Privacy Policy
Effective April 2025 · Questions: privacy@karmanprep.com
1. Overview
Karman ("we", "us", "our") operates karmanprep.com and the Karman tutoring platform. This Privacy Policy explains what personal information we collect, how we use it, and your rights regarding that information. We are committed to protecting student and family privacy and comply with applicable U.S. privacy laws including CCPA.
2. Information We Collect
Account information
- Name and email address (provided at sign-up)
- Password (stored securely and hashed by Clerk — never visible to Karman)
- Role (student, parent, or tutor)
- SAT test date (optional, provided during onboarding)
Platform activity
- Diagnostic assessment answers and scores
- Practice quiz responses and concept progress
- Session attendance and scheduling history
- Login timestamps and session duration
Payment information
- Billing details are processed entirely by Stripe. Karman never stores or has access to your full credit card number, CVV, or bank account details.
- We retain: your Stripe customer ID, subscription tier, subscription status, and billing history for account management.
Communications
- Email address for transactional emails (receipts, session reminders, progress reports)
- Email address for marketing communications (only with your explicit consent)
- Support messages sent to Karman
Automatically collected data
- Browser type, operating system, and IP address
- Pages visited and features used within the platform
- Error logs (via Sentry) to identify and fix technical issues
- Product analytics (via PostHog) to understand how features are used — no personally identifiable information is included in these analytics reports
3. How We Use Your Information
- Create and manage your Karman account
- Personalize your diagnostic results and study path
- Deliver and schedule tutoring sessions
- Send transactional emails (receipts, reminders, progress reports)
- Send marketing emails (only if you opted in — unsubscribe at any time)
- Process payments and manage your subscription via Stripe
- Monitor platform performance and fix technical issues
- Analyze how the platform is used to improve it for all students
- Comply with legal obligations
4. Third-Party Services
We share minimal data with the following trusted third-party services, each bound by their own privacy policies:
| Service | Purpose |
|---|---|
| Clerk | Authentication — handles sign-in, sign-up, and password security |
| Stripe | Payments — processes all subscription billing and payouts |
| Supabase | Database — stores account data, progress, and diagnostic results on encrypted servers |
| Resend | Email delivery — sends transactional and marketing emails |
| Sentry | Error monitoring — captures anonymized crash reports to fix platform bugs |
| PostHog | Product analytics — aggregated, non-personally-identifiable usage data |
5. Data Retention
- Account and progress data is retained for as long as your subscription is active.
- After cancellation, your data is retained for 90 days to allow reactivation, then deleted.
- Payment records are retained for 7 years as required by financial regulations.
- You may request earlier deletion at any time — see Your Rights below.
6. Your Rights
You have the following rights regarding your personal information:
- Access: request a copy of the personal data we hold about you
- Correction: request that we correct inaccurate or incomplete data
- Deletion: request that we delete your personal data (subject to legal retention requirements)
- Portability: request your data in a machine-readable format
- Opt-out of marketing emails: use the unsubscribe link in any email or email privacy@karmanprep.com
- California residents (CCPA): you have the right to know what data we sell (we do not sell personal data) and to opt out of any future sale
7. Children's Privacy
The Karman platform is designed for students age 13 and older. We do not knowingly collect personal information from children under 13. If a parent or guardian believes their child under 13 has created an account, please contact us at privacy@karmanprep.com and we will promptly delete the account. For students between 13–17, we encourage parental involvement and offer parent dashboard accounts.
8. Security
We use industry-standard security measures including encrypted data transmission (HTTPS/TLS), encrypted data storage via Supabase, row-level security policies that ensure users can only access their own data, and third-party authentication management via Clerk. No system is 100% secure. If you believe your account has been compromised, contact privacy@karmanprep.com immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by email at least 14 days before any material changes take effect. Continued use of the platform after that date constitutes acceptance of the updated policy.
10. Contact
For any privacy-related questions, requests, or concerns, email privacy@karmanprep.com. We respond within 5 business days.