Legal

Privacy Policy

This policy explains what personal data Scholarised collects through Scholarised, why we use it, who we share it with, and the rights you have. Because young people use our platform, it also sets out how we handle children’s data in line with the UK Children’s Code.

Last updated: 3 August 2026

1. Who is responsible for your data

Scholarised ("the Company", "we", "us") is the data controller for personal data processed through Scholarised. We are based in United Kingdom. We process personal data in line with UK data protection law, including the UK GDPR and the Data Protection Act 2018.

For any privacy question, or to exercise a right described below, contact us at [email protected].

2. The personal data we collect

  • Account data - your name, email address, password (stored as an encrypted hash, never in readable form) and the role you hold (student, parent, mentor, administrator).
  • Profile data - optional details you add, such as a profile photo, a short biography, subjects, year group, school or availability. Profile photos are stored in cloud file storage.
  • Family links - which child accounts belong to which parent account, so that billing, spending limits and oversight work.
  • Children’s data - where a parent sets up a linked child account, the child’s name, email and learning activity, managed by the parent.
  • Mentor verification data - information mentors provide for approval and background (DBS) checks, including certificate details and evidence they upload. This can include special category and criminal-record information, handled with extra care and only for safeguarding.
  • Booking and learning data - one-to-one sessions and group seats you book, hold, attend or cancel, session notes and follow-up points, course progress, quiz results and certificates.
  • Credit and payment data - every credit movement in your wallet (what was bought, granted, spent or refunded, and for whom), credit requests a child sends a parent, purchase records, and mentor payout records. Card payments are processed by Stripe; we never see or store full card numbers.
  • Notification data - the notifications we have sent you, your channel preferences, and, if you allow device notifications, the technical subscription details your browser gives us (an address for your device, the keys needed to encrypt a message to it, and a label such as "Chrome on Windows" so you can tell your devices apart).
  • Calendar link - a private token that lets your own calendar app subscribe to your sessions. See section 8.
  • Study assistant conversations - the messages you exchange with the in-app assistant, kept so you can return to them. See section 10.
  • Administrative records - a log of significant actions taken by our staff on accounts (for example approving a mentor or granting credits), so decisions about you can be traced and explained.
  • Technical data - the limited information needed to run and secure the service, such as sign-in session data and error records.

There is one field we have built but do not yet use: a student’s exam level and exam date. We will begin asking for these only when session recordings go live, because they decide how long a recording stays available to that student. Until then we do not collect them, and we do not record sessions at all.

3. Where the data comes from

  • From you, when you register, complete your profile, book, buy or contact us.
  • From a parent, where they create or manage a linked child account.
  • From a mentor, where they write up what a session covered.
  • From our providers, where they tell us the result of something we asked them to do - for example Stripe confirming a payment succeeded, or a screening provider returning the outcome of a background check.

4. How we use your data and our lawful bases

We use personal data for the following purposes, relying on these UK GDPR lawful bases:

  • To provide the service - creating your account, running sessions and group seats, courses, the credit wallet and mentor payouts. Lawful basis: performance of a contract.
  • To take payment - processing credit purchases, refunds and mentor payouts, and preventing payment fraud. Lawful basis: performance of a contract, and our legitimate interest in preventing fraud.
  • To keep the platform safe - vetting mentors, background checks, acting on safeguarding concerns and keeping records of them. Lawful basis: our legal obligations, the substantial public interest condition for safeguarding children, and our legitimate interest in a safe service.
  • To let a parent oversee a child - showing a parent their child’s bookings and spending, and enforcing any limit they set. Lawful basis: performance of a contract, and the legitimate interests of both the parent and the child.
  • To communicate with you - confirmations, session reminders, refund and cancellation notices, and support. Lawful basis: performance of a contract and our legitimate interests. Device notifications additionally rely on the permission you give your browser, which you can withdraw.
  • To provide the study assistant - answering your questions and keeping your conversation history. Lawful basis: performance of a contract.
  • To improve and secure the service - maintaining, protecting and improving the platform, and investigating misuse. Lawful basis: our legitimate interests, balanced against your rights.
  • To meet legal duties - keeping accounting records and responding to lawful requests. Lawful basis: legal obligation.

Where we rely on consent (for example device notifications or any optional communications), you can withdraw it at any time without affecting processing that already took place.

