Data Protection & Student Privacy
Privacy Policy
Last updated: August 2026 · Designed with UK data-protection and student privacy principles in mind.
1. Introduction & Our Student-First Privacy Commitment
Law.AI (alevellaw.com) is an educational revision platform designed specifically for UK A-Level Law students studying AQA, OCR, Eduqas/WJEC, and Pearson Edexcel specifications.
We treat student privacy and data protection as core principles of our platform design. We operate with strict data protection standards:
- No third-party tracking or advertising: We do not track students across third-party websites or deploy commercial tracking pixels.
- No data sales: We do not sell, rent, or trade student personal data, essays, or revision activity to third parties.
- No behavioural advertising: We do not build behavioural advertising profiles from student study activity.
- High privacy by default: Your study progress, flashcard reviews, exam attempts, and essay drafts are strictly private to your account.
2. Data Controller & Contact Information
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller for personal data processed through Law.AI is:
Legal Entity: [VERIFY: Full Registered Legal Entity Name, e.g., LawAI Education Ltd or Individual Sole Trader Name] trading as Law.AI (alevellaw.com)
Registered Office / Postal Address: [VERIFY: UK Registered Office Address / Postal Address]
Data Protection Lead Email: privacy@alevellaw.com
Data Requests: For Subject Access Requests (SARs), account erasure, or data corrections, email privacy@alevellaw.com with the subject line "Data Privacy Request".
3. Lawful Bases for Processing (UK GDPR Article 6)
Under UK GDPR Article 6, we process personal data under the following specific lawful bases:
- Contractual Necessity (Art. 6(1)(b)): To create and manage your student account, authenticate your login sessions, maintain your syllabus progress checklist, schedule active recall reviews, store timed exam drafts, and generate automated formative essay feedback.
- Legitimate Interests (Art. 6(1)(f)): To maintain platform security, prevent abuse and automated scraping, enforce per-user AI rate limits, monitor infrastructure uptime, and resolve technical errors.
- Legal Obligation (Art. 6(1)(c)): To maintain statutory VAT, accounting, and financial transaction records for paid subscription and Lifetime Pass purchases as required by UK tax legislation (HMRC).
- Consent (Art. 6(1)(a)): Where you choose to submit optional public feedback, suggestions, or Q&A discussions to the community board.
4. Personal Data We Collect (and What We Do Not Collect)
We collect and process only the minimal data strictly necessary to provide an effective, personalised revision service:
- Account & Authentication: Your email address and securely hashed authentication credentials (managed via Supabase Auth). If you choose to sign in using Google OAuth, we receive your verified email address, display name, and optional avatar image.
- Syllabus & Study Preferences: Your selected exam board (AQA, OCR, Eduqas, or Pearson Edexcel), target study year (Year 12 / Year 13), and interface display preferences.
- Study Progress & Recall Activity: Completed syllabus checklist modules, custom flashcards, spaced-repetition review ratings (quality scores and calculated review intervals), and bookmarked legal authorities.
- Practice & Timed Exam Attempts: Saved past-paper attempt records, question responses, elapsed time spent per question, and completion statuses.
- Essay Submissions & Formative Feedback: Submitted practice answers (between 20 and 20,000 characters), selected question IDs, maximum mark values, rubric assessment versions, awarded formative scores, and detailed rubric breakdown criteria (AO1 knowledge, AO2 application, AO3 analysis, strengths, improvements, and case authority citations).
- Community Feedback & Public Q&A: Student feedback posts, feature suggestions, star ratings (1–5), upvotes, and comments. When displayed publicly, user email addresses are strictly masked and only your chosen display name or a default "Student" alias is shown.
- Billing & Subscription Records: Stripe customer identifier (
cus_...), subscription identifier (sub_...), price identifier, and subscription status (e.g. active, canceled, lifetime). We never receive, handle, or store your payment card numbers, CVVs, expiry dates, or bank account details. All payment data is entered directly into Stripe's secure PCI-DSS Level 1 compliant infrastructure. - Operational Technical Logs: Sanitised Edge Function operational logs containing only technical metadata (request ID, timestamp, function name, outcome, HTTP status code, duration, attempt count, and AI provider name). No essay text, student names, or email addresses are written to server operational logs.
What we do NOT collect: We do not collect student phone numbers, home physical addresses (unless required by Stripe for payment card billing verification), biometric data, location tracking/GPS, or special category data (such as health, racial/ethnic origin, or religious beliefs).
5. Third Parties & Sub-Processors
We share data only with verified infrastructure providers who process data strictly under Data Processing Agreements (DPAs) with UK GDPR standard contractual safeguards:
- Supabase Inc. — Cloud database hosting, user authentication, and serverless Edge Functions. Data is protected using encryption in transit and at rest provided by our infrastructure providers. [VERIFY: Cloud Region, e.g. AWS eu-west-1 / London / Frankfurt].
- Stripe Payments UK Ltd & Stripe, Inc. — PCI-DSS Level 1 certified payment processing, checkout, and self-service customer billing portal management for subscriptions and Lifetime passes.
- Google LLC — Optional Single Sign-On (OAuth 2.0) authentication provider when you explicitly choose "Sign in with Google".
- AI Inference Providers (Groq Inc., Cloudflare Inc., OpenRouter Inc.) — High-speed inference providers used to evaluate essay submissions against question-specific marking rubrics.
- Vercel Inc. — Static website content delivery network (CDN) and edge routing.
No third-party analytics trackers: Law.AI does not load Google Analytics (GA4), Google Tag Manager, Meta/Facebook Pixels, Hotjar, PostHog, or any third-party marketing SDKs in your browser.
