Legal
Privacy Policy
Last updated: 24 May 2026
The short version
We collect the minimum we need to run the Service: your email address, the answers you submit for AI marking, and feedback ratings you leave on solutions. We share data with a few processors — our payment provider (Creem) for billing, our AI model providers (for marking and solutions), and Cloudflare (hosting) — and nobody else. We do not sell your data. You can delete your account and have your data erased at any time.
1. Who we are
The data controller is the operator of prepare.xtremepape.rs. For questions about this policy, or to exercise any of your rights described below, contact [email protected].
2. What we collect
Account data: your email address, account-creation timestamp, and (if you choose to provide it) a display name.
Usage data: the answers you submit for AI marking; the questions you view; ratings and notes you leave on worked solutions; timestamps and basic event logs.
Uploaded working (photos): if you choose to upload a photo of your handwritten working instead of typing it, we send that image to the AI marker and keep a private copy so we can review and improve marking quality. These images are never shown publicly — only our team can access them — and are automatically deleted on a rolling basis as storage fills. You can avoid this entirely by typing your answer instead of uploading a photo.
Billing data: if you buy a plan, our payment provider — Creem, acting as Merchant of Record — collects payment details. We receive only the information needed to recognise the purchase (e.g. plan, order ID, billing country) — never your card number.
Technical data: IP address, browser user-agent, and approximate region. Used for security, fraud prevention, and basic aggregate analytics.
What we don’t collect: we do not run third-party advertising trackers, social-media pixels, or behavioural-ad networks. We do not collect biometric data, precise geolocation, or any “special category” personal data.
3. How we use it
We process your personal data only to:
- Deliver the Service — authenticate you, store your progress, send your answers to the AI marker, return the graded result;
- Bill you — via our payment provider (Creem);
- Improve the Service — review aggregate, often anonymised, statistics on which solutions are flagged as wrong so we can re-generate them with a better model;
- Detect abuse — rate-limit scrapers, flag account sharing, prevent fraud;
- Communicate with you — send transactional emails (sign-in links, billing receipts), and occasional product updates you can opt out of.
4. Legal basis (for users in the UK / EU)
If you are in the UK or the European Economic Area, we rely on:
- Contract — to deliver the Service you signed up for;
- Legitimate interests — to secure the Service, prevent abuse, and improve product quality;
- Consent — for any optional marketing emails (you can withdraw consent at any time).
5. Who we share it with
We share personal data only with the following service providers (“processors”), each bound by a data processing agreement:
- Creem (creem.io) — our Merchant of Record for international card payments. Creem is the seller of record for those transactions: it processes card data and handles billing, invoicing, and any applicable sales tax / VAT. See Creem’s terms and policies.
- AI model providers — we send questions and your submitted answers (including photos of handwritten working you choose to upload) to third-party AI APIs for AI marking and worked-solution generation. We use commercial API tiers under data-processing terms that do not permit the provider to train its models on our requests. We may change or add AI providers as the Service evolves; any provider we use processes this data under equivalent protections.
- Cloudflare, Inc. — hosting, edge networking, database (D1), object storage (R2), email delivery. See Cloudflare’s Privacy Policy.
We do not sell, rent, or otherwise commercialise your personal data. We may disclose data if compelled by lawful court order or valid legal process — and only the minimum strictly required.
6. Where your data is stored
Cloudflare D1 and R2 store data on Cloudflare’s global edge network, which may include facilities in the United States, the European Union, the United Kingdom, and the Asia-Pacific region. For users in the UK and EEA, transfers are protected by the UK’s International Data Transfer Addendum / Standard Contractual Clauses as adopted by our processors.
7. How long we keep it
Account data: as long as your account is active, and for up to 90 days after you delete it (to handle billing disputes and abuse).
Submitted answers and feedback: as long as the associated account exists. You can delete individual submissions at any time.
Billing records: retained by our payment provider (Creem) and by us for the period required by applicable tax and accounting law (typically 6 years).
Server logs and security events: 30 days, then deleted or fully anonymised.
8. Your rights
Regardless of where you live, you can ask us to:
- Access a copy of the personal data we hold about you;
- Correct data that’s wrong;
- Delete your account and have associated personal data erased (we’ll keep only what we’re legally required to retain);
- Export your data in a portable, machine-readable format;
- Object to processing based on legitimate interests, or withdraw consent for marketing.
Email [email protected] from the address on your account. We respond within 30 days.
If you are in the UK or EEA and believe we have mishandled your data, you also have the right to complain to your local data protection authority (in the UK, the Information Commissioner’s Office, ico.org.uk).
9. Cookies and similar technologies
We use a small number of strictly necessary cookies — primarily your session token, which keeps you logged in. We do not use third-party advertising cookies. We may use first-party, privacy-respecting analytics (no personal identifiers, no cross-site tracking).
10. Children
The Service is intended for examination candidates aged 13 and older. If you are under the age of digital consent in your jurisdiction (typically 13–16), you may only use the Service with the involvement of a parent or guardian. If we learn that we have collected data from a child below the applicable age without verifiable parental consent, we will delete it promptly.
11. Security
We use industry-standard safeguards — TLS in transit, encrypted storage at rest, hashed credentials, scoped access keys, and principle-of-least-privilege access for the team. No system is perfectly secure; if we ever discover a breach affecting your personal data, we will notify you and applicable authorities within the timelines required by law.
12. Changes to this policy
If we make material changes, we will email registered users and update the “Last updated” date at the top of this page. Continued use of the Service after the change constitutes acceptance.
13. Contact
Email [email protected] for anything privacy-related.