Privacy

Useful measurement without learner profiling.

We use limited public-page analytics and anonymous hourly funnel totals to improve the site. Private answers, scores, identities, and session values are never written to the funnel counters.

First-party aggregate funnel counts

Selected milestones—such as opening a certification, starting or submitting a diagnostic, opening a source, and requesting a release notice—increment an hourly PostgreSQL counter. Each counter contains only an allowlisted event name, certification code, coarse page source, hour, and count.

The counter does not store an IP address, browser identifier, cookie, account ID, email, question response, score, or visited URL. Browser-side event requests explicitly omit credentials.

Release-notice requests

If you request early access, we store the normalized email address, certification, requested practice option, optional target exam month, general referral source, and consent time. We use this only for the release notice requested and any material correction to that release—not as a general marketing subscription.

We keep the request until the notice has been fulfilled or you ask us to delete it through the contact page.

Server-owned lifecycle measurement

When enabled, our application records a small allowlisted set of completed lifecycle milestones: diagnostic start and completion, Checkout creation, and paid, refunded, or disputed order status. The dimensions are limited to a fixed route category, certification, approved offer, coarse campaign category, result, and test or live commerce mode.

To deduplicate and correlate those milestones without storing account, anonymous-principal, attempt, or Checkout identifiers, the server replaces application-owned UUIDs with keyed one-way pseudonyms before storage or Stripe correlation. Pseudonyms are separated by test/live mode and a bounded immutable key epoch. The epoch can change only after every retained event from the prior epoch has expired or been purged.

The analytics table cannot store arbitrary metadata and assigns each event an expiry exactly 90 days after occurrence. An application-owned retention scheduler starts immediately, uses the PostgreSQL clock, and continues pruning expired rows even when collection is disabled or its key is unavailable.

Data excluded from lifecycle events

Lifecycle events never include question text, answer selections, rationale, names, email addresses, raw IP addresses, full user agents, URLs or query strings, authentication or session tokens, Stripe secrets, payment details, Stripe object IDs, or arbitrary metadata.

This first-party service is independent of Google Analytics and Clarity. It is server-owned, does not add a browser tag or cookie, and fails closed when its dedicated pseudonymization key is unavailable.

Contact and correction reports

When you use the contact or corrections form, we collect the reply email address, any optional name, the category and subject, and the message or correction details you submit. Correction reports can also include a WebLizard Labs page URL, certification code, revision identifier, and public source URL.

We use this information only to respond to the inquiry or investigate the reported content. The website sends the report through Azure Communication Services to our monitored Microsoft 365 support mailbox. The application does not store a second copy in its database, but Microsoft systems and the mailbox process and retain the message.

Retention and replies

We keep messages while they are needed for support, editorial investigation, reasonable follow-up, or applicable legal obligations, then delete them from the support mailbox under our operational retention practices. You can ask us to delete an eligible message through the contact form.

We do not send an automatic confirmation to the submitted address. Do not send passwords, session cookies, payment card details, protected exam material, or unnecessary personal information.

Microsoft Clarity

Public pages use Microsoft Clarity to collect cookieless, per-page interaction and usage information. Clarity Consent V2 is set to deny both analytics storage and advertising storage, so the integration does not set Clarity cookies or persist a visitor identity across pages.

Clarity is not loaded on the contact and corrections pages or on authentication, account dashboard, diagnostic, lab, practice-session, commerce, or workforce operations routes.

What this helps us improve

We use aggregate trends to improve navigation, page clarity, educational content, and the path from a diagnostic to verified study guidance. We do not use these systems to build learner profiles or inspect private assessment activity.

Microsoft describes how it processes Clarity data in its privacy statement and Clarity consent documentation.

Google Analytics

Google Analytics is optional and remains off until you choose Allow analytics. We store that choice in this browser's local storage. Rejecting optional analytics keeps the Google tag unloaded; you can change the choice later through Analytics settings in the footer.

When allowed, Google Analytics measures visits and navigation on successful public pages. Page locations use the canonical public URL without query strings or fragments; same-site referrers omit query strings and fragments, while external referrers are reduced to their origin. Advertising storage, advertising user data, advertising personalization, Google signals, and ad-personalization signals remain disabled.

Sensitive areas stay excluded

The Google tag is not rendered on the contact and corrections pages or on authentication, account dashboard, diagnostic, lab, practice, commerce, workforce operations, internal/API, health, metrics, or error responses.

Do not place private answers, scores, identity values, session values, payment details, or sensitive query data in public page URLs. Google describes its processing in the Google Privacy Policy.

Questions

If you have a privacy question, contact WebLizard Labs. Do not include passwords, session cookies, payment details, or protected assessment content.