Last updated: 2026-06-04b
Privacy Policy
This policy describes how the CFA L1 AI Prep Chrome
extension and the marketing site cfa-l1-prep.com ("the
service") collect, store, and use your information.
The short version
- Your study journal lives on your device, in
chrome.storage.local. We do not upload it to our servers unless you create a Pro account and turn on cloud sync (see "Accounts & cloud sync" below). Free use requires no account and stays entirely on your device. - Question text you paste into the AI explainer is processed transiently and never persisted in our database.
- If you upgrade to Pro, we create an account (email + sign-in handled by Clerk) and process your payment through Paddle as merchant of record.
- We collect the email + optional exam-date you give us on the waitlist, plus standard request metadata (IP-derived country, referrer, UTM parameters), and optional feedback you send us.
- We do not sell, rent, or share your personal data with third parties for marketing.
- We use Google Analytics to understand traffic and feature usage. The extension sends only anonymous usage events (no question text, no personal data), tied to a random on-device id — not a cookie.
- If you arrive from a Google ad, we record a Google click identifier (gclid) to measure which ads lead to installs — stored hashed on our servers and used only for advertising measurement.
What we store
On your device (Chrome extension)
- Your manual journal entries: LOS code, topic, difficulty, your answer, the correct answer, your three reflection notes, time per question.
- Your study sessions: start/end timestamp, source platform tag, running counters.
- Your settings.
For free users, this data never leaves your device. Uninstalling the extension or clearing local storage permanently deletes it. Cloud sync is a Pro-only, opt-in feature — see the next section.
Accounts & cloud sync (Pro)
Free use requires no account. When you upgrade to Pro, we create an account and store:
- Your account identity: a Clerk user id and your email address.
- Your subscription status (plan, active/canceled, renewal date), keyed to that account.
- If you enable cloud sync: a copy of your journal entries and settings, so you can use them across devices. These follow the same rule as on-device entries — they never contain question text, only LOS code, topic, difficulty, your answer, the correct answer, your reflection notes, and timing.
Authentication is handled by Clerk (our identity provider). Payments are handled by Paddle, which acts as the merchant of record and processes your payment details — we never see or store your full card number. Both act as data processors on our behalf.
Feedback you send us
If you rate the extension, submit feedback, or fill in the uninstall survey, we store your rating or reason, any optional message, an optional reply-to email if you provide one, the app version, and an anonymous device id. This is never linked to question text.
On our servers (when you submit the waitlist)
- Email address
- Selected target exam window (if you chose one)
- Referrer URL (where you arrived from)
- UTM parameters from the URL
- Country derived from your IP address (we do not store the raw IP)
- Timestamp of signup
Install attribution (advertising)
If you reach us from a Google ad, the link carries a Google Click Identifier (gclid). To measure which campaigns lead to installs, the extension records this identifier and reports the install to Google Ads:
- On our servers: we store a SHA-256 hash of the gclid (used to avoid counting an install twice) and retain the raw identifier only to report and audit the ad conversion. The raw identifier is automatically deleted after 90 days.
- On your device: the gclid is retained in local storage so the install isn't reported more than once; it is removed when you uninstall the extension or clear local storage.
This identifier is used only for advertising measurement. It is not used to build a profile of you and is never linked to your study data or question text.
When you use the AI explainer (v0.5+)
Question text you paste is forwarded to an LLM provider (OpenRouter routing across Anthropic, OpenAI, and Google models) to produce an explanation. We do not persist the question text in our database. Per LLM-provider policies, providers may retain inference logs for up to 30 days for abuse review; we have requested zero-retention agreements where available.
Analytics
Website
cfa-l1-prep.com uses Google Analytics 4 (GA4) to measure page
views, traffic sources, and conversions (such as waitlist signups and
install clicks). GA4 sets cookies and may collect a truncated IP address
and basic device/browser information. We do not use this data to identify
you personally.
Chrome extension
The extension reports anonymous usage events — for
example opening the app, requesting an explanation, or answering a
practice question — to GA4 via the Measurement Protocol. These events are
tied to a random identifier generated on your device and stored in
chrome.storage.local (not a cookie, and not
linked to your identity). We never send question text, journal
entries, or personal data in analytics — only coarse event names
and non-identifying parameters (e.g. topic, difficulty,
correct/incorrect). Clearing local storage or uninstalling the extension
resets this identifier.
What we don't do
- We don't read your browsing activity. The extension has no
tabspermission and no<all_urls>host permission. - We don't read your credentials on any prep platform.
- We don't reproduce or store copyrighted prep-platform question text.
- We don't sell your data.
Subprocessors
We rely on the following third parties to operate the service. Each processes only the data needed for its function:
- Clerk — account sign-in and identity (Pro accounts).
- Paddle — payment processing and merchant of record.
- OpenRouter, routing to Anthropic, OpenAI, and Google — AI explanation generation (transient question text only).
- Google Analytics — anonymous usage and traffic measurement.
- Cloudflare — hosting and database.
Data deletion
Email privacy@cfa-l1-prep.com to delete your waitlist entry, your Pro account, or any synced study data. On request we delete your account record, entitlement, and any synced journal entries and settings. Local (on-device) journal data is removed at any time by uninstalling the extension or clearing local storage.
Children
The service is intended for adult CFA® candidates and is not directed at anyone under 18.
Changes
We'll post material changes here with a new "Last updated" date.
Disclaimer
CFA Institute does not endorse, promote, or warrant the accuracy or quality of this product. CFA® and Chartered Financial Analyst® are registered trademarks owned by CFA Institute.