CFA Drill · EonDigi Inc. · Effective 29 July 2026 · Not affiliated with CFA Institute

Privacy Policy

This Privacy Policy explains how EonDigi Inc., a United States corporation (“Operator”, “we”, “us”, or “our”) collects, uses, and shares information when you use CFA Drill (https://cfa-drill.com). It is intended to help you understand our practices under frameworks such as CCPA/CPRA (California), GDPR (EEA/UK where applicable), and other applicable privacy laws.

1. Who we are

The controller / operator of CFA Drill is EonDigi Inc..

Privacy and data-protection requests: support@cfa-drill.com.

For product or account issues unrelated to privacy rights, use support@cfa-drill.com.

2. Information we collect

Account data: email address, display name (optional), authentication provider identifiers (e.g., Google), and email verification status via Firebase Authentication.

Usage and progress data: question statuses (unseen / learning / mastered / blindspot), correct and incorrect attempt counts, subject filters, and related timestamps stored in Firestore under your user id.

Technical data: IP address, device/browser type, and logs as processed by hosting and security infrastructure (Firebase / Google Cloud).

Payment data: processed by Stripe. We do not store full card numbers on our servers. We may store plan status, Stripe customer/subscription ids, and purchase metadata needed to provision Pro.

Advertising data (free tier): Google AdSense and related Google advertising technologies may use cookies or similar identifiers as described in Google’s policies and any consent banner shown on the site.

3. How we use information

To provide and secure the Service (auth, sync progress, unlock Pro).

To communicate about account verification, security, and material product changes.

To show ads on the free tier and measure basic performance.

To enforce Terms, prevent abuse, and comply with law.

4. Legal bases (GDPR where applicable)

Contract performance (providing the account and purchased features).

Legitimate interests (security, product improvement, fraud prevention) balanced against your rights.

Consent (where required for non-essential cookies/ads).

Legal obligation when we must retain or disclose information.

5. Sharing

We share data with processors who help run the Service: Google Firebase / Google Cloud, Google AdSense (free tier), and Stripe (payments). They process data under their own terms and privacy policies.

We may disclose information if required by law, to protect rights and safety, or in connection with a corporate transaction (merger, acquisition) subject to appropriate safeguards.

We do not sell personal information for money. Advertising partners may process data for personalized ads where permitted and consented.

6. International transfers

Data may be processed in Canada, the United States, and other locations where our providers operate. Where required, we rely on appropriate transfer mechanisms offered by those providers.

7. Retention

We retain account and progress data while your account is active. You may request deletion; we will delete or anonymize data except where retention is required for legal, security, or accounting purposes (e.g., payment records).

8. Your rights

Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of personal data, and to object to certain processing or withdraw consent.

To exercise rights, email support@cfa-drill.com with subject line “Privacy request — CFA Drill”. You may also lodge a complaint with a supervisory authority where applicable.

California residents may have additional rights under CCPA/CPRA, including knowing categories of data collected and requesting deletion. We do not discriminate for exercising privacy rights.

9. Children

The Service is not directed to children under 16 (or higher age required locally). We do not knowingly collect personal data from children. Contact us if you believe we have collected such data.

10. Security

We use industry-standard provider controls (Firebase Auth, HTTPS, access rules). No method of transmission or storage is 100% secure.

11. Changes

We may update this Policy by posting a new version with a revised effective date. Significant changes will be highlighted where practicable.

12. Contact

Privacy and data-protection requests: support@cfa-drill.com.

Product support (non-privacy): support@cfa-drill.com.

Back to CFA Drill