Back to Legal Hub

Legal Document

Data Protection Impact Assessment

Last Updated: 20th August 2026

About this DPIA Summary

This page is a summary of the Data Protection Impact Assessment that Revision Genie maintains for its core processing activities. The full internal DPIA is held by our Data Protection Officer and is reviewed at least annually and whenever a significant new processing activity is introduced.

The purpose of a DPIA is to identify and reduce risks to people's rights and freedoms that come from how we process their personal data. We treat children's data with particular care, in line with the ICO's Age Appropriate Design Code.

1. Purpose of Data Processing

1.1 Provide an AI-powered educational platform that helps students learn and revise.

1.2 Track learning progress so students, teachers and (where applicable) schools can see how a student is getting on.

1.3 Operate safety and safeguarding systems, including flagging conversations that suggest a user may be at risk.

1.4 Process payments and manage subscriptions.

1.5 Improve the service over time using aggregated and anonymised analytics.

2. Categories of Data Processed

2.1 Account data: name, email, age (year of birth), school affiliation, OAuth provider (if any), hashed password (if any).

2.2 Learning data: study activity, quiz responses, exam attempts and marks, skill ratings, mistakes, memory notes.

2.3 Communication data: AI chat (not retained by default), support tickets, in-app feedback.

2.4 Technical data: IP address, device/browser metadata, basic usage events.

2.5 Payment data: Stripe customer and payment references.

2.6 Push notification data (only where the user has turned push notifications on): the notification address issued by the browser's push service, the two encryption keys issued with it, the account it belongs to, a truncated user-agent string, held only to distinguish one subscribed device from another, and delivery bookkeeping (last seen, last success, consecutive failures).

3. Processors and Data Flows

Personal data is processed by:

Microsoft Azure OpenAI (AI inference and embeddings) - UK / EU regions, no training on customer data.

Azure Speech Services (text-to-speech for language lessons).

MongoDB Atlas (primary database).

Vercel and Vercel Blob (hosting and file storage).

Vercel Speed Insights (page-performance measurement, all pages) - page address, page-loading timings, and coarse browser, device and connection details. No page-usage or interaction events, no account identifier and no student content. Cookieless per Vercel's documentation, and therefore not gated on the cookie notice.

Upstash Redis (cache and rate limiting).

Stripe (payments).

Google and Microsoft (optional sign-in only).

SendGrid (transactional and notification email delivery) - recipient email address, message content and delivery events.

Sentry (server-side error monitoring) - European Union region. Technical error diagnostics only: exception type and message, stack trace, release version, and tags such as which background job failed. Request cookies, headers, query strings and bodies are stripped, any user reference is reduced to an internal account ID, and email-shaped values and credential-shaped fields (tokens, passwords, secrets, session identifiers, card and phone details) are redacted before transmission. No student content and no performance or session data are collected. Active only where error reporting is configured.

ContentSquare (product analytics, loaded only where the user accepts all cookies; used to improve the product, not for advertising or profiling).

Each processor is bound by a data processing agreement and assessed for UK GDPR-equivalent protections.

Browser push services (Google, Mozilla, Microsoft or Apple, according to the browser in use) additionally receive an encrypted notification payload, its delivery address and a time-to-live, wherever a user has enabled push notifications. The service is selected by the user's browser rather than by us, so it is not one of the contracted processors listed above; the payload is encrypted to the recipient device before transmission.

4. Identified Risks and Mitigations

4.1 Risk: AI responses could contain inappropriate or harmful content.

Mitigation: Azure OpenAI content filters plus our own safeguarding checks; clear AI identity disclosure; per-message feedback and reporting; human review for flagged messages.

4.2 Risk: AI could be used to write coursework verbatim, undermining academic integrity.

Mitigation: System prompts orient tutors towards teaching and explaining rather than producing finished work; schools can monitor student activity where authorised.

4.3 Risk: Cross-session memory could store sensitive personal data (e.g. mental health, classmates' names).

Mitigation: AI is instructed to save only stable, learning-relevant facts; users can view, edit and wipe all memory notes at any time.

4.4 Risk: User-uploaded documents in My Genies could contain third-party copyrighted material or personal data of third parties.

Mitigation: Acceptable Use Policy prohibits uploading content the user is not entitled to upload; storage and retention are limited; users can delete files at any time.

4.5 Risk: Safeguarding-flagged conversations contain sensitive disclosures.

Mitigation: Access is restricted to trained staff; retention is time-limited; disclosure to schools or authorities follows safeguarding policy.

4.6 Risk: Notifications could intrude on a child's device, arrive while they are asleep, or be used to draw them back into the service.

Mitigation: Nothing can be delivered without two separate affirmative acts (our own card and the browser's permission dialog); the request is made once only, never on page load, never before the student has earned a daily streak, and never again after a refusal, which is recorded on the account rather than in the browser; delivery is blocked between 21:00 and 07:00 UK time for every user regardless of age; only notice types on an explicit allow-list may be pushed and that list defaults to refusing anything not named on it, so it currently permits one; the notification wording is the in-app notice's own wording, and countdowns and loss framing are prohibited; an account-level switch in Settings silences every device at once.

5. Protection Measures

5.1 Encryption in transit (TLS) and at rest by all processors.

5.2 Role-based access controls on production systems.

5.3 Privacy-protective defaults at every age, plus two further defaults applied automatically at account creation for students who register as under 16: hidden from other people's leaderboards, and no approximate location stored on the account. Both remain reversible by the student.

5.4 Minimisation: we only collect and pass through data needed for the immediate purpose.

5.5 Regular reviews of access logs and security configuration.

6. Special Considerations for Young Users

6.1 Age-appropriate defaults and reduced data collection for users under 18, including the under-16 defaults described in 5.3.

6.2 No behavioural profiling or personalised advertising.

6.3 School-managed accounts allow teachers and school admins to provide supervision where authorised.

7. User Rights

7.1 Access, rectification, erasure, restriction, objection and portability are all supported - see our Privacy Policy.

7.2 Right to lodge a complaint with the Information Commissioner's Office (ico.org.uk).

Contact Our Data Protection Officer

For questions about this DPIA summary, our processing activities, or to exercise your data protection rights, please contact our Data Protection Officer, Joel Martin, at joel@revisiongenie.com.

Have questions about this policy?

Our support team is happy to help explain anything

Contact Support