CitizenIQ

Privacy Policy

Last updated: April 12, 2026

1. Who We Are

CitizenIQ ("we," "us," or "our") is an educational web application that helps applicants prepare for the USCIS naturalization civics test. The service is operated as a sole proprietorship. You can reach us at our contact form.

2. Information We Collect

Account information. When you sign in with Google, we receive your email address and display name from Google. We store this in our database to identify your account.

Study progress. Your quiz history, question accuracy, XP, streak count, session logs, and settings are stored in your browser's localStorage and synced to our database (Supabase) when you are signed in. This data is used solely to personalize your learning experience.

Payment information. If you purchase CitizenIQ Pro, payment processing is handled entirely by Stripe; CitizenIQ never stores credit card numbers. We receive a Stripe customer ID, a payment intent identifier, and a record of whether payment was successful. Stripe may store your payment information according to their own privacy policy. We retain transaction records (customer email, payment amount, and date) for up to 7 years for tax compliance purposes. You can request deletion of payment records by contacting our support team, subject to legal retention requirements.

Contact messages. If you submit a message through our contact form, we store your name, email address, and message text so we can respond.

AI grading data. If you use AI-powered answer grading or interview simulation (Pro features), your quiz answers and related question text are sent to our AI provider (DeepSeek) for evaluation. DeepSeek processes this data to return a grade and feedback. No personal identifiers are sent to DeepSeek — only the question and your answer text. When AI grading is used, your answer text is sent to DeepSeek's API servers which may be located outside the United States. DeepSeek processes data according to their own privacy policy; CitizenIQ does not control their data retention practices. AI grading is optional — without it, fuzzy string matching is used as a fallback and no data is sent to any third party.

Usage data. When you are signed in, we record the time you last used the app and which page you were viewing. This data is used to show online status to administrators for customer support purposes and is overwritten each time you visit. It is deleted when you delete your account.

Error and performance data. We use Sentry to monitor application errors. Sentry collects your IP address, browser type, operating system, page URL, and a technical description of what you were doing when an error occurred. Error reports are routed through our own domain before reaching Sentry. This data is used only to identify and fix bugs.

Cookies. We use strictly necessary cookies for authentication (Supabase session cookies prefixed with sb-) and payment security (Stripe checkout cookies). We do not use advertising or tracking cookies. See our Cookie Policy for details.

3. How We Use Your Information

  • To create and maintain your account
  • To deliver the CitizenIQ service and personalize your study experience
  • To process your one-time Pro payment and verify your access
  • To respond to your support messages or contact form submissions
  • To provide AI-powered answer grading and feedback (Pro feature)
  • To display online status to administrators for support purposes
  • To detect and fix application errors
  • To comply with legal obligations

We do not sell, rent, or share your personal information with third parties for marketing purposes.

4. Third-Party Services

We use the following third-party services that may process your data:

  • Supabase — database and authentication. Data is stored in the United States. Privacy policy: supabase.com/privacy
  • Google OAuth — sign-in only. We request only your name and email. Privacy policy: policies.google.com/privacy
  • Stripe — payment processing. Privacy policy: stripe.com/privacy
  • DeepSeek — AI-powered answer grading (Pro feature only). Your quiz answers and question text are sent to DeepSeek for evaluation. DeepSeek may process data outside the United States. Privacy policy: deepseek.com/privacy
  • Sentry — error monitoring. Collects technical error data routed through our domain. Privacy policy: sentry.io/privacy
  • Vercel — hosting and infrastructure. Privacy policy: vercel.com/legal/privacy-policy

5. Data Retention

We retain your account and study progress data for as long as your account is active. If you request account deletion, we will delete your personal data within 30 days, except where we are required by law to retain it. The specific retention periods for each category of data are as follows:

  • Account data (email, study progress): retained while your account is active, deleted within 30 days of account deletion
  • Payment records (transaction amount, email, date): up to 7 years for tax compliance
  • Contact messages: 1 year after resolution
  • Usage data (last seen, current page): overwritten on each visit, deleted with account
  • Error logs (Sentry): 90 days
  • Cookie consent preferences: retained until withdrawn

6. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Request a copy of your data in a portable format
  • Withdraw consent at any time (where processing is based on consent)

To exercise any of these rights, email us at our contact form. We will respond within 30 days.

7. California Residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, the right to delete your personal information, and the right to opt out of the sale of your personal information. We do not sell personal information to third parties. To submit a data request, contact us at our contact form.

Categories of personal information collected:

  • Identifiers (email address, display name)
  • Commercial information (purchase history)
  • Internet or other electronic network activity information (usage data, browser type)
  • Inferences drawn from the above (study progress, readiness scores)

Right to non-discrimination. We will not charge you different prices or provide a different quality of service because you exercised your rights under the CCPA.

Authorized agents. You may designate an authorized agent to submit requests on your behalf. To do so, provide written authorization to our support team via our contact form. We may require verification of your identity and the agent's authority before processing the request.

8. Children's Privacy

CitizenIQ is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us and we will delete it promptly.

9. Internal Data Access

A limited number of authorized administrators may access user account information (email, name, subscription status) and contact form submissions for the purpose of providing customer support, managing subscriptions, and responding to messages. Administrative access is restricted by server-side authentication checks and is limited to the minimum data necessary to operate the service.

10. Security

We use industry-standard security practices including HTTPS encryption, Supabase Row Level Security (RLS) to isolate user data, and server-side authentication checks on all protected routes. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date at the top of this page. Continued use of CitizenIQ after changes are posted constitutes your acceptance of the updated policy.

12. Contact

For any questions, concerns, or requests related to this Privacy Policy, contact us at our contact form.