Skip to main content

Privacy Policy

Last updated: August 2026

Quizifyme is built for teachers, professors, and homeschool educators. Quizifyme accounts are for educators only — students never have accounts and never sign in, and we do not knowingly collect any student personal information.

What we collect

  • Account information: your email address, name, and (for credentials accounts) a securely hashed password — we never store your password in plain text. If you sign in with Google or Microsoft, we receive the name/email/avatar those providers share.
  • Content you create: the video links/files you submit and the quizzes, transcripts, and other materials you generate and save.
  • Usage & analytics data: generation counts and basic product-usage events, collected through our own first-party analytics (see Cookies below) — never a third-party analytics or advertising network.
  • Billing information: handled entirely by Stripe. We store a Stripe customer/subscription reference and plan status only — your card number never touches our servers.

Why we collect it

To provide the Service (generate and store your quizzes), enforce plan limits, process payments, secure your account, respond to support requests, and understand product usage so we can improve it. We do not use your account information or content for advertising.

Cookies

Quizifyme sets first-party cookies only — cookies from quizifyme.com itself, never from an advertising or analytics network. This is the complete list. Your browser will only hold the ones that apply to what you have actually done: a visitor who never starts a sign-in, for example, never receives the sign-in cookies.

CookieWhat it is forHow long it lasts
authjs.session-tokenKeeps you signed in. On our live site your browser shows it as __Secure-authjs.session-token, and it may be split across numbered cookies (…-token.0, …-token.1) when it is large.14 days from your last visit — ordinary use extends it. Cleared when you sign out.
authjs.csrf-tokenSecurity token that stops another website submitting our sign-in form as you. Shown as __Host-authjs.csrf-token on our live site.Until you close your browser
authjs.callback-urlRemembers which page to return you to once you have signed in.Until you close your browser
authjs.pkce.code_verifierWritten only while you are completing a Google or Microsoft sign-in, to prove the sign-in coming back is the one this browser started.15 minutes
qzm_deviceRecognises this browser so we can tell when an unfamiliar one starts generating on your account (see "Abuse protections" below). It is a random identifier generated by us — not a device fingerprint — and it is not linked to advertising.400 days
qzm_anonAn anonymous identifier used only for our own first-party product analytics (e.g. counting how many people view the pricing page).1 year
qzm_attrRecords the page you first landed on, the site you arrived from, and any campaign or ad-click tag in the link you followed — including the click identifiers Meta, Google and TikTok add to an ad link — so we can tell which of our posts, referrals and ads bring teachers to Quizifyme.1 year
qzm_promoSet only if you follow a link carrying a valid discount code — remembers the code so it is applied when you check out.30 days
qzm_plan_intentSet only when you start creating an account from a plan button — remembers which plan you chose so checkout can resume once your account exists.1 hour
qzm_plan_intent_cThe same thing, for signups that go via Google or Microsoft (the redirect to them happens before we can set the cookie above).1 hour

Every cookie above is httpOnly — it cannot be read by JavaScript running in your browser — except qzm_plan_intent_c, which the page has to be able to write itself for the reason given in its row.

Quizifyme also keeps three small values in your browser's own storage rather than in a cookie: your light/dark theme choice (theme); a video link you pasted before signing in, so it is still there afterwards (qzm_pending_url, deleted as soon as it is used — it reaches us only if you go on to generate from that link); and a note that you dismissed the "verify this device" prompt for the rest of the browser tab (qzm-device-nudge-dismissed). None of the three is sent to us on its own.

We do not use third-party advertising or tracking cookies, and we do not run ads or advertising pixels on the Service.

Subprocessors

We share data only with the vendors that run the Service on our behalf:

CategoryPurposeData involved
Cloud hostingApplication hostingAll Service traffic
Database hostingDatabase hostingAccount, content, and usage records
AI processingAI generation of quizzes/materialsVideo transcripts submitted for generation (our AI provider's API terms do not permit training its models on customer content by default)
TranscriptionTranscript fetching & transcriptionVideo URLs/files you submit
StripePayment processingBilling details (card data never touches our servers)
Email deliveryTransactional emailEmail address, message content (e.g., verification links)
Google / MicrosoftOptional OAuth sign-inName, email, avatar (only if you choose that sign-in method)
Google (Forms & Docs export)Optional one-click Google Forms or Google Docs exportForms/Drive access & refresh tokens (only if you connect one of these features)

We do not sell or share your personal information with data brokers or advertisers.

