Privacy

How we look after your data.

This notice explains what The Bearded Tutor collects, why, and what your rights are. It covers the UCAT practice platform, website enquiries and purchases from the resource shop. It is written for students, parents and resource buyers — if anything is unclear, email Martin and ask.

Last updated: 9 August 2026

Who is responsible for your data

The website, practice platform and resource shop are run by Martin Hill, trading as The Bearded Tutor. Martin is the sole tutor and the person responsible for your data — there is no separate company or team behind this site.

If you have any question about your data, or want to use any of the rights below, email martin@thebeardedtutor.com. That is the fastest way to reach Martin directly.

Access to your account

The UCAT practice platform is invite-only. Martin sends students an invitation to the email address he already has as their tutor; accepting it creates the student account. Signing up for student practice without an invitation is switched off.

Teachers can create or access a resource account from the resource shop. A buyer-only account provides access to its private purchase library and downloads; it does not provide access to UCAT student practice.

What we collect

We keep this as small as we reasonably can. This section itemises the practice data stored about a student — the platform records a fair amount about how you think and work through a question, so we want to say that plainly rather than bury it in vague language.

Your account

  • Your name.
  • Your email address (used to send you a one-time login link — see “How you sign in” below).
  • Your target exam date, if you choose to set one — this is optional and only used to show you a countdown.
  • Your account role (student, resource buyer, tutor or administrator) and the date your account was created.

How you sign in

There is no password to remember or store. You sign in with a one-time “magic link” emailed to you, which Supabase (our authentication provider — see below) issues and verifies. We don’t hold a password for you because one is never created.

Every question you answer

For every practice question you attempt, we record:

  • The answer you gave.
  • How long elapsed between our server sending the question and receiving your answer. We use the start time recorded by our server rather than trusting a duration sent by your device.
  • How confident you said you felt about your answer (not confident / fairly confident / very confident) — you’re asked this after every question.
  • If you got it wrong, the reason you tell us yourself — we ask you to tag your own mistake as one of: misread the question, misread the data, a gap in understanding, a calculation slip, running out of time, falling for a trap answer, changing your answer, guessing, or “other”.
  • Whether the answer was marked correct, and your score.
  • The date and time you answered, and which practice session and topic the question belonged to.
  • Automatic flags the system may add to an attempt — for example, if you answered implausibly quickly, or if you said you were very confident but got it wrong. These help Martin spot patterns (or technical glitches); they are not shown to you as a judgement.
  • Whether you flagged a question for your own review during the session (separate from reporting a question as wrong or unclear — see below).

Your practice sessions

We record when each practice session started and finished, what kind of session it was (for example, a general drill or one recommended for you), and which questions were served to you and when.

Drill recommendations

Based on your practice history, the platform works out which topics you’d benefit from practising more, and stores that recommendation (and whether you’ve seen, done, or dismissed it) so it can suggest useful practice next time you log in.

Question reports

If you flag a question as wrong, confusing or broken, we store the reason you give, linked to your account and to the specific attempt, so Martin can review and fix it.

What we do not collect

The UCAT practice platform does not ask for your date of birth, school, address, or any health information. A resource purchase separately requires country and billing information through Stripe, as explained below. We don’t use advertising or analytics cookies — the only cookie the platform sets is the one that keeps you logged in, which is strictly necessary for the site to work. The signed-in practice platform has no analytics at all. The cookieless page counts used on public marketing pages are explained separately below.

Why we collect it

The practice data above is used for these purposes:

  • To show you your own progress — your dashboard and progress pages are built directly from the data above, so you can see your accuracy, pace and where you’re improving.
  • To let your tutor teach you better. Martin can see your individual results — every answer, your timing, your confidence ratings and your self-tagged mistakes — so he can target sessions at what you actually need. You should not be surprised by this: it is the whole point of the platform, and it works the same way a marked homework book would, just with more detail.

We also use your practice history, in aggregate, to work out which questions are too easy, too hard, or badly worded, so the question bank keeps improving for everyone.

