Privacy Policy
1. Who we are
Cert Trainer by OpsAgents (“the Trainer”) is operated by MSApps Mobile Ltd., 6 Galgalei HaPlada St., Herzliya, Israel, under the OpsAgents.agency brand. MSApps Mobile Ltd. is the controller of the personal data described here. For anything in this policy, write to michal@opsagents.agency.
The Trainer is an independent study tool. It is not affiliated with, endorsed by, sponsored by, or operated by Anthropic, PBC, and Anthropic receives no data from it. “Claude” and related marks are trademarks of Anthropic, PBC, used for descriptive reference only.
2. What we collect, and why
2.1 Your account
- Anonymous by default. When you open the Trainer we create an anonymous account identifier (via Firebase Authentication) so your answers can be graded and your progress kept. It carries no name or email.
- If you sign up with email and password we store your name, email address and a hashed password, plus whether you ticked the newsletter box. If you sign in with Google we receive the name, email and profile picture Google shares. MSApps employees may sign in through the company’s Zoho account.
- Why: to operate your account, keep your progress across devices, and — only if you opted in — send you new questions and study tips. You can unsubscribe at any time by replying to any such email or writing to us.
2.2 Your study activity
- For every question you answer: the question identifier, the option you chose, whether it was correct, the language you were using, the domain and the time. For mock exams: your attempts and scores. For group sessions: the room code, the display name you enter (optional) and your votes.
- Grading happens on our servers; the correct answers are never sent to your device. This is how we keep practice honest for everyone.
- Why: to grade you, show your mastery per domain, make the group modes work, and understand which questions are too easy, too hard or broken.
2.3 On your device
- Your points, streaks, badges, best game scores, chosen language and any answers awaiting grading while you were offline are stored in your browser’s or app’s local storage. This stays on your device; when you are signed in, your study activity is also kept in your account so it follows you.
2.4 Purchases
- On the web, paid access is sold through iCount, an Israeli payment and invoicing provider. You enter card details on iCount’s secure page — we never see or store card numbers. iCount tells us that a payment succeeded together with your account identifier, the product you bought, a transaction reference and the email you gave at checkout, which we use to unlock what you paid for and to send a confirmation.
- In the iOS and Android apps, purchases go through the Apple App Store or Google Play, managed for us by RevenueCat. We receive transaction and receipt identifiers and the product bought — never payment details. Apple’s and Google’s own privacy terms apply to the payment itself.
- Why: to deliver and keep unlocked what you bought, issue receipts, and meet our tax and accounting obligations.
2.5 Certification badge claims
- If you hold a Claude certification badge on Credly and submit its public URL to claim the benefit described in the app, we check that URL against Credly’s public badge record and store the URL you submitted and the result of that check.
2.6 Usage, performance and crash telemetry
The Trainer uses several analytics and diagnostics services. None of them is used for advertising, and we do not sell personal data.
| Service | What it records | Where it runs |
|---|---|---|
| PostHog | Page views, clicks and interactions, uncaught errors, and session replays in which everything you type is masked before it leaves your device.
PostHog traffic is routed through our own domain (/pxl) to PostHog’s servers, so browser ad-blockers may not intercept it. It is not loaded on our admin pages. |
United States |
| Google Analytics 4 | Page views and aggregate usage of the web pages. | Google (may process in the United States) |
| Mixpanel | Product events such as starting an exam or completing a purchase. Honours your browser’s Do Not Track setting. | United States |
| Firebase Performance | Page-load and network timings for the web app. | |
| Firebase Crashlytics | In the mobile apps only: crash reports with device model, OS version and the crash trace. |
Why: to find broken pages and questions, measure whether the Trainer actually helps people pass, and fix crashes. If you would rather we not process telemetry about you, write to us and we will honour that; the mobile apps’ crash reporting can also be disabled in your device’s settings.
3. Where your data is stored
- Accounts, study activity, purchases and badge claims are stored in Google Firebase (Firestore and Cloud Functions) in the europe-west3 (Frankfurt, EU) region. Firebase Authentication is a global Google service.
- Telemetry is processed by the providers in the table above, several of which are in the United States. Confirmation emails are sent through Zoho.
- Where data leaves the European Economic Area or Israel, we rely on the providers’ standard contractual safeguards.
4. Who we share it with
Only the service providers named in this policy, each acting on our instructions to run the Trainer: Google (Firebase, Analytics), PostHog, Mixpanel, RevenueCat, iCount, Credly (public badge lookup only) and Zoho (email). We share personal data with no one else unless the law requires it. We do not sell personal data and we show no advertising.
5. How long we keep it
- Account and study data: for as long as your account exists, and until you ask us to delete it (see below). Anonymous accounts that are never signed into are kept so returning devices recover their progress.
- Purchase records: for as long as tax and accounting law requires.
- Telemetry: under each provider’s standard retention schedule, which we keep at its default.
6. Your rights and choices
- You can ask us to access, correct, export or delete the personal data we hold about you, to object to processing based on our legitimate interests, and to withdraw consent where processing is based on it. Write to michal@opsagents.agency; we will answer within 30 days.
- Delete your account: email us from the address on the account, or from the app’s profile, and we will delete the account and the study activity linked to it. Purchase records needed for tax purposes are retained as the law requires.
- If you are in the EEA or UK you may also complain to your local data-protection authority; in Israel, to the Privacy Protection Authority.
7. Children
The Trainer is a professional certification study tool and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has given us personal data, write to us and we will delete it.
8. Security
All traffic is encrypted in transit. Database access is governed by Firebase security rules and our servers grade answers so the answer key never reaches a device. Payment card data never touches our systems. No method is perfect; if we learn of a breach affecting you we will tell you as the law requires.
9. Changes
When this policy changes we update the effective date at the top. Material changes will also be announced in the app.
Questions about this policy: michal@opsagents.agency.
← Back to the trainer