Privacy Policy
Effective Date: April 11, 2026
Graves Group LLC (“ScoreGap,” “we,” “us,” or “our”) operates the ScoreGap website, web application, Chrome browser extension, and related services (collectively, the “Services”). This Privacy Policy describes how we collect, use, disclose, and protect your Personal Data when you access or use our Services.
By using our Services, you acknowledge that you have read and understood this Privacy Policy. Your use of our Services is also subject to our Terms of Service.
Graves Group LLC · Bend, Oregon, United States
Contents
- Definitions
- Personal Data We Collect
- How We Use Your Personal Data
- How We Share Your Personal Data
- Third-Party Service Providers
- Chrome Browser Extension
- Cookies and Tracking Technologies
- Email Communications
- Data Security
- Data Retention and Deletion
- Children's Privacy
- Your Privacy Rights (CCPA)
- Do Not Sell or Share My Personal Information
- Changes to This Policy
- Contact Information
1. Definitions
“Personal Data” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identifiable individual. This includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws.
“Services” means the ScoreGap website at scoregap.com, the ScoreGap web application, the ScoreGap Chrome browser extension, and any related services, tools, or features we provide.
This Privacy Policy does not cover the practices of third parties we do not own or control, or individuals we do not manage.
2. Personal Data We Collect
The following describes the categories of Personal Data we collect and have collected over the past twelve (12) months.
- Email address
- Hashed password (email/password signup) or Google OAuth identifier (Google sign-in)
- Display name or username (for forum participation)
- Account creation date
- Target LSAT® score and target test date (if provided)
- Overall scores and section scores
- Per-question answers, question types, difficulty ratings, and time spent
- Test date and source platform (LawHub, 7Sage, manual entry, file upload)
- Whether a score is from a practice test or an official LSAT administration
- Wrong-answer journal entries (your written reflections on missed questions)
- Forum posts, comments, and votes
- Subscription plan, billing cycle, and subscription status
- Payment card type and last four digits (stored by Stripe, not by us)
- Transaction history and invoice records
We do not receive, process, or store your full credit card number, CVV, or billing address. All payment processing is handled by Stripe, Inc. See Stripe's Privacy Policy for details on how Stripe handles your payment data.
- IP address
- Browser type and version
- Device type and operating system
- Pages visited, features used, and referring URL
- Timestamps of interactions with the Services
- UTM parameters and referral source at time of signup
- Advertising campaign identifiers used to measure ad performance
Sources of Personal Data
We collect Personal Data from the following sources:
- Directly from you — when you create an account, enter test data, write journal entries, post on the forum, or contact us.
- From the Chrome extension — when you use the ScoreGap extension to import practice test results from LawHub or 7Sage (see Section 6).
- Automatically — through cookies, server logs, and analytics tools when you use the Services (see Section 7).
- From third-party authentication providers — if you sign in via Google, we receive your email address and basic profile information from Google.
3. How We Use Your Personal Data
We use your Personal Data for the following business and commercial purposes:
- Providing and operating the Services
Creating and managing your account; processing and displaying your practice test data; generating score predictions, analytics, and admissions probability estimates; operating the wrong-answer journal and discussion forum. - Processing payments
Processing subscription transactions via Stripe; managing billing, invoices, and subscription status. - Communicating with you
Sending transactional emails (account confirmation, payment receipts, subscription changes); sending product-related emails (onboarding, feature updates, trial reminders); responding to support inquiries. - Improving the Services
Analyzing usage patterns to improve features; monitoring for errors and performance issues; conducting internal research and product development. - Measuring advertising performance
Using conversion pixels and analytics to measure the effectiveness of advertising campaigns. These tools do not access your LSAT data or identity. - Protecting the Services
Detecting and preventing fraud, abuse, and security incidents; enforcing our Terms of Service. - Meeting legal obligations
Complying with applicable laws, regulations, legal processes, or governmental requests; protecting our rights or the rights of third parties.
We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated, or incompatible purposes without providing you notice.
5. Third-Party Service Providers
We use the following third-party service providers in the operation of our Services. Each provider receives only the data necessary to perform its function.
Hosting, content delivery, and database infrastructure. Processes all data stored in the Services.
Payment processing. Receives payment card information directly from you. We do not receive or store your full card number.
Web analytics. Collects anonymized usage data including pages visited, session duration, and traffic sources. Does not access your LSAT data or account information.
Product analytics. Collects usage events, feature interactions, and session data to help us improve the product. User identification is limited to account ID.
Advertising conversion measurement. A pixel tracks whether users who click our ads subsequently create accounts. Does not access your LSAT data or identity.
Authentication. If you choose to sign in with Google, we receive your email address and basic profile from Google's OAuth service.
6. Chrome Browser Extension
The ScoreGap Chrome extension imports practice test results from LSAC LawHub and 7Sage. By installing and using the extension, you authorize it to read score data from those platforms and transmit it to your ScoreGap account.
