Legal
Privacy Policy
Last updated August 22, 2026. Questions belong in the contact form.
This Privacy Policy explains how TaroPrep, based in New York, NY, handles personal information when you use our website, study workspace, AI tutor, subscriptions, classes, rewards, support, and communities. "Personal information" includes information that identifies, relates to, describes, or can reasonably be linked with a person or household.
1. Scope
This Policy applies to TaroPrep-controlled services. It does not govern a college, testing organization, Discord, Instagram, Google, Stripe, or another third party when you use that party's separate service. Their privacy notices apply to their independent processing.
2. Information you provide
- Account information: name, email, password hash, Google sign-in identifier, profile image, account type, graduation year, time zone, and authentication records.
- Study profile: target exam, test date, starting and goal scores, dream school, accessibility and interface preferences, planner settings, and notification choices.
- Study activity: question responses, time spent, eliminations, flags, saves, notes, test sessions, scores, skill estimates, vocabulary progress, lesson progress, streaks, rewards, achievements, and class activity.
- AI and support content: prompts, chat messages, attached images, linked question context, remixes, reports, feedback, support messages, and contact form submissions.
- Community information: Discord account identifier and membership confirmation, Instagram reward claim information, usernames, reward status, and related audit records.
- Guardian and classroom information: invitations, names, email addresses, membership, roles, and information shared through the relevant feature.
3. Payment information
Stripe collects and processes payment card, wallet, billing address, tax, fraud-prevention, and transaction information. TaroPrep does not receive or store a full payment card number or card security code. We store Stripe customer, checkout, subscription, price, invoice, payment status, renewal, cancellation, legal-consent, and transaction references needed to provide and support paid access.
4. Information collected automatically
We and our infrastructure providers may collect IP address, browser and device type, operating system, referring page, request time, visited route, language, approximate region, session identifiers, cookie choices, error data, security signals, performance information, and feature events. We use this information to authenticate requests, prevent abuse, diagnose failures, understand product use, and improve reliability. We do not use third-party advertising pixels.
We may derive and retain a two-letter country code from an IP address for account-level and aggregate product analytics. For historical coverage, a country-only geolocation provider may process IP addresses already retained in authentication session records. Staff geography reports do not display raw IP addresses.
5. Sources
We receive information directly from you, from your activity in the Service, from a guardian, educator, or class you join, from Google if you choose Google sign-in, from Stripe for billing, from Discord when you choose community verification, and from service providers that operate infrastructure or protect the Service.
6. How we use information
- create, verify, secure, and recover accounts;
- deliver questions, tests, lessons, vocabulary, planning, and analytics;
- personalize skill routing, recommendations, review, and study schedules;
- provide Taro, including question-aware explanations and image review;
- process subscriptions, synchronize plan access, prevent duplicate billing, and provide support;
- operate rewards, classrooms, guardians, reports, and communities;
- send verification, security, transaction, renewal, cancellation, service, and requested communications;
- detect fraud, abuse, scraping, security incidents, and violations;
- debug, measure, maintain, and improve the Service;
- comply with law, enforce agreements, protect rights, and resolve disputes.
7. AI processing
The private College workspace stores your application profile, saved schools, essay drafts and versions, tasks, and scholarship records. Before an AI scan, we save the submitted profile, selected essay, extracted document text, school-data context, and your consent version. When you run a scan, the required evidence is processed by AI for extraction or coaching. Raw PDF and DOCX files are read on your device; selected images are sent for analysis but their raw bytes are not retained in our database. We retain image names and hashes, scan outputs, model information, and billing records.
Application submissions and AI reviews are stored privately for your history and internal quality review. Authorized access is restricted and logged. Do not include government identifiers, confidential third-party records, signatures, or unnecessary contact information. Use “Export my data” in the workspace for a copy; account deletion removes these application records subject to the retention exceptions described in this policy.
When you use Taro, we send the prompt, relevant conversation, attached images, and question context needed to answer to our configured AI inference provider. We design the request not to include your email address or account name unless you place that information in the content yourself. Provider handling depends on the account configuration and provider terms. Do not place sensitive personal, financial, health, biometric, or confidential school information in prompts or images.
We use AI output to respond to your request. We may use de-identified or aggregated product signals to improve prompts, routing, safety, and features. We do not sell AI chats, and we do not use them to train an advertising profile.
