Privacy Policy
Status: Draft v2 — pending solicitor review. This policy covers the DewBee product as it currently stands, including parent and child accounts, uploaded school documents, AI-assisted topic extraction, and paid subscriptions. It is pending review by a qualified IP / digital-services solicitor before any public launch.
Two questions are specifically referred to that review, rather than left implied:
- We rely on Contract (Art. 6(1)(b)) for the child's own data, on the basis that the child is the direct beneficiary of the service. The child is not themselves a party to the parent's subscription contract, and we hold that position at medium confidence.
- The table below is headed "Processor", but Stripe is not only our processor — its own data-processing agreement reserves an independent controller role for fraud detection and compliance screening, which we cannot instruct. We judge the row accurate for the billing we do instruct; whether the distinction needs to be drawn for readers is referred.
Last updated: 15 August 2026 Effective date: From the date you submit your email to the waitlist, accept an invite, or sign in. Data controller: Tim Houghton (founder), trading as DewBee. Contact: hello@dewbee.co.uk. ICO registration: ZC140847
What this policy covers
This policy explains what personal data we collect when you:
- Join our waitlist via the public landing page
- Receive an invite and create an account
- Upload school documents so DewBee can build a revision plan
- Invite your child, who gets their own sign-in
- Subscribe to a paid plan
If you are the child using DewBee, there is a shorter notice written for you — see the Children's Privacy Notice. It covers the same processing in plainer language. Where the two describe the same thing, they are intended to agree; if you spot a difference, please tell us at hello@dewbee.co.uk.
What we collect, why, and the lawful basis
Waitlist
| Data | Why | Lawful basis |
|---|---|---|
| Email address | Issuing invites; sending product updates if you opted in | Contract (Art. 6(1)(b)) for the invite; Consent (Art. 6(1)(a)) for marketing |
| First name | Addressing you correctly in email | Contract |
| Marketing-consent boolean + timestamp | Demonstrating valid consent (optional, not required) | Consent |
| Source attribution | Understanding where signups originate | Legitimate interest (Art. 6(1)(f)) — minimal, non-tracking |
| Year-group (optional) | Cohort segmentation for prioritised invites | Legitimate interest |
| Free-text "why" (optional) | Understanding what brought you to DewBee | Legitimate interest |
Accounts
| Data | Why | Lawful basis |
|---|---|---|
| Email address | Authenticating you | Contract |
| First name | Display within the app | Contract |
| Role (parent / child) and household | Showing the right person the right screens; keeping households separate | Contract |
| Password (stored hashed by our authentication provider) | Signing in, where you choose a password rather than a one-time email link | Contract |
| Whether the child has seen the AI notice, and when | Showing that notice once rather than on every visit | Legal obligation / Contract |
| IP address | Rate limiting (anti-abuse) and the security audit log | Legitimate interest — security |
| Authentication cookies | Maintaining your signed-in session | Strictly necessary |
School documents you upload
When you add files, DewBee reads them to build the plan.
| Data | Why | Lawful basis |
|---|---|---|
| The document you upload (a curriculum guide, content guide or exam timetable) | Extracting subjects, exam boards, papers, topics and exam dates | Contract |
How that works, precisely:
- The file is sent to Anthropic (see sub-processors) so their Claude model can read it and return a structured topic list.
- The file itself is not stored by us. It is held in memory for the length of the request and discarded. We do not keep a copy, and there is no way for us to re-read it later — if you want to add more, you upload again.
- We do not send your child's personal data to the AI. The request contains the document and nothing else — no name, no email, no year group, no confidence ratings, no session history, no account identifier. This is enforced by an automated test that blocks release if it stops being true.
- These documents are school-issued and generally describe a whole year group rather than an individual, but they can contain names — please have a look before uploading, and avoid uploading anything you would not want processed.
Your plan
| Data | Why | Lawful basis |
|---|---|---|
| Subjects, exam boards, papers, tiers, topics | Building and displaying the revision plan | Contract |
| Recommended revision resources named in your document | Showing where to revise | Contract |
| Exam dates | Scheduling backwards from the exam | Contract |
| Confidence ratings per subject | Prioritising weaker subjects | Contract |
| Scheduled sessions and whether they were completed | Showing today's plan and progress | Contract |
| Capacity settings (days per week, session length) | Fitting the plan around your family | Contract |
Payment
| Data | Why | Lawful basis |
|---|---|---|
| Subscription status, billing period end, and the identifiers Stripe gives us for your customer and subscription | Knowing whether your access is active | Contract |
| Access codes, where you were given one | Granting free or comped access | Contract |
We never see or store your card details. Payment is handled entirely by Stripe; card data goes to Stripe directly and does not pass through DewBee.
We do not collect
- Special-category data (health, religion, biometric, etc.).
- Advertising or cross-site tracking identifiers.
Is giving us this data required?
(UK GDPR Art. 13(2)(e))
- Joining the waitlist: your email and first name are required — we cannot send you an invite without them. Year group, the free-text "why", and marketing consent are all optional, and leaving them blank does not affect your place.
- Holding an account: your email is required to sign in. There is no statutory obligation to give us any of it — it is a contractual necessity, and the consequence of not providing it is simply that we cannot provide the service.
- Uploading a document: entirely optional. Without one, DewBee cannot build a plan, but nothing else about your account changes.
Where your child's data came from
(UK GDPR Art. 14(1)(f) and 14(2)(f) — data not collected from the child directly)
If you are the child using DewBee: we did not get your email address and first name from you. Your parent or guardian gave them to us when they invited you, from their own account. Everything else we hold about you — your confidence ratings, which sessions you have marked done, and whether you have seen the AI notice — comes from you, as you use the app.
