Privacy Policy

Last updated: 23 April 2026

1. Who we are

GCSE SatNav is an online educational platform helping students navigate their GCSE journey through visual subject maps, AI-guided learning, and adaptive study planning.

We are the data controller for personal data collected through this website. If you have any questions about this policy or how we handle your data, contact us at support@gcsesatnav.com.

2. What personal data we collect

Account data

  • Email address
  • Name (used for personalisation)
  • Year group
  • Account type (student or parent)

Educational data

  • Subject and exam board selections
  • Topic and subtopic progress and confidence levels
  • Practice attempt scores (we store scores only — not your written answers)
  • Study plan preferences and session data

Parent-child link data

  • If you register as a parent, we link your account to your child's account. This link is established by invitation only — we store the relationship and your child's account reference.

Payment data

  • Payment is processed securely by Stripe. We do not store your card details. We store your subscription status and Stripe customer reference.

Technical data

  • Authentication session tokens (stored as secure cookies)
  • IP address (collected by our hosting provider for security and abuse prevention)
  • Theme preference (stored in your browser's local storage only — not sent to our servers)

3. Why we collect it and our legal basis

DataPurposeLegal basis
Account dataCreating and managing your accountContract
Educational dataProviding the service — progress tracking, AI coaching, study planningContract
Parent-child linksParent mode — monitoring progress, assigning focus areasContract
Payment dataProcessing subscription paymentsContract
Technical dataSecurity, fraud prevention, service reliabilityLegitimate interests
Email addressTransactional notifications (you can opt out of non-essential emails at any time)Legitimate interests

4. Who we share your data with

We share data only with service providers necessary to operate the platform. We do not sell your personal data. We do not share your data with advertisers.

ProviderPurposeLocation
SupabaseDatabase and authentication hostingUnited States
StripePayment processingUnited States
AnthropicAI tutoring — we send your subject, topic, and question to generate guidance. Your name and email are never sent to Anthropic.United States
ResendTransactional email deliveryEuropean Union (Ireland)
VercelWebsite hosting and performance monitoringUnited States

5. International data transfers

Some of our service providers are based in the United States. Where data is transferred outside the UK, we rely on the UK-US Data Bridge and Standard Contractual Clauses to ensure your data is protected to UK GDPR standards.

Resend (our email provider) operates from the EU (Ireland) and is subject to UK GDPR-equivalent protections under the UK-EU adequacy decision.

6. How long we keep your data

DataRetention period
Active account dataRetained while your account is active
Deleted account dataDeleted within 30 days of account deletion
Payment records7 years (required by HMRC tax regulations)
Anonymised usage statisticsMay be retained indefinitely (cannot identify you)

7. Children's privacy

This service is designed for students aged 13 and over. We do not knowingly collect data from children under 13. If we become aware that a child under 13 has created an account, we will delete it.

For users under 16, we recommend parental awareness and provide a parent account feature for this purpose.

Our commitments under the ICO Age Appropriate Design Code (Children's Code):

  • We do not profile children for advertising purposes
  • Privacy settings are set to the highest protection by default
  • We collect only the data necessary to provide the educational service
  • We do not use nudge techniques to encourage children to share more data or spend more time on the platform
  • We do not share children's data with third parties for commercial purposes

8. Your rights under UK GDPR

You have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion of your data ("right to be forgotten")
  • Restriction — ask us to restrict processing of your data
  • Portability — receive your data in a portable, machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, email support@gcsesatnav.com. We will respond within 30 days.

9. Automated decision-making

We do not make any automated decisions that have a legal or similarly significant effect on you. Our AI tutoring features provide educational guidance only — they do not make decisions about your academic performance or suitability for any course.

10. Cookies and local storage

  • Essential cookies — authentication session tokens, required for you to remain logged in. No consent required.
  • Local storage — your theme preference (dark or light mode) is stored only in your browser. It is not sent to our servers.

We do not use advertising, tracking, or analytics cookies.

11. Changes to this policy

We will notify registered users by email of any material changes to this policy, with at least 30 days notice before changes take effect. The date at the top of this page shows when the policy was last updated.

12. How to complain

If you have concerns about how we handle your personal data, please contact us first at support@gcsesatnav.com.

You also have the right to complain to the UK Information Commissioner's Office (ICO):

  • Website: ico.org.uk/concerns
  • Telephone: 0303 123 1113