StemAdmit
Legal

Privacy Policy

How we handle your data, in plain English. Last updated 21 July 2026. See also our Terms of Service and Refund & Cancellation Policy.

1. Who we are

StemAdmit provides online ESAT & TMUA preparation and tutoring services from the United Kingdom. We are the data controller for the personal data described here. For anything privacy-related, reach us through our contact page.

2. What we collect

  • Account details. Your email address and, if you sign in with Google, the name and profile photo Google shares with us. We never see your password — sign-in is handled by Google Firebase.
  • Study data. The questions you attempt, your answers, scores, diagnostic results, study-plan choices and progress over time. This is the data that powers your dashboard and predicted score.
  • Purchase data. Which plan you bought, when, and your billing status. Card payments are processed entirely by Stripe — your card number never touches our servers. We store only a Stripe customer reference.
  • Enquiries. What you send us in tutoring or contact forms, and your email address if you sign up for study emails.
  • Technical data. Standard server logs (IP address, browser type) and the cookies listed in section 5, including a device identifier used to enforce the per-account device limit.

We don’t collect any special-category (sensitive) data, and we don’t buy data about you from anyone.

3. Why we use it (and our legal bases)

  • To run the service — signing you in, saving progress, unlocking what you’ve paid for, and showing your dashboard. Legal basis: performing our contract with you.
  • To take payment and keep accounts — processing purchases via Stripe and keeping the records tax law requires. Legal basis: contract and legal obligation.
  • To send service emails — receipts, important account or policy changes. Legal basis: contract.
  • To send study tips and product updates — only if you gave us your email for that, and every email has an unsubscribe link. Legal basis: consent.
  • To keep the service safe and improve it — preventing account sharing and fraud, debugging problems, and understanding which content helps students most. Legal basis: our legitimate interests, balanced against your rights.

We never sell your personal data, and we don’t use it for third-party advertising.

4. Who processes it for us

A small set of providers process data on our behalf, each under a data-processing agreement:

  • Google Firebase — sign-in and our database (your account and study data).
  • Stripe — payments. Stripe acts as an independent controller for the card data it collects; see Stripe’s privacy policy.
  • Vercel — hosting and server logs.
  • Resend — sending our emails.

Beyond these providers, we disclose personal data only if the law requires it or as part of a sale or reorganisation of the business (in which case this policy would still protect it).

5. Cookies

We use only cookies that are essential for the service to work — nothing for advertising or cross-site tracking, which is why you don’t see a cookie banner:

  • Session cookie — keeps you signed in.
  • Device cookie — a random identifier that enforces the per-account device limit.

Blocking these in your browser will sign you out and may prevent paid content from loading.

6. Where your data lives

Our providers may store or process data outside the UK (for example in the EU or US). Where they do, the transfer is protected by recognised safeguards — UK adequacy decisions, the UK Extension to the EU–US Data Privacy Framework, or standard contractual clauses with the UK addendum.

7. How long we keep it

  • Account and study data: for as long as your account exists. Ask us to delete your account and we’ll erase it.
  • Purchase records: 6 years after the transaction, as UK tax law requires — even if the account is deleted.
  • Marketing email addresses: until you unsubscribe or ask us to remove you.
  • Server logs: kept briefly for security and debugging, then deleted automatically.

8. Your rights

Under UK GDPR you can ask us, free of charge, to:

  • give you a copy of the personal data we hold about you;
  • correct anything inaccurate;
  • delete your data (“right to be forgotten”);
  • restrict or object to how we use it; and
  • hand your data over in a portable format.

Send your request through our contact page and we’ll respond within a month. If you’re unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk — though we’d appreciate the chance to put it right first.

9. Young people

StemAdmit is built for students preparing for university admissions tests, who are typically 16 or older. We don’t knowingly collect data from children under 13. If you believe a child under 13 has created an account, contact us and we’ll delete it.

10. Changes to this policy

If we change this policy in a way that matters, we’ll tell you — by email or a notice on the site — before the change takes effect. The date at the top always shows the current version.

Privacy question or request? Reach us through the contact page.