Effective and last updated
Most privacy policies describe an ambition. This one describes an audit. Everything below was checked against the site’s own code, its database schema and the responses it actually sends. It was rewritten when accounts, saved practice history and payments went live, rewritten again when Cognivy first loaded an analytics tool, and rewritten again today because it loaded a second one. What each tool is, where it runs, where it is blocked outright and what it means for you is its own section, not a footnote.
Controller
Who is responsible
Cognivy, the operator of cognivy.io, decides why and how the personal data described here is processed, and is the controller for it. Contact for all privacy matters: hello@cognivy.io. Put Privacy in the subject line.
Start here
What Cognivy does not do
This list is shorter than it used to be, twice: once on 21 August when analytics arrived at all, again on 23 August when a second tool joined it. Both lines are named below rather than removed quietly. Everything remaining on it was checked rather than assumed:
- No advertising or cross-site tracking technology runs. There is no ad network, no advertising pixel, no tag manager beyond the two analytics scripts named on this page, and no fingerprinting that can follow you: the cookieless visitor count described below cannot recognise you on another day or on another website.
- No advertising cookie is set, and nothing set here is readable by another website. Every cookie and storage key on this site is listed by name.
- Cognivy never receives or stores your card number.
- Nothing is sold, rented or shared with data brokers or advertisers.
- There is no marketing email. Account email is transactional only: confirming an address, resetting a password.
- Nothing runs at all on the pages where you sign in or manage your account. Clarity additionally never runs where you practise or see your own plan and results; Google Analytics does run there, to count that you reached them, but is never given the question, the answer or the score on the screen. That boundary is described and checkable.
Until 21 August this page said no analytics, session-replay or heatmap technology ran here, that there were no third-party scripts, and that if non-essential storage were ever added you would be asked first, with declining as easy as accepting. Cognivy started loading Microsoft Clarity on its public pages that day, and decided not to put a consent banner in front of it. Two of those statements were therefore no longer true and the promise attached to them was withdrawn, in the open, here.
On 23 August the same thing happened again, in the other direction. Google Analytics arrived that day already asking nothing first, the same no-banner choice, but its first few hours here ran cookieless and this page said so — correctly, at the time. That was changed the same day: Google Analytics now sets a cookie too, without asking, and this page was rewritten again rather than left describing a version of the tool that no longer runs.
It would have been easy to delete a few sentences each time and say nothing. A policy that quietly loses a promise is worth less than one that never made it, so instead: what each tool is, what it records, the pages it may not touch, and how to stop it.
The list
What is collected, and when
Nothing here is collected until you do the thing that causes it. Reading a public guide is the first two rows, and only the first two.
- Reading any page: server and delivery logs. Like any website, requests reach a hosting provider, which records technical information such as your IP address, the page requested, timestamps, and your browser and device type. This is needed to serve pages, keep the site available and defend it against abuse.
- Reading a public page: a Microsoft Clarity recording of that page. On the guides, provider pages, pricing and these policy pages, a Microsoft product records how the page was used: pointer movement, clicks, scrolling, the size of your window, and the content that was on the screen while you were there. It is used to find where a page confuses people. It does not run on the sign-in, account, practice, diagnostic, plan or setup pages, so it never sees a password, a practice question or your results. The section on it is the detail.
- Answering a practice question: your practice history. For each answer we store which question it was, which option you chose, whether it was correct, how many milliseconds you took, whether your screen was phone, tablet or desktop size, and your browser language. Before you have an account this is held against a random id kept in your browser, not against you. See cookies and browser storage.
- Creating an account: your email address. Handled by our authentication provider. If you sign in with Google instead, we receive the email address and basic profile of the Google account you choose. We never see your Google password, and if you use an email and password, we never see the password either: it is stored by the authentication provider, hashed.
- Signing in: your earlier practice is linked to you. The practice held against your browser id is attached to your account, so it survives changing device. This is the point of having an account, and it is why signing in does not cost you your history.
- Setting up a plan: your target. The provider and assessment you are preparing for, and your language, are stored against your account so your plan is there when you return.
- Buying access: a purchase record. That you are entitled, when it was granted, when it expires and the order reference. We also store the event our payment processor sends us for each payment, renewal, failure and refund, so that access matches what you actually paid.
- Reporting a question: your report. Which question, what kind of problem, and any comment you write, up to 2,000 characters. Please do not put personal information in that box; it is read by a person reviewing the question.
- Emailing us: the message. Your message, your email address and our reply, so that we can help you and keep a record of what was agreed.
Your assessment date, if you give one, is carried in the web address while you use the site rather than stored, so it may appear temporarily in the delivery logs described above.
Why, and on what basis
Purposes and lawful bases
- Delivering and securing the site using server logs. Our legitimate interest in running a working, available site that resists abuse. The data is technical and is not used to build a profile of you.