What the extension accesses
- Score report pages on LawHub (lawhub.lsac.org) and 7Sage (7sage.com)
- Score data displayed on those pages: overall score, section scores, per-question results, question metadata, and time data
What the extension does NOT access
- Your LSAC or 7Sage login credentials
- Your personal profile, payment information, or registration data on those platforms
- Any content on websites other than LawHub and 7Sage score report pages
The extension only activates on specific score report pages. It does not run on other websites. Data captured while you are not signed in to ScoreGap is stored locally on your device and is synced to your account only after you authenticate.
8. Email Communications
We send the following types of email communications:
Account creation confirmation, payment receipts, subscription changes, and password resets. These cannot be opted out of as they are necessary for account operation.
Onboarding guidance, trial reminders, feature announcements, and usage-based nudges (e.g., analytics availability notifications). You may opt out of these emails.
You may opt out of non-essential emails at any time by clicking the “Unsubscribe” link in any email, or by updating your preferences in your account settings. We respect the email_optout preference on your account and de-duplicate sends to prevent repeated emails.
9. Data Security
We implement appropriate technical, organizational, and administrative security measures designed to protect your Personal Data from unauthorized access, use, alteration, and disclosure. These measures include:
- All data is transmitted over HTTPS (TLS encryption in transit)
- Data is stored on Cloudflare's secure infrastructure
- Account data is isolated — you can only access your own data
- Passwords are hashed using industry-standard algorithms; we do not store plaintext passwords
- Payment data is handled entirely by Stripe, a PCI DSS Level 1 certified processor
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your Personal Data, we cannot guarantee its absolute security. In the unlikely event of a data breach affecting your Personal Data, we will notify affected users by email within 72 hours of becoming aware of the breach.
10. Data Retention and Deletion
We retain your Personal Data for as long as your account is active or as necessary to provide you with the Services. Specifically:
- Account and test data is retained for the lifetime of your account
- Payment transaction records are retained for the duration required by applicable tax and financial reporting obligations
- Server logs and analytics data are retained for up to 12 months
- Forum posts remain visible unless you delete them; deleted posts are permanently removed
Your deletion rights
- You can delete individual practice tests from your dashboard at any time
- You can delete your own forum posts and comments at any time
- You can export all your data as CSV at any time
- To request complete account deletion and erasure of all associated Personal Data, email support@scoregap.com. We will process deletion requests within 7 days and confirm completion by email.
In some cases, we may retain Personal Data for longer if required to comply with legal obligations, resolve disputes, or enforce our agreements. Where we retain data for these purposes, we limit our use to those purposes.
11. Children's Privacy
The Services are not directed to individuals under the age of 13. We do not knowingly collect or solicit Personal Data from anyone under the age of 13. If you are under 13, please do not attempt to register for the Services or send any Personal Data about yourself to us.
If we learn that we have collected Personal Data from a child under age 13, we will delete that information as quickly as possible. If you believe that a child under 13 may have provided us with Personal Data, please contact us at support@scoregap.com.
12. Your Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act of 2018 (“CCPA”) and the California Privacy Rights Act of 2020 (“CPRA”) provide you with specific rights regarding your Personal Data. This section describes your rights and how to exercise them.
Right to Know and Access
You have the right to request that we disclose certain information to you about our collection and use of your Personal Data over the past 12 months, including: the categories of Personal Data collected; the categories of sources from which it was collected; our business or commercial purpose for collecting it; the categories of third parties with whom we share it; and the specific pieces of Personal Data we collected about you.
Right to Delete
You have the right to request that we delete any of your Personal Data that we collected from you and retained, subject to certain exceptions. We may deny your deletion request if retaining the information is necessary for us or our service providers to complete a transaction, detect security incidents, comply with a legal obligation, or make other internal and lawful uses compatible with the context in which you provided the information.
Right to Correct
You have the right to request correction of inaccurate Personal Data that we maintain about you.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights. Unless permitted by law, we will not deny you goods or services; charge you different prices or rates; provide you a different level or quality of goods or services; or suggest that you may receive a different price or rate or different level or quality of goods or services.
Exercising Your Rights
To exercise the rights described above, please submit a verifiable consumer request to us by emailing support@scoregap.com with the subject line “CCPA Request.” Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your Personal Data. We will respond to verifiable consumer requests within 45 days of receipt. If we require more time (up to 90 days), we will inform you in writing of the reason and extension period.
13. Do Not Sell or Share My Personal Information
We do not sell your Personal Data. We have not sold any Personal Data in the preceding twelve (12) months. We do not share your Personal Data with third parties for cross-context behavioral advertising as defined by the CPRA.
14. Changes to This Policy
We reserve the right to amend this Privacy Policy at our discretion and at any time. When we make material changes, we will notify you by email to the address associated with your account and update the “Effective Date” at the top of this page. Your continued use of the Services after any changes to this Privacy Policy constitutes your acceptance of the updated policy.
In the event of an acquisition or merger, we will provide notice and an opportunity to export or delete your data before your Personal Data becomes subject to a materially different privacy policy.
15. Contact Information
If you have any questions about this Privacy Policy, your Personal Data, or wish to exercise your privacy rights, please contact us:
Graves Group LLC
Bend, Oregon, United States
Email: support@scoregap.com
Phone: +1 (650) 464-1707 (call or text)