ArmorOne
  • Dashboard
  • Get Started
Legal

Privacy Policy

Effective and last updated: July 15, 2026

This Privacy Policy explains how ArmorOne Inc ("ArmorOne," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you visit or use www.armoroneprep.com and its account, practice, testing, score, dashboard, billing, and related features (the "Service").

Important points. You must be at least 13 to create an account. ArmorOne is a direct-to-consumer service, not a school service under the public Terms. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. Payment-card details are collected and handled by Stripe, not stored in ArmorOne's database.

1. Scope and who we are

ArmorOne operates an independent ACT-format test-preparation service for individual students and families. ArmorOne is the controller or business responsible for the personal information described in this policy. Questions and privacy requests may be sent to armoronetech@gmail.com.

This policy applies to the public website, anonymous diagnostic and Question of the Day features, account creation and sign-in, Google sign-in, practice and full-test features, score calculators and estimates, saved progress and results, daily streaks, account settings, ArmorOne Unlimited billing, support communications, and the related hosting, security, and analytics systems.

ArmorOne is not affiliated with, endorsed by, sponsored by, or approved by ACT Education Corp. "ACT" is a trademark of its owner and is used only to identify the exam format for which users prepare.

2. Notice at collection

The categories below describe what we collect, why we collect it, how long we generally keep it, and the types of recipients to which it may be disclosed. We do not sell or share any category for cross-context behavioral advertising.

Account, profile, and age-verification information

  • What we collect: name, email address, internal user ID, authentication provider, password credential in hashed form through Supabase Auth, date of birth, server-controlled age-verification status, target-exam preferences, and account timestamps.
  • Why: create and authenticate accounts, verify that account holders are at least 13, support account recovery, personalize account features, and prevent unauthorized access.
  • General retention: while the account is active, then until deletion or for a limited period when reasonably necessary for legal, security, fraud-prevention, or dispute purposes. Unfinished Google sign-ups are normally removed after the short verification window described in Section 10.
  • Recipients: Supabase; Google if you choose Google sign-in; Cloudflare when Turnstile is used; and professional advisors or authorities when legally necessary.

Study, progress, performance, and entitlement information

  • What we collect: target exams; recent feature activity; in-progress full-test state; diagnostic, practice, and full-test answers; correctness; question, section, category, and skill references; timestamps; estimated section and composite scores; saved reports; dashboard totals and weak-area summaries; daily streak dates and counts; Question of the Day selections and correctness; daily practice usage; full-test access usage; and technical records used to prevent duplicate saves or restore deleted attempts.
  • Why: deliver practice and tests, resume work, grade responses, show past results and summaries, preserve a daily streak, enforce free and paid access limits, prevent duplicate or replayed writes, and troubleshoot failed saves.
  • General retention: while the account is active and the information is needed to provide these features. A user may delete individual saved diagnostic or full-test reports where the Service provides that control. Some integrity records have the shorter fixed periods described in Section 10.
  • Recipients: Supabase and Vercel as infrastructure providers; professional advisors or authorities when legally necessary.

Subscription and transaction information

  • What we collect: Stripe customer and subscription IDs; billing email and name; product and price identifiers; subscription status; current billing-period end; cancellation status; checkout-operation identifiers and return path; Stripe event identifiers, event type, timestamps, processing status, and limited failure codes.
  • Why: start checkout, prevent duplicate subscriptions, unlock or end ArmorOne Unlimited access, open billing management, process cancellation, reconcile Stripe with ArmorOne, handle billing failures, and maintain transaction and compliance records.
  • General retention: for the subscription and account lifecycle and afterward as reasonably necessary for taxes, accounting, chargebacks, fraud prevention, disputes, and other legal obligations. Short-lived checkout and webhook records follow the periods in Section 10.
  • Recipients: Stripe and Supabase; financial institutions and payment networks acting through Stripe; professional advisors or authorities when legally necessary.

Device, network, analytics, and security information

  • What we collect: IP address; request time; requested page or endpoint; referrer; browser, operating system, and device type; approximate location derived from a request; filtered query parameters; authentication and security events; rate-limit keys and counts; Turnstile tokens and browser, device, interaction, and network signals; and a partial password-hash prefix used for breached-password screening.
  • Why: deliver and secure the Service, maintain sessions, diagnose failures, prevent bots, credential abuse, fraud, scraping, and excessive traffic, screen new passwords against known breached passwords, and understand aggregate website use.
  • General retention: according to the short operational periods in Section 10 or the provider's documented logging and reporting period. Vercel's Web Analytics visitor hash resets daily; aggregated analytics may remain available for the applicable reporting period.
  • Recipients: Vercel, Supabase, Cloudflare, and Have I Been Pwned; Google Fonts or Desmos when your browser requests those resources; professional advisors or authorities when legally necessary.

