Skip to content

Privacy Policy

Last updated 1 October 2026

Who we are

cookie (“cookie”, “we”, “us”) is a spaced-repetition study platform that uses AI, run from the United Kingdom by Tristan Pagden, trading as cookie and Cookie Tutoring. We are the data controller for everything described here. Our address for correspondence is 4th Floor, Silverstream House, 45 Fitzroy Street, London W1T 6EB, United Kingdom. This policy explains what data we collect when you use cookie, why we collect it, and the choices you have. If anything here is unclear, email us at support@cookie.education or use our contact page.

Your cookie account is one account across our apps: it is the same sign-in on Cookie Tutoring, which shares the credit balance you buy here. This policy covers the account itself and everything you do on cookie; Cookie Tutoring has its own notice for what it stores. Our other apps, Cookie Health, Cookie Learning, Cookie Manage and Cookie Finance, are not open to anyone yet; each will have its own notice when it opens.

What we collect

  • Account information: your email address, a username, and a securely hashed password (or, if you sign in with Google, the basic profile information Google shares with us; we never see or store your Google password).
  • Content you provide: source material you paste or upload to build decks (your notes, a worksheet, a question you did in a book), the questions and answers cookie generates from it, and your own written answers, including photographs of handwritten working and of your answers to a past paper.
  • Flashcards: the flashcards you write, ask cookie to write, bring in from Anki or copy from a deck someone has shared, including any pictures and sounds in them, and how well you said you knew each card each time you studied it. You can also add pictures, sound and video to a card yourself, including a sound you record with your microphone in cookie (it is recorded in your browser and kept only as the file you add), and keep the photos you made cards from on the cards. If you ask for cards from a web page, we read the page to write them and do not keep a copy of it. If you describe what you want cards on and leave "Check the facts with a web search first" ticked, we search the web for it first: what you described goes through our AI service to OpenAI, which runs the search with its own search system and Microsoft Bing, so it may reach Microsoft as well. The pages it finds are used to write your cards, and we don't keep them. The search costs credits, which the page shows before you start.
  • The assistant: if you use the chat or the Ask box, what you ask it and its replies. It also reads, for that question only, the page you are on (never what you have typed into a box, unless you asked from inside that box), any text you highlighted, and your study record: your level and exams, your topics and how well you know them, the past papers you have done, what is due and your streak. A chat is kept only if "Save this chat" is on when it starts. You can delete any saved chat, or all of them, at any time, and they are deleted with your account. Each saved chat is deleted 12 months after its last message, and we email you a month before; if you are 18 or over you can choose to keep a chat for longer. If you tell the assistant you are unsafe or worried, it offers a button to send what you wrote to our safeguarding lead; nothing is sent unless you press it, and nothing else from the chat goes with it. If you attach a picture to a message, we keep it in your account so the assistant can put it on a card or in a note for you; it is deleted with your account.
  • Web search, in the assistant: if the assistant needs a fact that isn't in your own work, it can search the web. The search goes through our AI service to OpenAI, which runs the search and sends back the pages it found, and our service reads the first few of them. OpenAI treats it as it treats everything else we send (below), and it runs the search with its own search system and Microsoft Bing, so your search may reach Microsoft as well. We don't keep the results, and a search costs credits, which the assistant tells you.
  • Notes: the notes you write in cookie, the drawings you make there, and the documents you upload as notes (a Word document, a PDF, slides, a spreadsheet, a picture or anything else you choose), with the folders you put them in. If you ask for a markdown copy of a document, we make it on your device and keep the copy as another note. If you ask cookie to write notes for you, from a description, from your own notes or decks, from a web page, from your results in a past paper or from the text of a paper you have open, we keep the note it writes only if you choose to keep it. Your notes and the files in them are deleted when you delete them, and with your account. If you share notes, we keep the copy you shared (the text of those notes and drawings, their folders, the title, description and exam details you gave it, and your username if you chose to show it) and show it to anyone who visits cookie until you stop sharing it or delete it. We also keep who added a copy of shared notes to their own notes, and the ratings and reviews people give them.
  • Widgets: the small interactive things you can add to a note or a card, such as a graph with sliders, a step-through, a quiz or things to put in order. We keep what each one shows and where you made it. A widget on a deck you share can be seen by anyone who can see the deck. If you export a deck to Anki, its widgets go in the file with it.
  • Usage & performance data: which questions you've answered, your scores, and spaced-repetition scheduling data. This is core to how the product works rather than optional telemetry.
