Skip to content
Legal

Privacy Policy

Effective 2026-08-31 · Version 1.6

This describes what ETHOS Prep actually does today. It is not legal advice, and ETHOS recommends independent professional review before this document governs a commercial launch, paid service, or user accounts — none of which exist yet. This policy will be updated, with a new version and date, whenever that changes.

1. Who this is

ETHOS Prep (“ETHOS,” “we”) is an independent Canadian police-applicant preparation service, operated from British Columbia. This policy covers everyone who uses ethosprep.ca and ETHOS Practice. Business identity details (registered name, mailing address) will be added here once finalized — see the contact section below for how to reach us in the meantime.

2. The short version

Creating an ETHOS account is optional and free — nothing in ETHOS Practice requires one, and there’s no purchasable product yet (see the Pricing page). If you don’t create an account, this section’s original promise still holds in full: nothing you do in ETHOS Practice (practice items, Interview Lab, the readiness dashboard, and the rest) is ever sent to a server or to any third party. If you DO create an account, ETHOS stores exactly your email address, a securely hashed (never plain-text) password, and a small amount of account-management metadata on its own server — see section 3a for exactly what and why. Either way, ETHOS Practice’s actual training tools continue to store real content locally in your browser, on your device only: practice history, physical training logs, and — in Interview Lab, the Experience Library, and roadmap notes — real personal narrative you choose to type. Creating an account does not upload any of that local content to ETHOS’s servers; it stays exactly where it already was unless a future version adds an explicit, separate sync feature you’re clearly told about first. You can permanently delete your local device data at any time using the control at the bottom of this page, and permanently delete your account (section 7) at any time from the account page. (Section 9 covers checkout/payment architecture, which exists in this product’s codebase but cannot currently be reached by anyone using the site normally.) Section 6 covers ETHOS’s first-party, pseudonymous product-analytics architecture, which also exists in the codebase but is off by default and, when on, never reads the local content described above.

3. What ETHOS handles, and why

One category below — account data (3a) — is collected by ETHOS and stored on its own server, because an account genuinely requires that. Everything else described in this section is stored only in your browser’s local storage on your device and is never collected by ETHOS, transmitted to a server, or seen by anyone at ETHOS.

3a. Account data (only if you create an account)

If you create an ETHOS account, ETHOS stores, on its own server: your email address; a securely hashed version of your password (never the password itself — ETHOS cannot see or recover it); whether your email is verified, and when; the date your account was created; which version of these Terms and this Privacy Policy you accepted, and when; a server-side session record while you’re signed in (see “Cookies” below); and a short internal activity log (e.g. “registered,” “signed in,” “password reset”) used for account security and support. This exists solely to operate account sign-in, email verification, password recovery, and — once real paid access exists — to let you recover access tied to a purchase made under your account email. Creating an account does not collect your name, phone number, mailing address, or any of the local practice/Interview Lab data described below — that remains local-only unless a future version adds an explicit sync feature.

3b. Product analytics (only if ETHOS turns collection on)

ETHOS Prep’s codebase includes a first-party, cookie-free product-analytics system, described fully in section 6. Data collection through it is off by default and, as of this policy version, has not been switched on for this site. When it is on, it can record: which page you’re on, which of a small, fixed set of named product actions you took (for example, starting the Readiness Snapshot, or reaching the Pricing page) and when, a random pseudonymous id generated in your browser (never your email or any other identifying value), and — if you arrived via a link carrying UTM campaign parameters — which campaign/source referred you. It never records the CONTENT of anything you type (practice answers, Interview Lab responses, Experience Library entries, roadmap notes), your password, or any authentication token, and it is not used to serve you ads or to track you across other websites.

3c. Account emails (only if you create an account)

If you create an account, ETHOS sends a small, fixed set of account-related emails to the address on file: a verification link when you sign up, a password-reset link if you request one, a security notice after your password is actually changed, and a one-time welcome message after your email is verified. Every one of these is directly about operating your account or keeping it secure — ETHOS does not send newsletters, promotional email, or any other marketing message today, and does not have a mechanism to get your consent for that yet. If that changes in the future, it will require its own separate, explicit opt-in under Canada’s anti-spam law (CASL) — never bundled with, or implied by, accepting these Terms or this Policy, and never turned on by creating an account. These emails contain no tracking pixels, no external images or fonts, and no analytics of any kind (see section 6); they are logged in a local ETHOS record used only for delivery/retry/security purposes, never shared with a third party.

