1. Who operates ITForMe
ITForMe is operated by ZRG Studios ("ZRG Studios," "we," "us," or "our"). This policy applies to the hosted ITForMe website, account system, quizzes, performance-based questions, career roadmaps, progress tools, and community correction features.
External websites and services linked from ITForMe have their own privacy practices. This policy does not control those services.
2. Information we collect
We collect information you provide, information returned by a sign-in provider after you authorize it, and limited technical information produced when you use the service.
- Account and OAuth identity: an internal account ID; provider name and stable provider subject; display name or username; avatar/profile fields; email when the selected provider supplies it; and linked/login timestamps. Discord uses identify only, so ITForMe receives basic Discord profile information but does not request Discord email.
- Learning records: career path and experience selections, certification status and dates, goals, notes, study sessions, timers, practice scores, quiz and PBQ answers, results, attempt history, response time, evidence records, and imported portable progress.
- Community activity: correction text, rationale, vote, status, timestamps, and the content/version involved. Open corrections and grouped vote totals may be visible to other users. Public attribution uses a generic community label rather than publishing your provider identity.
- Security and session data: session and CSRF cookies, anonymous workspace ID, linked-identity events, hashed provider-subject security records, and MFA configuration if you enroll it. MFA secrets are encrypted at rest.
- Billing records, only if paid offers become available: internal order and offer IDs, Stripe Checkout Session, PaymentIntent, refund and dispute identifiers, amount, currency, tax total, payment/refund/dispute state, access term, and timestamps. ITForMe does not collect or store full card numbers or card security codes.
- Technical operations data: request time, route, response status, IP address, browser or user-agent details, referrer, and proxy/security events may appear in Cloudflare, reverse-proxy, application, or server logs.
3. OAuth providers
ITForMe supports Discord, GitHub, and Google sign-in. The provider shows the information requested before you approve access. ITForMe never receives your provider password.
ITForMe does not retain OAuth access or refresh tokens. Basic provider profile snapshots and the stable provider identifier are retained so the same external identity returns to the correct internal account. Accounts are never merged merely because email addresses match.
Discord profile information is used only for authentication, account security, account display, and support. It is not used to profile Discord relationships or to make employment, housing, insurance, credit, or other eligibility decisions.
4. How we use information
- Authenticate users, link approved sign-in methods, prevent account collisions, and protect sessions.
- Save, score, display, export, import, and synchronize learner-owned progress.
- Calculate personal skill-confidence and knowledge-retention estimates from your learning evidence.
- Produce grouped item timing and accuracy statistics to identify questions that may be difficult or unclear. Only eligible authenticated activity enters these aggregates, and other users do not receive the contributing account identities.
- Operate community corrections and advisory voting, investigate abuse, enforce service rules, and maintain content integrity.
- Diagnose outages, secure the service, maintain backups, comply with legal obligations, and respond to privacy requests.
5. Cookies and local browser state
ITForMe uses essential cookies for sessions, CSRF protection, OAuth state, and an anonymous learning workspace. These cookies are needed for sign-in security and to keep one browser's progress separate from another's.
The hosted ITForMe application does not use third-party advertising cookies. Infrastructure providers may use necessary security or routing cookies under their own policies.
6. When information is shared
We do not sell personal information and do not share it for targeted advertising.
- OAuth providers process the authorization request when you choose their sign-in option.
- Cloudflare and infrastructure providers process traffic, security, hosting, database, and backup data as needed to deliver and protect the service.
- Stripe processes Checkout, payment, tax, receipt, refund, and dispute information if you choose a paid offer. Stripe receives payment and billing details directly under its own privacy policy; ITForMe receives the minimal provider identifiers and status needed to issue or reconcile access.
- Authorized ZRG Studios administrators may access data when needed for support, security, moderation, recovery, or legal compliance.
- Community correction text, rationale, status, and grouped votes may be displayed publicly as part of the correction workflow.
- Information may be disclosed when reasonably necessary to comply with law, protect users or the service, investigate abuse, or complete a merger, acquisition, financing, or transfer of the service subject to appropriate notice and safeguards.