  • Past papers you do in cookie: if you are signed in, which past paper you did and when, how long it took you, the marks you gave each question, the grade we worked out from the exam board's published grade boundaries, and anything you wrote, typed or highlighted on the paper. For a paper that isn't in our list, such as a school mock, we also keep the name you give it, the category you put it in (with its level, exam board and subject if you choose them), any grade boundaries you type in, and the grade you give it or that we work out from your boundaries. We never keep the paper itself, its mark scheme or its examiner report. You download those from the exam board's own website and they stay on your device.
  • Grade boundaries you keep: if you keep a set of grade boundaries to use on your question decks, its name, the exam it is for, its grades and, if the AI found it, the notes and web pages it came from. You can rename or delete any of them, and they are deleted with your account.
  • Your revision plan: the exams you are working towards (the exam boards' published dates, and any you add yourself), what you asked the plan to include, when you said you can study, the grades you are aiming for, any papers or subjects you described, and the plan cookie makes from them. We keep these in your account only if you ask for a calendar link, or plan with AI.
  • Calendars you ask the plan to work around: if you add a calendar to your revision plan, the start and end of each event, whether it is all day, and its title (cut to 120 characters). A calendar file stays in your browser unless you keep it in your account. A calendar's private link is kept locked (encrypted) and never shown again; with Google Calendar you connect your account and can disconnect it at any time. We read a linked calendar again every few hours so the plan can move when it changes. Removing a calendar from the plan deletes what we kept of it.
  • Payment information: if you subscribe to Pro, payments are handled entirely by Stripe. We never see or store your card details; we only receive confirmation of your subscription status from Stripe.
  • Device & push-notification data: if you opt in to push notifications, we store the subscription token your browser gives us so we can send them. We never collect this unless you explicitly opt in.
  • What you tell us about yourself: which age group you are in, asked once when you sign up (under 13, who cannot sign up themselves; 13 to 17; or 18 and over) and shown on your account page where you can change it; and the optional onboarding survey (what you are studying, the exam board, what you are working towards, and an age band only if we do not already have your answer). Never a date of birth.
  • Messages you send us through the contact form, and technical data your browser sends when it loads a page, plus an error report if something breaks (see Sentry below).
  • Where a new account signs up from, in coded form: when a new account first signs in, we keep a one-way code made from the network it connected from (the first three parts of the IP address, never the full address) for 7 days, so we can notice lots of free accounts being made in one place. It never blocks anyone automatically; a person looks first, because a school class signing up together looks the same.
  • Where your sign-up came from: when you create an account we note the page of cookie.education your visit began on, the other website that sent you there (its name only, such as google.com), the page you were heading to when you were asked to sign up, and any campaign tag in the link you followed (such as utm_source=tiktok). Your browser already has all of this when you sign up, so we store nothing on your device to get it. We use it to learn which of our pages and which other places bring people to cookie. It is kept with your account and deleted when you delete it. We never join it to the pages Umami counts, which stay anonymous.
  • If you have a tutor on Cookie Tutoring, what that product records about your lessons is described in its own policy; what it can read of your cookie data is set out under “If you have a tutor” below.

How we use it

We use your data only to run and improve cookie:

  • Generating exam-style questions from your source material and marking your answers.
  • Scheduling what to review next, based on your performance.
  • To show you the past papers you have done, how your marks and grades change over time, the questions you dropped marks on, and which paper to try next.
  • To put each past paper question you marked under a topic, so it can come back in your practice like the questions in your decks. We keep the topic and your mark, never the question itself. A setting lets you choose whether answers you had help with count towards your mastery; it is on unless you turn it off.
  • To answer your questions in the assistant at your level, and to take you to the page you ask for. Teacher mode, which you can switch off, makes it guide you to an answer rather than give it straight away.
  • If you add your revision plan to a calendar app, the app reads it from a private link that only you have. The same calendar has your Cookie Tutoring lessons and the homework your tutors set, so you only need one link. Anyone with the link can see it, so you can replace the link with a new one at any time.
  • If you plan with AI, or ask it what to do next, cookie sends the AI your exams, how much time you have, your grades, your mastery by topic, your decks' names and topics, and anything you wrote in "anything else we should know". It never sends your calendar's events or your lessons' details, only how many minutes a week you have and how many lessons. The AI suggests how to share your time; cookie places it.
  • Processing your subscription and billing, if you're on Pro.
  • Sending you emails or push notifications you've opted into (practice reminders, streak alerts); every one of these is off by default and controllable from your account settings.
  • Responding if you contact support.

