Skip to content
Legal

Privacy Policy

ExamPass is used by children. We treat that as the whole design brief, not a footnote. This page says exactly what we collect, why, and what we will never do.

Last updated 29 July 2026

Who we are

ExamPass is operated by Spout Technologies (Pty) Ltd ("we", "us"). You can reach us at any time at hello@exampass.app.

The short version

  • We collect the minimum needed to run a study account and mark practice.
  • We do not sell personal data. We never have and we will not.
  • There is no third-party advertising in ExamPass, and no ad tracking.
  • We do not build advertising profiles of learners.
  • You can ask us to delete an account and its data, and we will.

What we collect

Account details

To create a study account we collect a mobile number (used with a one-time SMS code), or an email address if you sign in with Google, Apple or a staff account. We also store the display name and optional profile picture a learner chooses, and the grade they are sitting (7, 9 or 12).

Signing in with Apple supports Apple's Hide My Email. If a learner uses it, we only ever see the relay address, which is fine — everything works normally.

Study activity

We record the questions attempted, the answers given, whether they were correct, how confident the learner said they were, and how long a session took. This is the product: it is what schedules revision, picks the next question and shows progress. It is not used for anything else.

Access codes and entitlements

When a learner redeems an access code from a school or agent, we store which code was used and what it unlocked, so the right content stays available for the period paid for.

Technical and diagnostic data

We use Firebase Analytics and Firebase Crashlytics to see which screens are used and to receive crash reports. These include device model, operating system version, app version, coarse region and a random app instance identifier. They do not include the content of a learner's answers, and we do not use them for advertising.

What we do not collect

No precise location. No contacts. No photo library beyond a picture the learner deliberately picks as an avatar. No microphone or camera access except when taking that avatar photo. No advertising identifier (IDFA), and ExamPass does not ask for App Tracking Transparency permission because it does not track you across other companies' apps or websites.

The AI tutor

When a learner asks the tutor for help, the question they are stuck on and their attempt are sent to our server, which passes them to our AI provider (Groq) to generate an explanation. We do not send a learner's name, number or email with it. Tutor conversations are not used to train third-party AI models. The tutor is available only where a guardian or school has given consent, and it explains the step rather than simply handing over answers.

Children and guardians

Many ExamPass learners are under 13. Accounts are normally created through a school or an agent, with a parent or guardian present. A guardian or school administrator may ask us to see, correct or delete a learner's data at any time by writing to hello@exampass.app. ExamPass is not directed at advertising to children and contains no third-party ad networks.

Who else can see the data

A school or agent that issued a learner's access code can see that learner's progress — subjects studied, accuracy, activity — because that is the point of sponsoring a learner. They cannot see a learner's password, and they cannot see tutor conversations.

We share data with these service providers, and no one else:

  • Google Firebase — sign-in, database, file storage, crash reporting and analytics.
  • Groq — generating tutor explanations, as described above.

We may also disclose data where the law requires it. We do not sell or rent personal data to anyone, for any purpose.

Where data is stored

Learner data is held in Google Cloud's africa-south1 region in Johannesburg — deliberately close to Zambia, so the app stays quick on a slow connection. Some processing (crash reports, tutor requests) happens on servers outside the region.

Working offline

Downloaded questions and your answers are stored on the device itself so practice keeps working without signal. That local copy is removed when the content is deleted in Settings → Storage or when the app is uninstalled.

How long we keep it

We keep an account and its study history while the account is active, so that revision schedules and progress survive from one term to the next. If you ask us to delete an account, we remove the personal data and the study history within 30 days, keeping only what we must for accounting and fraud prevention.

Your rights

You can ask us to give you a copy of your data, correct it, or delete it. Write to hello@exampass.app from the address or number on the account, or ask the school or agent who set it up. We answer within 30 days.

Security

Traffic is encrypted in transit. Access to the database is governed by server-side security rules, so one learner cannot read another's records, and app requests are attested with Firebase App Check. No system is perfect; if we ever suffer a breach affecting personal data, we will tell affected users and the relevant authority.

Changes

If we change this policy we will update the date at the top, and for anything significant we will tell you in the app before it takes effect.

Questions about your data?

Write to us and a person will reply — learners, parents, schools and agents all welcome.

hello@exampass.app