1. Introduction
Welcome to Analyst Quorum ("we", "us", "our"). We operate the website at analystquorum.com (the "Service"). This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and your rights regarding that information.
You accept this Privacy Policy, together with our Terms of Use, by ticking the acceptance box when you register. We record the date, time and document versions you accepted. If you do not agree with this policy, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
Email address. When you register on the platform, you provide your email address. We use this to send you an access token and service communications (e.g., inactivity warnings, account notices).
Name. You provide your name at registration. This is used to personalise communications addressed to you.
CFA level, pathway and exam date. You select which CFA exam level you are preparing for (Level I, II, or III), your exam window, and, for Level III, your specialisation pathway. This determines the content served to you and how your progress is tracked and compared with candidates preparing for the same exam.
Acceptance record. When you register, we record the date and time you accepted the Terms of Use and this Privacy Policy, and the versions you accepted.
2.2 Information Generated by the Service
Access token. We assign each user a unique 8-character alphanumeric access token. This token links your practice history to your session and is the only identifier used in client-side operations. Your email address is never sent to the browser.
Practice data. When you answer questions on the Service, we record: the question identifier, your answer, whether your answer was correct, the date and time of the attempt, your running accuracy per topic, and the number of practice cycles completed per topic. This data is linked to your access token.
Essay practice (Level III). When you complete a constructed-response (essay) practice session, your written answer is submitted to our automated scoring model for evaluation and a score report is returned to you in the same session. We retain the text of your essay answers, together with the score report, for internal scoring-quality review. Our team uses it to check and improve the accuracy of our automated scoring. This stored response text is used only for that review, is never shown to other users, is not used for advertising, is deleted when you delete your account, and is in any case automatically deleted after 6 months. We also retain the scoring outcome: points scored, points available, the essay and topic/subtopic identifiers, and the date of the attempt. Scoring is performed by our scoring engine using a third-party model provider (Google, see Section 6); your response text is sent to that provider solely to produce your score and is not used to train their models.
Community question statistics. Each time any user answers a question, anonymous counters on that question record are incremented (total attempts, correct answers, timing). These counters contain no user identifier and never did. They are properties of the question, not of you. They power features such as the question difficulty indicator. Because they are not linked to any account, they are not affected by account deletion (see Section 9).
Usage data. We may collect standard web server logs including your IP address, browser type, pages visited, and the date and time of your visit. This information is used for security monitoring and service improvement.
Cookies and analytics. We use Google Analytics 4 for website analytics. It sets cookies only after you accept non-essential cookies in our cookie consent banner, which lets you accept or decline them first; until you accept, no analytics cookies are set and no analytics data is collected. Advertising (Google AdSense / Ad Manager) is not currently active and would likewise operate only behind that consent banner. See Section 7.
2.3 Feedback Submissions
If you submit a question report or feedback through the Service, we record a link to your account, the question reference, the type of issue, and any notes you provide. Because your notes are free text and may contain personal information, feedback you submitted is deleted (not anonymised) when you delete your account. See Section 9.
3. How We Use Your Information
We use the information we collect to:
- Deliver and operate the Service (send access tokens, serve questions, record attempts)
- Display your progress and performance data within the Service
- Score your essay practice answers using our automated scoring model and show you the results
- Produce anonymous, aggregated cohort statistics so you can compare your performance with peers at your level (see Section 4)
- Send service communications (token delivery, inactivity warnings, account updates)
- Analyse aggregate usage to improve question quality and platform performance
- Serve relevant advertisements via Google AdSense / Google Ad Manager, if and when advertising is activated (with consent, see Section 7)
- Monitor for security threats and prevent abuse
- Comply with applicable legal obligations
We do not sell your personal information to third parties. We do not currently send marketing email of any kind. See Section 14.
Legal bases for processing (GDPR). Where applicable, we process your personal data on the following legal bases:
- Contract performance: delivering the Service you signed up for (practice questions, progress tracking, essay scoring, access tokens, display of your own results and percentile).
- Legitimate interests: producing anonymous cohort statistics (assessed in a Legitimate Interests Assessment, see Section 4), security monitoring, abuse prevention, and evaluation-quality review of the scoring engine's outputs.
- Consent: analytics and advertising cookies, once activated, and any future marketing communications. You may withdraw consent at any time; see Sections 7 and 14.
- Legal obligation: where we must retain or disclose information to comply with applicable law.
4. Peer Comparison and Cohort Statistics
The Service shows you how your performance compares with other candidates at your level ("cohort statistics"): topic averages, percentile standing, and "Outperforming / Underperforming" indicators. To produce these, your practice results (attempts, accuracy, timing, essay points) are combined into anonymous aggregates together with those of other candidates. Individual results are never shown to other users.
