Wysebridge students pass at 81% vs the 47% national average.Start your free trial →

Legal

Privacy Policy

Effective date: May 22, 2026  ·  Wysebridge, LLC

Plain-language summary

Wysebridge collects only what it needs to run your account and improve the platform. We do not sell your personal data. We use Supabase for storage, Stripe for payments, and Google for optional sign-in. You can request deletion of your data at any time.

This Privacy Policy describes how Wysebridge, LLC ("Wysebridge," "we," "our," or "us") collects, uses, and discloses information about you when you use our website at wysebridge.com, our web application at app.wysebridge.com, and any related services (collectively, the "Platform"). By using the Platform, you agree to the practices described in this Policy. If you do not agree, please do not use the Platform.

1. Information We Collect

1.1 Information You Provide

  • Account registration: name, email address, and password (or OAuth token if you sign in with Google).
  • Payment information: billing name, address, and card details — collected and processed directly by Stripe. Wysebridge never stores full card numbers.
  • Communications: any messages you send to our support team, survey responses, or feedback you submit.
  • Study activity you voluntarily input, such as notes or feedback on practice questions.

1.2 Information Collected Automatically

  • Usage data: pages visited, features used, questions answered, flashcards reviewed, exam sessions started and completed, and time spent on the Platform.
  • Device and browser information: IP address, browser type and version, operating system, screen resolution, and referring URL.
  • Session data: authentication tokens, session identifiers, and cookie values (see Section 5).
  • Performance data: page load times, errors encountered, and feature interaction events.

1.3 Information from Third Parties

  • If you sign in with Google, we receive your name, email address, and profile picture from Google's OAuth service.
  • Stripe may share event data (e.g., subscription status changes, payment failures) with us via webhook.

2. How We Use Your Information

We use the information we collect to:

  • Create and maintain your account and authenticate your identity.
  • Deliver the Platform's core features: practice questions, exam simulations, flashcards, study guides, AI tutor, and progress analytics.
  • Process payments, manage your subscription, and send receipts and billing communications.
  • Power our adaptive learning engine, which routes practice questions to your weakest MPEP chapters based on your performance history.
  • Send transactional emails (password resets, account confirmations, exam reminders) and, where you have opted in, product update and promotional emails.
  • Monitor and improve Platform performance, diagnose bugs, and develop new features.
  • Comply with legal obligations, resolve disputes, and enforce our Terms of Service.
  • Protect against fraud, abuse, and security threats.

We do not use your data to train third-party AI models, and we do not sell, rent, or share your personal data with third-party advertisers.

3. Sharing & Disclosure

We share your information only in the following circumstances:

3.1 Service Providers

We engage trusted third-party companies to operate portions of the Platform under data processing agreements that restrict their use of your data. Current sub-processors include:

  • Supabase — database hosting and authentication (PostgreSQL, Row-Level Security enforced).
  • Stripe — payment processing. Stripe is PCI DSS Level 1 certified.
  • Google — optional OAuth sign-in (Google Identity Services).
  • Anthropic / OpenAI — AI Tutor responses. Prompts may include your question text; no account-identifying information is included in AI requests.
  • Vercel / Cloudflare — CDN and edge delivery for the Platform.

3.2 Legal Requirements

We may disclose your information if required by applicable law, court order, or government authority, or when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, or investigate fraud.

3.3 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred to the acquiring entity. We will provide notice before your data is transferred and becomes subject to a different privacy policy.

3.4 Aggregated / De-identified Data

We may share aggregated or de-identified data (for example, "Wysebridge students score an average of 74% on Chapter 700 after two weeks of study") that cannot reasonably be used to identify you.

4. Cookies & Tracking

We use cookies and similar technologies to operate and improve the Platform:

  • Essential cookies: required for authentication and session management. The Platform does not function without these.
  • Preference cookies: remember your display settings and study preferences.
  • Analytics cookies: we use privacy-respecting analytics to understand aggregate usage patterns. These do not fingerprint individual users.
  • No third-party advertising cookies are set on the Platform.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. Disabling essential cookies will prevent you from logging in.

5. Data Retention

We retain your account data for as long as your account is active or as needed to provide you services. If you close your account, we delete your personal information within 90 days, except where retention is required by law (for example, financial records related to billing, which we retain for 7 years as required by applicable tax regulations).

Aggregated, de-identified study performance data (not linked to your account) may be retained indefinitely to improve the Platform.

6. Your Rights & Choices

Depending on your location, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request correction of inaccurate or incomplete data.
  • Deletion: request deletion of your account and associated personal data.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection / restriction: object to or request restriction of certain processing.
  • Withdraw consent: where processing is based on consent, withdraw it at any time (this does not affect prior processing).
  • Opt out of marketing emails: use the unsubscribe link in any marketing email, or update your preferences in Account Settings.

To exercise any of these rights, email us at privacy@wysebridge.com. We will respond within 30 days (or sooner where required by applicable law).

California residents: you have the right not to be discriminated against for exercising your CCPA/CPRA rights. We do not sell personal information as defined under California law.

EEA/UK residents: our legal bases for processing include performance of a contract (operating your account), legitimate interests (improving the Platform, preventing fraud), and compliance with legal obligations. You may lodge a complaint with your local supervisory authority.

7. Security

We implement reasonable technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encrypted connections (HTTPS/TLS) on all Platform endpoints.
  • Database Row-Level Security (RLS) via Supabase, ensuring each user can access only their own data.
  • Hashed and salted passwords — plaintext passwords are never stored.
  • Payment data processed exclusively by Stripe (PCI DSS Level 1); card numbers never touch our servers.
  • Regular dependency audits and security scanning.

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

8. Children's Privacy

The Platform is intended for individuals who are at least 18 years old (or the age of majority in their jurisdiction). We do not knowingly collect personal information from anyone under 13. If we learn we have collected information from a child under 13 without parental consent, we will delete it promptly. If you believe a minor has provided us with personal information, please contact us at privacy@wysebridge.com.

9. International Data Transfers

Wysebridge is operated from the United States. If you access the Platform from outside the U.S., your information may be transferred to and processed in the U.S. or other countries where our service providers operate. These countries may have data protection laws different from your own.

For transfers from the European Economic Area (EEA) or United Kingdom, we rely on Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Agreement (IDTA) to ensure adequate protections for your personal data.

10. Third-Party Services

The Platform may contain links to third-party websites (for example, the USPTO website, Prometric, or legal reference sources). This Privacy Policy does not apply to those third-party sites. We encourage you to review their privacy policies before providing personal information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (at the address associated with your account) and/or by posting a prominent notice on the Platform at least 14 days before the changes take effect. The "Effective date" at the top of this page will always reflect the current version. Continued use of the Platform after the effective date constitutes your acceptance of the updated Policy.

12. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:

Wysebridge, LLC

Privacy inquiries: privacy@wysebridge.com

Support: support@wysebridge.com

We aim to respond to all privacy inquiries within 5 business days and to resolve all requests within 30 days (or sooner as required by law).

Last updated: May 22, 2026

Terms of Service →