCM.
- Documents are encrypted before they leave your device.
No system is perfectly secure. If you find a vulnerability, please report it to support@circuvent.com.
Children
Prep is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will remove it.
Changes
If this policy changes materially we will say so in the app before the change takes effect. The date at the top always reflects the current version.