5. Children’s data and the UK Children’s Code

Scholarised is used by children, so we follow the principles of the UK Children’s Code (the Age Appropriate Design Code). In practice this means:

  • The best interests of the child come first when we design features and decide how data is used.
  • High privacy by default - child accounts are set to the most protective settings, and we never make a child’s data or profile public.
  • Data minimisation - we collect only what a child account needs in order to learn and be kept safe, and no more.
  • A learner under 16 does not register alone. A parent opens the account, holds the billing and oversees it, and a child login can never reach a payment screen.
  • In a group session other participants only ever see a first name and a surname initial. There is no profile to click through to, and no contact details are shared.
  • No profiling of children for marketing, and no advertising based on anyone’s behaviour.
  • We do not use nudge techniques to encourage children to weaken their privacy or share more data.
  • Clear, age-appropriate information so young people can understand how their data is used.

If you believe a child has given us data without the involvement of a parent or guardian, contact us and we will take appropriate steps, including deleting it where required.

6. What a parent can and cannot see

A parent managing a linked child account is given the oversight they need to be responsible for it, and no more than that:

  • A parent can see the child’s name and account details, the sessions and seats they have booked, attended or cancelled, the credits spent on them, and the shared family balance.
  • A parent can set an optional monthly credit limit for that child, and can see and answer any request the child sends asking for more credits.
  • A parent cannot read the child’s conversations with the study assistant, and cannot read a mentor’s private notes about a session.
  • A parent can ask us to correct or delete their child’s data, and can close the child’s account.

Where a child is old enough to understand their own rights, we will take their views into account before acting on a request made on their behalf.

7. Who we share data with

We do not sell your personal data. We share it only where needed to run the service:

  • Mentors and learners - the limited information needed to arrange and deliver a booked session. A mentor sees the name of the learner they are teaching and any note left at booking. Other participants in a group session see only a first name and a surname initial.
  • A parent - as described in section 6.
  • Stripe - our payments provider, to take payment for credits and to pay mentors.
  • Our email provider - to send the service emails described in section 4.
  • Your browser’s notification service - where you allow device notifications, the message is delivered through the push service operated by your browser vendor. The content is encrypted so that only your device can read it.
  • Cloud hosting and file storage - the services that run the platform and store uploads such as profile photos, acting on our instructions.
  • The provider that powers the study assistant - your messages are sent to it in order to generate a reply. See section 10.
  • A background-screening provider - for mentors only, where we arrange a DBS check rather than verifying a certificate the mentor already holds.
  • Our professional advisers - accountants and lawyers, where they need it and under a duty of confidence.
  • Authorities - where we are legally required to, or where it is necessary to protect a child or investigate a safeguarding concern.

Our providers act as our processors under contracts that require them to protect your data and use it only for the services they provide to us. Stripe also acts as a controller in its own right for payment data, under its own privacy notice.

8. Calendar subscription links

You can subscribe your own calendar app to your Scholarised sessions. To make that work we generate a private link containing a secret token. Anyone holding that link can read your session times, titles and the name of the other person, without signing in, because that is how calendar subscriptions work in every calendar app.

  • The link is only created if you ask for it, and only ever shown to you.
  • Treat it like a password: do not share or publish it, and do not add it to a calendar other people can read.
  • You can replace it at any time from your settings, which stops the old link working immediately.
  • The feed is read-only. Your calendar app cannot change anything on the platform.
  • When you add the link to Google, Apple or Outlook, that provider will hold a copy of the entries in your calendar under its own privacy terms.

9. Notifications and device messages

You control which notifications you receive, and how, in your account settings. A small number of messages are essential to the service and continue while you hold an account, for example a payment confirmation or notice that a session has been cancelled.

If you allow notifications on a device, we store the technical details needed to reach it. We delete a device’s details when you turn notifications off, when the browser tells us the subscription is no longer valid, or after repeated delivery failures.

10. The study assistant

The platform includes an assistant that answers questions about using Scholarised and about studying. What you type, and the instructions we give it, are sent to the artificial-intelligence provider that generates the reply. Your conversations are stored on your account so you can return to them, and you can delete a conversation.

  • Please do not type sensitive personal details, or anyone else’s personal details, into the assistant. It does not need them.
  • The assistant is scoped to the role you hold, so it cannot look up another person’s account.
  • Nothing the assistant says is a decision about you. See section 16.
  • If you have a safeguarding concern, do not raise it with the assistant. Use the contact route in section 18 so a person sees it.