We do not sell your data, and we do not use it to serve you ads.

Why we are allowed to. Running your account, generating and marking your questions and taking payment are performance of our contract with you. Keeping the service secure, preventing abuse, fixing faults, understanding how the site is used, and keeping your corrections to find errors in our AI are our legitimate interests, which we have weighed against yours and, where you are under 18, in your favour, which is why keeping corrections is off by default unless you have told us you are 18 or over. Reminders and push notifications are consent, which you can withdraw at any time. Keeping financial records is a legal obligation. You can object to anything we do on legitimate interests.

You need to give us an email address, a username and your age group to have an account, because we cannot run one without them. Everything else we ask for is optional.

Using your corrections to improve our AI

We use your corrections to our AI’s output (telling us a mark was wrong, putting a question in a better topic, correcting something we generated) to make that AI better. We never use your uploaded source material or your notes, we never use anything from a lesson unless you have separately agreed to that, and we never use anything that identifies you. You can turn this off at any time, and turning it off does not reduce the service.

A correction means one of these, and nothing else:

  • you challenge a mark, and tell us why you think it was wrong;
  • you move a question into a different topic;
  • you tell us a topic is wrong or missing through the feedback box on the categories page;
  • if you have a tutor, your tutor corrects a mark our AI gave you, which is a real subject expert saying what the right answer was.

Your source material is never used to train anything, whether you turn the setting above on or off. That is not a default we might change: past papers, textbook scans and specifications belong to the people who wrote them, and your notes are yours.

A stored correction holds the marks (the score our AI gave and the score a person gave, criterion by criterion) and, if you wrote one, your note in your own words, kept apart from your name and email. It does not hold the AI's marking comments or model answer, because those restate a mark scheme that may belong to an exam board. Please do not put personal details in that note; it is about the mark, not about you.

You can turn this off under Helping us improve our AI in your account settings. It is on by default if you have told us you are 18 or over, and off by default otherwise, including if you have not told us your age at all. What we store is separated from your name and email, and deleting your account permanently breaks the link between the two.

Who we share it with

We use a small number of third-party services to run cookie, each processing only what they need to do their specific job:

