Examplar logo Examplar
Home Roadmaps Editor GitHub
Privacy & storage

Privacy & Data Storage

Your study progress stays in this browser. The hosted service stores the identity and access records needed for your personal exam library.

Study data stays in your browser. Answers, progress, local imports and editor changes use browser storage. Hosted complete packs are delivered after access checks and are not saved as offline packs by the official player.

Stored in your browser

Imported exams, images, recent attempts, progress, editor changes, theme preference, and local exam visibility settings.

Not sent to the server

Your selected answers, local imported files and filenames, personal progress, and individual study history. Hosted exam requests identify the exam and active session.

Your hosted account

Signing in sends your email to the service and its transactional email provider to deliver a single-use code. The service stores your verified email, personal licences, purchase sale IDs where applicable, authorized browser installations, access sessions and administrative audit records. Codes, session credentials and personal keys are stored as cryptographic digests, not plaintext. Gumroad purchase verification uses the purchase email and licence key; payment-card details remain with the checkout provider.

A random browser installation ID supports the two-browser limit. A secure HTTP-only login cookie keeps you signed in for up to 30 days. A short-lived study authorization in sessionStorage supports one active paid session. These are access controls; analytics opt-out does not disable them. Privileged roles require passkeys. We store public keys and verification metadata; private keys and biometrics remain with the authenticator. Keep a second passkey for recovery. Administrators can manage licences, block access and inspect service activity. Removing a user deactivates access and retains a recoverable account record. Permanent deletion and audit retention require an operational process.

Online analytics

The existing public deployment sends limited product telemetry events to Azure Application Insights. On that configured public site, analytics is enabled by default and can be disabled from the Privacy settings control. Authorized maintainers can inspect event timestamps and coarse Azure-derived client and location metadata for operational analysis. Analytics is not initialized on localhost, private self-hosted URLs, or file URLs. This private preview does not inject an analytics connection string. The description below concerns that separate public-site telemetry; hosted account records are described above.

  • Collected: page views, exam start/completion events, Study Mode session starts, one first-answer interaction per Study session, and completion aggregates, attempt review and missed-question study actions, import success/failure and coarse file size/type buckets, progress and editor import/export actions, unlock, pro modal, purchase-link, and import-activation counts, results-screen upsell and pass-story link counts, GitHub repository link counts from post-result and guide CTAs, generated landing-page CTA, configured session, and exam first-answer interaction counts, pass/fail and coarse score/duration buckets, simple sanitized labels from approved campaign parameters (ref, utm_source, utm_medium, utm_campaign, utm_content), and the external referrer hostname. Values resembling emails, URLs, or paths are discarded.
  • Sanitized campaign labels and the external referrer hostname are kept in sessionStorage for the current tab so later events can retain their acquisition context. A later URL with explicit campaign parameters replaces that tab record. It contains no visitor ID, timestamp, arbitrary query parameter, or full referrer URL. Opting out clears the tab attribution.
  • Azure Application Insights temporarily uses the sender IP to derive coarse country, region, and city information, then does not store the full IP address under the configured default behavior. Azure can also attach browser, operating system, device type, and device model metadata to telemetry.
  • Bundled exam labels are restricted to ab730, ab731, ab620, sc900, az900, az104, saac03, clfc02, ai901, az305, az400, dp900, dp700, ai103, and sc300. Every other exam is reported only as imported.
  • Study start and first-answer events contain only bounded exam/session context. Study completion telemetry sends session-level question, answered, and correct counts plus coarse accuracy and duration buckets. These aggregates are not linked to question identifiers or content; however, results from very small Study sessions may be inferable. Examplar does not send individual answer events, question IDs or text, options, answer state, or selected responses.
  • Not collected: full referrer URLs or paths, arbitrary query parameters, imported content, filenames, personal study records, persistent visitor IDs, names, or emails. The Study first-answer event is emitted once per Study session; exam first-answer events are bounded interaction counts too.
  • You can turn analytics off from the Privacy settings control on the online site.
  • The analytics workspace is configured with 30-day retention.

External checkout

Purchase links open Gumroad in a new tab. On that click, Examplar adds one coarse referrer domain so a later sale can be attributed to a channel: an allowlisted campaign source such as Google or Reddit, the sanitized external referrer hostname, or examplar.app when no source is available. For a Google Ads visit, Examplar also accepts the bounded click identifiers gclid, gbraid, and wbraid, keeps them in sessionStorage for the current tab, and forwards them only to the Gumroad purchase URL. They are not added to Azure product telemetry or persisted across tabs. Gumroad runs the Google Ads purchase tag on its receipt page to attribute a completed order and report its value, currency, and order ID; enhanced conversions are disabled, so Examplar does not configure that tag to send a buyer email. The incoming page URL, referrer path, campaign name/content, answers, progress, and email are not forwarded by Examplar. When analytics is disabled, stored campaign attribution and Google Ads click identifiers are cleared, and Examplar does not add the extra referrer parameter or Google Ads click identifiers to the checkout URL. The parameters are also not added outside the public site. Gumroad separately processes the buyer and payment details entered on its checkout.

Imports and editor changes

Dragging a local exam file into the app or saving it in the editor updates that browser profile. Authorized administrators publish hosted content through Administration. Hosted paid packs are excluded from the browser editor/export workflow.

Offline behavior

Local imports and the application shell can work offline. The Live catalogue and hosted previews require a connection. Complete hosted exams renew authorization every minute; if it cannot be renewed, the official player pauses no later than the remaining five-minute lease. Login, administration, catalogue and API content are not stored in the service worker cache. Previously delivered content cannot be remotely erased from a recipient's control.

Self-hosting and shared exams

The separate public/local edition can pre-install static exams in user-content/exams/. Live uses its managed catalogue and private pack storage. In both editions, each user's progress and imported private exams stay in their own browser storage.

Storage locations

  • IndexedDB: imported exam content, images, image metadata, progress, and recent attempt review summaries.
  • localStorage: theme, analytics opt-out, exam activation settings, and legacy compatibility mirrors.
  • sessionStorage: sanitized campaign attribution and bounded Google Ads click identifiers for the current browser tab on the public site.
  • Cache Storage: app shell files needed for offline use.

Backups

Browser storage is scoped to the site origin and browser profile. Clearing site data can remove imports and progress. Use the export actions when you need a backup or want to move data to another browser.

Examplar Offline-ready. Browser edits stay local unless exported.

Source Report issue Privacy & storage