3d. Partner/trainer connection data (only if you connect with a trainer)

ETHOS supports independent trainers and coaching organizations connecting with applicants who choose to work with them. None of this exists unless YOU explicitly accept a specific trainer’s invitation — no trainer can see anything about you before that. Once connected, ETHOS stores, on its own server: the fact of the connection itself; which named ETHOS practice module (e.g. “Memory & Observation”) a trainer has suggested you practice, and any short instructions they wrote for it; whether you’ve marked that suggestion done (self-reported by you — ETHOS has no server-side record of your actual practice activity to verify this against, see section 3 above); and any written feedback the trainer leaves, which is always visible to you. A connected trainer never sees your password, payment/purchase information, account security events, analytics data, or the content of your Interview Lab/Experience Library/roadmap notes (those remain local-only, per section 3 above, and were never sent to ETHOS’s server in the first place). You can end a connection at any time from your account page — this immediately and permanently removes the trainer’s access to anything about you going forward.

Practice and readiness activity

Which practice items you’ve attempted, scores, timestamps, and your readiness dashboard state. This exists so your progress persists between visits on the same device and so the product can show you what you’ve covered and what you haven’t.

Interview Lab, Experience Library, and roadmap notes

Behavioural-interview responses, follow-up answers, preparation notes, reflections, reusable named descriptions of your own real experiences, and free-text notes you add to your application roadmap. This is the one category that can contain real personal narrative — about your own work, school, or life history — because that’s what these features are for. See “Sharing information about other people” below.

Physical-readiness logs

Dates, times, reps, or distances you log against a physical standard (POPAT, RCMP PFA), and an optional free-text note per entry. ETHOS does not ask for or store medical, injury, or disability information — there is no field for it.

Application profile and preferences

Which agency/track you’re preparing for and which roadmap stage you’ve reached, so the product can show you relevant content. No name, email address, phone number, or mailing address is collected anywhere in the product today.

What ETHOS does not collect
  • Your real name, phone number, or mailing address, whether or not you have an account
  • An email address, UNLESS you choose to create an account (section 3a) — browsing and using ETHOS Practice never requires one
  • Payment or billing information — no payment processor is connected
  • The content of anything you type — practice answers, Interview Lab responses, Experience Library entries, or roadmap notes — through analytics, even when analytics is on (section 3b/6)
  • Advertising identifiers, third-party behavioural-tracking identifiers, device fingerprints, or precise location, of any kind
  • Any cookie other than the one functional, account-sign-in session cookie described in section 6, which is set only if you have an account and are signed in — analytics (section 3b), when on, uses no cookie at all
4. Where it’s stored, and who can see it

Account data (3a), analytics events when collection is on (3b), account-email delivery logs (3c), and partner/trainer connection data (3d) are the only categories stored on ETHOS’s own server — see section 11 for your rights over it and section 7 for how to delete it. Of those, only 3d is ever visible to anyone other than ETHOS itself: a connected trainer sees exactly the scope described in 3d, and nothing else — never your account credentials, email address beyond what they already used to invite you, payment information, or analytics data. Everything else described in section 3 lives only in your browser’s local storage, on the device you’re using — never on a server ETHOS operates or controls, and never visible to a trainer or anyone else. For that local data:

  • It doesn't sync between devices or browsers — switching computers, browsers, or clearing your browser profile starts fresh. Creating an account does not change this — see section 3a.
  • ETHOS cannot see it, back it up, restore it, or hand it to anyone, including in response to a request — there is no copy anywhere but your own device.
  • Anyone else who uses the same browser profile on the same device can read it. If this is a shared, work, school, or borrowed device, use the control in section 7 before you're done.
5. Sharing information about other people

Interview Lab, the Experience Library, and roadmap notes are about your own experiences, but real stories sometimes involve other people — coworkers, supervisors, classmates. Avoid including more identifying detail about other people than your answer actually needs, and never enter information you’re not free to disclose (confidential workplace, investigative, or legal information). This is guidance, not a rule ETHOS enforces technically — everything you type stays on your own device regardless.