  • Supabase hosts our database, handles authentication, and stores uploaded files.
  • Vercel hosts the application itself and processes web traffic to serve it to you.
  • OpenAI (United States) processes the source material and answers you submit to generate questions and flashcards and mark your work, through the AI service we run ourselves at ai.cookie.education. When you ask cookie to write notes, we send OpenAI what the notes are to be made from: your description, the text of the notes, deck, document or web page you chose, or your marks and the marking on a past paper, and, if you leave "Check a web search first" ticked, what you described, to search the web for it. Your notes are not otherwise sent to anyone, unless you share them: then anyone can read the copy you shared, add a copy to their own notes or download it, and pictures and uploaded documents are never part of it. When you use the assistant, we send OpenAI your question, the conversation so far, what the assistant read to answer it (the page, the text you highlighted, the box you asked from, your study record) and, when you ask about a past paper question, a picture of that question with your writing on it. We keep only the chats you chose to save. When you ask cookie to check your marking on a past paper or to explain part of one, we send OpenAI the part of the page you chose, the matching part of the mark scheme and your answer (as text, or as a picture of what you wrote). We keep the marks and the explanation, not the paper. When you ask cookie to make a widget, we send OpenAI what you asked for and the text of the card or note it is for. When you attach a picture to a message to the assistant, we send OpenAI the picture with your message. If you ask the AI to read your grade boundaries, we send OpenAI what you wrote and your deck's exam. If you ask it to find them on the web, we send OpenAI's web search (which uses Microsoft Bing) your exam board, qualification, subject, exam series and tier and anything you added, and then send OpenAI the pages it found. Nothing is kept unless you keep the grade boundaries it gives you. This is the core AI functionality of the product; without it, cookie can't do what it's for. OpenAI keeps what it receives for up to 30 days to check for abuse, then deletes it. We hold a second, dormant provider, Anthropic, for use only if OpenAI is unavailable; if we ever switch, this page will say so first. Content sent via their commercial APIs (the only way cookie uses them) is not used to train their models by default, per each provider's own API terms. That is their position. Ours: we never train any model on your source material or your notes, or on anything from a lesson unless you have separately agreed to that. We do use corrections you make to our AI’s own output, which you can turn off in your account settings.
  • Stripe processes Pro subscription payments. See Stripe's own privacy policy.
  • Google, only if you sign in with Google, which tells us your email address, your name and a link to your Google profile picture, and nothing else. Google decides for itself how it uses your sign-in, under its own privacy policy.
  • Google Calendar, only if you connect it to your revision plan. We read your calendar, never change it, and use the start and end of each event, whether it is all day, and its title (cut to 120 characters) so the plan can keep clear of them. We read it again every few hours so the plan can move when it changes. We never send your calendar's events to an AI. You can disconnect it at any time, and removing it from the plan deletes what we kept of it. cookie's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • Resend delivers transactional email (practice reminders, contact-form replies) on our behalf. Its logs of what was sent, including the address it went to, are held in the United States.
  • Sentry receives error reports (e.g. a stack trace if something breaks) so we can find and fix bugs. This can incidentally include the page you were on and, for a signed-in error, your user ID, and never your password or the content of your decks or answers.
  • Cloudflare (United States) runs the check on the sign-up page that tells people apart from automated sign-ups (Turnstile). When you open that page it receives your IP address and technical details your browser sends, such as its user agent, and uses them only to detect and block bots; it does not see what you type into the form. Cloudflare may also use those signals to improve its bot detection, which it does as a controller in its own right. See Cloudflare's Turnstile privacy addendum.
  • Umami is a privacy-respecting, cookieless analytics tool that reports aggregate usage (which pages are visited, and which buttons on them are pressed) without tracking you individually across sites or setting a tracking cookie. Its only purpose is statistics about how the site is used so we can improve it; it is shared with nobody but Umami acting for us, and you can turn it off here for this browser, free, whether or not you are signed in:

Stripe, Google and Cloudflare decide for themselves how they use what they receive for the parts described above, under their own policies. Everyone else on this list acts only on our instructions and may not use your data for their own purposes. We don't share your data with anyone else unless the law requires it (for example, the Online Safety Act requires us to report child sexual abuse material to the National Crime Agency) or we need to share it to protect someone from serious harm, for instance by telling the police.

If you have a tutor

A tutor is someone whose invitation you accepted. Nobody can connect to your account without that; accepting is the only thing that creates the link.

Once you have, a tutor can see:

  • your decks and the questions in them;
  • your flashcard decks, and how well you knew each card when you studied it;
  • the answers you wrote, including photos and whiteboard drawings you attached as working;
  • the marks and the comments the AI gave you on them;
  • your practice streak, which topics you are finding hardest, and predicted grades.

Past papers. If your tutor sets you a past paper, they can see your attempts at it from then on: the marks you gave each question, the AI's marks if you asked for them, which questions you left out, how long it took and your grade. You can also share any past paper you have done with a tutor from My papers. They then see the same things for that paper, and, only if you tick "Include what I wrote on the paper", what you wrote and typed on the question paper. They see your writing over their own copy of the paper; we never send them your file or a picture of it, because we never have either. You can stop sharing a paper at any time, and stopping sharing your work with a tutor stops all of it.

Notes. A tutor can send you notes, or set them as reading. They arrive as your own copy in your notes, in a folder named after them, with the pictures, drawings and widgets in them; sound, video and uploaded documents are not sent. The pictures count towards your storage. The copy is yours to keep and change. When you open one, your tutor can see that you have, and when you mark it as read, they can see that too.

You can choose notes or folders to share with a tutor from your notes. They can read them on Cookie Tutoring, and put one on the board in a lesson, as they are at that moment; they cannot change them or download them, and uploaded documents and pictures are never shared. You can stop at any time, and stopping sharing your work with a tutor stops this too.

