Back to Legal Hub

Legal Document

Privacy Policy

Last Updated: 20th August 2026

1. Information We Collect

At Revision Genie, we prioritise the privacy and protection of all our users, with special consideration for children and young people. This Privacy Policy explains how we collect, use, and protect your personal information in accordance with UK GDPR, the Data Protection Act 2018, and the ICO's Age Appropriate Design Code.

Revision Genie is operated by Revision Genie Ltd, a company registered in England and Wales. Revision Genie Ltd is the data controller for your personal information.

1.1 Account Information: When you register we collect: your name, email address, date of birth or year of birth (to confirm you are old enough to register), school affiliation (if any), the OAuth provider you signed in with (Google or Microsoft) if you used social login, and a password (hashed) if you registered directly. You can also choose to add a username, profile picture and profile banner, all of which are generated within Revision Genie rather than imported from third parties.

1.2 Educational Data: We collect information about your learning activities, including study sessions, quiz responses, exam practice attempts, lesson progress, mistakes, skill ratings, XP, streak data, league position, and notes you save to your study memory. We use this to provide personalised educational support.

1.3 Chat and AI Interactions: Conversations with our AI tutors are not retained by default. We do retain conversations that have been flagged by our safeguarding systems for review (for example, where a message suggests a user may be at risk). Where you upload an image, document or YouTube link to chat, the underlying file or URL is stored in our secure storage for a limited period so that the conversation can continue.

1.4 User-Uploaded Content: If you create custom AI tutors in My Genies and upload documents to them, those documents are stored in our secure storage and processed to enable retrieval-augmented answers. You can delete uploaded files at any time.

1.5 Technical Data: We automatically collect certain technical information when you use our service, such as browser type, device information, IP address (used for security and rate limiting), and basic usage events.

1.6 Payment Information: If you purchase a paid plan, payment processing is handled by Stripe. We do not store full card numbers; we store a Stripe customer reference, subscription or payment reference, and basic billing metadata.

1.7 Age-Appropriate Settings: We collect minimal data by default at every age, and never use a child's data for advertising or behavioural profiling. Students who register as under 16 also get two extra defaults applied automatically when their account is created: they are hidden from other people's leaderboards, and no approximate location is recorded on their account. See section 8 for the detail.

1.8 In-App Product Analytics: When you are signed in, we record which pages you visit inside Revision Genie so we can see how the product is really used and make it better. We store the page's route template rather than the exact address, so identifiers such as usernames, class ids and share tokens never form part of the record, and anything after the question mark in a web address is discarded before it reaches us. We do not store IP addresses, browser user agents or the websites you came from as part of these page-visit records (the one-off note of the site that first sent you to us is described in 1.9). These records are kept for 30 days and are then deleted automatically, leaving only anonymous daily totals that cannot be linked back to you or to anyone else. This is our own first-party analytics: it stays within our systems and is never shared with or sold to a third party. Pages you view while signed out are counted only as anonymous daily totals: which page was viewed, how many visits began there, and how many of those visits went on to a second page. No identifier of any kind is sent or stored for those counts, so they cannot be linked to you, to your device or to anyone else.

1.9 How You Found Us: When you first arrive on Revision Genie we note the domain name of the website that linked you to us (for example google.com, never the full web address you came from or anything you searched for), any campaign tags included in the link itself, and the first page you visited (as a route template, so identifiers and tokens are stripped out). We keep this in a cookie on your device for up to 30 days and, if you go on to create an account, we record it on that account so we can understand how people find Revision Genie and which of our own campaigns are worth continuing. If you never create an account, the cookie simply expires and nothing is kept.

1.10 Sign-Up and Setup Counters: So that we can find and fix the parts of signing up that do not work, we count how many people reach each question in our sign-up form and our welcome setup chat, and what happened at each one: it was answered, it was skipped, it was left unanswered, or it was refused. Where a question refused someone we also record the reason from a fixed list we have written in advance, such as that an email address was already registered, that a password was under eight characters, or that a typed subject did not match anything we teach. These are counts and nothing more. We record no name, no account reference, no device reference and nothing you typed: the fact that an email address was already registered is recorded, never the email address itself. Nothing here can be linked back to you or to anyone else, even by us, and because there is no identifier in these counts there is nothing in them to delete if you close your account. The only things recorded alongside a count are the day and whether you had told us you were a student, teacher or parent.

