Last updated: 2026-08-10.1
This policy explains what personal data Aquinas Revision ("the app", "we", "us") collects, why, and what rights you have over it. It's written under UK GDPR and the Data Protection Act 2018.
Note for students:many people using this app are under 18. If you're under 13, please ask a parent or guardian to read this with you and to agree to sign-up on your behalf — see Children using this app below.
Aquinas Revision is operated by ConsoleOne, the data controller for the personal data described below.
Contact: isiahsmpsn@gmail.com
If you have a concern about how we handle your data that we haven't resolved, you can complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk.
| Data | Where it comes from | Why we need it |
|---|---|---|
| Email address, password (stored securely by our authentication provider, never in plain text) | You, when you sign up | To create and secure your account |
| Religions and Paper 2 themes you study | You, during onboarding | To show you only the content relevant to your course |
| Quote and key term favourites and "known/learning/new" status | You, using the flashcard and key terms glossary features | To power spaced-repetition revision |
| Essay plans you write or fork, including your own written text | You, using the essay planner | To save your work between sessions |
| Mock/past exam scores, timing mode, and a per-question breakdown (topic, question type, marks) for both mock exams and standalone practice questions | Generated when you complete a mock exam or practice question | To track your progress over time and power the analytics dashboard — visible to your own teacher if you're in a class, see section 5 |
| Your exam answer text and the question it responds to (Premium only) | You, when you request AI marking — or, for teacher-marked class tasks, your teacher on your behalf | Sent to our AI marking provider to generate a mark and feedback |
| A photo of a handwritten answer, only while it's being transcribed (Premium only) | You, if you choose to photograph an answer instead of typing it | Sent to our AI provider to convert your handwriting into text — the photo itself isn't stored afterwards, only the resulting text |
| A record that you used AI marking or AI transcription at a given time — including how many tokens the request used and the resulting cost (not the content of your answer or photo) | Generated automatically | To enforce a fair daily usage limit, and to calculate any refund deduction if you cancel Premium within 14 days having already used AI marking |
| Content of any Task your teacher assigns you (frozen mock exam/practice question content), and your answers to it | Your teacher (task content) and you (your answers, when you complete a task) | To run the Tasks feature — let your teacher assign work, and (for teacher-marked tasks) mark your submitted answers |
| Your chosen extra-time percentage for timed mock exams (0%, 25%, or 50%) | You, in account settings | Applied automatically to the timer whenever you choose Timed mode |
| Which school and class(es) you belong to (students: up to 3 classes; teachers: the school you registered or joined, and any classes you created) | You, when you join or create a class — or a teacher, when they add you directly | To run classes, Tasks, and class-level Premium access |
| Subscription status, renewal date, and Stripe's internal customer/subscription IDs — for your own personal subscription, and (for teachers) any class subscriptions you manage | Our payment provider, after you or your class subscribes | To know whether you (or your class) have Premium access |
| A record that you agreed to this policy, our Terms, AI marking, and AI transcription (policy name, version, timestamp) | Generated when you sign up / first use AI marking or AI transcription | To evidence what you agreed to and when |
| IP address (for requests made while signed out) or your account ID (while signed in), held only for a short window (typically minutes) | Automatically, from requests to certain endpoints | To limit abuse (rate limiting) — not used to identify or track you beyond that window |
| Authentication session cookie | Set automatically when you log in | Required to keep you logged in |
We do notcollect your name, phone number, or physical address anywhere in the app. If you join or create a class, we know which school and class(es) you belong to (see the table above) — nothing more. At signup, we ask your date of birth once to confirm you're old enough to agree to this policy yourself — it's used locally in your browser to check your age and is never sent to us or stored; only a yes/no record that the check passed is kept. We do not run advertising or analytics trackers.
Payment card details are never seen by us.Checkout happens entirely on Stripe's hosted payment page.
We do not rely on "legitimate interests" as a basis for anything in this app, and we do not use your data for profiling, targeted advertising, or any purpose beyond running the features described above.
We use a small number of specialist providers ("processors") to run the app. We don't sell data to anyone, and we don't share it for marketing purposes.
| Provider | What they process | Why |
|---|---|---|
| Supabase | Account credentials, all study data | Database and authentication hosting |
| Stripe | Email address (for checkout), payment details, subscription status | Payment processing |
| Anthropic (Claude API) | The specific question and answer text (or handwriting photo, for transcription) submitted for AI marking or transcription — including, for teacher-marked class tasks, answers your teacher submits on your behalf | Generates the mark and feedback, or transcribes a photographed answer to text |
Each provider only receives what it needs to do its job, and each is contractually restricted from using your data for its own purposes.
If you're a student and you're part of a class, your teacher (and any other teacher at the same school) can see:
Teachers can only see this for students in their own classes, at their own school — never students at a different school, or students outside a class they're part of. Leaving a class (or a teacher removing you from one) stops any new data being shared this way, though scores already published to your results stay with your account, same as any other exam attempt.
If you're a teacher, registering a school shares your email address with us for verification purposes, and — once approved — your school's name and chosen syllabus (which you set at registration) becomes visible to any student who joins your school.
We use one essential cookie, set by our authentication provider, to keep you logged in. It's strictly necessary for the app to function and isn't used for tracking, analytics, or advertising. If we ever add analytics or any non-essential cookie in future, we will ask for your consent first via a cookie banner, and update this section.
Under UK GDPR, you can:
We don't rely on "legitimate interests" or use your data for direct marketing anywhere in the app, so the right to object under Article 21 UK GDPR (which applies specifically to those two bases) doesn't have anything to bite on here — withdrawing consent or requesting erasure/restriction covers the same practical ground for everything we actually do.
You can delete your own account instantly from the Account page in the app — no need to contact us. For anything else (access, export, correction, restriction), email isiahsmpsn@gmail.com. We'll respond within one month, as required by law.
This app is designed for GCSE-age students and is likely to be accessed by children. We've applied the following principles from the ICO's Age Appropriate Design Code:
If you're a parent/guardian and believe your child under 13 has created an account without your consent, contact us at isiahsmpsn@gmail.com and we will delete the account.
Your study data is protected by row-level security rules that mean only you (and no other user) can read or write it, other than the teacher-visibility described in section 5. Passwords are hashed by our authentication provider and are never visible to us in plain text. Data in transit is encrypted (HTTPS/TLS).
If we make material changes to this policy, we'll update the date at the top and, for significant changes, notify logged-in users in the app.