Last updated: 4 September 2026

Privacy policy

This policy explains what data CanQuiz processes, for what purpose, and with which providers. It covers canquiz.com and app.canquiz.com.

Controller

The data controller is Michel Rodrigues, an independent developer. For anything concerning your data, including exercising your rights, write to privacy@canquiz.com.

What data is processed

On signup: your email address and the identifier from the provider you sign in with (Google, Discord or GitHub), or just your email if you use the magic link. While using the app: the quizzes you create, your answers, your review progress, and the files you upload to generate quizzes. No payment data is collected, because there are no payments.

AI generation

By default, generation runs on CanQuiz's own provider, which today is Google (Gemini). The material you send is transmitted to Google to build the quiz, and Google processes it on CanQuiz's behalf as a data processor, without using it to train its models; it does log it for a limited period to detect prohibited use, which is the only retention that applies to the paid tier of its API. If you prefer to supply your own API key, the material is transmitted to your provider (Anthropic or OpenAI) and is subject to that provider's policy and to your relationship with them; that key is stored in your browser's local storage, travels with the request so the provider can be called on your behalf, and is not saved in CanQuiz's database. Files you upload as attachments are removed by a daily sweep, at most 48 hours after you upload them.

Public quizzes

The quizzes you create are private by default. If you choose to publish one, its content becomes accessible to anyone with the link, including people without an account, and appears in the public listing. You can unpublish it at any time, though anyone who already copied it keeps their copy.

Providers

Hosting and delivery: Vercel, which keeps request logs with your IP address for a short period. Database and authentication: Supabase. Product analytics: PostHog, in its European region; your profile and your events are deleted on request by writing to privacy@canquiz.com. Error reporting: Sentry, in its European region, where events expire after ninety days. In-app support chat: Crisp, which keeps the conversation with your email address and whatever you wrote until you ask for it to be deleted. Transactional email: Resend, through Supabase. AI generation: Google (Gemini) by default, or Anthropic or OpenAI if you supply your own key. Each provider processes the data on CanQuiz's behalf, Google included; the exception is an AI provider you reach with your own key, which acts under your relationship with them.

Analytics and cookies

On canquiz.com analytics runs without cookies and without persistent storage: no identifier is placed in your browser, so there is no consent banner. On app.canquiz.com product analytics and session replay do use browser storage, so neither runs until you accept them in the notice shown on your first visit; you can change your mind at any time under Settings > Privacy and account. Error reporting always runs, without cookies and without an identifier in your browser, because it is what catches the failures that happen before anyone has had the chance to accept anything. In session recordings, the page text and everything you type are masked.

Legal basis and retention

Processing your account data and content is based on performing the service you asked for. Product analytics and session replay are based on your consent, which you can withdraw at any time. Error reporting is based on the legitimate interest of keeping the service working and secure. Data is kept while the account exists and is removed when you delete it. Three things survive deletion, and it is worth saying why: quizzes other people forked, which are their content and stop being linked to you; database backups, which exist only to restore the service and expire according to the retention Supabase sets; and error reports, which expire after ninety days.

Your rights

You can request access, rectification, erasure, restriction, portability and objection by writing to privacy@canquiz.com. Erasure does not need to be requested: in the app, under Settings > Privacy and account, you can delete your account yourself, and it removes your quizzes, your folders, your review progress, your AI conversations and any files you uploaded. You can also download all of your data as a JSON file from that same screen. You can also complain to the Spanish Data Protection Agency.