1. Who is responsible for your data
Utricle is the controller of the personal data described here.
The registered name and address of the operating entity are not yet published on this site; where a formal request requires them, ask through our contact form and we will give them to you in writing.
Everything below is written to be true of the system as it is actually built, not of a system we might build. Where a practice is planned but not yet live, it says so.
2. What we collect
Account information
- Your email address — the identifier for the account, and how we reach you.
- Your name, if you choose to give one. It is optional and used only to address you.
- Your password, stored only as a one-way bcrypt hash. We cannot read it, recover it, or tell you what it is.
- Your two-factor secret, if you enable 2FA, stored encrypted at rest.
- Your role, and which products you hold access to.
Study data
- Test sessions, the answers you gave, and how long you spent on each question.
- Flashcard reviews and their scheduling state.
- Notes and highlights you create.
- Marks, flags, and session settings.
This is the data that makes the product work. It powers your analytics and your percentiles. We also use it in aggregate — never attributed to you — to find questions that are ambiguous or wrong, which is the single most useful quality signal we have.
Security and technical data
- Sign-in events: time, IP address, and browser user-agent. Used for account recovery, lockout, and detecting credential sharing.
- Audit entries for privileged and administrative actions.
- Server logs, which contain IP addresses and request paths.
Payment data
- The transaction hash, amount, asset, and timestamp of each on-chain payment, and the plan it bought.
- Not card numbers, bank details, wallet private keys, or seed phrases. The architecture gives us no place to put them: payment is settled on-chain and we never touch a card rail.
3. What we do not collect
- Government identifiers — no national ID, passport, or social security number.
- Phone numbers, unless you volunteer one in a support conversation.
- Location beyond the coarse country implied by an IP address in a security log.
- Microphone, camera, contacts, or anything else from your device.
- Your browsing anywhere outside Utricle. We embed no advertising pixels, no social-network trackers, and no cross-site analytics.
4. Why we are allowed to hold it
Where a lawful basis has to be named — for example under the GDPR:
- Performance of a contract
- Account data, study data, subscription and payment records. We cannot run the service you bought without them.
- Legitimate interests
- Security logs, abuse detection, and aggregated content-quality analysis. Our interest is in a platform that is not fraudulent and questions that are not wrong; the data used is the minimum that achieves it.
- Legal obligation
- Retention of payment records for tax and accounting.
- Consent
- Any optional communication you opt into. Withdrawable at any time without affecting anything else.
5. How we use it
- To run the Service — your sessions, your progress, your access.
- To send transactional email: password resets, email verification, payment confirmations, expiry reminders, security alerts, and referral rewards — if someone you invited subscribes, we email you the discount code you earned. These are not marketing and cannot be switched off while the account is open.
- To improve question quality, using anonymised, aggregated accuracy statistics.
- To prevent abuse: rate limiting, lockout after failed sign-ins, and detection of credential sharing and payment fraud.
We do not profile you for advertising, sell or rent your data, or make automated decisions with a legal effect on you. Account suspension is reviewed by a human before it becomes permanent.
One automated control does act before a human sees it, and we would rather describe it than let you meet it unannounced. If an account is used from an unusual number of distinct networks within an hour, or is served an unusual number of questions in a short time, the system pauses the starting of new tests on it for two hours. It does not suspend the account, block sign-in, touch your data, or stop your window running, and it clears itself. The thresholds and how to get one lifted are in the Acceptable Use Policy.
6. Who else sees it
Your data is shared only in these cases:
- Infrastructure providers
- Hosting, database, cache, object storage, and transactional email. They process data strictly on our instructions under a written processing agreement, and may not use it for their own purposes.
- Our crypto payment processor
- Checkout is operated by NOWPayments (nowpayments.io), which issues the deposit address, watches the chain for your transfer, tells us when it settles, and holds the funds until they are paid out to us. When you start a purchase, our server sends it four things: the amount in US dollars, the asset the payment is denominated in (we set that, not you — see the Subscription & Billing Terms), our own internal order reference for that purchase, and a one-line description of what you bought (product, plan, duration). It is not sent your name, your email address, or your IP address — your browser never contacts it, only our server does. Your paying wallet address is visible to it, as it is to anyone reading the public chain. Where it processes that data outside your own country, the safeguards in section 11 apply.
- Legal process
- Where we are compelled by a valid, binding legal demand. We satisfy ourselves that it is valid and narrow, and we notify you unless the law forbids it.
