Privacy Policy
Last updated 12 September 2026
This policy explains what Pass 104 does with personal data. It is written to be checked rather than skimmed: it identifies the companies involved and explains the parts each of them plays.
The short version: we collect your email address, your name, and the exams you take. There is no analytics, no tracking, no advertising and no profiling. Requests pass through Cloudflare before reaching the application server on Fly.io. We do not sell your data.
1. Who is responsible
The data controller is Emanuele Ledda, VAT number 04237890928, REA CA-374294, Via Vittorio Emanuele III 102, 09020 Gesturi (SU), Italy. You can reach us about anything in this policy at [email protected].
We are a sole trader in Italy. We are not required to appoint a Data Protection Officer and have not appointed one, so the address above reaches the person who makes these decisions.
2. What we collect
Only what the service needs to work, plus three optional questions you may leave blank.
| Data | When | Required |
|---|---|---|
| Email address | When you sign in for the first time | Yes — it is your account |
| First and last name | On the profile screen after your first sign-in | Yes |
| Job title, current role, study goal | On the same screen | No — you can skip or clear all three |
| Your exams: questions drawn, answers given, flags, scores | Every time you take an exam | Yes — this is the product |
| Subscription status and billing period | If you subscribe to Pro | Yes, for Pro only |
| Renewal-notice recipient, covered period and send time | At the start of each Pro billing period | Yes, for Pro only |
| Sign-in records (timestamps, IP address, browser) | Kept by our authentication provider for security | Yes |
| Terms version and acceptance time | When your account is created | Yes — it records the agreement you made |
| Your withdrawal declaration, and the time you sent it | Only if you withdraw from a Pro purchase within 14 days | Yes — the law requires us to record and confirm it |
| A visit count, and a nightly-scrambled code so a reload is not counted twice (see below) | Whenever anyone loads one of our four public pages | Yes — but it is never linked to your account |
We do not collect your date of birth or age, and there is no field for it. We never see your payment details. Card numbers, billing addresses and any VAT number you provide are entered on Polar's own checkout page and stay with Polar — they never reach our servers, and there is no payment library in this website's code.
There is no analytics script, tag manager, advertising pixel, session recorder or error-reporting service in this application. No script from another company runs on any page. Fonts are served from our own domain rather than from a font CDN, so simply loading a page does not disclose your IP address to anyone but us and our hosting provider.
We do count visits to our public pages — the home page, this page, the Terms and the sign-in page — but we do it on our own server, and no third party is involved. For each visit we record the day, which page, the site that linked you to us (the site's name only, never the full address you came from), your country, and the campaign tag in the link if it had one. None of that is about you personally.
So that a single person reloading a page is not counted as several visitors, we also store a scrambled code worked out from your IP address, your browser's user-agent and a secret number. We never store your IP address itself. The secret number is destroyed and replaced every night, so the code cannot be worked back to you, and tomorrow's code for the same person is completely different and cannot be connected to today's. It follows you nowhere: not to another day, not to another device, and not into your account — a signed-in visitor's page views are not linked to who they are.
3. Why, and on what basis
- To give you the service you asked for — your account, your exams, your results, your subscription, and a record of the Terms version accepted when the account was created. Legal basis: performance and formation of a contract, Art. 6(1)(b) GDPR. Without this data there is no account to sign in to.
- To keep the service secure and working — sign-in records, and server logs which may briefly contain an IP address. Legal basis: legitimate interest, Art. 6(1)(f) GDPR, in operating a service that is not abused.
- To know how many people visit the site and how they found it — the day, the page, the referring site's name, the country, any campaign tag, and the nightly-scrambled code described in §2 that lets us tell a reload from a second visitor. Legal basis: legitimate interest, Art. 6(1)(f) GDPR, in understanding whether the site reaches anyone and which channels are worth our effort. We weighed that against your interests and kept the processing to the minimum it could be: it runs on our own server with no third party, sets nothing on your device, stores no IP address, cannot follow you between days or devices, and is never used to make a decision about you. You can object at any time — see §9.
- To answer you when you write to us — the address you write from, your message, anything you attach to it and the history of the exchange. This covers ordinary support and the requests described in §8, including any identity evidence you choose to send with one. Legal basis: performance of the contract or steps taken at your request, Art. 6(1)(b) GDPR; compliance with a legal obligation, Art. 6(1)(c) GDPR, where you are exercising a right we are required to answer; and legitimate interest, Art. 6(1)(f) GDPR, in operating the service and in establishing or defending legal claims.
- To understand who we are writing questions for — the optional role, job title and goal. Legal basis: your consent, Art. 6(1)(a) GDPR. You give that consent by filling in a field and withdraw it by clearing the field in Settings, which deletes the answer. The service works identically whether these fields are filled in or blank.
- To record a withdrawal, if you make one — the declaration you sent and the time you sent it. Legal basis: compliance with a legal obligation, Art. 6(1)(c) GDPR. Italian consumer law (art. 54-bis Codice del Consumo) requires us both to offer the withdrawal function and to confirm your declaration back to you on a medium you can keep, so we cannot run this without keeping the record.
