Last updated: August 4, 2026
Who is responsible
Insomnia Studyroom is responsible for deciding why account information is processed. Privacy questions, access requests, corrections, and account-deletion requests can be sent to the site administrator through the contact page.
Account information collected
For email registration, the required information is your email address and password. Firebase Authentication creates a unique user ID and records whether the email is verified. Firebase may also process IP addresses, user-agent information, and related security metadata to authenticate users and prevent abuse.
Insomnia Studyroom does not receive or store your raw password in its website files or Firestore documents. The password is transmitted securely to and handled by Firebase Authentication.
Purposes of collection
- Create and authenticate an account.
- Send and confirm email-verification and password-reset messages.
- Control access to saved-progress and future community features.
- Protect accounts, prevent abuse, and respond to support or privacy requests.
Account processing is required to provide account features. You may refuse by leaving the consent box unchecked; you can still browse public lessons, but an email account cannot be created.
Firebase and processing location
Insomnia Studyroom uses Google LLC's Firebase Authentication for email and password accounts. Account information is transmitted to Firebase when you register, sign in, verify an email address, or reset a password. Firebase Authentication processes authentication data in the United States. Google acts as a service provider or data processor for Firebase customer data. Review Firebase privacy and security information and the Google Privacy Policy.
Cloud Firestore access is currently disabled in the website code, so profiles and study progress are not currently read from or written to that database.
Retention period
Authentication information is retained while the account exists. Firebase states that logged IP addresses are generally retained for a few weeks. After the site administrator initiates deletion of the Firebase user, Firebase removes the associated authentication information from live and backup systems within 180 days, unless a longer period is required by law.
Messages sent to the administrator may be retained only as long as needed to answer the request and document its completion.
Account withdrawal and deletion
Request account deletion through the contact page using the email address associated with the account. The administrator may ask you to verify control of the account before deleting it. The deletion process removes the Firebase Authentication user and any account profile stored under that user ID. Public content may require separate review where deletion would affect other users or where retention is legally required.
Browser-only study history is not removed by deleting the Firebase account. Clear this site's browser data to remove local study history, quiz results, wrong-answer notes, focus statistics, interface settings, and campsite preferences from that device.
Advertising and analytics
Google Analytics is installed on the home page but its script is not loaded unless you allow the Audience measurement category. When allowed, Google Analytics may set the _ga first-party cookie and collect page visits, session statistics, approximate location, browser, device, and operating-system information for aggregate site reports.
Advertising cookies are not currently installed. If advertising is introduced later, this policy and the consent controls must be updated before non-essential advertising storage is enabled.
Embedded YouTube content and fonts
The Focus menu embeds a playlist using YouTube's privacy-enhanced domain. When you load or interact with the player, Google or YouTube may receive technical information and may set or read cookies according to your settings. The website also loads Google Fonts, which can disclose standard technical information such as your IP address, browser type, and requested resource to Google.
Children's privacy
Do not create an account if applicable law requires parental or guardian consent and that consent has not been obtained. A parent or guardian may contact the administrator to request review or deletion of a child's account. Do not submit school records or other sensitive personal information through support or future community features.
Policy changes and contact
This policy may be updated when account, database, analytics, advertising, or hosting features change. The updated date will be revised when material changes are made. Privacy questions and rights requests can be submitted through the contact page.