Privacy Policy

Status: Draft v2 — pending solicitor review. This policy covers the DewBee product as it currently stands, including parent and child accounts, uploaded school documents, AI-assisted topic extraction, and paid subscriptions. It is pending review by a qualified IP / digital-services solicitor before any public launch.

Two questions are specifically referred to that review, rather than left implied:

  1. We rely on Contract (Art. 6(1)(b)) for the child's own data, on the basis that the child is the direct beneficiary of the service. The child is not themselves a party to the parent's subscription contract, and we hold that position at medium confidence.
  2. The table below is headed "Processor", but Stripe is not only our processor — its own data-processing agreement reserves an independent controller role for fraud detection and compliance screening, which we cannot instruct. We judge the row accurate for the billing we do instruct; whether the distinction needs to be drawn for readers is referred.

Last updated: 15 August 2026 Effective date: From the date you submit your email to the waitlist, accept an invite, or sign in. Data controller: Tim Houghton (founder), trading as DewBee. Contact: hello@dewbee.co.uk. ICO registration: ZC140847

What this policy covers

This policy explains what personal data we collect when you:

  • Join our waitlist via the public landing page
  • Receive an invite and create an account
  • Upload school documents so DewBee can build a revision plan
  • Invite your child, who gets their own sign-in
  • Subscribe to a paid plan

If you are the child using DewBee, there is a shorter notice written for you — see the Children's Privacy Notice. It covers the same processing in plainer language. Where the two describe the same thing, they are intended to agree; if you spot a difference, please tell us at hello@dewbee.co.uk.

What we collect, why, and the lawful basis

Waitlist

DataWhyLawful basis
Email addressIssuing invites; sending product updates if you opted inContract (Art. 6(1)(b)) for the invite; Consent (Art. 6(1)(a)) for marketing
First nameAddressing you correctly in emailContract
Marketing-consent boolean + timestampDemonstrating valid consent (optional, not required)Consent
Source attributionUnderstanding where signups originateLegitimate interest (Art. 6(1)(f)) — minimal, non-tracking
Year-group (optional)Cohort segmentation for prioritised invitesLegitimate interest
Free-text "why" (optional)Understanding what brought you to DewBeeLegitimate interest

Accounts

DataWhyLawful basis
Email addressAuthenticating youContract
First nameDisplay within the appContract
Role (parent / child) and householdShowing the right person the right screens; keeping households separateContract
Password (stored hashed by our authentication provider)Signing in, where you choose a password rather than a one-time email linkContract
Whether the child has seen the AI notice, and whenShowing that notice once rather than on every visitLegal obligation / Contract
IP addressRate limiting (anti-abuse) and the security audit logLegitimate interest — security
Authentication cookiesMaintaining your signed-in sessionStrictly necessary

School documents you upload

When you add files, DewBee reads them to build the plan.

DataWhyLawful basis
The document you upload (a curriculum guide, content guide or exam timetable)Extracting subjects, exam boards, papers, topics and exam datesContract

How that works, precisely:

  • The file is sent to Anthropic (see sub-processors) so their Claude model can read it and return a structured topic list.
  • The file itself is not stored by us. It is held in memory for the length of the request and discarded. We do not keep a copy, and there is no way for us to re-read it later — if you want to add more, you upload again.
  • We do not send your child's personal data to the AI. The request contains the document and nothing else — no name, no email, no year group, no confidence ratings, no session history, no account identifier. This is enforced by an automated test that blocks release if it stops being true.
  • These documents are school-issued and generally describe a whole year group rather than an individual, but they can contain names — please have a look before uploading, and avoid uploading anything you would not want processed.

Your plan

DataWhyLawful basis
Subjects, exam boards, papers, tiers, topicsBuilding and displaying the revision planContract
Recommended revision resources named in your documentShowing where to reviseContract
Exam datesScheduling backwards from the examContract
Confidence ratings per subjectPrioritising weaker subjectsContract
Scheduled sessions and whether they were completedShowing today's plan and progressContract
Capacity settings (days per week, session length)Fitting the plan around your familyContract

Payment

DataWhyLawful basis
Subscription status, billing period end, and the identifiers Stripe gives us for your customer and subscriptionKnowing whether your access is activeContract
Access codes, where you were given oneGranting free or comped accessContract

We never see or store your card details. Payment is handled entirely by Stripe; card data goes to Stripe directly and does not pass through DewBee.

We do not collect

  • Special-category data (health, religion, biometric, etc.).
  • Advertising or cross-site tracking identifiers.

Is giving us this data required?

(UK GDPR Art. 13(2)(e))

  • Joining the waitlist: your email and first name are required — we cannot send you an invite without them. Year group, the free-text "why", and marketing consent are all optional, and leaving them blank does not affect your place.
  • Holding an account: your email is required to sign in. There is no statutory obligation to give us any of it — it is a contractual necessity, and the consequence of not providing it is simply that we cannot provide the service.
  • Uploading a document: entirely optional. Without one, DewBee cannot build a plan, but nothing else about your account changes.

Where your child's data came from

(UK GDPR Art. 14(1)(f) and 14(2)(f) — data not collected from the child directly)

If you are the child using DewBee: we did not get your email address and first name from you. Your parent or guardian gave them to us when they invited you, from their own account. Everything else we hold about you — your confidence ratings, which sessions you have marked done, and whether you have seen the AI notice — comes from you, as you use the app.