Your subjects, topics and exam dates come from the document your parent uploaded, which came from your school.
Children's data
DewBee is designed to be used by a child, with an account of their own, created by their parent or guardian. We process a child's email address, first name, and the revision data listed above.
- A parent or guardian creates the child's account by inviting them; we do not accept direct signups from children.
- No data from the child's account is ever sent to the AI — with the one caveat set out above: the uploaded document goes as-is, so if the school printed a name on it, that goes too.
- The child has their own rights over their data and does not need a parent's permission to exercise them — see the Children's Privacy Notice.
- We have completed a Data Protection Impact Assessment covering the ICO's Age Appropriate Design Code (Children's Code).
Marketing emails
- Transactional (everyone): your invite, account emails such as a child's invitation, and service notices. Lawful basis: contract.
- Marketing broadcasts (only if you ticked the optional consent box): early-access news, revision tips, product updates. Lawful basis: consent. Withdraw any time via unsubscribe or by emailing us.
Sub-processors
| Processor | What they do | Where data is processed | Transfer mechanism |
|---|---|---|---|
| Supabase Inc. | Database + authentication | EU / Frankfurt | Processed in the EU |
| Vercel Inc. | Application hosting | EU / Frankfurt | Processed in the EU |
| Anthropic PBC | AI extraction — receives the school documents you upload | United States | SCCs + UK IDTA addendum |
| Stripe | Payments and subscription billing | United States | UK–US Data Bridge (UK extension to the EU–US Data Privacy Framework) + SCCs / UK IDTA |
| Resend | Sending account and invite emails | Emails are sent from Ireland, but Resend is a US company and its platform (dashboard, database, logs, support) is in the United States | UK–US Data Bridge / DPF + UK extension, and SCCs / UK IDTA |
| Kit | Marketing email broadcasts (only with your consent) | United States | UK–US Data Bridge / DPF + UK extension |
| Upstash Inc. | Redis-backed rate limiting | EU / Frankfurt where available | Processed in the EU |
| Google (Google Analytics 4) | Website analytics. If you choose "Essential only" we set no analytics cookies and nothing follows you between visits — but the Google Analytics script still loads and sends Google a basic, cookieless page view (your IP address, browser, and the page address). Accepting analytics cookies enables the full measurement | United States | UK–US Data Bridge / DPF + UK extension |
Vercel Web Analytics also runs on the marketing site; it is cookieless, stores no identifier on your device, and collects only aggregate traffic shape. See the Cookie Policy for the full cookie inventory, the consent posture, and how GA4 is configured.
On Anthropic specifically, because it is the one that receives your uploaded documents:
- Your documents are not used to train Anthropic's models.
- Anthropic retains API content for up to around 30 days for trust-and-safety purposes, then deletes it. This is their standard tier, and it is a deliberate decision on our part: it is defensible precisely because no child personal data is included in what we send. If we ever change what we send, we will move to a zero-retention arrangement first and update this policy.
How long we keep it
| Data | Retention |
|---|---|
| Waitlist record | Until you ask us to delete it, or 24 months after your last interaction |
| Account, household, plan, topics, exam dates, confidence ratings, session history | For as long as the subscription is active, plus 30 days after it ends |
| Uploaded documents | Not retained by us. Held in memory for the request only. Up to ~30 days at Anthropic (above) |
| Payment records | Subscription status for the life of the account; Stripe holds transaction records under its own retention and UK tax law |
| Authentication session cookies | 7 days from last sign-in |
| Audit log (administrative and account actions) | 12 months |
| Rate-limit data | < 60 seconds per request |
| Marketing list (Kit) | Until you unsubscribe, or 24 months after last engagement |
Your rights under UK GDPR
You have the right to: Access, Rectification, Erasure, Restriction, Portability, Object to processing, and Withdraw consent.
Rights requests are currently handled manually — there is no self-service account-deletion screen in the product yet. Email hello@dewbee.co.uk (subject "DSAR" or "Erasure") and we will respond within 30 days. A child may make a request directly and does not need their parent's permission.
You can also complain to the UK Information Commissioner's Office (ICO): ico.org.uk / 0303 123 1113.
How we secure your data
- All connections use HTTPS / TLS 1.2+
- You can sign in either with a one-time email link or with a password. Passwords are stored hashed by our authentication provider (Supabase); we never see or store them in plain text
- Session cookies are httpOnly + Secure + SameSite=Lax
- Database access is governed by Postgres Row-Level Security, so one household cannot read another's data
- Service-role keys are scoped to server-side code only
- Rate limits are enforced on every public POST endpoint and on uploads
- Application and database are hosted in the EU / Frankfurt; the exceptions are the sub-processors named above
- An audit log records administrative and account actions with the actor's IP
- An automated, release-blocking test asserts that no child personal data can reach the AI
Cookies
See our Cookie Policy for the full inventory and consent posture.
Changes to this policy
We will email you about any material change. Material changes affecting lawful basis or sub-processors will be notified at least 14 days before they take effect.
Contact
- Privacy questions: hello@dewbee.co.uk
- DSAR / Erasure: hello@dewbee.co.uk (subject "DSAR" or "Erasure")
- ICO complaints: ico.org.uk
Disclaimer
This Privacy Policy is a draft prepared by the founder. It has not yet been reviewed by qualified legal counsel. Before any public launch, this policy must be reviewed and updated by a qualified IP / digital-services solicitor familiar with UK GDPR, the ICO Children's Code, PECR, and UGC platform safe-harbour. It is not legal advice; it is a working draft.