Who else sees it

We do not sell personal data, use it for advertising, or share it with unrelated third parties. The service providers named below receive only the data needed to do their specific jobs.

A small number of service providers process data on our behalf, strictly to make the platform work. Each only does the specific job below:

  • Supabase — hosts our database, private resource-file storage and sign-in. Practice records, enquiries and resource order records are stored in a Supabase database in Ireland (the “eu-west-1” region), inside the European Economic Area. Supabase also issues and verifies your one-time login link.
  • Vercel — hosts the website itself: it serves the pages you see and runs the platform’s server code. It also provides the limited, cookieless public-page analytics described below.
  • Google Workspace — sends the login-link emails, from Martin’s @thebeardedtutor.com address. It sees the email address a login link is sent to, for that purpose only.
  • Stripe— provides the resource-shop checkout, processes payment and helps prevent fraudulent payments. Stripe receives the buyer’s name, email address, billing address, delivery/postal address and payment-card details. The Bearded Tutor receives Stripe references, billing- and delivery-country evidence and payment status, but does not receive or store the full card number or security code. Stripe may also process information to meet its own legal and regulatory duties; see Stripe’s privacy policy.

Cookieless analytics on public marketing pages

We use Vercel Web Analytics to count visits to the public home page, resource-shop page and public product pages. This is only to understand whether people find and read those pages. We do not set analytics cookies, track you across other websites, record clicks or form interactions, and no page view is sent from login, account, checkout, private resource-library, practice, progress, session, review, student or tutor pages.

For an accepted page view, we send only the canonical page address (with any query string or fragment removed). Vercel adds standard page-view context such as the time, referring site, browser, operating system, device type and approximate location. It derives a short-lived visitor identifier from request data rather than setting a cookie; the identifier resets every day, so it cannot follow a visitor from one day to the next. We do not add a name, email address, account identifier or UCAT practice activity to analytics data, and we do not send custom analytics events. Analytics data is available to Martin in aggregate for the rolling retention period included with Vercel Pro.

A control below the footer on each measured public page lets you turn these page counts off. The choice is stored only in your browser’s local storage so it applies when you return; it is not sent to Martin or Vercel. We also honour Global Privacy Control and Do Not Track browser signals automatically. This limited audience measurement is intended to use the statistical purposes exception in UK storage-and-access rules, while still giving every visitor a simple, free way to object.

How long we keep it, and how to get it deleted

While you’re an active student, we keep your account and practice history so your progress and your tutor’s view of it stay accurate and complete.

There is no automatic deletion after a period of inactivity. We keep your account and practice history for as long as your account exists, and delete it — along with all of your practice history — as soon as your account is deleted, and not before. You are in control of when that happens: you can delete your own account, yourself, at any time, from Account in the menu at the top of the page once you’re signed in. You’ll be asked to type a confirmation first, since this cannot be undone.

You can also ask for your account and all of your practice data to be deleted at any time by emailing martin@thebeardedtutor.com. Deleting your account deletes everything that hangs off it — your practice sessions, every answer you’ve given, your drill recommendations and any question reports you’ve made are all removed together, automatically, as soon as your account is deleted. There is no separate step needed to clear each of those.

Deletion removes your account and practice history from the live platform immediately. A restricted disaster-recovery backup may retain a copy during its normal 14-day retention period. Backups are not used during normal operation and access is limited to Martin. If scheduled cleanup cannot run, an overdue snapshot is removed on the next successful backup run. If a backup ever has to be restored, completed deletion requests must be honoured before the platform is reopened to students.

Resource-order, payment-reference and cancellation-waiver records are different from practice history. They are not automatically erased with a practice account because Martin may need to retain core transaction records for tax, accounting, consumer-rights or legal-claim purposes. They are kept only for as long as those purposes require; information that no longer needs to be retained should be deleted or minimised.

