Privacy policy
Cookd stores your own practice data and what it needs to sign you in. It never stores College Board questions.
The short version
- Question text, passages, answer choices, answer keys, explanations and images stay on College Board’s page. The extension reads them in your browser to show them and never uploads them.
- Cookd keeps what you did on each question: the question ID and topic, your answers, timing, changes, cross-outs, marks, tools you opened, mistake reasons and your notes.
- Without an account, that stays in your browser. With an account, it syncs to Cookd so you can see your stats anywhere.
- You can download everything as JSON or delete your account at any time in Settings.
- No ads, no selling data, no analytics trackers.
What Cookd stores
Your account
Your name, email address and, if you use Google, your Google profile picture and Google’s sign-in tokens (encrypted). Your time zone, from the extension, so “today” on your dashboard is your today. Cookd never sets a password.
Signed-in browsers and tokens
The browsers you sign in on (for example “Chrome on macOS”), the extension’s version, and when each last synced. Personal access tokens for AI apps, by name. Tokens are stored only as hashes and can’t be recovered.
Your practice
For every question you answer with the extension: the question ID, section, domain, skill and difficulty; your first and final answer (a letter or the number you typed); whether it was right after you checked; how long it took; changes, cross-outs and marks; tools you opened; your mistake reason; and a short timeline of those actions in milliseconds. The timeline never includes key presses or text. Also your notes, your practice sets and your practice sessions. Question IDs are kept only in your own records, never in a list shared across students.
What’s left to practice
Counts the extension makes from the Question Bank list: for each skill and difficulty, how many questions there are, how many you haven’t answered and how many are open mistakes, and when it counted. Counts only, never question IDs or content. Practice sets and AI apps you connect use them to fit what you have left.
AI apps you connect
Which apps you allowed and their access tokens (hashed). Disconnecting an app deletes both.
Running the service
Short-lived rate-limit counters keyed by IP address, token or a hash of an email address, deleted within an hour. Sign-in sessions record the IP address and browser user agent. The server keeps request logs (IP address, time and path) for a limited time.
When someone creates an account, downloads the extension or clicks an install button on this website, the server sends Cookd’s operator a short notification with the country (from Cloudflare) and the browser’s name, such as “Chrome on macOS”. It never includes your email address, your name or anything you typed, and nothing extra is stored for it.
What Cookd never collects
College Board content of any kind, your browsing outside the Question Bank, what you type, your passwords, your location beyond the time zone, or anything about you from other sites.
Google user data
If you sign in with Google, Cookd asks Google only for your basic profile: your name, email address and profile picture (the openid, email and profile scopes). Cookd uses them only to create your account, sign you in and show which account is signed in. It can’t see your Gmail, Drive, contacts or anything else in your Google account.
Cookd doesn’t sell this data, use it for advertising, or share it with anyone except the services below that run Cookd. Nobody at Cookd reads it unless you ask for help with your account, it’s needed to keep Cookd secure, or the law requires it. Deleting your account in Settings deletes it, and you can remove Cookd’s access to your Google account at any time at myaccount.google.com/connections.
Cookd’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who else handles it
| Service | What for | What it receives |
|---|---|---|
| Hetzner | Runs the Cookd server and database (Helsinki, Finland) | The data described above; request logs kept for a limited time |
| Cloudflare | DNS, TLS and the connection to the server; encrypted backup copies (EU) | Requests to Cookd; encrypted backups |
| Resend | Sign-in emails | Your email address and the code |
| Desmos | The calculator, in the extension and in the demos on this website | Your browser’s request for the calculator, made only when you open it; Cookd sends it nothing |
| Sign in with Google, if you choose it | The sign-in request; Google shares your name, email and picture with Cookd | |
| AI apps you connect | Answering your questions about your practice | Only what you allow: your practice history, stats, notes and what’s left to practice, never question text |
Cookies
Cookd sets cookies only to keep you signed in and to finish sign-ins. There are no advertising or analytics cookies. (The operator’s own test browser also carries one cookie that turns off the notifications above for it.)
How long it’s kept
- Your practice, notes, sets and question counts: until you delete them or your account.
- Sign-in codes: 10 minutes. Sign-in sessions: 30 days after you last use Cookd.
- Rate-limit counters: up to an hour.
- Server request logs (IP address, time and path): up to a month.
- Encrypted backups: up to 12 months, then deleted. Data you delete leaves the backups within that time.
Your controls
- Export: Settings, Your data, Download JSON gives you everything above.
- Delete: Settings, Delete account removes your account and every attempt, session, note, set, question count, token and connected app at once. Backups that still hold it are deleted within 12 months.
- Disconnect: revoke a browser, token or AI app in Settings at any time.
- Without an account: your practice stays in the extension’s storage in your browser. Removing the extension deletes it.
Age
Cookd is for people 13 and older. If you’re under 13, please don’t create an account. If an account belongs to a child under 13, delete it in Settings or ask us to.
Changes
When this policy changes, the date at the top changes.
Contact
Cookd is run by Lev. Questions, data requests or deletion help: email [email protected].