1.11 Push Notifications: If you turn on push notifications, we store what is needed to reach that one browser: the notification address your browser gives us, which is a web address at a push service run by the company that makes your browser; two keys your browser creates so the message can be encrypted to that device; which account the device belongs to; and a short description of the browser and operating system you were using, which is kept only so that one device can be told apart from another and is never used to build a profile of you. We also record when the device was last seen and whether recent messages got through, so we stop sending to a device that no longer exists. We do not store your IP address, your location, or any kind of device fingerprint. Push notifications are off until you say yes twice: once in our own card, and again in your browser's own permission box. Today we send one kind of push notification and nothing else: when another user invites you to a live quiz. Nothing is sent between 9pm and 7am UK time, whatever your age. There is one switch, in Settings. Turning it off unsubscribes the device you are using and stops notifications on all of your devices at once. We delete the stored device when you switch it off, when you sign out on it, when the push service tells us it has gone, and when you delete your account.

2. How We Use Your Information

2.1 Educational Support: We use your information to provide personalised learning experiences and track your educational progress.

2.2 Service Improvement: We analyse usage patterns to enhance our educational tools and features.

2.3 Communication: We send essential service updates, account notifications, support replies, and (where you have opted in) practice reminders and newsletters.

2.4 Safety and Safeguarding: We monitor for content and patterns that may indicate a safeguarding concern, and may review flagged conversations to keep users safe.

2.5 Child Safety: For users under 18, we implement additional safeguards and never use data for advertising or commercial profiling.

2.6 Guardian Visibility: If a student links a parent or guardian account to their own, we show that guardian the student's learning signals: progress, homework status, streaks, activity level, subjects and grade estimates, mock exam results (only where a teacher has released them, or the student marked them themselves), remaining AI allowance, and tasks the guardian has set. A guardian can never see the student's chats with our AI tutors, their notes or files, their social connections, or any safeguarding information. Linking requires a short-lived code that only the student can display, the student is notified when a guardian links, and the student can see and remove linked guardians at any time in their settings. The link record is deleted when either side removes it and when either account is deleted.

3. Legal Basis for Processing

Under UK GDPR we must have a lawful basis for processing your personal data. The bases we rely on are:

3.1 Contract: We process your account information, learning data and payment information so we can deliver the educational service you have signed up for.

3.2 Legitimate Interests: We process technical data, basic usage analytics, and security-related information for the legitimate interest of keeping the service running, secure and improving over time. Where you are a child, we balance these interests carefully against your rights.

3.3 Legal Obligation: We process and may retain certain data to comply with legal obligations (for example, tax records relating to your payments, or safeguarding disclosures to appropriate authorities).

3.4 Consent: We rely on your consent for optional activities such as marketing emails or newsletters. You can withdraw consent at any time in your account settings.

3.5 Vital Interests: We may process information without consent where we reasonably believe it is necessary to protect someone's life or safety (for example, a serious safeguarding disclosure).

4. Data Retention

We keep your data only for as long as we need it. Headline retention periods are:

Account data: kept for as long as your account is active. Inactive accounts are deleted after 12 months of inactivity. We email you a reminder at 6 months and a warning a month before deletion, so you can sign in to keep the account or download your data first.

AI chat conversations: not retained by default. Safeguarding-flagged conversations are kept for up to 24 months for review and audit.

Uploaded files (chat attachments): retained for up to 30 days and then cleaned up automatically.

Uploaded files (My Genies knowledge base): retained until you delete them or delete the genie.

Support tickets: kept for up to 24 months after resolution.

Payment records: retained for at least 7 years to meet UK accounting and tax requirements.

In-app page-visit records: kept for 30 days, after which only anonymous daily totals remain.

Push notification devices: kept until you switch them off, sign out on that device, or delete your account, or until the push service tells us the device has gone. There is no fixed period.

Anonymised analytics: may be retained indefinitely.

See our Data Retention Policy for the full breakdown.

5. Your Rights and Controls

5.1 Access: You can access and download your personal information through your account settings or by request.

5.2 Rectification: You can correct inaccurate information in your account settings, or by contacting us.

5.3 Erasure: You can request deletion of your account. We operate a 2-day cooling-off period, after which your account is anonymised and your personal data deleted. Certain records (such as financial records or anonymised safeguarding information) may be retained where the law requires.

5.4 Restriction and Objection: You can ask us to restrict how we use your data, or object to processing based on legitimate interests.

5.5 Portability: You can ask us to provide your data in a portable format.

5.6 Withdraw Consent: Where we rely on consent (e.g. marketing emails), you can withdraw it at any time without affecting prior processing.

5.7 Memory Controls: You can view, edit and delete any notes our AI has saved about you in Settings → AI Memory.

5.8 Right to Complain: If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office (the UK's data protection regulator) at ico.org.uk or by calling 0303 123 1113.

6. Information Sharing and Third-Party Processors

We share information only when necessary to provide our service or when required by law. We never sell your personal information and we never share it for advertising or commercial profiling.

We use the following trusted third-party processors to run Revision Genie:

Microsoft Azure (United Kingdom / European Union regions) - Azure OpenAI for AI tutoring and Azure Speech Services for text-to-speech in language lessons. Microsoft contractually commits not to train its models on our customer data.