Communications

  • What we collect: the email address, message, attachments, and related information you provide when requesting support, exercising privacy rights, reporting security concerns, or giving feedback.
  • Why: respond, verify and fulfill requests, investigate concerns, improve the Service, and maintain appropriate records.
  • General retention: for as long as reasonably necessary to resolve the request and for legal, security, or recordkeeping needs.
  • Recipients: communications providers, relevant service providers, and professional advisors or authorities when necessary.

Information we do not intentionally collect

Through the public Service, ArmorOne does not intentionally collect payment-card numbers, precise geolocation, biometric identifiers, government ID numbers, health or disability information, audio or video recordings, contacts, Gmail contents, Google Drive files, or school-maintained education records. Do not send those categories to us unless ArmorOne has specifically agreed in writing to receive them.

3. How we obtain information

  • From you. You provide account, birthday, profile, study, answer, billing-choice, communication, and feedback information.
  • From your use of the Service. We create progress, score-estimate, streak, usage, entitlement, security, request, and analytics records from your interactions.
  • From Google. If you choose Google sign-in, Supabase and Google complete the OAuth flow and provide basic identity information such as your Google account ID, name, email address, and profile image if available. We do not request Gmail, contacts, Drive, or Google-calendar access, and Google does not provide your birthday for ArmorOne's age check; ArmorOne asks you for it separately.
  • From Stripe. Stripe provides customer, checkout, subscription, invoice, cancellation, and payment-event information needed to operate ArmorOne Unlimited. Stripe independently collects payment method, billing, fraud-prevention, and transaction information under its own privacy notice.
  • From service providers. Hosting, authentication, security, analytics, and calculator providers make operational data available for delivery, abuse prevention, support, and troubleshooting.

4. Password and bot screening

Email-and-password sign-up is protected by Cloudflare Turnstile and by the Have I Been Pwned Pwned Passwords service. ArmorOne hashes the submitted password inside its server function and sends only the first five characters of the SHA-1 hash to the Pwned Passwords range API with response padding. The full password and full hash are not sent to Have I Been Pwned. ArmorOne compares the returned range locally and refuses a password found in the breached-password corpus. This screening does not search your email address against breach records.

5. Cookies, local storage, and similar technology

Supabase Auth uses browser storage and authentication cookies or tokens as needed to keep you signed in, complete password recovery and Google OAuth, refresh sessions, and secure requests. Cloudflare Turnstile may use necessary browser storage or cookies to operate its security challenge.

ArmorOne also uses local storage for in-progress diagnostic and full-test state, failed-save recovery queues, dashboard display preferences and cached summaries, recently used practice questions and forms, versioned question-bundle caches, and the current Question of the Day and answer selection. Some of this data may contain answers, progress, account IDs, or score-related information. Question-bundle caches are designed to expire after about seven days; Question of the Day caches roll over daily; several preferences, histories, or local-only recovery records remain until replaced, expired by their internal limit, cleared by the Service, or cleared by you.

Vercel Web Analytics does not use analytics cookies. We do not currently use advertising cookies, remarketing pixels, cross-site behavioral-advertising pixels, or third-party advertising profiles. You can clear site data in your browser, but doing so may sign you out, remove local-only progress, or make the Service download content again.

6. How we use information

  • Provide, personalize, maintain, and support the public and account-based Service.
  • Create, authenticate, recover, secure, and administer accounts.
  • Verify age and prevent the creation or retention of accounts for users we know are under 13.
  • Deliver questions, diagnostics, practice, full tests, score estimates, saved reports, dashboards, Question of the Day state, and daily streaks.
  • Enforce daily practice, free full-test, paid subscription, content-access, and reliability limits.
  • Process subscription checkout, billing management, cancellation, webhook events, entitlement reconciliation, refunds where approved, and transaction support through Stripe.
  • Detect and prevent fraud, bots, scraping, credential misuse, security incidents, duplicate writes, and other prohibited activity.
  • Send password-reset, account, security, billing, administrative, legal, and service messages. We do not currently send marketing email.
  • Measure and improve reliability, usability, content, and features using aggregate, de-identified, or limited operational information.
  • Respond to requests, enforce our Terms of Service, comply with law, and establish, exercise, or defend legal claims.

We do not use personal information to make decisions that produce legal or similarly significant effects about you. Where laws outside the United States require a legal basis, our bases may include performing a contract with you, taking requested pre-contract steps, complying with law, protecting vital or legal interests, pursuing legitimate interests in operating and securing the Service, and consent where required.

