Privacy Policy

Last updated: 10 September 2026

ReviseWithAI (“we”, “us”) provides an AI-assisted revision platform for GCSE and A-level students, on the web and as a mobile app. This policy explains what personal data we collect, why, where it goes, and how you can control it. We are the “controller” of this data for the purposes of UK GDPR and the Data Protection Act 2018.

ReviseWithAI is operated by Henry Smith, trading as ReviseWithAI, as a UK sole trader — not currently a registered limited company, based at 14 Norwood Terrace, Ilkley, LS29 7EY. This policy has not been reviewed by a lawyer. It has also not been checked against the founder’s current ICO registration status or against vendors’ current data-transfer certifications (see section 6) — those need confirming separately, they aren’t something readable from source code.

1. Who this is for

ReviseWithAI is aimed at GCSE and A-level students (roughly ages 13–18), many of whom are under 18 and some of whom are under 16. We currently don’t collect a date of birth or verify age at signup — an account only requires a first name, last name, email address and password. Because we can’t verify age, we apply the same privacy-protective defaults to every account regardless of age: no behavioural advertising, no profiling for marketing purposes, no public profile or location data, and friend connections are opt-in on both sides (see section 2).

ReviseWithAI is not intended for direct, unsupervised use by children under 13. If you are under 13, a parent or guardian should create and manage the account on your behalf. If we become aware that a child under 13 is using the service without a parent or guardian’s involvement, we will deactivate the account. A parent or guardian who believes their child has given us personal data without appropriate consent can contact us (section 11) to have it removed.

2. What we collect

  • Account details: first name, last name, email address, and a password (stored as a salted hash, never in plain text).
  • Study data: the subjects, exam boards and subtopics you choose, your quiz answers, scores, and the notes you add or upload.
  • Content you upload for the notes feature: pasted text, uploaded files, or content imported from Notion via its OAuth connection. If you connect Notion, we store an encrypted access token, not your Notion password.
  • Usage data: which questions and quizzes you’ve completed, so we can schedule what to revise next, plus a daily summary of your activity (quizzes done, time spent, topics studied) if you have daily summary emails switched on.
  • Friends: if you send or accept a friend request, the other person can see your username and study activity that the friends feature displays; this is opt-in on both sides and you can remove a friend at any time.
  • Billing data, if you or a parent pays for a plan: handled by Stripe directly — we receive a customer/subscription reference, not your card details.
  • If a parent pays on your behalf (Parent-Purchased Subscriptions): the parent’s email address, so we can link the subscription and send them a receipt and access to manage it.
  • Session/login data: a sign-in token. On the web app this is held in a secure, httpOnly session cookie set by our authentication provider (NextAuth) — not accessible to page scripts. On the mobile app it’s held in the device’s secure keychain (Expo SecureStore). Your day’s revision queue is also temporarily cached in your browser’s session storage so it survives a page refresh; this clears when you close the tab.
  • Technical/error data: if our error-monitoring tool (Sentry) is enabled, it captures details of unhandled errors (e.g. stack traces, the page/route involved) to help us fix bugs. It is configured not to record your inputs or page content (no session replay) and not to attach personal data by default.
  • Standard web/server logs (e.g. IP address, timestamp, requested URL) generated by our hosting infrastructure for security and diagnostic purposes, kept for a limited period.

3. How we use it, and our legal basis

UK GDPR requires us to have a lawful basis for each use of your data. Here’s what we do and which basis applies:

  • Running the product — generating quizzes, marking your answers, and deciding what to show you next (necessary to perform our contract with you).
  • AI marking and question generation, performed by OpenAI’s API — your quiz answers and notes are sent to OpenAI to be processed. OpenAI does not use API inputs to train its models by default, and we don’t direct it to (contract).
  • Transactional email (password resets, sponsorship/parent-invite links, receipts, security notices) via Mailgun (contract and our legitimate interest in running a secure service).
  • Daily revision reminders and the daily summary email, also via Mailgun — sent only if you’ve left the relevant preference switched on in Settings (consent, which you can withdraw at any time by turning the preference off).
  • Marketing email — sent only if your marketing preference is switched on. If you signed up before [date this is fixed], that preference may have defaulted to on rather than requiring you to opt in; we’re correcting that so marketing email requires an affirmative opt-in, in line with the Privacy and Electronic Communications Regulations (PECR). Check Settings and turn it off at any time — every marketing email also carries an unsubscribe link (consent).
  • Payment processing, via Stripe, for paid plans (contract, and legal obligation for the accounting records that follow from it).
  • Security and abuse prevention — e.g. rate-limiting login and password-reset attempts, detecting and blocking abuse of paid AI features (legitimate interest).
  • Error monitoring via Sentry, to find and fix bugs (legitimate interest).

