Information we collect
Staff accounts
When a school administrator or teacher creates an account, we collect a username and password. Passwords are hashed and never stored in plain text.
Student sessions
Students do not create accounts. When a student joins an exam, we collect the name they provide and assign an anonymous session identifier. No email addresses, phone numbers, or persistent identifiers are collected from students.
Exam activity
During an exam session, we log activity events such as focus changes, clipboard attempts, and connection status. These events are used for proctoring and are associated with the anonymous session, not a persistent student profile.
How we use your information
- Authenticate staff and authorize access based on roles
- Deliver exams to students via anonymous sessions
- Provide proctoring signals and integrity reports to teachers
- Enable grading, analytics, and exam management
- Send transactional emails (account invitations, password resets)
Storage and security
Data is stored in a PostgreSQL database and file assets are stored in Amazon S3. All connections use TLS encryption. Access to production systems is restricted to authorized personnel.
JWT-based authentication is used for staff sessions. Student exam sessions use short-lived access tokens scoped to a single exam.
Student privacy
TestBreak is designed with student privacy as a core principle. Students do not create accounts, do not provide email addresses, and are identified only by the name they enter when joining an exam. Anonymous grading further separates student identity from their submissions during evaluation.
Data retention
Exam sessions, activity events, and submissions are retained for as long as the associated school account is active. Schools may request deletion of their data by contacting support. When a school is deactivated, associated data is retained for a reasonable period before permanent deletion.
Third-party services
We use the following third-party services:
- Amazon Web Services (S3, SES) for file storage and transactional email
- OpenAI for AI-assisted features such as PDF extraction and grading assistance
We do not sell, rent, or share personal information with third parties for marketing purposes.
Your rights
Staff users may request access to, correction of, or deletion of their account information by contacting their school administrator or our support team. Schools may request deletion of all data associated with their institution.
Contact
For questions about this privacy policy or your data, contact us at help@testbreak.com.
See also our Terms of Service.