7. When and to whom we disclose information

We disclose personal information only for the purposes described in this policy:

  • Supabase. Authentication, sessions, password recovery, database storage, row-level access control, server functions, API delivery, and operational logs.
  • Vercel. Static-site hosting, delivery, request logs, and Web Analytics. Vercel states that Web Analytics stores anonymized data, uses no analytics cookies, and resets its request-derived visitor hash daily.
  • Cloudflare. Turnstile bot and abuse detection on account creation and Google age-verification steps.
  • Stripe. Customer creation, Checkout, recurring subscription payments, fraud prevention, invoices, receipts, payment-method management, Billing Portal, cancellation, and payment events.
  • Google. Optional Google sign-in and fonts loaded by the website. Your use of a Google account remains subject to Google's terms and privacy practices.
  • Have I Been Pwned. Pwned Passwords partial-hash range screening during email-and-password account creation.
  • Desmos. The optional embedded graphing calculator on calculator-enabled diagnostic, practice, and full-test pages. Desmos code is requested when the calculator is opened and may receive request, device, referrer, and calculator-interaction information under Desmos's privacy practices.
  • Professional advisors and transaction participants. Attorneys, accountants, auditors, insurers, financing sources, and prospective or actual parties to a merger, acquisition, reorganization, financing, bankruptcy, or asset transfer, subject to appropriate confidentiality and legal requirements.
  • Authorities and safety recipients. Courts, regulators, law enforcement, government agencies, affected users, or other parties when we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, or the integrity of the Service.
  • At your direction. Other recipients when you request or consent to the disclosure.

We may use or disclose information that has been aggregated or de-identified so it cannot reasonably be linked to you. We do not attempt to reidentify de-identified information except to validate the de-identification process, protect security, or comply with law.

8. No sale or targeted advertising

ArmorOne does not sell personal information for money or other valuable consideration. We do not share personal information for cross-context behavioral advertising, process it for targeted advertising, or disclose it to third parties for their own direct marketing. We also do not use sensitive personal information to infer characteristics about you or for purposes that require a separate right to limit under California law.

9. Children's privacy and minors

The Service is intended for a general audience age 13 and older and is not directed to children under 13. You may not create an ArmorOne account if you are under 13. We request date of birth during account creation and check age on the server. An email-and-password account is not created when the submitted date of birth is under 13. A new Google account that submits an under-13 date of birth is deleted, and an unfinished Google sign-up is scheduled for removal after the verification window.

If we learn that we collected personal information from a child under 13 in a manner covered by the Children's Online Privacy Protection Act, we will take appropriate steps to delete it. A parent or guardian who believes a child under 13 provided information may contact armoronetech@gmail.com. We may verify identity and parental authority before disclosing or deleting information.

Users from 13 to the age of legal majority should use the Service with the involvement and approval of a parent or legal guardian. A verified parent or guardian may contact us about a minor's account, subject to applicable law.

10. Schools, FERPA, and student records

The public Service is offered directly to individual students and families. ArmorOne is not acting for a school, district, or educational institution under the public Terms of Service. Unless we sign a separate written agreement, ArmorOne does not agree to act as a school official, institutional contractor, or education-record service provider under FERPA or state student-data laws. Schools, teachers, tutors, and organizations must contact us before assigning, administering, or bulk-registering students. Do not submit school-maintained education records to the public Service.

11. Retention and deletion

We retain each category only for as long as reasonably necessary for the purpose described above, considering the account or subscription lifecycle, feature needs, security and fraud risk, legal and accounting duties, disputes, and backup integrity. Current application-level periods include:

  • Pending Google verification: an unverified account becomes eligible for cleanup about 10 minutes after creation. Automated retry records may remain longer if cleanup fails, but the system retries and isolates persistent failures.
  • Rate limits: expired ArmorOne rate-limit windows are normally pruned after about two hours.
  • Checkout operations: an operation expires after about 24 hours and is eligible for deletion after a further seven days.
  • Stripe event records: processed records are generally eligible for deletion after 30 days; failed records after 90 days; abandoned processing records after seven days.
  • Deleted-attempt integrity records: a limited tombstone used to prevent replay of a deleted saved result is generally eligible for deletion after 90 days.
  • Temporary full-test content grants: stale grants are generally eligible for deletion after seven days of inactivity.
  • Account and study data: retained while the account is active and the feature is provided, unless you delete an available saved result or request account deletion. Summary records update as underlying results change.
  • Billing records: retained while needed to provide paid access and afterward as reasonably necessary for tax, accounting, refund, chargeback, fraud, and legal obligations. Stripe independently retains transaction information under its own policy.
  • Browser data: remains according to the limits in Section 5 or until you or the browser clears it. Signing out does not necessarily clear every local cache or local-only progress record.

