Privacy Policy
- The short version
- Who is responsible for your data
- What we collect
- Why we collect it, and our legal basis
- AI processing and third-party providers
- Who else sees your data
- Cookies and local storage
- How long we keep things
- Your rights under UK GDPR
- Students, age and parents/guardians
- Security and international transfers
- Changes and how to complain
1The short version
The rest of this page is the detail behind those four sentences.
2Who is responsible for your data
Speclab is the data controller for the personal data described here. We're a small independent product based in the United Kingdom. During development the contact address for all data protection matters is privacy@reviverevision.co.uk (placeholder address).
We are not currently registered with the ICO as we are pre-launch and not yet processing real user data at scale; registration will be completed before public launch where required.
3What we collect
Account data
- your email address;
- a securely hashed password (we never store the password itself);
- optionally, a display name and which year group you're in;
- your plan (free or premium) and, once billing exists, a customer reference from our payment processor — never your card number, which stays with the processor.
Revision data
- your checklist progress across the specification;
- your confidence self-tags (the 1–5 ratings);
- your Mistake Log entries and their retest schedule;
- your Score Log — the marks and AO feedback from AI-marked answers;
- session history: which subtopics you studied, when, and for how long.
Content you write
- your chat messages to the AI tutor, and its replies, kept as conversation history so a session can continue where it left off;
- the practice answers you submit for marking.
Technical data
- basic server logs (IP address, browser type, timestamps, errors) used for security, debugging and rate-limiting;
- counts of how many AI-marked answers you've used today, so daily limits can be enforced.
We do not ask for your address, phone number, date of birth, school, or any special category data (health, ethnicity, religion and so on). Please don't put personal details about yourself or other people into chat messages or practice answers — the tutor doesn't need them, and they'd end up in your conversation history.
4Why we collect it, and our legal basis
- To provide the service (answering your questions, marking your answers, remembering your progress, scheduling retests) — legal basis: performance of a contract with you.
- To enforce usage limits and keep the service secure (rate limiting, abuse prevention, server logs) — legal basis: legitimate interests in running a service that isn't abused or bankrupted by a scripted account.
- To take payment, once Premium exists — legal basis: performance of a contract, and legal obligation for keeping financial records.
- To send you service emails (password resets, important changes to these policies) — legal basis: performance of a contract. Marketing emails, if we ever send any, would be consent only, with an unsubscribe link.
We do not build advertising profiles, we do not run third-party ad trackers, and we do not use your revision content to train our own models.
5AI processing and third-party providers
When you send a chat message, or press "Submit for marking", the content of that message or answer — along with the question and relevant specification context — is transmitted to a third-party AI provider, which generates the response and sends it back to us. We access these models through OpenRouter, which routes requests to the underlying model providers. The models currently used are provided by DeepSeek and, as a fallback, Google (Gemini).
In practice this means:
- your chat messages and practice answers leave our servers and are handled by those providers under their own terms and privacy policies;
- we send the content of your message, not your name or email — but the message content itself is whatever you typed, so avoid including personal information in it;
- we may switch to a different provider or model if one is unavailable or if a better option appears. If we change providers in a way that materially changes where your data goes, we'll update this policy and tell you.
We select providers partly on their stated data-retention and training policies, and we prefer providers that do not train on API traffic. We can't, however, guarantee the practices of a third party beyond what they contractually commit to.
Other processors we rely on, or expect to rely on at launch:
- a cloud hosting provider for our servers and database;
- a transactional email provider for password resets and service notices;
- a payment processor, once Premium launches, which handles card details directly so that we never see or store them.
6Who else sees your data
We do not sell your personal data, and we do not share it with advertisers or data brokers. Beyond the processors listed above, your data is only disclosed:
- where we're legally required to (a court order, or a lawful request from a regulator);
- where it's genuinely necessary to investigate abuse, fraud, or a security incident;
- if the product were ever sold or transferred, in which case any buyer would be bound by this policy and you would be told beforehand.
Your teachers and your school do not have access to your account. Nothing you write is shared with your centre.
7Cookies and local storage
We keep this deliberately minimal. We use:
- an essential session cookie to keep you logged in;
- browser local storage for small preferences — currently your light/dark theme choice, stored under the key
rr-theme, and your default session preferences. This never leaves your device.
We do not use advertising cookies, third-party analytics trackers, social media pixels, or cross-site tracking of any kind. Because we only use strictly necessary cookies and local preferences, there is no consent banner — there's nothing to consent to.
8How long we keep things
- Account and revision data — for as long as your account is open. Long history is the point of a mistake log, so we don't auto-delete your progress.
- Chat history — kept so sessions stay coherent. You'll be able to clear individual conversations from within the app.
- Free-tier Score Log — retained for 30 days, as described on the pricing page. Premium keeps full history.
- Server logs — typically 30 days, then deleted.
- After account deletion — your personal data is deleted within 30 days, other than anything we're legally required to retain (for example basic financial records, which UK tax law requires us to keep for six years once payments exist).
9Your rights under UK GDPR
You have the right to:
- Access — ask for a copy of the personal data we hold about you;
- Portability — ask for it in a machine-readable format you can take elsewhere;
- Rectification — have inaccurate data corrected;
- Erasure — have your account and its data deleted ("the right to be forgotten");
- Restriction and objection — ask us to stop certain processing, including anything we do on the basis of legitimate interests;
- Withdraw consent at any time, where consent was the basis for processing.
You'll be able to delete your account yourself from the settings page. For anything else, email privacy@reviverevision.co.uk. We'll respond within one month, free of charge, and we may ask you to confirm your identity first so we don't hand your data to someone else.
10Students, age and parents/guardians
Speclab is built for A-level students, so most users are expected to be aged 16 to 18. The service is not intended for children under 13 and accounts should not be created for them.
If you are a parent, guardian, or teacher and you have a concern about a student's data — including a request to see what's held or to have an account deleted — please contact privacy@reviverevision.co.uk and we'll deal with it. Where the student is old enough to exercise their own rights, we will normally involve them in the request.
We design with this age group in mind: no advertising, no behavioural profiling, no engagement-maximising notifications, and no sharing of student content with third parties beyond the AI processing described in section 5.
11Security and international transfers
Passwords are stored hashed, traffic is encrypted in transit over HTTPS, and access to the production database is restricted. No system is perfectly secure, but if a breach occurred that put your rights at risk, we'd notify the ICO within 72 hours and tell affected users without undue delay.
Some of our processors — particularly the AI providers — operate outside the UK. Where personal data is transferred internationally, we rely on the UK's adequacy regulations or on standard contractual clauses with the UK International Data Transfer Addendum, as appropriate.
12Changes and how to complain
We'll update this policy as the product develops — and it will certainly change when this draft is reviewed properly before launch. Material changes will be notified by email or in the app. The version number and date at the top of this page always reflect the current version.
If you're unhappy with how we've handled your data, please tell us first so we can try to fix it. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ico.org.uk).