- Running your account and giving you what you paid for, including your practice history, your plan and your access. Performance of our agreement with you.
- Recording practice so it can be shown back to you before you have an account. Our legitimate interest in a product that works without forcing you to register first. It is tied to a random browser id, not to your identity.
- Keeping purchase and payment records. Performance of our agreement with you for access and refunds, and our legal obligations for keeping business and tax records.
- Improving the questions using reports you submit and anonymised answer statistics. Our legitimate interest in a bank whose questions are correct. See the shared question bank.
- Answering your message when you email us. Our legitimate interest in responding to people who contact us, or performance of our agreement where it concerns a purchase.
- Seeing where a public page confuses people, using Microsoft Clarity. Our legitimate interest in fixing pages that do not work, judged against the fact that the pages it records are public ones and the private and paid ones are excluded outright. You can object to this, and stopping it takes one setting in your browser.
- Counting visits, sources and how far people get, using Google Analytics. Our legitimate interest in knowing whether the site works as a whole, not just page by page, and in particular whether it turns a visit into a diagnostic and a diagnostic into a purchase. It runs on more pages than Clarity does, described in its own section, but is never given a question, an answer or a score.
One thing here is worth stating against ourselves. The Clarity and Google Analytics cookies are not necessary for anything you asked us for, and the rule for storage of that kind is that you are asked before it is written, not after. Cognivy does not ask for either. That is a deliberate choice by the operator, not an oversight, and this page names it rather than hiding it behind the legitimate-interest lines above. Nothing else on this list relies on consent, and there is still no marketing of any kind.
Who else touches it
Hosting and processors
- Vercel hosts and delivers this site. Its systems handle the requests described above and generate the delivery logs.
- Supabase provides the database that holds your account, your practice history, your plan and your entitlement, and provides the authentication that holds your email address and password.
- Lemon Squeezy handles checkout, card details, renewals and refunds. Your card details go to them and never to us. We receive confirmation of what was paid, an order reference and the email address used, which is how access reaches the right account.
- Google, twice, for two unrelated reasons. As a sign-in option, only if you choose it — if you use an email address and password, that use of Google is not involved. Separately, and regardless of how you sign in, Google also provides Google Analytics, which counts visits and traffic sources on most of the site. What it receives is described in its own section. Neither use tells Google anything about the other: signing in with Google does not identify you to Google Analytics.
- Microsoft provides Clarity, which records how public pages are used. What it receives is described in its own section. It receives nothing from the sign-in, account, practice, diagnostic, plan or setup pages, and it is never given your email address, your name or your account id.
- Our mail service delivers account emails such as address confirmation and password resets, and carries messages you send us and our replies.
Each processes data only to perform its function for Cognivy, under its own terms and security obligations. Cognivy does not use third-party advertising or cross-site tracking, and there is no advertising network involved in this site at all. Microsoft and Google Analytics are the two that run code in your browser on a page you are merely reading, and both are described in full in the section on analytics and session replay.
The two third-party scripts, and one count we keep ourselves
Analytics and session replay
When you open a public page, your browser tells our server the path you opened (never the query string, so a sign-in link can never be part of it), the practice id described in the storage section, whether you were signed in, the name of the website that linked you here (never its full address) and any campaign tags in the link (utm_source, utm_medium, utm_campaign). No IP address is stored, and it never runs on /account, /auth, /signin or the admin pages.
It exists because the alternative was worse. The two tools below can tell us how many people visited, but only inside Google’s and Microsoft’s own dashboards, which means the only way to answer “how many people used the practice” was to send more to them, not less. This count stays here, is a hash rather than a name, and is the reason no third tracker was added.
Our four sites (cognivy.io, matrixreasoningtest.com, numericalreasoningpractice.com and verbalreasoningpractice.com) keep one shared count of visits. When you open a page, our server combines your IP address and browser name with a random value that is replaced every day, and keeps only the resulting code. Your IP address and browser name are not stored. Because each day’s random value is deleted the next day, the code cannot recognise you on another day or link your visits between our sites. With it we keep the page you opened, the name of the site that linked you (never the full address), any campaign tags in the link, and whether you clicked Buy. If you are signed in, a one-way code of your account is kept so a new account is counted once. Nothing is stored on your device for this, so it does not depend on the cookie banner.
Legal basis: our legitimate interest in knowing how many people use the sites and what brings them.
Cognivy loads Microsoft Clarity on its public pages. Clarity records how a page was used and plays it back to us later: where the pointer moved, what was clicked, how far you scrolled, how big your window was, and what was on the screen while you were there. It also aggregates those sessions into heatmaps. It exists here for one purpose, which is finding the places where a page confuses people rather than helping them. This page is a public page, so reading this paragraph is itself being recorded.
