Fire Cert Academy

Privacy Policy

Effective date: April 14, 2026

1. Introduction

Fire Cert Academy, LLC (“Company,” “we,” “us,” or “our”) respects your privacy and is committed to protecting it. This Privacy Policy explains what information we collect when you use firecertacademy.com (the “Site”) and our services (the “Services”), how we use and share that information, and the choices you have.

2. Information we collect

We collect the following categories of information:

  • Account information. Name, email address, and password when you create an account. If you purchase a subscription, billing details are collected and processed by our payment processor — we do not store your full card number.
  • Usage data. Pages you visit, actions you take on practice tests, scores, and study history. This helps us improve the Services and show you your progress.
  • Device and log data. IP address, browser type, device information, and timestamps, captured when you interact with the Site.
  • Sample test lead information. If you take a sample test and choose to unlock detailed results, we collect your first name, email, and company name to send you the unlock link and, with your knowledge, to add you to our per-discipline mailing list.

3. How we use your information

We use the information we collect to:

  • Provide, maintain, and improve the Services;
  • Authenticate you, deliver practice tests, and track your progress;
  • Process subscriptions and payments;
  • Send transactional emails (receipts, password resets, unlock links);
  • Send marketing and educational emails related to the discipline you expressed interest in (you can unsubscribe at any time);
  • Prevent fraud, abuse, and unauthorized access;
  • Comply with legal obligations and enforce our Terms of Use.

4. Service providers we share information with

We do not sell or rent your personal information. We share information with the following service providers so we can run the Services:

  • Supabase, Inc. — database, authentication, and file storage.
  • Stripe, Inc. — subscription billing and payment processing. Stripe’s privacy practices apply to payment details we do not store.
  • Brevo (Sendinblue SAS). — transactional email delivery (magic links, receipts) and opt-in marketing email.
  • Vercel Inc. — application hosting and delivery.
  • PostHog Inc. — product analytics (see Section 5 for details).

We may also disclose information when required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets.

5. Analytics

We use PostHog to measure how the site is used — pages visited, sample tests started and completed, account signups, and subscription events. PostHog receives your Supabase user ID and email after you log in so we can measure retention across sessions. We do not share this data with third parties for advertising. If your browser sends a Do-Not-Track header, PostHog is disabled automatically; you can also clear the ph_* cookies in your browser to opt out.

6. Cookies and tracking

We use cookies and similar technologies to keep you logged in, remember preferences, and measure aggregate usage. You can manage cookies through your browser settings; disabling cookies may affect some features of the Site.

7. Data security

We use industry-standard safeguards including TLS for data in transit and access controls on our databases. No method of transmission over the internet is 100% secure, but we work to protect your information against unauthorized access, alteration, and destruction.

8. Your rights and choices

You may:

  • Access, update, or delete your account information from your account page, or by emailing us;
  • Unsubscribe from marketing emails using the link at the bottom of any such email;
  • Request a copy of the personal information we have about you, or request that we delete it, by submitting a message on our contact page.

9. Third-party links

The Site may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. Review their privacy policies before providing any personal information.

10. Children’s privacy

The Services are intended for users who are 18 or older. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. Changes become effective when posted. The “Effective date” above reflects the most recent revision. Material changes will be communicated by email or by a notice on the Site.

12. Contact

For privacy questions or requests, reach us through our contact page.