Privacy Policy
1. What we collect
- Account data: email address, name (if provided), university, year of study, age (optional), exam date (optional).
- Usage data: question attempts, mock exam scores, time spent, sections drilled.
- Product analytics: when you're signed in, we record key product events tied to your account — sign-up, questions attempted, mock exams started and completed, subscription started, and opening the in-app BNF — so we can understand how the Service is used and measure funnels and retention. Visitors to the public marketing site are counted without an individual profile.
- Billing data: handled by Stripe — we receive only the customer reference, subscription status, and renewal date.
- Technical data: IP address (for rate limiting + abuse prevention), browser type, referrer.
- Cookies & local storage: a session cookie for sign-in, and — once you're signed in — a first-party analytics identifier (set by PostHog, stored in your browser) so product events can be linked to your account. No third-party advertising cookies.
2. Why we use it
- Run the Service (legal basis: contract).
- Personalise your study plan + dashboard stats (legal basis: legitimate interests).
- Send transactional emails (sign-in links, receipts) (legal basis: contract).
- Optional weekly progress emails if you opt in (legal basis: consent — withdraw any time).
- Detect + prevent abuse (legal basis: legitimate interests).
- Comply with legal obligations (e.g. VAT records).
3. Who we share data with
- Supabase (database + auth) — EU region. Acts as our data processor.
- Stripe (payments) — UK + global. Acts as the data controller for payment data.
- Vercel (hosting) — global edge network.
- Plausible (cookieless analytics) — only if enabled; aggregate-only, no individual tracking.
- PostHog (product analytics) — EU region; acts as our data processor. Records the product events above for signed-in users to build usage funnels and retention. Configured without session recording and without advertising; we don't profile anonymous visitors.
- Sentry (error monitoring) — only if enabled; we strip PII from reports.
We don't sell or rent your data. We don't pass it to advertisers.
4. International transfers
Our database (Supabase) and product analytics (PostHog) are hosted in the EU. Stripe processes some data in the United States. We rely on the UK's adequacy decisions and Standard Contractual Clauses to safeguard those transfers.
5. How long we keep it
- Account + attempt data: while your account is active, plus 12 months after deletion (so we can restore on request).
- Billing records: 7 years (UK statutory retention).
- Error logs: 90 days.
- Plausible analytics: aggregate only — no individual retention.
- PostHog product analytics: identified usage events kept while your account is active and deleted when you delete your account.
6. Your rights
Under UK GDPR you can:
- Access a copy of your data.
- Correct inaccurate data.
- Delete your data (we'll close your account and remove personal data within 30 days).
- Export your data in machine-readable form.
- Object to processing based on legitimate interests.
- Withdraw consent for weekly emails any time.
- Complain to the Information Commissioner's Office.
To exercise any of these, email privacy@psaspeedrun.com.
7. Security
Data in transit is encrypted with TLS. Data at rest in Supabase is encrypted with AES-256. Auth uses HTTP-only cookies. The answer key for questions (model answers + explanations) is locked to a service-role database key and never reachable from a browser session. We undertake periodic security reviews, particularly on the auth + payment paths.
8. Children
PSA Speedrun is intended for medical students and qualified doctors. We don't knowingly process data from anyone under 18. If you believe a minor has created an account, please contact us.
9. Changes
We may update this policy. Material changes will be notified by email at least 14 days before they take effect.
10. Contact
Data protection enquiries: privacy@psaspeedrun.com. General contact: hello@psaspeedrun.com.