Your rights

Under UK data protection law, you can ask us to:

  • Show you the personal data we hold about you.
  • Correct it, if anything is wrong or out of date — your name and target exam date can be changed yourself in your account; anything else, email Martin.
  • Delete it — see “How long we keep it” above. This right may be limited where a legal obligation requires a financial transaction record to be retained.
  • Restrict or object to how we use it.

To use any of these rights, email martin@thebeardedtutor.com. If you’re unhappy with how we’ve handled your data and we haven’t resolved it, you can complain to the UK’s data protection regulator, the Information Commissioner’s Office (ICO).

If you’re under 18

Most students using this platform are 16 to 18, and some are under 18. If you’re a parent or guardian and you have any question about what we hold on your child, or want anything changed or deleted, you’re welcome to contact Martin directly at martin@thebeardedtutor.com — you don’t need to go through your child to do this.

If you send an enquiry through the website

This section covers the “Send your enquiry” form on the main Bearded Tutor site, which anyone can use to ask about tutoring — most people who fill it in are prospective parents or students, not platform users, and some are not students at all yet.

When you submit that form, we store:

  • Your name and email address.
  • Your phone number, if you chose to give one — it’s optional.
  • What you’d like help with, if you picked a subject (or the UCAT platform) from the dropdown — also optional.
  • The message you typed.
  • The date and time you sent it.

We store this only so Martin can read and reply to your enquiry. We do not use it for marketing, we will not add you to a mailing list, and we will not contact you about anything other than the enquiry itself unless you separately agree to that — for example, by becoming a student. Only Martin can read enquiries stored on the platform. The same Supabase database and Google Workspace email account described in “Who else sees it” above are used to store your enquiry and to email Martin that it has arrived; no other service sees it.

A daily automatic sweep deletes the website’s database copy once it is more than 30 days old. The form also emails a copy to Martin’s Google Workspace account. That emailed copy is kept with his ordinary business correspondence while he deals with your enquiry. If you become a client, the relevant correspondence may be kept for longer as part of that ongoing client relationship; at that point it is no longer kept simply as an enquiry. You can email martin@thebeardedtutor.com at any time to ask what Martin holds about you or ask for it to be deleted.

If you buy a resource

The resource shop is for UK customers. Stripe collects the buyer’s name, email address, payment details, billing address and a delivery/postal address during checkout. Checkout restricts the delivery country to the United Kingdom, and the verified payment notification checks both billing and delivery countries before granting access. The Bearded Tutor’s order record stores the billing- and delivery-country evidence needed to enforce UK-only sales; the full addresses and payment-card details remain with Stripe.

For each checkout and completed order, we record:

  • The resource bought, amount paid and currency.
  • The buyer’s email address and account identifier.
  • Stripe’s checkout, customer and payment references, and whether the order is pending, paid, cancelled, rejected, fully refunded or finally reversed.
  • The billing- and delivery-country evidence used to keep checkout UK-only; Stripe also retains the full billing and delivery addresses supplied at checkout.
  • Whether and when the buyer expressly consented to immediate digital supply and acknowledged losing the 14-day cancellation right, together with the version of that wording.
  • When the order was created and last updated.

We use this information to take and reconcile payment, enforce the UK-only sales boundary, provide the purchased download to the correct buyer, handle full refunds or final payment reversals, evidence the buyer’s cancellation acknowledgement, prevent misuse and keep required business records. We do not use purchase details to add buyers to a marketing list.

Download files are held in a private Supabase Storage bucket. The permanent storage address is not public. After an authenticated buyer’s order is checked, the site issues a short-lived signed download link; possession of an expired or unsigned address does not provide access.

Core order and payment records may need to remain after download access or a practice account ends, for the tax, accounting and legal purposes explained above. You can ask what purchase data is held, correct an error, or request deletion by emailing martin@thebeardedtutor.com. Martin will delete information that is no longer needed, but may have to retain the minimum transaction record where the law requires it.

Changes to this notice

If how we handle your data changes, we’ll update this page and change the “last updated” date at the top. For anything significant, we’ll aim to let existing students know directly rather than relying on you to check back.