We only display a cohort comparison for a topic when the sample behind it is large enough that no individual could be identified or singled out:
- at least 10 distinct candidates at your level must have practised the topic (this floor counts people, not attempts, so no statistic can ever rest on the activity of one or two candidates); and
- the cohort must hold at least 80 answered questions in that topic for multiple-choice statistics, or at least 30 scored essays for essay statistics; and
- you must have enough of your own attempts in the topic (at least 20 multiple-choice answers, or 3 essays) before we compare you to anyone.
Even above these thresholds, we do not declare you ahead of or behind the cohort unless the gap is larger than the statistical margin of error; otherwise the Service shows both numbers and says "Too close to call".
Your percentile standing is shown only once at least 30 candidates at your level each have at least 20 answered questions or 3 scored essays. Your results stop counting toward a level's statistics six months after that level's exam sitting. The number of candidates behind your standing is shown only when it is above 100.
Multiple-choice and essay statistics are computed and displayed separately for topic-by-topic comparisons. Your overall percentile standing combines them, weighting your multiple-choice accuracy and your essay points equally, in the same way as the accuracy figure shown on your dashboard.
Cohort aggregation is carried out under our legitimate interest in providing comparative learning analytics, assessed and documented in a Legitimate Interests Assessment. An individual opt-out is not offered because the displayed outputs are anonymous aggregates protected by the thresholds above; if you object to contributing, contact us (Section 13) and we will assess your objection individually. Deleting your account removes your data from all future aggregate computation.
5. Data Storage and Security
Your data is stored in Airtable, a cloud database service operated by Formagrid Inc. (United States). By using the Service, you acknowledge that your data may be transferred to and processed in the United States or other countries where Airtable operates.
We apply the following measures to protect your data:
- All connections to the Service are encrypted via HTTPS/TLS
- Your email address is stored in Airtable and is not exposed to other users or sent to the browser
- Access tokens are the only identifier used in client-side operations
- Airtable API keys are never exposed client-side; all database operations are routed through server-side Cloudflare Worker processes
- Rate limiting is applied to all API endpoints to prevent brute-force attacks
- The curriculum administration tool is protected by Cloudflare Access (authentication required)
Despite these measures, no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security.
6. Third-Party Services
We use the following third-party services that may process your data:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Airtable (Formagrid Inc.) | Database storage (questions, students, attempts, acceptance records) | airtable.com/privacy |
| Cloudflare | Website hosting and page delivery, DNS, content delivery, API proxy, access control, edge key-value storage | cloudflare.com/privacypolicy |
| Google (Gemini API) | Automated essay scoring. Your essay response text is sent for scoring only and is not used to train Google's models (paid API tier). We keep our own copy of the response and its score for internal scoring-quality review (see Sections 2.2 and 8) | policies.google.com/privacy |
| Resend | Transactional email delivery | resend.com/legal/privacy-policy |
| Anthropic (Claude) | Platform development and operations tooling. Used to build and maintain the Service; does not use data processed for us to train its models | anthropic.com/legal/privacy |
| Google Analytics 4 | Website analytics. Active only after you accept analytics cookies in our cookie consent banner; no analytics cookies are set or data collected until you accept | policies.google.com/privacy |
| Google AdSense / Ad Manager | Advertising. not yet active; will launch only behind a cookie consent banner | policies.google.com/privacy |
We are not responsible for the privacy practices of these third parties. Where required, we have entered into data processing agreements with these providers.
7. Cookie Policy
We use the following types of cookies and browser storage:
Strictly necessary. Required for the Service to function (e.g., session management, keeping you logged in during practice, recording your acceptance of essay practice terms). These cannot be disabled.
Analytics cookies. Set by Google Analytics 4 only after you accept non-essential cookies in our cookie consent banner. These collect anonymised data about how you use the Service. You can decline them in the banner or via Google's opt-out tools.
Advertising cookies. Will be set by Google AdSense if and when advertising is activated. These may track your browsing activity across websites. You can manage your ad preferences at adssettings.google.com.
No analytics or advertising cookies are currently set. If they are introduced, a cookie consent banner will appear on your first visit and allow you to accept or decline non-essential cookies. Non-essential cookies are not set before you consent.