6. Cookies and tracking

ETHOS Prep uses no advertising or third-party tracking technology of any kind — no ad pixels, no cross-site trackers, no session-replay or screen-recording tools, no device fingerprinting. If you don’t have an account, or aren’t signed in, ETHOS sets no cookies at all. If you create an account and sign in, ETHOS sets exactly one cookie — a session cookie that identifies you as signed in — so the product knows who you are on later requests. This cookie is strictly functional (not tracking or advertising), is marked HttpOnly (JavaScript on the page cannot read it) and Secure in production, expires automatically after 30 days, and is deleted immediately when you sign out.

Separately, ETHOS Prep’s codebase includes a first-party product-analytics system, built to help ETHOS understand basic product usage (for example: are people finding the Readiness Snapshot, and finishing it) without third-party tools. Collection through it is off by default and has not been switched on for this site as of this policy version. When it is on, here is exactly how it works:

  • No cookie of any kind — the analytics identity is a random id stored in this browser's own localStorage/sessionStorage, the same mechanism ETHOS Practice's other local features already use, not a cookie.
  • First-party only, and same-origin — every analytics request goes to ETHOS's own server, never a third-party analytics company, ad network, or data broker.
  • Pseudonymous, not identifying — the id is a random value generated in your browser, never derived from your email, IP address, or device characteristics (no fingerprinting).
  • A small, fixed, named set of product actions only (e.g. "viewed the landing page," "started the Readiness Snapshot," "reached Pricing") — never the free-text content of anything you type, and never your password or an authentication token.
  • If your account is verified, some of these events are additionally associated with your account (not your email) so ETHOS can measure account-level activity like verification and first-training rates — see section 3b.
  • You can generate a fresh, unlinked pseudonymous analytics identity at any time using the same "Clear My Data" control in section 7 that clears the rest of your local data.

No separate cookie-consent banner is shown, because nothing described in this section is a cookie: the account-sign-in session cookie above is strictly functional and only ever set after your own affirmative action of creating an account and signing in, and analytics (when on) never sets a cookie at all. If that changes — for example, if a future version adds an advertising or cross-site tracking cookie — this policy and the site’s consent handling will be updated before that ships, not after.

7. Your control over this data

You can permanently delete everything ETHOS Prep has stored in this browser’s local storage at any time, below. This removes it completely — it cannot be undone, and (per section 4) there is no other copy for ETHOS to separately delete. Clearing your browser’s site data, or using a private/ incognito window, has the same effect for that browser. If you have an account, you can separately, permanently delete it — including your email and password, which ETHOS erases and cannot recover — at any time from the account page; see section 11 for what that does and doesn’t remove. If you’re connected with a trainer (section 3d), you can end that connection at any time from the same page — this immediately removes their access to your assignment/feedback data going forward; it does not delete the historical record of the connection itself, kept for the same audit reasons described in section 8.

8. How long information is kept

Local browser data (section 3, excluding 3a) has no fixed retention period — it persists on your device until you remove it (via the control above, your browser’s own storage controls, or resetting the device), since there is no server-side copy for ETHOS to expire on a schedule. Account data (section 3a) is kept for as long as your account exists, and is deleted — not merely deactivated — when you delete your account (section 7/11). Purchase and payment records, once real paid access exists, are retained separately from account data for as long as reasonably necessary for financial record-keeping, independent of whether the associated account still exists — the exact retention period for those records is a business/accounting decision this policy will state concretely once real paid access goes live, rather than being invented here ahead of that decision. Analytics data (section 3b/6), while collection remains off by default, has no committed retention period yet — this policy will state a concrete one before collection is ever switched on for real visitors, rather than being invented ahead of that decision. Partner/trainer connection data (section 3d) is retained after you end a connection, so that a genuine authorization dispute (e.g. “did this trainer still have access on this date”) can be investigated — but ending a connection immediately and permanently stops any further access, regardless of what historical record remains.