Your subjects, topics and exam dates come from the document your parent uploaded, which came from your school.

Children's data

DewBee is designed to be used by a child, with an account of their own, created by their parent or guardian. We process a child's email address, first name, and the revision data listed above.

  • A parent or guardian creates the child's account by inviting them; we do not accept direct signups from children.
  • No data from the child's account is ever sent to the AI — with the one caveat set out above: the uploaded document goes as-is, so if the school printed a name on it, that goes too.
  • The child has their own rights over their data and does not need a parent's permission to exercise them — see the Children's Privacy Notice.
  • We have completed a Data Protection Impact Assessment covering the ICO's Age Appropriate Design Code (Children's Code).

Marketing emails

  • Transactional (everyone): your invite, account emails such as a child's invitation, and service notices. Lawful basis: contract.
  • Marketing broadcasts (only if you ticked the optional consent box): early-access news, revision tips, product updates. Lawful basis: consent. Withdraw any time via unsubscribe or by emailing us.

Sub-processors

ProcessorWhat they doWhere data is processedTransfer mechanism
Supabase Inc.Database + authenticationEU / FrankfurtProcessed in the EU
Vercel Inc.Application hostingEU / FrankfurtProcessed in the EU
Anthropic PBCAI extraction — receives the school documents you uploadUnited StatesSCCs + UK IDTA addendum
StripePayments and subscription billingUnited StatesUK–US Data Bridge (UK extension to the EU–US Data Privacy Framework) + SCCs / UK IDTA
ResendSending account and invite emailsEmails are sent from Ireland, but Resend is a US company and its platform (dashboard, database, logs, support) is in the United StatesUK–US Data Bridge / DPF + UK extension, and SCCs / UK IDTA
KitMarketing email broadcasts (only with your consent)United StatesUK–US Data Bridge / DPF + UK extension
Upstash Inc.Redis-backed rate limitingEU / Frankfurt where availableProcessed in the EU
Google (Google Analytics 4)Website analytics. If you choose "Essential only" we set no analytics cookies and nothing follows you between visits — but the Google Analytics script still loads and sends Google a basic, cookieless page view (your IP address, browser, and the page address). Accepting analytics cookies enables the full measurementUnited StatesUK–US Data Bridge / DPF + UK extension

Vercel Web Analytics also runs on the marketing site; it is cookieless, stores no identifier on your device, and collects only aggregate traffic shape. See the Cookie Policy for the full cookie inventory, the consent posture, and how GA4 is configured.

On Anthropic specifically, because it is the one that receives your uploaded documents:

  • Your documents are not used to train Anthropic's models.
  • Anthropic retains API content for up to around 30 days for trust-and-safety purposes, then deletes it. This is their standard tier, and it is a deliberate decision on our part: it is defensible precisely because no child personal data is included in what we send. If we ever change what we send, we will move to a zero-retention arrangement first and update this policy.

How long we keep it

DataRetention
Waitlist recordUntil you ask us to delete it, or 24 months after your last interaction
Account, household, plan, topics, exam dates, confidence ratings, session historyFor as long as the subscription is active, plus 30 days after it ends
Uploaded documentsNot retained by us. Held in memory for the request only. Up to ~30 days at Anthropic (above)
Payment recordsSubscription status for the life of the account; Stripe holds transaction records under its own retention and UK tax law
Authentication session cookies7 days from last sign-in
Audit log (administrative and account actions)12 months
Rate-limit data< 60 seconds per request
Marketing list (Kit)Until you unsubscribe, or 24 months after last engagement

Your rights under UK GDPR

You have the right to: Access, Rectification, Erasure, Restriction, Portability, Object to processing, and Withdraw consent.

Rights requests are currently handled manually — there is no self-service account-deletion screen in the product yet. Email hello@dewbee.co.uk (subject "DSAR" or "Erasure") and we will respond within 30 days. A child may make a request directly and does not need their parent's permission.

You can also complain to the UK Information Commissioner's Office (ICO): ico.org.uk / 0303 123 1113.

How we secure your data

  • All connections use HTTPS / TLS 1.2+
  • You can sign in either with a one-time email link or with a password. Passwords are stored hashed by our authentication provider (Supabase); we never see or store them in plain text
  • Session cookies are httpOnly + Secure + SameSite=Lax
  • Database access is governed by Postgres Row-Level Security, so one household cannot read another's data
  • Service-role keys are scoped to server-side code only
  • Rate limits are enforced on every public POST endpoint and on uploads
  • Application and database are hosted in the EU / Frankfurt; the exceptions are the sub-processors named above
  • An audit log records administrative and account actions with the actor's IP
  • An automated, release-blocking test asserts that no child personal data can reach the AI

Cookies

See our Cookie Policy for the full inventory and consent posture.

Changes to this policy

We will email you about any material change. Material changes affecting lawful basis or sub-processors will be notified at least 14 days before they take effect.

Contact


Disclaimer

This Privacy Policy is a draft prepared by the founder. It has not yet been reviewed by qualified legal counsel. Before any public launch, this policy must be reviewed and updated by a qualified IP / digital-services solicitor familiar with UK GDPR, the ICO Children's Code, PECR, and UGC platform safe-harbour. It is not legal advice; it is a working draft.

← Back to home