01Who we are
SQEase is a SQE1 exam-preparation platform operated by Finlay Salisbury, a sole trader trading as SQEase. For the purposes of UK GDPR, Finlay Salisbury is the data controller. Address for service of documents: 2 Rodney Street, London N1, England. Data protection queries: privacy@sqease.uk.
02Data we collect
You give us directly
- Account data — name, email, password (hashed), exam date, study goals.
- Marketing data — email address (if you opt in to receive updates).
- Billing data — handled by Stripe; we receive plan, billing period, country and last-four digits.
- Study materials — documents, notes, photos and Google Drive imports you upload.
- Questions you ask Lex — what you type or dictate to our AI tutor, and the replies it gives.
- Voice recordings — only while you hold the microphone button to dictate to Lex. Audio is streamed straight from your device to our transcription provider and converted to text; it is not recorded to a file, and neither we nor the provider keep the audio. The microphone is released the moment you stop, and the app never listens in the background. See §05.
- Camera photos — only the pages you choose to photograph in the mobile app to turn handwritten notes into questions. They are uploaded, read once to extract text, and then deleted (§06). We never access your camera roll or take photos on our own initiative.
- Support correspondence — messages you send via email or in-app chat.
We collect automatically
- Usage data — questions answered, time per question, mode, topic scores.
- Product-analytics events — when you're signed in, we record first-party operational events (sessions, screens viewed, and features used such as exams, Lex, uploads and flashcards) to understand how the app is used and improve it. This is processed in our own infrastructure and is not shared with third-party advertising or analytics networks. Event records contain no study-material content.
- Device data — browser, OS, screen size, IP address (truncated).
- Cookies — see our Cookie Policy.
03Why we use it
We use your data to provide the platform, bill you, personalise difficulty, send service emails, and improve AI quality. See our full data-use table in the source policy.
04Legal basis
- Contract — to provide the service.
- Legitimate interests — security, fraud prevention, quality improvement.
- Consent — marketing emails and non-essential cookies.
- Legal obligation — tax, accounting, lawful disclosure.
05Who we share it with
We never sell your personal data. We share it only with vetted processors:
| Processor | Purpose | Location |
|---|---|---|
| Stripe | Payments & billing | Ireland / US (SCCs) |
| Firebase / Google Cloud | Hosting, auth, database | EU / UK |
| Google AI (Gemini) | Question generation | EU / US (SCCs) |
| Anthropic | Question critique & tutoring | US (SCCs) |
| OpenAI | Specific generation tasks | US (SCCs) |
| Deepgram | Speech-to-text for Lex voice input | US (SCCs) |
| Tavily | Web search when Lex verifies a point of law | US (SCCs) |
| Resend | Service & marketing email delivery | US (SCCs) |
Two of these behave differently from the rest, and it matters.
- Deepgram receives your voice directly from your device, not through our servers — dictation streams from your browser or phone straight to Deepgram, using a short-lived access token our server issues for that one session. Our servers never receive the audio; we receive only the resulting text and a count of seconds used for billing. Deepgram processes the audio to return the transcript and does not use it to train its models.
- Tavily receives a search query, not your identity. When you ask Lex to check something against live sources, we send a search phrase derived from your question. We do not send your name, email or account identifier with it.
If you choose Google Sign-In, or import study material with the Google Drive picker, Google tells us only what you consent to share at that moment.
06AI & our knowledge base
When you upload a document, our pipeline extracts legal topics and principles — not your document content. We do not use your personal data or uploaded documents directly to train AI models.
Your files are processed transiently, then deleted. On the website, documents are converted to text in your browser and only that text is sent to us. In the mobile app, where in-browser conversion isn't possible, the file itself is uploaded and converted to text on our servers — and the original file is deleted straight away, before any processing begins. From there both work identically: we extract a generic legal syllabus, strip out personal or sensitive detail, and delete the text once processing finishes. The one exception is a document you have only partly used: if it covers topics you haven't generated questions from yet, we keep its text so you can come back for the rest without re-uploading. That is capped at 30 days, and it ends sooner if you generate from every topic or delete the document — whichever comes first. We never keep your original files. What we retain is only what we generate from them — the list of legal topics, the practice questions, and any flashcards.
Instead, the extracted topics prompt us to conduct independent legal research. This resulting research populates our cautious, in-house knowledge base. We then use this knowledge base to fine-tune our own AI models, hosted securely on Google Cloud. Foundation-model providers operate under strict contractual undertakings that your input is never used to train their public models.
07Optional profile details
We may prompt you for optional information about your study method, funding method, workplace, training contract provision, education provider, intended area of law, and similar professional details. These answers are stored on your account profile, where you can view, edit or remove them at any time, and we use them only to personalise your experience.
We do not sell this information, and we do not share it with third parties except the processors listed in §05 where needed to run the platform. Providing it is entirely optional.
08How long we keep it
- Account data — active + 30 days after deletion.
- Study materials — until you delete them.
- Uploaded files & photos — deleted as soon as the text is extracted; the extracted text is deleted once processing finishes, or after at most 30 days for a document you have only partly used (§06).
- Voice recordings — never stored. Audio is transcribed as it streams and is not written to disk by us or by our transcription provider.
- Lex conversations — held on your device for the session and not stored on our servers. If you report a reply to us, that reply and the message that prompted it are kept for review.
- Billing records — 6 years (HMRC).
- Usage logs — 13 months identifiable, then aggregated.
09International transfers
Where data leaves the UK we rely on the UK Addendum to the EU SCCs, the UK-US Data Bridge, or adequacy decisions.
10Your rights
Access, rectification, erasure, restriction, portability, objection, withdraw consent, and automated-decision rights. Use our DSAR form or email privacy@sqease.uk.
11Security
TLS 1.3 in transit, AES-256 at rest, bcrypt passwords, least-privilege access. Full detail on our Security page.
12Changes to this policy
Material changes notified 14 days in advance by email and in-app.
13Contact & complaints
If you're unhappy, complain to the ICO at ico.org.uk.