Privacy Policy
Last updated: March 2026
Plain-English Summary
We collect your name, email, and how you use Swot Up so we can help you revise. We never sell your data. We never share your personal information with advertisers. Your revision progress is yours. You (or your parent or guardian) can ask us to delete everything at any time — just email hello@swotup.app.
1. Who We Are
Swot Up Ltd ("we", "us", "our") operates the Swot Up revision service. We are registered with the Information Commissioner's Office (ICO) as a data controller. For any privacy-related questions, contact us at hello@swotup.app.
2. Children's Privacy
We take the privacy of children and young people extremely seriously. Our service is designed primarily for students, many of whom are under 18. We comply fully with the ICO's Age Appropriate Design Code (Children's Code) and apply the following principles:
- We collect only the minimum personal data necessary to provide the Service.
- We never sell children's data to any third party, under any circumstances.
- We do not show advertisements to users.
- We do not profile children for commercial purposes.
- We do not use nudge techniques, dark patterns, or manipulative design.
- We do not track users' physical location.
- We apply the most privacy-protective settings by default.
- Users under 13 must have verified parental consent before creating an account.
3. What Data We Collect
3.1 Data you provide to us
- Name and email address (required for account creation)
- Year group, school name, exam boards, and subjects studied
- Your answers to practice questions
- Messages sent to the AI Tutor
- Feedback submitted through the app
3.2 Data we collect automatically
- Usage data — which features you use, how often, and session duration
- Device type and browser (for technical compatibility purposes only)
- Strictly necessary cookies (to keep you logged in to your account)
3.3 Data we do NOT collect
- Physical location or GPS data
- Contacts or address book
- Photos, camera, or video
- Social media profile information
- Financial or payment information — all payment processing is handled directly by Stripe and we never see or store your card details
4. How We Use Your Data
| Purpose | Data Used | Lawful Basis |
|---|---|---|
| Provide and operate the Service | Name, email, revision activity | Contract |
| Personalise learning content | Year group, exam board, school | Legitimate interests |
| AI tutoring and coaching | Tutor messages, question answers | Contract |
| Improve the Service | Anonymised usage data, feedback | Legitimate interests |
| Billing and payments | Via Stripe only — we don't store payment details | Contract |
| Security and fraud prevention | Usage logs, device info | Legitimate interests |
5. AI and Data Processing
Our AI tutoring features are powered by Anthropic's Claude model. We have a Data Processing Agreement in place with Anthropic governing how your data is handled. Your conversation data is not used to train Anthropic's AI models and is not retained by Anthropic beyond what is strictly necessary to fulfil each individual request.
6. Who We Share Your Data With
We do not sell your data. We share data only with the trusted service providers necessary to operate the Service:
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Anthropic | AI tutoring (Claude) | United States | SCCs |
| Clerk | Authentication | United States | SCCs |
| Supabase | Database & storage | EU (London) | UK adequacy |
| Stripe | Payment processing | US & EU | SCCs |
| Vercel | Hosting & CDN | Global | SCCs |
SCCs = Standard Contractual Clauses, the lawful mechanism for international data transfers under UK GDPR.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Active account data | Duration of account |
| AI conversation history | 12 months from creation |
| After account deletion | 30 days, then permanently deleted |
| Payment records | 7 years (UK tax law requirement) |
8. Cookies
We use only strictly necessary cookies, which are required to maintain your logged-in session and to provide the Service securely. We do not use tracking, analytics, or advertising cookies. You do not need to consent to cookie use beyond what is strictly necessary, and no cookie banner is required.
9. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Access — Request a copy of the personal data we hold about you
- Rectification — Ask us to correct inaccurate or incomplete data
- Erasure — Ask us to delete your data (the "right to be forgotten")
- Restriction — Ask us to limit how we process your data in certain circumstances
- Portability — Receive your data in a commonly used, machine-readable format
- Object — Object to processing based on legitimate interests
- Withdraw consent — Where we rely on consent as our lawful basis, you may withdraw it at any time
To exercise any of these rights, email hello@swotup.app. We will respond within 30 days. If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
10. Security
We implement appropriate technical and organisational measures to protect your data:
- All data is transmitted over HTTPS/TLS encryption
- Authentication is managed by Clerk using industry-standard security practices
- Our database is protected by row-level security policies
- Strict access controls — only authorised personnel can access personal data
- In the event of a personal data breach, we will notify the ICO within 72 hours and affected users without undue delay
11. Parents and Guardians
Parents and guardians have the right to review, correct, or request deletion of their child's personal data at any time. You may also withdraw consent for a child under 13 to use the Service by contacting us at hello@swotup.app.
Where Swot Up is provided under a school licensing arrangement, the school acts as the data controller for pupils' data collected in that context, and Swot Up Ltd acts as a data processor. In such cases, please refer to your school's privacy notice as well.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, the Service, or legal requirements. We will notify you of any material changes by email. The date at the top of this page always shows when it was last updated.
13. Contact
For any privacy-related questions, to exercise your rights, or to raise a concern, please contact us at hello@swotup.app.
Swot Up Ltd · England & Wales