Privacy policy

How we handle your data

This policy covers the UnInquizitive extension, website, API, and support systems. We do not sell personal information or use it for targeted advertising.

Effective and last updated August 13, 2026

What the extension processes

On supported W. W. Norton pages, the extension reads the Norton account identifier and InQuizitive email shown to the page so it can connect the correct UnInquizitive account. It also reads page controls, questions, course access state, course and assignment details, and results needed to run the features you request.

Question text, answer choices, Norton passwords, cookies, and session tokens are processed only in your browser and are not stored by UnInquizitive. Ordinary actions performed by the extension are still visible to Norton in the same way as actions performed on its website.

Course syncing and reminders

Course syncing is part of UnInquizitive's core service. It begins only after you complete the first-run disclosure and press Continue. The extension then scans courses available to the active Norton identity so it can show upcoming assignments, due-date reminders, progress summaries, one-click assignment access, and plan recommendations.

Course syncing cannot be disabled separately while using the extension. Uninstalling the extension stops future scans, but it does not automatically erase information already stored. You can request deletion using the contact information below.

What we collect

  • Identity and account: a keyed hash of the Norton account identifier, the InQuizitive email shown by Norton, internal user identifiers, identity status, and migration history. The raw Norton identifier is converted in server memory and is not stored.
  • Device security: a device public key, key fingerprint, device status, session records, account-switch signals, and security audit events. The private device key stays in Chrome storage and is not sent to us.
  • License and billing: plan, usage, authorized assignments, referral activity, entitlement history, Stripe customer and transaction identifiers, prices, payment status, refunds, and disputes. Stripe handles full card details.
  • Course inventory: course and assignment titles, one-way identifiers, completion status, due dates, grades when available, and scan timestamps. This supports reminders, one-click assignment access, progress and workload summaries, plan recommendations, aggregate analytics, and support.
  • Run statistics: run mode, question count, clicks saved, elapsed time, reported time, extension version, and completion time. We do not store assignment answers in these records.
  • Reliability and security: page type, expected feature checks, hashed public Norton JavaScript versions, client version, timestamps, IP address, browser metadata, bounded identity-mismatch reports, and whether a known conflicting page control from another extension was detected. We do not collect a general list of installed extensions.
  • Feedback and support: messages you submit, whether you chose anonymous feedback, and information you provide through support.
  • Website analytics: page URL, referrer, device and browser type, approximate location, and pseudonymous visitor or session information collected by Vercel Analytics and, when enabled, Google Analytics.

Why we use it

  • Connect the correct Norton identity without requiring a separate login.
  • Create and manage trials, licenses, referrals, purchases, and usage.
  • Show upcoming work, due-date reminders, one-click assignment access, progress summaries, plan recommendations, and account-eligible products. Course or assignment data does not set a price or experiment cohort. Randomized cohorts based on an internal user identifier, plan, and experiment revision may test offer text or prices, while aggregate checkout, purchase, refund, retention, and plan-consumption results measure the outcome.
  • Detect license sharing, repeat trials, referral abuse, fraud, and compromised accounts.
  • Find Norton site changes, fix product failures, provide support, and understand product performance.
  • Process payments, refunds, disputes, accounting, and legal obligations.

Chrome Web Store Limited Use

UnInquizitive's use of information received through Chrome extension APIs follows the Chrome Web Store User Data Policy, including its Limited Use requirements. We use this information only to provide, secure, maintain, and improve the extension features described here. We do not use it for advertising or sell it.

Who receives data

We disclose only what is needed to providers that operate the service:

  • Supabase for database and infrastructure services.
  • Stripe for checkout, billing, tax, fraud, refunds, and disputes.
  • Vercel for website hosting and analytics.
  • Google Analytics when the website analytics integration is enabled.
  • Support and professional service providers when needed to answer a request, secure the service, or meet legal obligations.

We may also disclose information when legally required, to prevent harm or fraud, or as part of a business transfer subject to appropriate protections.

Retention

  • Expired website handoff codes and authentication challenges are short lived and removed by scheduled cleanup.
  • Need-profile analytics and inactive course inventory are removed after 180 days.
  • Compatibility snapshots are kept for up to 180 days and capped at 2,000 unique snapshots.
  • Abuse reports are normally kept for 180 days and capped at 25,000 rows.
  • A conflicting-extension signal is limited to one account-level row containing first and last detection times, a count, and the reporting extension version.
  • Identity, license, entitlement, billing, trial, and referral records are kept while needed to operate the account and afterwards for fraud prevention, disputes, accounting, and legal obligations. A minimal trial marker may be retained indefinitely to prevent repeated free trials.
  • Feedback, support messages, and aggregate run statistics are kept until they are no longer needed for support, security, or product analysis.

Your choices and rights

Depending on where you live, you may ask to access, correct, delete, or receive a portable copy of your personal information, object to or restrict some processing, and appeal a denied request. We do not sell personal information or share it for cross-context behavioral advertising.

Uninstalling the extension stops future course syncing but does not automatically delete server records. To request access, correction, deletion, or a portable copy, email privacy@uninquizitive.com from the InQuizitive email connected to the account when possible. We will acknowledge the request, verify identity without requesting a Norton password, and respond within the period required where you live, normally no later than 45 days. We may retain records required for security, fraud prevention, billing, disputes, or law and will explain an applicable denial and appeal method. We will not discriminate against you for exercising an applicable privacy right.

Security, children, and changes

We use encrypted transport, signed device requests, restricted database roles, access controls, and audit records. No system is perfectly secure, so report suspected account misuse to support promptly.

The service is not directed to children under 13, and we do not knowingly collect personal information from them. Anyone under 13 must not use the service. If we learn that we collected such information, we will delete it as required by law. If local law requires parental consent for an older minor, that consent is required before use.

We may update this policy when the product or law changes. Material changes will be posted here and, when appropriate, shown in the product before they take effect.

Contact

The person or business identified as the merchant in Stripe Checkout and on a purchase receipt operates UnInquizitive and controls the information described here. Email privacy questions or requests to privacy@uninquizitive.com.

UnInquizitiveUnited Statesprivacy@uninquizitive.com