If your tutor also teaches you on Cookie Tutoring, they can ask our AI to suggest a plan for your next lesson. It reads which topics you are finding hardest and your predicted grades, their own notes from recent lessons, and, if you share them, the marks on past papers you shared, how your flashcard decks are going and the start of up to three notes you shared with them. It never reads what you wrote on a paper. The plan is their preparation and is charged to their credits, not yours. If your tutor asks the assistant about you, it can read, for their question, what they can already see of yours here, and the notes and past papers you chose to share with them.

A tutor can correct a mark our AI gave you: if they think it is wrong, their mark replaces it, your progress and predicted grades are recalculated from it, and the answer is labelled “marked by your tutor” so you always know it came from a person and not the AI. That is deliberate: it means a real subject expert, not only software, can change what your predicted grade is built on. A tutor cannot spend your credits or answer anything as you. They can set you work, send you individual questions, and log work you did on paper, which is read in and marked on their credits, not yours. All of it arrives as your own copies, so if your tutor later deletes their version, yours and your answers to it stay yours.

If you want to end that, email us at support@cookie.education and we'll disconnect them. We'll do it on your say-so alone; we won't ask your tutor first.

Cookies

cookie sets two cookies. One is a session cookie from our authentication provider (Supabase) that keeps you signed in; it's strictly necessary for the app to work. The other, cookie_ref, is set only if you accept a friend's invitation before you have an account: it holds that invitation's code so it can be credited when you sign up, is cleared as soon as it has been, and lasts at most 30 days. Neither is used for tracking or advertising. We don't use any advertising or cross-site tracking cookies, so we don't show a cookie-consent banner, because there would be nothing meaningful to consent to. The app also keeps some of your own work in your browser's storage so it loads quickly and works offline; that is your data, on your device, and is not sent anywhere. On the sign-up page only, Cloudflare's Turnstile check reads technical signals from your browser to tell a person from an automated sign-up; that is strictly necessary to keep sign-up secure and is not used for tracking or advertising.

Where your data is stored

Our database is hosted in the EU (Ireland), and Umami keeps its statistics in the EU. Supabase's support staff can reach the database from the United States when they need to keep it running. OpenAI, which processes content for question generation and marking, and Vercel, Stripe, Resend, Sentry and Cloudflare, are US-based companies, and your data goes to them for the specific job each does. Where data leaves the UK it does so under the UK International Data Transfer Addendum to the EU standard contractual clauses, or under the UK Extension to the EU–US Data Privacy Framework where the provider is certified, and we have assessed the risk of those transfers. Sentry keeps the error reports themselves in the EU. You can ask us for a copy of the safeguards we rely on.

How long we keep it, and deleting your account

We keep your data for as long as your account is active. You can permanently delete your account at any time from your account settings. Deleting your account immediately and permanently removes your profile, private decks, questions, answers, the past papers you have done and what you wrote on them, and every file you've uploaded to cookie, and this can't be undone. If you have an active Pro subscription, it's cancelled automatically as part of deletion (Stripe separately retains billing records for its own legal/tax obligations, independent of what we delete).

Five things outlive the account, and this is the whole list: a record of what we were paid, kept for six years after the end of the tax year it falls in, as the tax rules require; any email you sent us, kept up to six years (longer only where it is about a child's safety, or is a record the tax rules make us keep); any report you made, or that was made about something you published, deleted three years after it was made once it has been dealt with; the corrections described above, which are kept unlinked from you and deleted after 3 years at most; and, for one month only, a one-way code made from your email address (not the address itself) with your free-credit balance, its reset dates and which tutors you had a free intro lesson with. If you make a new account with the same email address in that month, it carries on from that balance instead of starting afresh and can't have a second free intro with the same tutor; after the month the record is deleted automatically. We keep it so that deleting and re-making an account can't be used to reset free credits (our legitimate interest in preventing abuse of the free plan), and we tell you again on the delete button. The log of our AI calls (which feature, when and what it cost, never your content) goes with your account; while your account exists, each entry is unlinked from you after 13 months and deleted after 24. If you used Cookie Tutoring, deleting your account also deletes the lesson documents you uploaded there, unless one was taken down after a report, which is kept as a moderation record. The whiteboard picture from a lesson belongs to both people in it and is kept for 365 days from the lesson; the payment and safeguarding records Cookie Tutoring keeps follow the windows on its own policy. Error reports in Sentry expire after 90 days, and our database backups roll over within a month.

