Privacy Notice
Last updated: 20 August 2026
1. Who we are
CCDV-F Prep is operated by Jon Wells, a sole trader. Jon Wells is the data controller for the personal data described here, meaning we decide why and how it is processed. You can reach us through the in-app feedback form.
2. What we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Email address and password hash | Creating and securing your account, sign-in, password resets | Performance of a contract |
| Display name and profile settings | Personalising the app | Performance of a contract |
| Study history: answers, scores, drill and mock exam sessions, per-domain stats | Providing adaptive practice and your dashboard | Performance of a contract |
| Explain prompts and usage counts | Generating explanations and enforcing the daily fair-use cap | Performance of a contract; legitimate interests (preventing abuse) |
| Entitlement and purchase records (pass type, dates, order reference) | Granting paid access and supporting your purchase | Performance of a contract; legal obligation (records) |
| Feedback you submit | Fixing issues and improving the product | Legitimate interests |
| Technical data: IP address, device and browser information, log and error data | Security, fraud prevention, diagnosing faults, service improvement | Legitimate interests |
You may use drills and the reference as a guest without an account; guest activity is not saved to your profile.
3. Who we share it with
- Service providers / subprocessors — hosting and database infrastructure, email delivery, and error logging, acting on our instructions.
- Anthropic — the AI provider that generates Explain responses. Your prompt (the question or topic) is sent to generate the explanation.
- Paddle.com — our Merchant of Record for the sale of passes, payments, tax compliance, invoicing, and refunds. Paddle collects your payment details directly under its own privacy notice; we never see your card number.
- Professional advisers — legal and accounting advisers where necessary.
- Authorities — where required by law or to protect our legal rights.
We do not sell your personal data.
4. International transfers
Our providers may process data in the United States and other countries. Where data leaves the UK or EEA, transfers rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.
5. Retention
We keep account and study data for as long as your account is active, and delete or anonymise it within 90 days of account deletion. Purchase and tax records are kept for as long as the law requires (typically 6–7 years). Technical logs are kept for up to 12 months. Feedback is retained in anonymised or pseudonymised form for product analysis.
6. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent where processing is based on consent. UK/EEA users may also complain to their supervisory authority. Contact us through the feedback form and we will respond within one month.
7. Security
We use appropriate technical and organisational measures, including encryption in transit, hashed passwords, row-level access controls on the database, and server-side enforcement of paid features. API keys are stored as encrypted server secrets and are never exposed to the browser. No system is perfectly secure, but we work to protect your data and will notify you of a breach where the law requires.
8. Cookies and local storage
We use strictly necessary cookies and browser storage to keep you signed in and to remember interface preferences. Paddle sets cookies needed to complete checkout. We do not run advertising or cross-site tracking cookies. You can clear or block storage in your browser settings, though sign-in will stop working.
9. Changes
We may update this notice; the date above shows the latest version. See also our Terms & Conditions and Refund Policy.