9. Third parties

None are active. ETHOS Prep uses no third-party analytics provider, error-monitoring service, advertising network, payment processor, or AI service today — the first-party product-analytics architecture described in section 6 is ETHOS’s own code, running on ETHOS’s own server, not a third-party service, and remains off by default. The site’s fonts are served from ETHOS’s own hosting (self-hosted at build time), not fetched from Google at runtime. If ETHOS ever hosts this site with a provider (a step that hasn’t happened yet), that host will generate its own standard, ordinary web-server access logs (IP address, timestamp, page requested) as a normal part of serving any website — that’s the hosting provider’s practice, not something ETHOS’s own code generates or controls, and this section will name the host once one exists. Checkout and payment-processing architecture exists in this product’s codebase (built to support a future paid tier), but it is switched off — no purchase can be completed, and no payment processor is connected or receives any information today. When real paid access goes live, this section will name the specific payment processor used and describe exactly what it can access (which does not include your card details — a provider-hosted checkout page collects those directly, never ETHOS’s own server), and the only additional information collected at that point will be the email address you provide at checkout, used solely to identify your purchase.

10. Security

ETHOS applies reasonable technical safeguards: browser security headers and a content-security policy that restrict what the site can load and run; passwords are never stored in plain text (a salted, one-way hash only — see section 3a); and the server-side account data described in section 3a is the only personal information ETHOS holds anywhere outside your own device — everything else described in this policy (section 3, excluding 3a) stays entirely on your device and is never sent to a server at all. Nothing here should be read as a claim of encryption-at-rest, guaranteed security, or any compliance certification (SOC 2, ISO, PCI, HIPAA, or otherwise) — none apply, and no application can promise protection against someone who has direct access to your own account credentials, device, or browser profile.

11. Your privacy rights

As a British Columbia business handling personal information within B.C., ETHOS Prep’s practices are governed by B.C.’s Personal Information Protection Act (PIPA) rather than the federal PIPEDA, which generally doesn’t apply to a provincially-regulated business’s activity within the province. If you don’t have an account, everything ETHOS handles about you stays on your own device and is never collected by ETHOS — there is nothing for ETHOS to access, correct, export, or delete on your behalf, because you already have complete, direct control via section 7. If you DO have an account:

  • Access/export: sign in and use “Download my account data” on the account page to get a copy of the account data ETHOS holds about you, immediately — no waiting period required for this self-service path. If you'd rather request it directly, email hello@ethosprep.ca and ETHOS will respond within 30 business days, consistent with PIPA.
  • Correction: your account email and password are self-service (sign in to change your password; ETHOS does not currently support changing an account's email — delete and recreate the account instead, see section 13 of the Terms). For any other correction request, email hello@ethosprep.ca.
  • Deletion: sign in and use “Delete my account” on the account page to permanently and immediately erase your email and password from ETHOS's systems — self-service, no waiting period. Purchase/payment records, once real paid access exists, are retained separately for financial record-keeping even after account deletion — see section 8.
  • Analytics: while collection remains off by default (section 3b/6), any pseudonymous analytics events are not currently included in the self-service account-data download, since they're not stored as part of your account record. If collection is ever switched on for real visitors, this policy will state concretely how analytics data factors into export/deletion requests before that happens.

If you believe ETHOS is handling information inconsistently with this policy, contact us (section 13); you may also contact the Office of the Information and Privacy Commissioner for British Columbia. This site (including account data) is not yet deployed to any production host — see section 9 for what that section will say once one exists. If account data is ever hosted or processed outside British Columbia, ETHOS will revisit whether PIPEDA also applies before that happens, not after.

12. Age

ETHOS Prep does not knowingly direct this product at children. It’s intended for prospective police applicants, which in practice means older teens and adults researching or preparing for a career with a minimum application age (typically 19+ for most Canadian services). ETHOS does not collect the kind of information that would let it verify anyone’s age, and doesn’t claim to.

13. Changes to this policy, and contact

This policy will change as ETHOS changes — most significantly when real paid access is introduced, which will require a real update here before it ships, not after. If this policy materially changes after you’ve accepted a version (as an account holder), ETHOS will ask you to accept the new version rather than silently applying it. Each version carries the date and version number shown at the top of this page. For privacy questions or concerns, email hello@ethosprep.ca.