If you have public decks, you can choose to keep them available for other people to browse and import instead of deleting them too; they're fully anonymised (never linked back to you or your account) either way. You are offered this choice at the point of deletion; the default, if you don't choose otherwise, is to delete everything. Public flashcard decks are always deleted with your account; copies other people have already added to their own decks stay with them, with nothing linking them to you. Notes you share are deleted with your account in the same way, and so are your ratings and reviews of other people's.

Deleting some of your data without deleting your account

You don't have to delete your whole account to delete specific data. From any deck, open its menu and choose “Delete” to permanently remove that deck: its questions, your answers to them, any files you uploaded as source material, and any images attached to those answers. This is immediate and permanent, the same as account deletion: the underlying files are erased, not just the record that they existed, and there's no retention period afterwards. Everything else in your account (your other decks, your profile, your subscription) is untouched.

To delete a past paper you did, open it in My papers and choose “Delete”. This removes your marks, your times, the grade and everything you wrote on it, straight away and for good. Your other attempts are untouched.

For anything this doesn't cover, such as a single answer or a specific uploaded file within a deck you want to keep, email support@cookie.education and we'll do it by hand.

Your rights

You have the right to a copy of your personal data, to have it corrected or deleted, to restrict or object to our processing of it, to withdraw a consent you have given, and to receive the data you gave us in a form you can take elsewhere. You can download a copy of your data as JSON (including your saved chats and the assistant's settings), edit your profile, and delete your account or individual decks yourself from your account settings; for anything else, email support@cookie.education and we will respond within one month.

You can complain to us about how we handle your data, using the complaint form or by email. We acknowledge a complaint within 30 days and answer it as quickly as we can. If you are not satisfied, you can complain to the UK Information Commissioner's Office at ico.org.uk.

Marks, predicted grades and automated decisions

The questions cookie writes, the marks and comments it gives your answers, and the worked solutions are produced by an AI model. A predicted grade is calculated by us from those marks, against grade boundaries you choose for the deck: an exam board's own published boundaries, ones you typed in or kept in your account, or illustrative round numbers. None of this has a legal effect and nothing about your account is decided by it; it exists to guide your revision. You can challenge any mark, which asks the AI to reconsider it with your reasoning in front of it, and if you have a tutor they can record their own view of it. A grade on a past paper you did in cookie is worked out by us from the marks you gave it, against that exam board's published grade boundaries for the same exam series, and it says so beside it. When cookie checks a past paper you marked yourself, your own mark stays and the AI's mark is shown beside it as an estimate. You can challenge it in the same way as any other mark.

Children

Under 13. A child under 13 cannot sign themselves up for cookie, and the signup form is not for them. They can have an account only when a parent or guardian creates one for them through Cookie Tutoring, our tutoring service. The adult confirms they hold parental responsibility for that child, agrees to these terms on the child's behalf, and sets the password themselves. We record who did that and when. The child is never asked to agree to anything, and we never send account email to them. The adult who set the account up can change its password or close it at any time. The child signs in with the email address and password the adult set; we don't allow a Google sign-in to be joined to an account set up this way.

If you believe a child under 13 has an account that no parent or guardian set up this way, contact us and we'll remove it.

13 and over. Anyone 13 or over can create their own cookie account without a parent or guardian, and we ask your age group (13 to 15, 16 to 17, or 18 or over, and never your date of birth) when you sign up. Unless you have told us you are 18 or over, we treat your account as a young person's in how we design things: reminders say what there is to do rather than what you might lose, and we do not show you prompts to upgrade. If you are under 18 and your lessons are looked after by a parent or guardian through Cookie Tutoring, they can see your lessons and your messages with your tutor; that is described in Cookie Tutoring's privacy policy.

Changes to this policy

If we make material changes to this policy, we'll update the date at the top of this page and tell you by email before they take effect. If we start doing something materially different with your data, we will say so before it starts, not after; and if you do not agree, you can delete your account.

Contact

If you have questions about this policy or your data, email support@cookie.education or use our contact form.