Privacy policy
Last updated 7 October 2026
Markwise helps GCSE and A-level students practise past papers and get them marked. Most of our students are 13 to 18, so we keep what we collect to the minimum the app needs, we never sell it, and we never show you adverts. This page explains what we keep, why, and how to get it deleted.
Who we are
Markwise is run from the United Kingdom and is responsible for your data under UK data protection law (the UK GDPR). You can reach us through the support page.
Markwise is operated in the United Kingdom. Contact: alfieinka14@gmail.com.
What we collect
- Your account: your email address, sign-in provider and account identifier. If you use a password, Supabase stores a password hash rather than readable text. Google sign-in shares basic account details with us; it does not give us access to your Gmail inbox.
- Your profile: your first name, username, profile picture, age (we store your birth year), school, GCSE or A-level, your subjects, exam boards, tiers, target grades and exam date.
- Friends: who you follow and who follows you, and challenges you send or receive.
- Coins: your coin balance, what you earned and spent them on, and anything you bought with them.
- Your marked papers: which paper you marked, the marks and grade for each question, the feedback, and the topics you dropped marks on.
- Revision: your generated lessons, review dates, self-assessments, reflections and AI credit usage. Recall answers typed in a lesson stay in your browser and are not saved or sent for AI marking.
- Billing: Stripe customer and subscription identifiers and subscription status when you subscribe. Card details go directly to Stripe, not Markwise.
- Your study days: the dates you opened or marked a paper or completed a revision review, for your streak.
- Abuse prevention: a random browser identifier, keyed hashes of account and network identifiers, request timing and AI usage. We use these to stop repeated free allowances and automated requests; we do not store raw IP addresses in these security records.
- Support messages you send us, with the email address you give.
The photos, files and text you send for marking are passed to the AI model to mark that paper, and kept with your result for 30 days so you can look back at your work. Only you can see them. After 30 days they're deleted automatically; the result itself stays.
Why we use it
- To run your account and mark your papers: this is the service you signed up for.
- To show your streak, XP, weak topics and grades, generate lessons from selected marking feedback when you request them, and schedule your recall reviews.
- To show your username, profile picture and weekly XP on leagues and to students who look you up. Your first name and school are only shown to your friends (people you follow who follow you back). Other students never see your email, age, subjects or results.
- To check you're old enough to use Markwise, and to show your school's leaderboard and classmates you might know.
- To answer you when you contact support, and to keep the app secure.
Who else handles it
We use the services below to run Markwise. Some also process information for their own security, legal or payment purposes under their own privacy policies.
- Stripe handles subscription payments and billing. If you use Link, Stripe may ask for a phone number or verification code. Markwise does not receive your full card number or security code. Stripe’s privacy policy applies to its payment records.
- Cloudflare Turnstile verifies that AI requests are made by a person when enabled. It processes browser and network information for that security check.
- Supabase stores accounts, app data and uploaded answers. Our project is hosted in London; provider support and associated processing may occur elsewhere. See Supabase’s privacy policy.
- Vercel runs the app, and counts which pages are visited (Vercel Web Analytics) so we can see what's useful. It doesn't use cookies or record who you are, and we don't send it your results.
- AI providers receive the answers, mark schemes and selected feedback needed for marking and lessons. Cloudflare Workers AI runs gpt-oss for marking, Qwen for lessons and reading uploads. If its text service is unavailable, Groq runs gpt-oss as a backup and receives the relevant text transcriptions and feedback. Cloudflare states it does not use customer content to train models without explicit consent. Groq states that inference content is not retained by default, but may be retained for up to 30 days for reliability or suspected misuse unless zero data retention is enabled. Groq processes data in the United States. See Cloudflare’s data usage information and Groq’s data handling information. Do not upload names, contact details or other sensitive information in your answers. We do not sell student work or use it to train our own AI models.
Our legal basis
We use account, study and security information for our legitimate interests in providing a safe revision service, taking particular care with students’ interests and rights. Where you enter a valid subscription contract with us, necessary billing and service processing is also used to perform that contract. We keep records required by law to meet legal obligations. Optional study reminder emails are sent only when you enable them; you can turn them off in settings or unsubscribe.
Processing outside the UK
Hosting, payment and AI providers may process information outside the UK. Applicable provider contracts and legally recognised safeguards, such as UK adequacy regulations or approved contractual transfer safeguards, govern those transfers where required. Contact us for information about the safeguards applying to your data.
Cookies
We use cookies to keep you signed in and a signed security cookie, lasting up to 90 days, to recognise repeated AI requests from the same browser. Dark mode is saved in your browser’s local storage. We do not use advertising cookies, and our page-visit counting works without cookies.
How long we keep it
Queued submissions and temporary answer-reading checkpoints are private. Queued work expires after seven days; the daily cleanup removes expired data within eight days. They are removed when processing finishes or you cancel. Waiting does not use your AI credits.
We keep your account and results until you delete your account. Deleting it (Profile → Settings → Delete account) removes your profile, marked papers, uploaded answers, streak and league entries straight away. Security request records are kept for up to 24 hours; browser usage records and spending alerts for up to 35 days. These limited security records can remain after account deletion to prevent abuse. Support messages are kept for up to two years. Email correspondence may be kept for the same period, or longer where necessary for a legal claim or statutory record. Stripe may retain payment records independently. Provider backups may take additional time to expire after deletion.
Age
You need to be 13 or over to use Markwise. If you're under 13, please don't sign up. If we find out an account belongs to someone under 13, we'll delete it.
Your rights
You can ask for access to your data, correction, deletion, restriction or portability where applicable, and object to processing based on legitimate interests. You can delete your account yourself at any time. We normally respond to rights requests within one month and may ask for information to confirm your identity. To ask for anything else, use the support page. If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk.
Send privacy requests to alfieinka14@gmail.com. We do not make decisions about your exam entry or education eligibility. AI marks and revision suggestions are guidance for practice.
Changes
If we change this policy in a way that matters, we'll tell you in the app before it takes effect.