8. Data Retention
| Data type | Retention period |
|---|---|
| Account data (name, email, CFA level, pathway, exam date, access token) | Until you delete your account (immediate, see Section 9), or until the Inactive-Account Retention purge: if your account is inactive for approximately 6 months, we send a warning email about 7 days beforehand and then permanently purge the account and all linked practice data |
| Practice attempt and progress records | With your account. Deleted when the account is deleted or purged for inactivity |
| Archived level progress (Level-Archive Retention) | When you change CFA level, your outgoing level's progress is archived. It is restored automatically if you change back to that level within 6 months of the level change; after 6 months it is permanently destroyed. This clock is separate from, and can run at the same time as, Inactive-Account Retention |
| Essay response text | Retained for scoring-quality review. Your written essay answers are stored together with the score they received so our team can review and improve scoring accuracy. Used only for that purpose, automatically deleted after 6 months, and deleted immediately if you delete your account. The resulting per-topic/subtopic scores persist separately as part of your progress |
| Essay scores (points per attempt, per topic/subtopic) | With your account |
| Community question statistics (anonymous per-question counters) | Retained for the life of the question. They contain no user identifier (see Sections 2.2 and 9) |
| Feedback submissions | Until resolved, then archived for 12 months, or deleted immediately when you delete your account, whichever comes first |
| Terms/Privacy acceptance record (date, time, versions accepted) | Life of the account, plus as required to demonstrate compliance with applicable law |
| Rights-request correspondence log | Retained as proof of compliance where you exercised a data-protection right by email; contains minimal data and no practice history |
| Server/web logs | 30 days |
Provider-side retention after deletion. When we delete your data from our database, our database provider (Airtable) retains residual copies for a period outside our control: deleted records remain in the base's trash for approximately 7 days, and Airtable also keeps base snapshots and revision history that our current subscription plan does not allow us to purge on demand. See Section 9 for what this means when you delete your account.
9. Deleting Your Account
You can delete your account yourself at any time from your account page. Deletion is immediate and permanent. There is no grace period, recovery option, or soft delete. A confirmation email is sent to your registered address when the deletion begins.
What is deleted:
- your account record (name, email, level, pathway, exam date, access token)
- all of your practice progress records, including any archived level progress
- your essay attempt records (scores and quota records), and any stored essay responses and scores we held for scoring-quality review
- any feedback or question reports you submitted, including your free-text notes. These are deleted outright, not anonymised
- all server-side session and operational keys linked to your account
- locally stored data in the browser on the device you delete from
If you have used the Service on other devices, any residual data stored locally in those browsers cannot be cleared remotely; it no longer connects to any account and will not authenticate.
What is not deleted:
- Community question statistics. The anonymous counters described in Section 2.2 (total attempts, correct answers, timing per question) are increments on question records. They contain no identifier linking them to you and never did, so there is nothing personal to delete and no way to reverse individual contributions out of them. They are retained for the life of each question.
- The rights-request log entry, if you exercised a data-protection right by email. Retained as minimal proof of compliance.
Provider-side residual copies. After deletion, your account and all of your study data have been deleted from our database. However, our database provider (Airtable) retains residual copies for a period outside our direct control: deleted records remain in the base's trash for approximately 7 days, and Airtable keeps base snapshots and revision history which our current subscription plan does not permit us to purge on demand. These residual copies are not used by us for any purpose and expire on Airtable's own schedule. For this reason we say your data has been deleted, and we do not claim it has been instantly erased from every system.
If you cannot access your account (for example, you no longer control the registered email address or cannot log in), you can request deletion by email instead. See Section 11.
After deletion, you may register again with the same email address; the new account starts completely fresh.
10. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten"): available directly and immediately from your account page (see Section 9), or by email if you cannot log in
- Object to or restrict certain processing (including contribution to cohort statistics, see Section 4)
- Portability of your data in a machine-readable format
- Withdraw consent where processing is based on consent
To exercise any of these rights, email us at privacy@analystquorum.com (requests to hello@analystquorum.com are also accepted). We will respond within 30 days (or within any shorter period required by applicable law).
If you are located in the European Economic Area (EEA), United Kingdom, or a jurisdiction with equivalent data protection laws, you may also have the right to lodge a complaint with your local data protection authority.
11. Requests by Email
Account deletion is self-service (Section 9) and does not require contacting us. If you cannot use the self-service route, or for access, correction, portability, or objection requests, email privacy@analystquorum.com from your registered address. We verify that requests come from the email address on the account before acting on them.
12. Children's Privacy
The Service is intended for adults (18+) preparing for professional examinations. We do not knowingly collect personal information from anyone under the age of 18. If you believe a minor has provided us with personal data, please contact us at privacy@analystquorum.com and we will delete it promptly.
13. Changes to This Policy and Contact
13.1 Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the version number and "Last updated" date at the top of this page. For material changes, we will notify users via email (if we hold your email address) or via a notice on the Service. Your continued use of the Service after any change constitutes acceptance of the updated policy.
13.2 Contact us
If you have questions about this Privacy Policy or your data, contact us at:
Email: privacy@analystquorum.com (or hello@analystquorum.com) Website: analystquorum.com
14. Marketing Communications
We do not currently send a newsletter or any marketing email. The only emails you will receive from us are transactional: access token delivery, token resets, inactivity warnings, and account notices (such as confirmation that a deletion has started). These are sent as part of operating the Service and cannot be opted out of while your account is active.
If we introduce a newsletter or other marketing communications in the future, they will be strictly opt-in: a separate, never pre-ticked consent, recorded with its date and wording, with a working one-click unsubscribe in every message, and this policy will be updated first.