7. Obsidian and portable progress
The hosted application cannot browse or monitor a directory on your computer. Local-vault connection features are limited to the local application you run on your own device.
If you upload a Markdown/YAML progress export to the hosted service, ITForMe parses the recognized progress records into your workspace. The uploaded file is not used as a public content source. Downloaded exports are controlled by you after they leave ITForMe.
If you upload an IT-only private Markdown study deck, ITForMe stores the parsed prompts, answers, and deck metadata in your hosted workspace so you can practice and schedule reviews. Unclassified decks are rejected. Accepted records can be included in access-controlled service backups under the normal retention cycle. They are not published, used for community statistics, or represented as ITForMe-reviewed answers.
8. Retention and deletion
Account identity and learning records are retained while needed to provide your account and progress history. Security events, moderation records, server logs, and backup copies may be retained longer when needed for fraud prevention, incident response, legal compliance, and reliable recovery.
If you disconnect one of several sign-in providers, ITForMe removes the linked identity snapshot for that provider. Disconnecting a provider does not delete the ITForMe account or its learning records.
A signed-in learner may delete an account through the Account page after a fresh sign-in from a currently connected provider. Live identity, learning, private-deck, answer, evidence, schedule, streak, MFA, and session data is removed. Correction proposal text and rationale may remain without an author under the community moderation license; votes are removed. Retained security events are stripped of their account, provider-subject digest, and metadata.
Minimal order, refund, dispute, and provider-event records may remain after account deletion without the ITForMe account link when needed to complete a refund or dispute, reconcile a payment, meet accounting or tax obligations, prevent duplicate fulfillment, or comply with law. Card details remain with Stripe. The exact commercial retention schedule and legal basis must be reviewed before ITForMe accepts payment.
A UUID-only deletion receipt is created in the same database transaction as live account deletion, so both changes commit or roll back together. The receipt is not stored in an independent restore journal; restoring an older database backup may temporarily restore account data that existed at that backup time. Ordinary backup copies expire through the documented backup rotation unless longer retention is legally required, and privacy requests involving restored data are handled through the documented response process.
Anonymous work may remain associated with its random browser workspace until it is claimed, deleted through an available control, or removed during maintenance. Clearing cookies removes the browser's ability to find that anonymous workspace but does not itself send a verified deletion request.
9. Your choices and privacy requests
- Download a complete JSON account archive containing non-secret account, provider-profile, security, community, and learning data after a fresh provider sign-in.
- Export supported certification plans, study sessions, and practice-score records in portable Markdown/YAML form for study-data interoperability.
- Correct many learning records through the application and remove supported evidence or history entries using the available controls.
- Disconnect a sign-in provider after linking another provider so you are not locked out.
- Delete a signed-in account through the Account page after fresh provider verification, or contact us for a correction or privacy request that cannot be completed in the application.
- Appeal a privacy-response decision or raise a concern with the relevant data-protection authority where local law provides that right.
10. Security
ITForMe uses HTTPS in production, OAuth with state and PKCE, host-only secure session cookies, tenant-scoped workspaces, access controls, protected secrets, encrypted MFA secrets, restricted administrative access, backups, and security logging. OAuth provider tokens are not configured for storage.
No Internet service can guarantee absolute security. Protect your provider accounts and recovery methods, sign out on shared devices, and contact us if you suspect unauthorized access.
11. Children's privacy
ITForMe is not directed to children under 13. You must also meet any higher minimum age required in your country to consent to online services and data processing. If we learn that ineligible child data was collected, we will take reasonable steps to delete it.
12. International use
ITForMe is operated from the United States. If you use it from another country, information may be processed in the United States and in locations where the selected OAuth or infrastructure providers operate, subject to applicable safeguards and law.
13. Changes to this policy
We may update this policy when the service, providers, or legal requirements change. The page will show the new effective date. Material changes may also be announced in the application before they take effect when practical.
14. Contact and privacy requests
Use the Account page for a complete archive or self-service deletion. For other privacy questions, inaccessible-account requests, or corrections that cannot be completed in the service, email the privacy contact below. Include the OAuth provider used for the account, but never send a password, OAuth token, MFA secret, or recovery code.