Privacy Policy

Last updated: June 2026 · Controller: [YOUR NAME / TRADING NAME], [YOUR ADDRESS], United Kingdom.

This policy explains what personal data we collect, why, and your rights under UK GDPR and the Data Protection Act 2018. Questions: [email protected]

1. Who we are

ET Trainer is operated by [YOUR NAME / TRADING NAME] based in the United Kingdom. We are the data controller for the personal data described in this policy. We are not required to register with the ICO if our annual turnover is below £632 million and we process only personal data for core business purposes — but if your processing expands, check your ICO registration obligations.

2. What data we collect and why

DataWhy we collect itLegal basis
Email addressAccount identification, sending password resets (when added), and transactional communicationsContract performance
Username / first nameDisplay in the app (optional — you can leave it blank)Legitimate interest
Hashed passwordAuthenticating your account. We use PBKDF2 — the original password is never stored.Contract performance
Study progressSaving your revision sheet, achieved topics, and mock results so they persist across devicesContract performance
AI answers you typeProcessing through the AI to produce marking and feedback. We do not store your raw answers long-term — they are passed to Anthropic and the AI response is returned. The question text is stored in the questions bank if it becomes a curated item.Contract performance
Transaction recordsStripe Checkout session IDs and braincell credit amounts for billing accuracy and VAT complianceLegal obligation / contract
Problem reports you submitQuality improvement — you can submit a text note flagging a question. Stored linked to your user ID.Legitimate interest
Session data (cookie)An HttpOnly, Secure session cookie holds a random token (hashed server-side) to keep you logged in for 30 days.Contract performance

We do not collect: payment card details (handled entirely by Stripe), precise geolocation, or data from children under 13.

3. Cookies

We use one functional cookie (session token) to keep you logged in. It is HttpOnly and Secure (not accessible to JavaScript). We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

If you add analytics (e.g. Cloudflare Web Analytics — which is cookie-free) you should update this section accordingly.

4. Third-party processors

ProcessorPurposeLocation
CloudflareHosting (Pages), serverless compute (Workers), database (D1). Your data is stored in the EU or UK region where possible.US (SCCs in place)
AnthropicAI inference — your typed answers and questions are sent to Anthropic's API to generate marking and feedback. Anthropic's API data is not used to train their models by default (as of their API terms).US (SCCs in place)
StripePayment processing. We only receive the Checkout Session ID and amount — not your card number.US/EU (SCCs in place)

All transfers to the US are covered by Standard Contractual Clauses (SCCs) with each processor.

5. How long we keep your data

6. Your rights under UK GDPR

You have the right to:

To exercise any right, email [email protected]. We will respond within one calendar month.

7. Security

Passwords are stored as PBKDF2 hashes with a random salt. Connections use HTTPS only (enforced via the _headers file). Session tokens are HttpOnly cookies, hashed server-side. We follow Cloudflare's security recommendations including WAF rate-limiting on authentication endpoints.

No security is perfect. If you discover a vulnerability, please disclose it responsibly to [email protected].

8. Under-18s and safeguarding

Many 2365-03 learners are aged 16–18. We do not market to or knowingly collect data from under-13s. We do not collect sensitive personal data. If a parent or guardian believes their child has registered without consent, contact us at [email protected] and we will delete the account promptly.

9. Changes to this policy

We may update this policy. We will notify registered users by email at least 14 days before material changes take effect.

10. Contact

Data controller: [YOUR NAME / TRADING NAME]
Address: [YOUR ADDRESS]
Email: [email protected]

This policy was drafted as a starting point and should be reviewed by a UK-qualified solicitor or data protection specialist before going live with real users.