Following a verified account-deletion request, we delete or de-identify account-linked profile, progress, result, streak, usage, and entitlement information from active systems unless limited retention is reasonably necessary for security, fraud prevention, legal compliance, accounting, disputes, or enforcement. If an active ArmorOne subscription is linked to the account, we will coordinate stopping its future renewal before completing deletion; you should also use the cancellation control in Settings when available. Deletion from encrypted or provider backups may occur on the applicable backup cycle rather than immediately, and retained backup data is not used for ordinary product purposes.

12. Your choices and privacy rights

Subject to location and applicable exceptions, you may have rights to:

  • confirm whether we process personal information and access or know the categories, sources, purposes, recipients, and specific information involved;
  • correct inaccurate personal information, including by editing available account fields or contacting us about locked fields such as date of birth;
  • delete personal information or the account;
  • receive a portable copy of certain information;
  • withdraw consent where processing is based on consent;
  • opt out of sale, sharing, targeted advertising, or certain profiling, although ArmorOne does not currently conduct those activities;
  • limit certain uses of sensitive personal information, although ArmorOne uses sensitive account information only for permitted account, security, age-verification, and Service purposes; and
  • appeal a denial and exercise rights without unlawful discrimination or retaliation.

Submit a request to armoronetech@gmail.com or use the email link in account Settings. Describe the request and identify the account email. We may verify control of the email or account and request only the additional information reasonably needed to verify and fulfill the request. Authorized agents may act where permitted by law, subject to proof of authorization and identity verification. To appeal, reply to our decision with "Privacy Appeal" in the subject line. We will respond within the time required by applicable law.

13. California and other U.S. state disclosures

During the preceding 12 months, ArmorOne may have collected these statutory categories: identifiers; customer-record and account information; commercial and subscription information; internet or electronic-network activity; education-related study and performance information supplied by the user; inferences such as weak-area or performance summaries; communications; and sensitive information consisting of account credentials and date of birth used for account access, security, and age verification.

We collect and disclose those categories for the business and commercial purposes described in Sections 2, 6, and 7. The recipient categories are infrastructure, security, identity, analytics, payment, and calculator providers; professional advisors; transaction participants; authorities; and recipients you direct. We have not sold these categories or shared them for cross-context behavioral advertising during the preceding 12 months. We have no actual knowledge that we sell or share the personal information of users under 16.

California Shine the Light. We do not disclose personal information to third parties for their own direct-marketing purposes.

14. Online tracking, Do Not Track, and Global Privacy Control

ArmorOne does not track identified users across unrelated websites for advertising. Vercel provides cookie-free, aggregate Web Analytics; its request-derived visitor hash resets daily and is not designed to track visitors across days or websites. Other parties may collect limited request or interaction information through the Service as follows: Google when fonts load or you choose Google sign-in; Cloudflare on pages where Turnstile runs; Stripe when you enter Checkout or Billing Portal; Desmos when you open the calculator; and infrastructure providers when they deliver or secure the Service. Their independent processing is governed by their own policies.

Because browser "Do Not Track" signals do not have a uniform legal or technical standard and ArmorOne does not conduct cross-site advertising tracking, the Service does not change behavior in response to DNT. We honor Global Privacy Control and other legally recognized opt-out preference signals where required. Because we do not sell or share personal information for targeted advertising, receiving such a signal does not currently change our practices; it will be treated as an opt-out if a covered practice is introduced.

15. Security

We use safeguards designed to protect personal information, including HTTPS; Supabase authentication and hashed password storage; server-side age verification; row-level database security; narrow database functions; restricted administrative credentials; request, response, and document size limits; rate limits and admission controls; Turnstile; Pwned Passwords screening; Stripe webhook-signature verification; security headers; logging controls; and backup and recovery procedures. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

Use a unique password, protect your Google and email accounts, keep devices and sessions secure, and sign out on shared devices. Contact us promptly if you believe an account or personal information has been compromised.

16. United States operation and international transfers

ArmorOne is operated from the United States and is intended primarily for U.S. users. Providers may process information in the United States and other countries where they operate. If you use the Service from elsewhere, information may be transferred to a country with different privacy laws. Where applicable law requires a transfer mechanism or additional rights, we and our providers rely on the mechanisms and safeguards available to us under that law.

17. Changes to this policy

We may update this policy as the Service, providers, or law changes. We will post the revised version, update the effective date, and provide additional notice or request consent when required by law. Materially different collection or use will not begin without any notice or consent required at the point of collection.

18. Contact us

Questions, privacy-rights requests, parental inquiries, or security concerns may be sent to armoronetech@gmail.com.

ArmorOne
Privacy Terms
© 2026 ArmorOne. All rights reserved.