There is no consent banner. Clarity starts when a public page loads, and the two cookies in the section above are written at that moment, without your agreement being sought first. Those cookies are not necessary for anything you asked Cognivy to do, and the ordinary expectation for storage of that kind is that you are asked beforehand and that declining is as easy as accepting. Cognivy is not doing that. Our other practice sites do. This one, today, does not.
We would rather write that sentence than let you find it in devtools. If it is the thing that decides whether you trust this site, that is a fair way to decide.
Where it does not run, which is the part that matters most. Open one of the pages below directly, or refresh on it, and Clarity is not put into the page at all. There is no script and therefore nothing to switch off. Arrive at one by clicking through from a public page, where the script is already loaded, and it is stopped before the new page is drawn.
- Sign-in and authentication (
/signin,/auth). A password is typed on one of these, and sign-in links carry one-time codes in the address. Neither is ever recorded. - Your account (
/account), where your email address and your purchase are on the screen. - Everything you practise (
/practice,/diagnostic,/plan,/setup). These show questions, options, and after your attempt the correct answer and its explanation, along with your own results. None of it goes to Microsoft. The material people pay for is not put into a third party’s recording store, and neither is your score.
That boundary is not a setting in someone’s dashboard that can be changed without a trace. It is a list of routes in the site’s own code, and two automated checks hold it: one refuses to let a new page exist without a decision about which side of the line it is on, the other drives a real browser and reads what is actually sent to Microsoft. The second one is there because the first cannot see the difference between working and broken. It was the one that caught a real gap while this was being built: recording used to stop a moment too late when you clicked through from a guide, which sent the address of the practice page you were opening. It now stops on the click instead, and the check fails if that ever comes back.
It is also checkable from where you are sitting, which is the version that does not require trusting us: open a practice page, look for _clck in your cookies, and it is absent.
What Clarity is never given. Your email address, your name and your account id are never passed to it, on any page. It is not told whether you have paid. There is no advertising use of any of it, and it is not combined with an advertising profile by us.
Where it goes and how long it stays. Clarity is Microsoft’s product, so what it records goes to Microsoft and is held on their systems under their terms, described in the Microsoft Privacy Statement. Microsoft is a US company operating internationally, and we do not control how long they keep it or where they process it, so we are not going to state a number here as though we did.
How to stop it. Any browser setting or extension that blocks trackers stops Clarity, because it is loaded from clarity.ms and blocking that domain is enough. Clearing your cookies removes _clck and _clsk. You can also object to it and ask us to delete what it holds about your visits by emailing hello@cognivy.io with Privacy in the subject line.
Google Analytics, added 2026-08-23
Cognivy also loads Google Analytics. It is built for a different job than Clarity, above: where Clarity shows us how one page was used, Google Analytics counts how many people visited, which page or search brought them, and how many went on to start a diagnostic or reach checkout. It does not record your screen, your pointer or what you typed.
It sets a cookie and identifies your browser across visits, without asking first. The first version of this section, live for about two hours on 2026-08-23, said the opposite: that Google Analytics ran cookieless and sent nothing. That was a deliberate choice we made and then reversed the same day, once it was clear the cookieless setting meant the tool collected literally no measurement at all, which defeated the reason it exists. We chose real measurement over the cookieless default, the same trade Clarity above already makes: _ga and _ga_<container id> are written the moment the script loads on a page where it runs, and Google can tell that the same browser that read a guide on Monday came back to buy on Thursday.The cookie section lists both by name.
What does not change with this. No advertising signal is sent alongside it: ad storage, ad personalization and ad user data are all explicitly turned off in the same call that turns analytics on, and that is a separate setting from the cookie question, not a consequence of it. Cognivy runs no advertising and this data is not combined with an advertising profile, by us or, on the settings we send, by Google.
Where it does not run. The same credential and sign-in surfaces Clarity is kept off are also kept fully clear of Google Analytics: /signin, /auth, /account. Sign-in links carry one-time codes in the address, and those addresses are never sent anywhere; if you follow one, the redirect lands you on an ordinary page before Google Analytics has any chance to see it. Unlike Clarity, Google Analytics does run on the practice, diagnostic and plan pages, because counting that someone reached a diagnostic or a checkout page is the whole reason it is here; it still receives no question text, no answer and no score.
How we checked this, and the one thing we could not finish checking. The route restriction above was proven with a real browser against a running build of this site, the same method Clarity’s check uses: loading /auth, /signin and /account directly never puts the script in the page at all, and navigating into them from an allowed page correctly stops it from sending anything for that page, checked at the level of what the code queues to send. Confirming the very last step — that the resulting request actually reaches Google’s servers rather than being dropped somewhere in between — is normally checked the same way, but Google’s own servers throttle repeated automated requests from one machine testing itself over and over, which is exactly what building and re-testing this does. We proved delivery works in isolation, then hit that throttle before we could prove it end to end against the finished component. The definitive check is the one this site already runs for Clarity: verify once against cognivy.io itself after this ships, not against a local copy.