11. International transfers

Some of our providers process data outside the UK. Where they do, we rely on safeguards recognised under UK data protection law, such as UK adequacy regulations or the International Data Transfer Agreement, so your data keeps an equivalent level of protection.

We intend to offer the service to learners outside the UK in future, including in the United Arab Emirates. If we do, Scholarised would remain the controller of your data and would continue to apply UK data protection standards to it. We will update this policy before anything about that changes in practice.

12. How long we keep data

We keep personal data only as long as we need it, then delete or anonymise it. In practice:

  • Account and profile data - while your account is active, and for a short period afterwards so an account can be restored if it was closed by mistake.
  • Credit and payment records - for as long as tax and accounting law requires, normally six full financial years. Because credits are valid for four years, a wallet history is kept at least that long so a balance can always be explained.
  • Session and learning records - while your account is active, so you keep your history, progress and certificates.
  • Mentor verification and background-check data - only as long as needed to show a mentor was cleared, and reviewed regularly. Certificate evidence is not kept longer than we need it.
  • Safeguarding records - for as long as is appropriate to protect children, which can be considerably longer than other records, and longer where a concern has been flagged.
  • Notifications and device subscriptions - notifications are cleared periodically; device details are deleted as described in section 9.
  • Administrative logs - kept as a permanent record of decisions taken on accounts, because their whole purpose is accountability.
  • Study assistant conversations - until you delete them or your account closes.

When session recordings go live we will keep a recording until the student’s stated exam date plus 90 days, with an absolute maximum of 48 months from the recording, and a shorter default where no exam date has been given. That rule is published here in advance so it is clear before anything is recorded, and we will confirm it and ask for consent before the first recorded session.

Where you ask us to delete your account we do so, unless we must keep certain records by law or to protect a child.

13. Cookies, local storage and the installable app

We use only the cookies and local storage needed to make the platform work - for example to keep you signed in and to remember basic preferences such as light or dark appearance. We do not use advertising or cross-site tracking cookies, and there is no advertising on the platform.

Scholarised can be installed on a phone or computer like an app. When you install it, a small background component is stored on your device so it can show an offline message and load faster. It stores only files needed to display the app, never your account data or your sessions, and removing the installed app removes it.

You can control cookies and site storage through your browser settings, though the service will not work properly without the essential ones.

14. How we protect your data

We use appropriate technical and organisational measures to protect personal data, including hashing of passwords, encryption in transit, role-based access controls so staff and mentors only reach what they need, private links for uploaded files, and an audit trail of significant administrative actions. Sensitive mentor verification data is handled separately and seen by as few people as possible.

No online service can be completely secure, but we work to protect your information and to respond quickly to any issue. If a data breach is likely to be a risk to you, we will notify you and the Information Commissioner’s Office (ICO) as the law requires.

15. Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to how we use your data;
  • receive certain data in a portable format;
  • withdraw consent where we relied on it;
  • object to processing we carry out on the basis of our legitimate interests.

To exercise any of these, contact us at [email protected]. We will respond within the time limits set by law, normally one month. There is normally no charge. We may ask you to confirm who you are before we act.

Children have the same rights as adults. For a younger child a parent or guardian usually exercises these rights on their behalf; an older child may exercise their own rights where they are able to understand them.

16. Automated decisions, profiling and marketing

We do not make decisions that have a legal or similarly significant effect on you using automated processing alone. Mentor approvals, background-check outcomes, account suspensions and refund decisions are all made or confirmed by a person.

The study assistant generates text. It does not decide anything about your account, your money or your access to the service. We do not profile children for marketing, and we do not run behavioural advertising for anyone.

17. Changes to this policy

We may update this policy from time to time. If we make a significant change we will take reasonable steps to tell you, for example by a notice in the app or by email. The "last updated" date at the top shows when it last changed.

18. Contact us, safeguarding, and how to complain

If you have a question or concern about your data, please contact us first at [email protected], or by post at Scholarised, United Kingdom. Safeguarding concerns sent to that address reach our Designated Safeguarding Lead. If a child is in immediate danger, contact the emergency services first.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator, at ico.org.uk. We would appreciate the chance to address your concern before you approach the ICO.

Questions?

If anything here is unclear, or you want to exercise a right described on this page, contact us at [email protected].