Privacy Policy
Last updated: August 3, 2026 · Effective date: August 3, 2026
This Privacy Policy explains how Testium Labs ("we", "us", "our", or the "Provider") collects, uses, discloses and protects personal information in connection with the CFA Level 1 Test mobile application, our website at clearlevelone.com and related services (together, the "Service"). It also describes the rights available to you depending on where you live. Please read it together with our Terms & Conditions.
1. Who is responsible for your data
The data controller is Testium Labs, the developer of CFA Level 1 Test. For any privacy question, or to exercise your rights, contact our privacy team at privacy@testiumlabs.com.
2. Scope
This policy applies to users worldwide. Where mandatory local law grants you greater rights than those described here, those rights prevail. The Service is intended for a global, English-speaking audience of adults preparing for the CFA® Program Level I exam.
3. Information we collect
- Account data. If you create an account or sign in with email, Sign in with Apple, or Sign in with Google, we process a user identifier and your email address (and, if you provide it, a display name). Authentication is handled through Supabase Auth.
- Study & progress data. Your answers, correct/incorrect counts, streaks, mock-exam results and derived statistics. This is stored primarily on your device and, if you have an account, associated with your identifier so it can sync and power the leaderboard.
- Purchase & subscription data. Your entitlement/subscription status, managed through Apple (StoreKit). We never receive or store your payment-card details; Apple processes all payments.
- AI explanation content. When you request an AI explanation, the question text, its answer options and the selected answer are sent to our server and then to our AI subprocessor (OpenAI) to generate the explanation. We instruct that no directly identifying personal data is sent with the question.
- Device attestation & anti-abuse data. We use Apple's App Attest and an anonymous device key, plus coarse technical signals (e.g., truncated IP for rate-limiting), to verify that requests come from a genuine app instance and to prevent abuse of the AI service. These signals are not used to identify you personally.
- Technical & log data. Device model, operating-system version, app version, language, and diagnostic/crash information, used for security, troubleshooting and to keep the Service working.
- Support communications. If you contact us, we keep your messages and contact details to respond and keep records.
We do not knowingly collect special categories of data (e.g., health, biometric, precise geolocation) and we do not require them to use the Service.
4. How we use your information and our legal bases
Where the EU/UK GDPR applies, we rely on the following legal bases (Art. 6 GDPR):
- Performance of a contract — to provide the Service, your account, sync your progress, run the leaderboard and manage subscriptions.
- Legitimate interests — to secure the Service, prevent fraud and abuse (including device attestation and rate-limiting), maintain and improve features, and analyse aggregate usage. We balance these interests against your rights.
- Consent — where required, for optional features; you may withdraw consent at any time without affecting prior processing.
- Legal obligation — to comply with applicable law, tax and accounting rules, and lawful requests.
We do not use your personal information for third-party advertising, and we do not sell it.
5. AI processing
AI explanations are generated by a third-party large-language-model provider (currently OpenAI) acting as our processor/subprocessor. Only the content needed to produce the explanation (question, options, chosen answer, topic) is transmitted. Explanations are generated automatically and may contain errors; see the disclaimers in our Terms & Conditions. We do not use your inputs to train our own models, and we require our AI provider to handle the data under its enterprise/API terms rather than for training its foundation models where such controls are available.
6. Who we share information with
We share personal information only with service providers ("processors") that help us run the Service, under contracts that require appropriate safeguards:
- Apple — App Store, StoreKit payments, Sign in with Apple, App Attest.
- Google — Sign in with Google (only if you choose it).
- Supabase — authentication, database and edge functions (account and progress/leaderboard storage).
- OpenAI — generation of AI explanations (receives question text, not directly identifying data).
We may also disclose information if required by law, to enforce our Terms, to protect the rights, safety or property of users or the public, or in connection with a merger, acquisition or asset sale (subject to this policy). We do not sell your personal information and we do not "share" it for cross-context behavioural advertising as those terms are defined under U.S. state privacy laws.
7. International data transfers
We operate globally, so your information may be processed in countries other than your own, including the United States. Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), adequacy decisions, or other lawful transfer mechanisms. You may request a copy of the relevant safeguards via privacy@testiumlabs.com.
8. Retention
We keep account and progress data for as long as your account is active, and thereafter only as needed for the purposes described here or as required by law (e.g., tax records). Anti-abuse and rate-limit records are kept for a short period. If you delete your account, we delete or irreversibly anonymise the associated personal data in our systems, except where retention is legally required (see Delete your account).
9. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, hardware-backed device attestation and least-privilege server credentials. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If a personal-data breach affects you, we will notify you and the competent authorities where required by law.
10. Your rights (EEA, UK, Switzerland)
Subject to conditions and exemptions in the GDPR/UK GDPR, you have the right to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; data portability; and to withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority. To exercise your rights, email privacy@testiumlabs.com or delete your account in-app. We will respond within the timeframes required by law and will not discriminate against you for exercising your rights.
11. U.S. state privacy rights (California and others)
If you are a California resident, the CCPA/CPRA gives you the right to know/access the categories and specific pieces of personal information we collect, to delete it, to correct it, and to opt out of "sale" or "sharing" (we do neither) and of certain profiling. You also have the right not to receive discriminatory treatment for exercising your rights, and you may use an authorised agent. In the prior 12 months we have collected the categories described in Section 3 (identifiers, commercial/transaction information, internet/usage activity, and user-generated content) for the business purposes in Section 4. Residents of Virginia, Colorado, Connecticut, Utah and other U.S. states with comparable laws have similar rights. To exercise them, email privacy@testiumlabs.com. We honour recognised opt-out preference signals where legally required.
12. Children
The Service is intended for adults and is not directed to children. We do not knowingly collect personal information from children under 16 (or under 13 in the United States, or the applicable age of digital consent in your country). If you believe a child has provided us personal data, contact us and we will delete it.
13. Cookies and local storage
The app stores certain preferences and progress locally on your device. Our website uses only essential/functional storage and does not use third-party advertising or tracking cookies. We honour "Do Not Track" and Global Privacy Control signals to the extent required by law.
14. Third-party links
The Service may link to third-party sites or services (e.g., Apple, the official CFA Institute website). We are not responsible for their privacy practices; review their policies separately.
15. Changes to this policy
We may update this policy from time to time. We will post the current version here with a new "Last updated" date and, where required, notify you of material changes. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
16. Contact
Privacy enquiries: privacy@testiumlabs.com. General support: support@testiumlabs.com.
CFA Institute does not endorse, promote, or warrant the accuracy or quality of the products or services offered by CFA Level 1 Test. CFA®, Chartered Financial Analyst®, and the CFA Institute marks are trademarks owned by CFA Institute. CFA Level 1 Test is an independent study aid and is not affiliated with, authorised by, or endorsed by CFA Institute.
CFA Level 1 Test