6. AI Essay Evaluation & Formative Marking Disclosures
When you submit a practice essay or past-paper answer for AI marking in the Practice section, your submission is evaluated using our calibrated marking router:
- Data transmission: We minimise the information sent to AI providers and do not intentionally include account names, email addresses or user identifiers in essay-evaluation requests.
- Processing & model training: Requests are transmitted over encrypted connections. Provider retention and training settings are configured to minimise use of submitted content where supported.
- Educational Formative Disclaimer: Marks, Assessment Objective (AO) score breakdowns, and rubric comments generated by Law.AI are formative self-study calibration estimates. They are designed to help you identify strengths and areas for improvement. They do not constitute official marks, predicted grades, or formal assessments from awarding bodies (AQA, OCR, Eduqas/WJEC, or Pearson Edexcel).
7. Cookies and Browser Storage
Law.AI does not use cookies or browser storage for third-party advertising or cross-site tracking.
We use essential browser storage, including local storage and session storage, to provide features such as:
- keeping you signed in;
- saving revision progress and preferences;
- remembering your current revision activity;
- saving draft answers to prevent accidental data loss;
- supporting flashcards and revision features;
- maintaining checkout information while you move to Stripe; and
- providing limited offline functionality.
Some of these technologies are necessary to provide features you have requested and may therefore be used without consent where permitted under the Privacy and Electronic Communications Regulations (PECR).
If we introduce non-essential storage technologies, tracking or functionality that requires consent, we will request consent before using them.
8. Data Retention & Account Deletion Schedule
We retain your personal data only for as long as needed to provide your educational revision services:
- Active accounts: Your study progress, flashcards, and essay submissions are retained while your account remains active so you can track revision over time.
- Account deletion: When an account is deleted, associated personal data is deleted or anonymised where appropriate, subject to lawful retention requirements. Deleted information may remain temporarily in secured backups until those backups expire under our normal backup lifecycle.
- Inactive accounts: Accounts that have remained completely inactive for an extended period (such as 24 consecutive months) may be queued for deletion.
- Statutory accounting exceptions: Stripe payment transaction records, VAT invoices, and statutory financial ledgers are retained for up to 6 to 7 years in compliance with UK statutory accounting and tax regulations (HMRC and the Companies Act 2006).
9. Your Rights Under UK GDPR
Under Chapter III of the UK GDPR and the Data Protection Act 2018, you possess statutory data protection rights regarding your personal information:
- Right of Access (Article 15): You have the right to request confirmation of whether we process your data and receive a copy of all personal data held about you (Subject Access Request).
- Right to Rectification (Article 16): You have the right to request the correction of inaccurate or incomplete personal data.
- Right to Erasure / "Right to be Forgotten" (Article 17): You have the right to request the permanent deletion of your account and associated personal data, subject to lawful retention obligations (such as statutory financial records).
- Right to Restriction of Processing (Article 18): You have the right to request that we restrict processing of your data under specific statutory conditions (for example, while the accuracy of data is being contested).
- Right to Data Portability (Article 20): You have the right to receive your personal data, revision records, and submissions in a structured, commonly used, machine-readable format (such as JSON).
- Right to Object (Article 21): You have the right to object to processing based on legitimate interests.
- Rights Related to Automated Decision-Making (Article 22): We do not make automated decisions that produce legal or similarly significant effects concerning students. AI essay evaluations are purely formative study aids.
Response Timeframe: We respond to all verified statutory data requests within one month of receipt, free of charge. In complex cases, this period may be extended by up to two further months, in which case we will notify you within the initial month.
Right to Complain to the Regulator: If you are concerned about how we handle your personal data, please contact us first at privacy@alevellaw.com so we can resolve the issue. You also have the statutory right to lodge a complaint at any time with the UK supervisory authority, the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
10. Children's Privacy & Age-Appropriate Design (ICO Children's Code)
Law.AI is an educational revision service designed for A-Level students, including young persons aged 16–17. Under Section 9 of the Data Protection Act 2018, the age of digital consent in the UK is 13; students aged 16 and 17 can lawfully create accounts and manage their own study data.
Law.AI is designed with the ICO Children’s Code principles in mind. Because our service is intended for A-Level students, including users aged 16–17, we apply privacy protections such as high privacy settings by default, data minimisation, clear privacy information, restrictions on commercial profiling and avoiding designs that encourage students to disclose unnecessary personal information.
11. International Data Transfers
Where personal data is transferred outside the United Kingdom (for example, to cloud infrastructure operated by Supabase, Stripe, Google, or AI inference providers in the United States or European Economic Area), we ensure appropriate safeguards are implemented in compliance with Chapter V of the UK GDPR:
- UK Adequacy Regulations: Transfers to countries recognized by the UK Government as providing an adequate level of data protection (including the EEA).
- Standard Contractual Safeguards: Transfers governed by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the European Commission's Standard Contractual Clauses (SCCs).
- Data Privacy Framework: Transfers to certified US organizations under the UK Extension to the EU-US Data Privacy Framework.
12. Security & Technical Safeguards
We implement rigorous technical and organizational security measures to safeguard student data:
- Database Row Level Security (RLS): PostgreSQL Row Level Security is enforced on all database tables, ensuring that authenticated students can only access, modify, or delete their own data.
- Server-side secret isolation: Database service-role keys, Stripe private secrets, and AI provider API keys are strictly confined to server-side Edge Functions and are never exposed in client browser code.
- Score tampering prevention: Student essay scores and feedback cannot be written directly from browser clients; they are generated exclusively through secure, server-validated Edge Functions.
- Cryptographic webhook verification: Stripe billing webhooks use cryptographic HMAC signature validation (
stripe-signature) to verify authenticity before updating user subscription entitlements. - Encryption in transit and at rest: Data is protected using encryption in transit and at rest provided by our infrastructure providers.