Where it goes. Google is the processor, under the Google Privacy Policy. We do not control how long Google keeps it or where it is processed, so we are not going to state a number here as though we did, the same position taken on Clarity above.
How to stop it. The same tracker-blocking setting or extension that stops Clarity also stops Google Analytics, since it loads from googletagmanager.com. Clearing your cookies removes _ga and _ga_<container id>. You can object to it and ask us to delete what it holds about your visits by emailing hello@cognivy.io with Privacy in the subject line.
Retention
How long it is kept
- Delivery logs are short-lived and kept only for the period our hosting provider retains them.
- Your account, practice history and plan are kept while your account exists. Ask us to delete the account and they go with it.
- Practice recorded before you signed in, and never linked to an account, is kept against its random id only. It has nothing in it that identifies you.
- Purchase and payment records are kept for as long as accounting and tax rules require, which is longer than the refund window and longer than an account may last. These survive account deletion, because we are required to keep them.
- Question reports and the answer statistics in the shared bank are kept indefinitely, because they are the record of why a question was changed. Neither identifies you.
- Emails are kept for as long as needed to deal with your query and to keep a reasonable record of it afterwards.
- Clarity recordings of public pages are kept by Microsoft for as long as their own policy says, which is theirs to set and not ours. We do not hold a copy outside Clarity, and we cannot honestly quote a retention period we do not control. See analytics and session replay.
- Google Analytics data is kept under Google’s own retention settings, not ours, for the same reason. See Google Analytics.
Where it goes
International transfers
Pages are served from a global network, so a request may be handled at the location nearest you. Our hosting, database, payment and email providers are international companies and may process data, including your account and payment records, in countries other than your own. Where they do, they are required to apply appropriate legal safeguards for that transfer under their own data-processing terms.
Microsoft, which provides Clarity, and Google, which provides Google Analytics, are both United States companies and are the two to be specific about, because each receives something on a page you are only reading rather than one you signed in to. What reaches each of them is described in the sections linked above, and each transfer runs under that company’s own terms rather than any arrangement particular to Cognivy.
Security
Security
The site is served over HTTPS only, with HTTP requests permanently redirected and strict transport security enabled. Your practice data and account are held in a database where every table denies access by default and each way in is a named, audited function rather than open query access. Answers to questions are never sent to your browser before your attempt has been recorded, which is what keeps the practice measurement honest.
We never hold your card number and, if you sign in with Google, never hold a password. No system is perfectly secure, and Cognivy claims no security certification.
Your rights
Your rights
Depending on where you live, you may have the right to ask for a copy of the personal data held about you, to have it corrected, to have it deleted, to restrict or object to how it is used, and to receive it in a portable form. Where processing relies on consent, you can withdraw that consent at any time.
Email hello@cognivy.io and we will deal with it. Please write from the address on your account, so we can be reasonably sure the request is yours. There is no charge, and we do not require a form.
Two honest caveats. For a visitor who has only read the guides, we hold nothing that identifies you beyond the technical delivery logs, so there is usually nothing to retrieve or delete. And deleting your account cannot delete the purchase and payment records, which we are legally required to keep; everything else goes.
Escalation
Complaints
If you are unhappy with how a privacy request was handled, tell us first and we will try to put it right. You also have the right to complain to the data protection authority in your country. In the EU and EEA that is your national supervisory authority, and you can complain either where you live, where you work, or where the problem happened.
Age
Children
Cognivy is built for adults preparing for workplace assessments. It is not directed at children, not intended for school entrance exams, and we do not knowingly collect personal data from children.
Changes
Changes to this policy
When this policy changes materially, the date at the top changes with it. This page carries its own date rather than a shared one, so a change here is never disguised by an unrelated edit elsewhere.
The last material change was on 25 September 2026, when this site began counting its own page views. Two statements above were corrected rather than left standing: the practice id is now written on your first visit instead of at your first answer, and it now has a second job that is not something you asked for. Nothing was added to your browser to do it and no third-party tool was involved. The change before that was on 23 August 2026, when Microsoft Clarity was added to the public pages. The previous version of this page said no analytics ran here and that you would be asked before any non-essential storage was added. Both of those are now withdrawn, and the section on Clarity says so in its own words rather than leaving you to notice the absence. The change before that was on 19 August 2026, when accounts, saved practice history and paid access went live.
The changes that would trigger the next rewrite are known: letting Clarity onto a practice, sign-in or account page, adding a second analytics or advertising tool, storing an IP address or anything else alongside the page counts described above, sending marketing email, or sharing anything with a party not named above. None of them will arrive quietly. Today is the proof of that and also the reason the promise is worth less than it was yesterday, which is a fair thing for you to hold against it.
Questions about any of this go to hello@cognivy.io.