We don’t use your data for automated decision-making that has a legal or similarly significant effect on you without human involvement. AI marking scores your answers and feeds our spaced-repetition scheduling, but it decides what to show you next in a revision queue — it doesn’t make decisions about you outside the product.

4. Cookies and similar technologies

We use a strictly-necessary session cookie (set by our authentication provider) to keep you signed in, and your browser’s session storage to cache your current day’s revision queue. Neither is used for advertising, cross-site tracking or profiling, so under PECR we don’t need to show a cookie consent banner for them — strictly necessary cookies are exempt from that requirement. We don’t currently run analytics or advertising cookies/pixels. If that changes, we’ll update this section and add a consent mechanism before any non-essential cookie is set.

5. Where it’s stored

Application data is stored in a managed PostgreSQL database (Neon). We don’t operate our own database servers. Our web and API servers run on a cloud VPS. Email is sent via Mailgun’s EU infrastructure, and AI processing is performed by OpenAI’s API — each receives only the data needed to perform that function (e.g. Mailgun receives an email address and message content; OpenAI receives the text being marked or used to generate a quiz).

6. International transfers

Some of the providers above are based outside the UK, principally in the United States (OpenAI, Stripe, and our error-monitoring provider Sentry). Where we transfer personal data outside the UK, we rely on a recognised safeguard under UK GDPR Chapter V — for example, the provider’s participation in the UK extension to the EU–US Data Privacy Framework, or the ICO’s International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses in our contract with them. Which mechanism applies to which vendor can change as their certifications do, so this needs confirming against each vendor’s current data processing agreement before publishing — we haven’t independently verified each one’s current status here. Mailgun’s EU region and Neon’s configured region should also be confirmed as part of the same check.

7. Parents and Parent-Purchased Subscriptions

A student can ask a parent to pay for their plan, or a parent can buy a plan directly for a child by email. In either case, the parent’s email address is stored so we can link the subscription and send a payment receipt. A parent does not need a ReviseWithAI account themselves to sponsor a plan; the payment link we send them is time-limited and single-use. A parent who has purchased a plan for a child can view and cancel that subscription, but cannot see the child’s study data, quiz answers or notes through that link.

8. How long we keep it

We keep your account and study data for as long as your account is active. If you delete your account, we deactivate it immediately, invalidate any active login session straight away, and overwrite identifying fields (your email and username) so they can’t be used to find or re-register the account. Some records — for example, billing records tied to a completed payment — may be retained in a de-identified or minimal form for as long as necessary to meet our legal or accounting obligations (typically several years under UK tax record-keeping rules). Routine infrastructure backups may retain deleted data for a limited rolling period before they, too, age out.

9. Your rights

Under UK GDPR, you have the right to:

  • ask what personal data we hold about you and get a copy of it (access);
  • have inaccurate data corrected (rectification);
  • ask us to delete your data, subject to the retention needs in section 8 (erasure) — you can also do this yourself from Settings;
  • ask us to restrict or object to certain processing, including an absolute right to object to direct marketing at any time;
  • receive the data you gave us in a portable format (portability); and
  • complain to the UK’s data protection regulator, the Information Commissioner’s Office, at ico.org.uk, if you think we’ve mishandled your data — though we’d appreciate the chance to put it right first.

To exercise any of these, contact us at [email protected]. We’ll normally respond within one month.

10. Changes to this policy

We’ll update this page if what we collect or how we use it changes materially, and update the date at the top.

11. Contact

Questions about this policy or your data: [email protected]. Operated by Henry Smith, trading as ReviseWithAI (UK sole trader — no company registration number), 14 Norwood Terrace, Ilkley, LS29 7EY.

ReviseWithAI

AI revision for GCSE & A‑level students.