MongoDB Atlas - hosts our primary database.

Vercel - hosts the website and serverless functions.

Vercel Blob - stores uploaded files (chat attachments, profile pictures, knowledge base documents).

Vercel Speed Insights - measurement of how quickly our pages load, so we can find and fix slow pages. It runs on every page. It receives the address of the page viewed, page-loading performance timings, and coarse technical details such as browser type, device type and connection speed. It does not record which buttons you pressed or how far you scrolled, and we never pass it your name, your account ID, your schoolwork or your chat content. Vercel states that this product does not use cookies and does not identify individual visitors or track them across websites, which is why it is not held behind the cookie notice. See our Cookie Policy.

Upstash Redis - caching and rate limiting.

Stripe - processes all card payments and stores card information securely on our behalf.

Google (Google Sign-In) - optional sign-in.

Microsoft (Microsoft Sign-In) - optional sign-in.

SendGrid - email delivery for service emails, support replies and (where opted in) practice reminders and newsletters. It receives the recipient's email address, the content of the message, and delivery events such as bounces and complaints.

Sentry (European Union region) - server-side error monitoring, so that faults are reported to us and fixed. It receives technical diagnostics only: the error type and message, the stack trace, the version of our software, and labels such as which background job failed. Request cookies, headers, query strings and submitted content are stripped before anything is sent, any reference to a user is reduced to an internal account ID, and values that look like an email address, password, token, card number or phone number are redacted automatically. It never receives your schoolwork or chat content, and we do not collect performance or session-replay data through it. Error reporting is active only where this service is configured.

ContentSquare - product analytics that helps us understand how the site is used so we can improve it. Loaded only if you choose to accept all cookies. We use it to improve the product, never to advertise to you or to build a commercial profile of you. See our Cookie Policy.

All processors are bound by data processing agreements and are required to meet UK GDPR-equivalent standards.

Browser push services: if you turn on push notifications, each notification is also passed to the push service built into your browser. That service is run by the company that makes the browser you are using: Google for Chrome, Mozilla for Firefox, Microsoft for Edge, or Apple for Safari. We do not choose it and cannot change it, because your browser decides which service to use and hands us the address. We pass it the notification address for your device, the notification itself, and how long it should keep trying to deliver it. The notification is encrypted to your device before it leaves us, so the push service carries it without being able to read the words inside. This is how push notifications work at all, so if you would rather nothing was passed on this way, leave push notifications switched off, or switch them off in Settings.

We may also share progress data with the school or class teacher that registered a student account, where the school has authorised this. We may disclose information to law enforcement or safeguarding authorities where we are legally required to do so or where we reasonably believe it is necessary to protect a user.

7. International Data Transfers

We prefer to keep personal data within the United Kingdom and European Economic Area, but some of our processors (notably aspects of Azure and Stripe) may transfer or back up data outside the UK and EEA.

Where data is transferred internationally, we rely on UK and EU recognised safeguards such as the UK International Data Transfer Addendum or Standard Contractual Clauses, plus additional measures such as encryption.

8. Special Protections for Young Users

8.1 Age-Appropriate Design: Our service follows the ICO's Age Appropriate Design Code.

8.2 Privacy-Protective Defaults: We apply minimal data collection by default at every age. For students who register as under 16, two further defaults are applied automatically at the moment the account is created: their name is hidden from other people's leaderboards, and no approximate location is recorded on their account. Neither default stops the student using anything. They can still see and take part in leaderboards, and they can turn their visibility back on themselves at any time in Settings.

8.3 No Advertising Profiling: We never use children's data for advertising or behavioural profiling.

8.4 Clear Communication: We provide age-appropriate privacy information and easy reporting tools.

8.5 What We Do Not Offer: There is no per-user profile visibility switch, and we do not claim one. What exists is the leaderboard control described above, which every student has, and a school-level setting that lets a school restrict its students' profiles so they are visible only within that school. Where a school turns that on, it applies to all of that school's students and is controlled by the school rather than by us or by the individual student.

See our Children's Code Compliance page for the full breakdown.

9. Data Security

9.1 Encryption: All personal data is encrypted in transit (TLS) and at rest by our processors.

9.2 Access Controls: We maintain strict controls over who can access user data.

9.3 Regular Reviews: We regularly review our security practices and update them as needed.

9.4 Incident Response: We have procedures in place to handle security incidents promptly. Where required by law we will notify affected users and the ICO.

Contact Information

For questions about your privacy or to exercise your data protection rights, please contact our Data Protection Officer, Joel Martin, at joel@revisiongenie.com.

Revision Genie Ltd is the data controller for your personal information and is registered with the Information Commissioner's Office under registration number ZC008367. For more information about how we protect young users, please see our Children's Code Compliance page.

Have questions about this policy?

Our support team is happy to help explain anything

Contact Support