- A successor entity
- If the business is sold or merged, data transfers with it. You would be told before it happened, and the buyer would be bound by this policy or one no less protective.
We do not sell personal data, and we never have.
7. Cookies and local storage
Almost everything we set is needed to sign you in and keep the session honest, plus a small amount of local storage for preferences. There is one exception: if you arrive on an invite link carrying a ?ref= code, we store that code for 30 days so that the person who invited you is credited when you register. It records who invited you, not who you are, and it is set only once you have pressed Accept on the consent banner. If you have not answered the banner yet, or you answered no, the code is not stored at all and the credit is simply lost — the server checks your recorded answer on every request and will not write the cookie without one. One consequence is worth stating plainly: if you later subscribe, we email the person who invited you to tell them a reward has been earned and to send them their discount code. That message says only that someone they invited subscribed — it never names you, your address, or what you bought. There are no advertising or cross-site analytics cookies at all. The complete inventory, with names and lifetimes, is in the Cookie Policy.
8. How long we keep it
- Active accounts
- For as long as the account exists.
- Deleted accounts
- Removed within 30 days of deletion, by cascade through the database. Backups age out on their own cycle, which does not exceed 30 further days. Two categories deliberately survive deletion — payment records and audit entries — and both are described below.
- Study data after a window expires
- Held for 7 days after the window ends, then permanently deleted for that product: tests and the answers in them, per-question history, notes, highlights, flashcards, and assessment attempts. An internal archive is kept for a further 30 days as an operational safeguard and is then destroyed as well. One exception, in the direction of keeping your work rather than losing it: where we have cancelled a window administratively — correcting a duplicate or mis-issued purchase, for instance — the automatic deletion does not run on it, and the study data stays until a member of staff deletes it deliberately or you delete your account. We would rather over-retain than destroy months of your work because somebody tidied a billing record. The full rule is in the Subscription & Billing Terms.
- Sign-in, security and audit entries
- Kept indefinitely. Successful sign-ins, failed sign-ins, and privileged administrative actions are all rows in one audit log — there is no separate, shorter-lived sign-in log. That log is deliberately not linked to the account record, so its rows survive the deletion of the account they describe, including an ordinary customer's own sign-in history: an account that acted and then vanished is precisely the case the log exists for. An entry holds the time, the acting account id, the email address as it was at that time, what was done, and the originating IP address. It holds nothing about your studying. There is no automatic expiry on any of it today, and we would rather say so than publish a deletion schedule that nothing enforces.
- Payment records
- Seven years, because tax and accounting law requires it. This survives account deletion — it is the one category we cannot erase on request, and it is limited to the transaction itself.
- Support correspondence
- Two years, so we have the history if you come back about the same issue.
9. Your rights
Wherever you live, you can:
- Access the data we hold about you, and get a copy in a portable format.
- Correct anything inaccurate — most of it directly in your settings.
- Delete your account and its data, from Settings → Danger zone, without asking us first.
- Object to processing based on legitimate interests, or restrict it while a dispute is resolved.
- Withdraw consent to anything you opted into.
- Complain to your national data-protection authority. We would rather you came to us first, but it is your right either way and you do not need our permission.
Requests go to our contact form. We answer within 30 days, free of charge. We will ask you to prove control of the account's email address, and nothing more.
10. Security
TLS on every connection, bcrypt password hashing, encrypted 2FA secrets, rate limiting, account lockout, single-session enforcement, and audit logging. The fuller picture, and how to report a weakness you find, is in the Security & Vulnerability Disclosure policy.
No system is perfectly secure. If a breach affects your personal data and creates a real risk to you, we will tell you and the relevant authority within the deadlines the law sets — and we will tell you what we know before we have finished the post-mortem, rather than after.
11. International transfers
Our infrastructure providers may process data in countries other than yours, including outside the EEA and the UK. Where that happens we rely on Standard Contractual Clauses or an equivalent safeguard.
12. Children
The Service is not directed at anyone under 16 and we do not knowingly collect their data. If you believe a child has given us data, tell us and we will delete it.
13. Changes
We may update this policy. Material changes are emailed to you and posted in-app before they take effect, and the “last updated” date at the top of this page moves. We do not revise a live policy and leave the date alone.
14. Contact
For any privacy question or data request, reach us at our contact form.