- To warn you before an automatic renewal — your account email, the billing period covered and whether the notice was sent. Legal basis: performance of the subscription contract, Art. 6(1)(b) GDPR, and compliance with applicable consumer notification duties, Art. 6(1)(c). Article 65-bis of the Italian Consumer Code imposes such an electronic reminder on fixed-term services that renew automatically; we use the same safeguard for this indefinite month-to-month service.
Where we rely on your consent, you may withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
We do not use your data for automated decision-making or profiling within the meaning of Art. 22 GDPR. Your per-domain scores are arithmetic on your own answers, shown only to you, and produce no decision about you.
4. Who else sees it
The seven named platform providers are listed below; Google is involved only when you choose its sign-in option. There is no advertising or data-broker relationship of any kind.
| Company | What for | Role |
|---|---|---|
| Supabase | Database, accounts and authentication | Processor, acting on our instructions |
| Cloudflare | DNS, network security, proxying requests, and storing our encrypted database backups | Processor, acting on our instructions |
| Fly.io | Running the application server in Frankfurt, Germany | Processor, acting on our instructions |
| Polar Software, Inc. | Selling and billing the Pro subscription | Independent controller for billing; our processor for subscription management |
| Resend | Delivering sign-in emails, monthly renewal/cancellation notices, and the acknowledgement sent if you withdraw from a Pro purchase | Processor, acting on our instructions |
| Infomaniak | Hosting the mailbox in Switzerland that receives and answers email sent to [email protected] | Processor, acting on our instructions |
| Only if you choose "Continue with Google" to sign in | Independent controller for your Google account |
These processors may use the subprocessors named in their own current notices. We review those lists and their change notices as part of our processor register. You may ask us for the current list relevant to this service.
Polar is the seller, not just a payment processor
Pro is sold by Polar Software, Inc. (3500 South DuPont Highway, Dover, DE 19901, United States) acting as merchant of record. That means Polar — not us — is the party you buy from: it sets the final price including your country's VAT, takes the payment, issues the invoice, and is the name that appears on your card or bank statement. To start checkout we send Polar your email address and our internal user identifier. We receive your subscription's status, identifiers and dates, never your card or billing details.
Polar plays two roles. For the payment itself — your card details, billing address, any VAT number, invoices, tax and fraud records — Polar is an independent controller. It collects that data directly from you, keeps it under its own obligations as seller, and handles it under its privacy policy and buyer terms. For the limited account and subscription information Polar processes on our behalf, it acts as our processor under its data processing addendum. Because we do not hold your billing data, Polar must answer requests about that data. You may contact Polar directly or write to us; if you write to us, we will forward the request and confirm that we have done so.
Signing in with Google
If you use "Continue with Google" we ask Google only for your email address and basic profile information, and only so we can create or find your account. We do not request access to your Gmail, Drive, Contacts, Calendar or any other Google service, and we could not read them if we wanted to. We never receive your Google password. You can revoke our access at any time from your Google account's security settings; doing so does not delete your Pass 104 account, which you delete here.
5. Where it is stored
The production application's primary database is a Supabase Postgres project in Frankfurt, Germany (EU), and the application server runs in Fly.io's Frankfurt region. Requests first pass through Cloudflare's global network. Choosing Frankfurt controls the primary location; it does not mean that every item of operational data is processed only inside the EU.
Provider support, security, delivery and logging systems may process identifiers, request data or email content outside the EU. Several providers are established in the United States, and authorised personnel may access data from there. Remote access from a third country is treated as an international transfer even where the primary database and application machine remain in Frankfurt.
Transfers to Supabase rely on the European Commission's Standard Contractual Clauses in its Data Processing Addendum. Fly.io makes a Data Processing Agreement available and participates in the EU–US Data Privacy Framework. Cloudflare participates in that Framework and also provides Standard Contractual Clauses. Resend participates in the Framework and incorporates the Standard Contractual Clauses in its DPA. Polar and Google process data under their published transfer safeguards. Infomaniak hosts the support mailbox in Swiss datacentres and does not move that mail outside its own infrastructure; Switzerland is covered by a European Commission adequacy decision, so no additional safeguard is required for it. Where an adequacy decision does not apply, the relevant processor terms use contractual safeguards such as the Standard Contractual Clauses.
You may obtain a copy of the Standard Contractual Clauses and other transfer safeguards relevant to your data, free of charge, by emailing [email protected]. We may remove information that is confidential or unrelated to you.
6. How long we keep it
- Your account, profile, Terms-acceptance record, renewal-notice records and exam history: for as long as your account exists. This is deliberate — every exam you have taken stays readable to you indefinitely, on any plan.
- If you delete your account: your profile, every exam and result, and your sign-in credentials are removed from the live service immediately and permanently. There is no grace period and we cannot undo the deletion. We take our own encrypted backup of the database each night and keep it for 30 days; a copy of your data remains in those files until the last one that contains it expires. They are held separately from the live service, isolated from ordinary use, and are never used to restore a deleted account.
