Privacy Policy

The Short Version: We know legal text is boring, so here is the summary. We only collect the data we absolutely need to run your account and provide a great experience. We will never sell your personal information, and we do not use your data to train external, public AI models. Your data belongs to you.

We're MountUp Support LLC, the team behind 2CFRGeek. We built this platform to help grants professionals genuinely understand 2 CFR 200 — and that means treating your data the way we'd want ours treated. We only ask for what we actually need to serve you, we never sell it, and we don't use it to train external, public AI models. This policy explains, in plain language, exactly what we collect and why.

1. The Information We Collect

We only collect what you give us directly, plus a small amount of activity data generated as you use the platform. Here's the complete, honest list:

Account identity

Your first name, last name, and email address (used to sign in and reach you), plus an optional organization or company name. If you sign up with Google, we receive the name and email Google shares with us — no Google password ever touches our servers.

Learning profile

During onboarding you can tell us your primary professional role (for example, Grant Manager or Auditor) and your self-reported 2 CFR 200 experience level (Beginner, Intermediate, or Advanced). These help us tailor your drills — they're optional.

Access & subscription

Your app role (learner, organization admin, organization member, or platform administrator), your subscribed tier (Essentials, Mastery, Command Center, Advisory, or Enterprise), and your subscription status. We store a Stripe customer ID and Stripe subscription ID to link your account to billing — that's it. Your card number, CVC, and full card details are handled entirely by Stripe and never reach our database.

Exam inventory

A count of your available Official Exam tickets and your free-drill question count, so we can show you what you have access to and gate the exam correctly.

Learning & exam performance

As you practice and sit exams, we record your answers, scores, the questions you answered, the 2 CFR 200 subpart each question covers, your session timestamps, time remaining, and your current position so you can resume where you left off.

Credential records

When you sit the Official Credential Exam, we store your final score, your scaled readiness score (100–1000), your per-domain proficiency (Administrative, Cost, Audit), your pass/fail status, the issue date, and a public verification hash so employers can confirm your credential. We also record a silent tab-switch count and whether time expired — these are for internal integrity analytics only and never penalize your result.

Organization data (Command Center & above)

If you lead a team, we store your organization's name, your seat limit, the custom KPIs you define, and the email invitations you send to teammates (each with a pending, accepted, or declined status). For tiers with Policy Vault access, we also store the internal policy documents you upload (extracted text and semantic search indexes), AI-generated gap analysis reports comparing your policies to 2 CFR 200, and Smart Q&A questions and answers — all scoped to your organization and never shared outside it. For Enterprise tiers, we also store your configured LMS and SIEM webhook URLs and HMAC signing secrets so we can deliver compliance events to your external systems.

Multiplayer & team session data

When you host or join a team training session (War Room, Boss Fight, Relay Race, Red Team, or Ledger), we store the display name you choose, your session votes and submissions, any margin notes or annotations you create, and your participation timestamps. Guests who join via PIN code provide a display name only — no account is required. Session data is visible to other participants in the same room.

Candidate exam dispatch

If an organization admin dispatches an exam ticket to a candidate, we store the candidate's email address (to send their magic link), their exam result, and a one-time secure token — but the candidate does not receive a full account unless they choose to register. The organization admin is responsible for ensuring the candidate has consented.

Security & integrity logging

To protect the platform, we log administrative actions and security warning events (such as attempted screenshots during an exam) along with the acting user and an IP address. These logs are visible only to authorized platform administrators.

Marketing & sales inquiries

If you download a cheat sheet, we keep your first name and email to send your resource and (unless you opt out) a short nurture sequence. If you contact us about Advisory or enterprise work, we keep the name, work email, organization, and message you submit.

2. How We Use Your Information

We use your data to run your account, deliver drills and exams, grade your attempts, issue and verify credentials, process payments through Stripe, show you progress analytics, secure the exam environment, deliver compliance events to your configured LMS/SIEM webhooks (Enterprise tier), and send you the occasional administrative or product email. That's it. We do not sell your personal data, and we do not use it to train external, public AI models. Internal AI features (like question generation assist) operate on our own content, not on your private answers. We may use our own audit-verified generated content (study modules, practice scenarios, and gap analyses we produce from public federal regulation text) to improve our internal AI models — but never your private answers, organization policy documents, or personal data.

3. Cookies & Tracking

Essential cookies keep you signed in and make the platform work. Non-essential analytics cookies are only set after you say yes through our cookie consent banner — and you can withdraw that consent any time by clearing your cookies. We don't use hidden trackers to follow you around the web.

4. Data Security

We protect your data with encryption in transit and at rest, role-based access controls so users only see what's theirs, and a separate exam backend that re-fetches the correct answers at grading time rather than trusting the browser. No system is perfectly secure, but we treat yours like our own. If a real incident ever occurs, we'll tell affected users promptly and honestly.

5. Data Retention

We keep your data while your account is active and for as long as we need it to provide the service. You can delete your account at any time from your dashboard — when you do, we remove your personal data within 30 days. Some records (like issued credential verifications and financial records) may be kept longer where law requires it, but those are kept secure and never used to contact you.

6. Your Rights

Under GDPR, CCPA, and similar laws, you can access, correct, export, or delete your personal data, and you can object to certain processing. To exercise any of these, just reach us through our Contact / Support page. We'll verify who you are and respond without unreasonable delay — usually within 30 days.

7. Children's Privacy

2CFRGeek is a professional platform for adults working in or learning federal grants compliance. We don't knowingly collect data from anyone under 16, and the exam content isn't directed at children. If you believe a minor has registered, contact us and we'll remove the account.

8. Changes to This Policy

If we change what we collect or how we use it, we'll update this page and note the new "last updated" date. For anything material, we'll also let active subscribers know by email. MountUp Support LLC, 75 E 3rd St, Ste 7, Sheridan, WY 82801, is the data controller responsible for your information. You can reach us at +1 (307) 303-0153 or through theContact / Support page.

9. Sub-Processors

We rely on a small number of trusted third-party services to operate the platform. Each receives only the minimum data needed to perform its function:

  • Stripe — processes all payments and stores your card details. We receive a Stripe customer ID and subscription ID only.
  • Google — powers Google Sign-In. If you use it, Google shares your name and email with us; your Google password never touches our servers.
  • Brevo — delivers our transactional and marketing emails (cheat sheet delivery, nurture sequences, launch announcements). You can unsubscribe from marketing emails at any time.
  • Cloud LLM providers — power our AI-assisted question and scenario generation. They process our proprietary content, not your private answers or personal data.

We don't share your personal data with any other third party, and we never sell it.

10. International Data Transfers

Our infrastructure and sub-processors may process data outside your country of residence. We rely on standard contractual clauses and provider-level safeguards to protect your data during these transfers, as required by GDPR and similar laws. If you have a question about a specific transfer, contact us and we'll explain.

by MountUp

The premier 2 CFR 200 compliance and exam engine. Adaptive testing, team ops drills, and official certification — built for CGMS candidates and compliance directors.

2CFRGeek provides tools for educational and compliance preparation purposes. Use of this software does not guarantee audit success or regulatory compliance. Users are responsible for verifying all information against the most current federal statutes.

© 2026 2CFRGeek. All rights reserved. A product of MountUp Support LLC. Not affiliated with OMB or any federal agency.

We use cookies to enhance your experience and analyze site usage. By clicking "Accept," you consent to the use of non-essential cookies. See our Cookie Policy.