How we protect your data

We apply the following protections across the Service:

  • Encryption in transit: all traffic to and from Quizifyme is encrypted with HTTPS/TLS.
  • Encryption at rest: our database is encrypted at rest (see Subprocessors above), and any files you upload are encrypted at rest by our storage providers.
  • Passwords: for credentials accounts, we store only a salted hash of your password — never your password itself (see "What we collect" above).
  • Access controls: administrative surfaces are role-gated to authorized staff, and production access is restricted. Payment card data never touches our servers — it's handled entirely by our PCI-DSS-compliant payment processor, Stripe.
  • Abuse protections: we rate-limit sign-in, registration, and other sensitive endpoints, and we limit how many browsers can generate new material on one account. Up to five browsers are trusted automatically; beyond that — or on a browser you have removed under Account → Your devices, or on any new browser in the week after you remove one, or if our systems flag unusual activity — that browser must first clear a one-time six-digit code emailed to your account address. This applies only to generating new material: signing in, and reading, printing or exporting quizzes you already have, are never blocked by it.
  • Google OAuth tokens: the optional Forms/Drive connection described below is minimally scoped — it can only create new files and cannot read your existing Drive — and the resulting tokens are stored encrypted at rest. You can revoke this access at any time from myaccount.google.com/permissions.

Google Forms, Docs & Drive access

Quizifyme's "Create Google Form" and "Google Docs" exports are optional and share a single, separate one-time Google connection beyond sign-in. When you connect it (from either export), Quizifyme requests two additional Google permissions:

  • Forms (forms.body): lets Quizifyme create and populate a new Google Form with the quiz you asked it to export — questions, choices, and correct answers/points. Only used when you use the Google Forms export.
  • Drive, file-scoped (drive.file): lets Quizifyme place a file it creates in your Drive — the Google Form when you use the Google Forms export, or the Google Doc when you use the Google Docs export. This scope only ever sees files Quizifyme itself creates — it does not grant access to your existing Drive files or folders.

These permissions are used only to create the specific Google Form or Google Doc you request when you click "Create Google Form" or use the Google Docs export — Quizifyme does not read, list, modify, or otherwise access any other Google Forms, Docs, Drive files, Gmail, or Google data. The resulting access/refresh tokens are stored in our database, encrypted at rest, and used only to make that request on your behalf.

You can revoke this access at any time from myaccount.google.com/permissions — this immediately stops Quizifyme from being able to create forms or docs on your behalf. Signing in with Google for authentication is unaffected by revoking (or never granting) the Forms/Drive permissions above; they are entirely separate from account sign-in.

Quizifyme's use of Google user data complies with the Google API Services User Data Policy, including Limited Use.

Concretely: no Google user data — your Google account profile, OAuth tokens, or any file created through the Forms or Docs export above — is ever transferred to, or used to train or improve, any artificial-intelligence or machine-learning model (ours or anyone else's), and none of it is ever shared with an AI system. The AI processing described below operates solely on the video transcripts and other content you submit directly to Quizifyme, which never includes Google user data.

AI processing

When you generate a quiz, the relevant transcript text is sent to our AI provider solely to produce the materials you requested. This is a description of our provider's current default API policy, not a contractual guarantee we control: our provider's API does not train its models on customer content submitted through the API.

Retention & deletion

We retain your account and content for as long as your account is active. You can delete individual quizzes at any time. You can also self-serve delete your entire account from Account → Danger zone; this permanently deletes your account, saved quizzes, and associated content, and cancels any active subscription. This action cannot be undone. You may also request deletion by emailing support@quizifyme.com.

Children & COPPA

Quizifyme is not directed to children under 13, and accounts are intended for educators aged 18 and older. We do not knowingly collect personal information from children. Because the Service has no student-facing accounts or student data collection at all, there is structurally little for COPPA to govern in normal use — this is a description of the product's design, not a certification claim.

FERPA-adjacent statement

Quizifyme is a tool for teachers to prepare instructional materials — it does not collect, store, or process student education records of any kind (no student names, grades, IDs, or performance data). Because no student records ever enter the Service, Quizifyme does not itself hold FERPA-covered data; each school or district remains responsible for its own FERPA obligations regarding how teachers use materials produced by any tool, including this one.

Your rights

You can access, correct, or delete your account information at any time from your Account settings, or by emailing support@quizifyme.com.

California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, request deletion of it, and request correction of inaccurate information. We do not sell or share your personal information (as those terms are defined by the CCPA/CPRA), and we do not use or disclose sensitive personal information for purposes requiring an opt-out. To exercise these rights, email support@quizifyme.com.

EEA/UK visitors (GDPR)

If you are located in the European Economic Area or UK, we process your data under the following legal bases: performance of a contract (providing the Service you signed up for), legitimate interests (product analytics, security), and consent (optional OAuth sign-in, marketing email if you opt in). You have the right to access, correct, delete, or port your data, and to object to certain processing — contact support@quizifyme.com to exercise these rights.

Contact

Privacy questions or requests: support@quizifyme.com.

Effective date: August 2026. This policy is provided for transparency.