- If you never come back: we keep the account while it exists because its exam history is the reason users return. We review dormant accounts periodically and may close an account that has had no sign-in for several years. Before doing so, we will give the account holder at least 30 days to sign in and keep it.
- Support correspondence: kept in the support mailbox while it is needed to deal with what you wrote about, and deleted once it is not. Where an exchange concerns a dispute, we keep it until the applicable limitation period has expired.
- Sign-in and security records: kept only for the period needed to investigate abuse, protect accounts and meet the provider's security obligations, then rotated or deleted under the provider's retention schedule.
- Visit counts: the nightly secret is destroyed after 24 hours, which is what makes the scrambled visitor codes permanently unreadable. The codes themselves are deleted after 90 days. The plain counts that remain — how many visits a page had on a day, from which country and referring site — are not personal data and we keep them.
- Invoices and payment records: held by Polar as the seller, for the period its own tax obligations require — typically ten years. Deleting your Pass 104 account does not and cannot delete those, because they are not ours to delete.
7. Cookies and local storage
There is no cookie banner on this site, and that is not an oversight. We use no profiling, analytics or advertising cookies — none at all — so under the Italian Data Protection Authority's cookie guidelines there is nothing here that requires your consent. What follows is the information those guidelines do require.
The visit counting described in §2 is not a cookie and does not change this. It happens entirely on our server: nothing is written to your device and nothing already on your device is read. The rule that would require your consent (art. 122 of D.Lgs. 196/2003) applies to storing or reading information on your equipment, and we do neither in order to count you.
| Name | Kind | What it does | Lasts |
|---|---|---|---|
sb-…-auth-token, or numbered parts such as sb-…-auth-token.0 and .1 | Cookie | Keeps you signed in. Supabase may split a long session into numbered cookies; together they are one session. | Until you sign out or it expires |
sb-…-auth-token-code-verifier | Cookie | Used briefly during Google sign-in to bind Google's reply to the request made by your browser and prevent a forged reply. | Deleted after sign-in completes; otherwise within eight hours |
__cf_bm (when bot protection is active) | Cookie | Cloudflare bot detection. It helps distinguish legitimate requests from automated abuse and is not used to track you across websites. | 30 minutes after your last activity |
cf_clearance (after a security challenge) | Cookie | Records that your browser passed a Cloudflare security check so it is not challenged on every request. | For the security-challenge period configured for the site |
_cfuvid (when visitor-based rate limiting is active) | Cookie | Lets Cloudflare distinguish visitors sharing one IP address so a busy network does not cause everyone on it to share one rate limit. | Until the browser session ends |
sidebar-collapsed | Local storage | Remembers whether you collapsed the sidebar. Never leaves your browser. | Until you clear your browser data |
pass104:pending-sign-in | Session storage | Holds the email you just requested a code for, so switching to your mail app and back does not lose the form. | One hour, or until the tab closes |
The authentication and security cookies are necessary to sign you in and protect the service. The sidebar preference is stored only after you use that control and does nothing beyond remembering your choice. None is used for analytics, advertising or profiling, so consent is not required. Polar's checkout opens on Polar's own domain and uses cookies under its own policy.
8. Your rights
Under the GDPR you may ask us to access, correct, delete or restrict our use of your personal data. You may also ask for a portable copy of data you provided to us. Two rights can be exercised immediately in Settings:
- Correction — edit your name and the optional fields in Settings at any time.
- Deletion — Settings has a "Delete account" section that removes everything at once. If you have a Pro subscription it is cancelled with Polar first, so you are not charged again.
Access and portability are separate rights. For access, you may ask for a copy of all personal data we hold about you. For portability, you may ask for the profile and exam data you provided in a structured, machine-readable JSON file so you can take it elsewhere.
For anything else, email [email protected]. We will answer within one month. If a request is unusually complex or numerous, we may extend that period by up to two further months; if so, we will tell you within the first month and explain why.
If you think we have handled your data badly, you may complain to the Italian supervisory authority, the Garante per la protezione dei dati personali, or to the authority in your own EU country. We would rather you told us first, but you are not required to.
9. Your right to object
Where we rely on legitimate interest — for sign-in, server and security records used to protect the service, and for the visit counting described in §2 and §3 — you have the right to object at any time on grounds relating to your particular situation. Email [email protected]. We will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the data is needed for legal claims. We will explain our decision either way.
We do not use personal data for direct marketing. If that changed, you could object at any time and we would stop using it for that purpose.
10. Children
This service is for adults. Our Terms require you to be at least 18, and we do not knowingly collect data from anyone under that age. This is a professional certification study tool and is neither designed for nor directed at children. If you believe a minor has created an account, email us and we will delete it.
11. Changes
If we change this policy we will update the date at the top. If a change materially affects you — a new company handling your data, a new purpose, or a materially different retention period — we will provide a prominent notice before it takes effect, by email or inside the service as appropriate.