8. Legal bases for processing
Where laws such as the GDPR require a legal basis, we process information to perform our contract with you, pursue legitimate interests such as security and service improvement, comply with legal obligations, protect vital interests in rare safety situations, and rely on consent where required. You may withdraw consent for future processing, but withdrawal does not affect prior lawful processing.
9. Service providers and disclosures
We disclose information only as reasonably needed to providers that support hosting and delivery, databases, authentication, email, payments, analytics, AI inference, security, error monitoring, and community verification. Current categories include Vercel, Neon, Better Auth infrastructure, Google, Resend, Stripe, Discord, and AI inference services. Providers process information under their agreements and security terms.
We may also disclose information to comply with law or valid legal process; protect users, rights, safety, and security; investigate fraud; complete a merger, financing, reorganization, or sale subject to appropriate protections; or with your direction. Educators, guardians, and class members receive only information made available through the feature and their role.
10. No sale or targeted advertising
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising and do not use third-party ad networks. We treat a recognized Global Privacy Control signal as an opt-out request where legally required, although our current practices do not involve sale or advertising sharing.
11. Retention
We retain account and study information while the account is active and until deletion, unless a shorter feature-specific setting applies. AI chats and images remain until the chat or account is deleted. Temporary OAuth state expires quickly. Security, abuse, and audit records may be kept longer when reasonably necessary. Billing, consent, tax, refund, fraud, and dispute records may be retained for the period required by law or needed to establish, exercise, or defend claims, commonly up to seven years.
Deleted information may remain for a limited period in encrypted backups and disaster-recovery systems before ordinary rotation. De-identified aggregate information may be retained if it cannot reasonably be linked back to you. We review retention based on purpose, sensitivity, legal duties, and risk.
12. Security
We use safeguards appropriate to the nature of the Service, including hashed passwords, signed and HttpOnly session cookies, server-side authorization, scoped database access, encrypted transport, secret separation, rate limits, webhook signatures, payment tokenization, audit records, and restricted staff roles. No system is perfectly secure. You are responsible for securing your email account, device, and login methods.
13. Your choices
Settings allow you to correct profile information, change preferences, review authentication methods, manage billing, and export selected data. You may delete AI chats, leave classes or communities, revoke Google or Discord authorization through those services, block optional browser storage, or request account deletion. Essential cookies are required for sign-in and security.
14. Privacy rights
Depending on where you live, you may have rights to know, access, correct, delete, restrict, object to, or receive a portable copy of personal information; opt out of sale, sharing, targeted advertising, or certain profiling; withdraw consent; and appeal a denied request. We do not discriminate against users for exercising privacy rights.
Submit a request through the contact form from the account email. We may verify identity and authority before acting. An authorized agent may be required to provide permission and identity evidence. We will respond within the period required by applicable law. Some records are exempt, including information needed for security, legal compliance, transactions, or claims.
15. California and other US state notices
The categories collected during the preceding 12 months are identifiers, account and customer records, commercial and subscription information, internet activity, approximate geolocation, educational and study activity, audio-visual content you upload, inferences about study needs, and support communications. We use and disclose them for the business purposes described above. We do not knowingly sell or share information of consumers under 16.
California and other covered residents may exercise applicable access, correction, deletion, portability, opt-out, limitation, and appeal rights through the contact form. We do not use sensitive personal information to infer characteristics beyond providing and securing requested features.
16. International transfers
TaroPrep is operated from the United States, and providers may process information in the United States and other countries. Those countries may have different privacy laws. Where required, we rely on recognized transfer mechanisms and provider contractual protections.
17. Children and teens
The Service is designed for high-school students, parents, and educators, not children under 13. We do not knowingly allow a child under 13 to create an account or knowingly collect personal information from such a child without a legally valid parental process. If you believe a child under 13 provided information, contact us so we can investigate and delete it. Teens should use the Service with parent or guardian awareness, especially for purchases and image uploads.
18. School use
If a school directs use under a separate written agreement, that agreement may include additional student-data terms. Without such an agreement, TaroPrep is a consumer service selected by the user and not a school-designated education records system. Educators must not upload protected student records unless authorized and appropriately contracted.
19. Changes and contact
We may update this Policy as the Service, providers, or law changes. We will post the new date and provide additional notice for material changes where required. For privacy questions, rights requests, or concerns, use the contact form or email jacob@taroprep.com. Account deletion details are in the Deletion Policy.
