Legal

Privacy Policy

Effective: 18 September 2026Version 4.0

This Privacy Policy explains what personal data SQEpractice (the “Service”, “we”, “us”) collects when you use sqe-practice.com, why we use it, who we share it with and what your rights are. It applies whether you use guest mode or a registered account. Please also read our Terms of Service.

Who we are

SQEpractice is the controller of the personal data described in this policy. This means we decide how and why it is used. You can contact us about privacy at support@sqe-practice.com or through the Support page.

Information we collect

Account information

When you register with an email address, we collect your email address and password. We store your password only in a hashed form that we cannot read back. If you add a name in Settings, we store it as your display name.

Sign in with Google

If you choose to sign in with Google, Google gives us your email address, your name and a link to your profile picture. We do not receive your Google password.

Study plan

If you set up a study plan, we ask when you expect to sit SQE1, which papers you are preparing for, whether this is your first attempt or a resit, and how many hours a week you can study. We use this to build your plan.

Guest mode

When you start guest mode, we create a guest account so your progress can be saved. We do not ask for your name or email address. Cloudflare Turnstile checks that a real person, not a bot, is starting the session. If you register later, your progress moves to your new account.

Practice and performance data

As you use the Service, we record your answers, the time you take, the confidence you record, your scores and mock results, your mistakes and when they are due for review, flashcard reviews, bookmarks, notes, study plan progress and points. We use this to run the features you use: marking, mock reports, mistakes review, analytics, your study plan and your predicted SQE1 score. If you report a problem with a question, we keep your report so we can fix the question.

AI term explanations

When you use Explainon a word or phrase, we send Anthropic the text you selected (up to 80 characters), the sentence it comes from (up to 600 characters) and the language you chose. Anthropic’s Claude model writes the explanation and returns it to us. We do not send your name, email address or account details to Anthropic.

We save each explanation against the term and language, not against you, and may show it to other users who look up the same term. We also record which terms you looked up and when, so we can apply daily limits.

Payment data

When you buy an access pass, you pay on a Stripe Checkout page. Stripe collects your card details. We never see or store your full card number. From Stripe we receive and keep what you bought, the amount you paid, the payment status and date, and Stripe’s reference numbers for the payment and for you as a customer.

Support requests

When you contact us, we receive your email address and your message, including its category and subject. We use them to reply. Messages sent through the Support page reach us by email through our email provider, Brevo.

How we use it and why

UK data protection law requires a lawful basis for each use of your data. We rely on:

  • Contract— to create and run your account, provide practice, mocks, analytics, your study plan and AI term explanations, sell and provide access passes, and send the emails you need to use the Service, such as address verification, password resets and purchase confirmations.
  • Legitimate interests— to keep the Service secure and prevent abuse, to understand how the Service is used and which sources bring visitors so we can improve it, to run the leaderboard, and to send progress updates, study reminders, a reminder before your pass ends and occasional messages about the Service. We only do this where your interests and rights do not override ours. You can object at any time.
  • Legal obligation— to keep payment and accounting records.
  • Consent— we do not use advertising cookies or advertising pixels. If we ever want to, we will ask for your consent first, and you will be able to withdraw it at any time.

We do not sell your personal data. We do not make decisions about you based only on automated processing that have legal or similarly significant effects. Your predicted score is an automated estimate shown only for your own information.

What other users can see

If you have a registered account, your display name, points and rankappear on the leaderboard, where other users can see them. If you have not set a display name, we show “Learner” followed by a short code instead. Guests are not ranked. Your email address is never shown.

Your display name is the name in your Settings. You can change it at any time. Use a nickname if you would rather not show your real name.

Cookies and browser storage

We use a small number of first-party cookies and browser storage items. We do not use advertising cookies, advertising pixels or third-party tracking cookies. If we ever want to, we will ask for your consent first.

Cookies

  • sqe_access— keeps you signed in. It is HttpOnly, so scripts on the page cannot read it. It lasts 15 minutes and is renewed while you use the Service.
  • sqe_refresh— renews your sign-in. It is HttpOnly and is sent only to our sign-in endpoints. It lasts 30 days.
  • sqe_presence— a random ID used only to count how many people are online. It is HttpOnly and lasts 180 days. Our server deletes each presence record about 30 minutes after your last activity.
  • sqe_registration_source— if you arrived from a recognised source, such as Google, Reddit or YouTube, this holds the name of that source for 30 days. If you register, we note the source on your account. It holds no personal details.
  • sqe_ref— if you arrive through a referral link, this holds that link’s code for 30 days so we can record which link you came from if you register. It is HttpOnly.

The two sign-in cookies are strictly necessary. The others are used only for our own measurement. Cloudflare, which delivers our website, may also set strictly necessary security cookies to protect it from attacks and bots.

Browser storage

  • sqe.anonymousId— a random ID created in your browser. It is sent with page-view events so we can count unique visitors. It stays until you clear your browser storage.
  • sqe.trafficAttribution— the source that brought you to the Service and when. It is kept for 30 days.
  • Settings such as whether you have seen the product tour, your Explain language and your keyboard shortcuts, and marks you make on a question during a session. These stay in your browser.

You can delete cookies and clear site storage in your browser at any time. The Service keeps working without them, except that you will need to sign in again.

Analytics and logs

We use our own first-party analytics. When you open a page, we record the page path (never the query string), the anonymous ID from your browser, the source that brought you if we know it, the time, and your account if you are signed in. We also record key actions, such as signing up, signing in, starting a practice session or mock, starting checkout and setting up a study plan. We use this to understand how the Service is used and to improve it.

We delete these product events after 180 days. We do not use advertising pixels or tags, and we do not share your activity with advertising networks.

Our hosting providers keep basic server logs, which can include your IP address. We use them for security, to prevent abuse and to fix problems. They are kept for a limited period and then deleted.

Service providers

We use a small number of trusted providers to run the Service. Each one receives only the data it needs for the purpose below:

  • Stripe— takes payments for access passes. Stripe also uses some payment data as an independent controller, for example to prevent fraud and meet its own legal duties.
  • Brevo— sends our emails, such as verification, password reset, purchase and reminder emails, and delivers support messages to us.
  • Anthropic— writes AI term explanations using its Claude model. It receives the selected text, the sentence around it and the chosen language, but not your name, email address or account details.
  • Google— provides Sign in with Google, if you choose to use it.
  • Cloudflare— hosts and delivers our website through its network, and runs Turnstile bot protection when you start guest mode. It processes your IP address and technical request data.
  • Railway— hosts our backend servers and the database where your account and practice data are stored.

International data transfers

Some of our providers process data outside the UK, for example in the United States or the European Union. When they do, we rely on safeguards recognised by UK data protection law, such as adequacy regulations or approved contract clauses.

How long we keep data

  • Account, study plan and practice data— for as long as your account exists. It is deleted when you delete your account.
  • Guest accounts— kept so you can come back to your progress. You can ask us to delete a guest account at any time.
  • Product analytics events— 180 days. If you delete your account, events are no longer linked to it.
  • Presence records— about 30 minutes after your last activity.
  • Record of your AI look-ups— for as long as your account exists. Saved explanations are not linked to anyone.
  • Payment records— kept after your account is deleted, for as long as tax and accounting law requires (usually six years).
  • Support messages— for as long as we need them to deal with your request and any follow-up.
  • Cookies and browser storage — as described in Cookies and browser storage.

Deleting your account

You can delete your account at any time in your Settings. This permanently deletes your account and the practice data linked to it. It also ends access to any pass on the account. Deleting your account does not give a refund by itself, so please contact support first if you want one. We keep payment records as explained above.

Your rights

Under UK data protection law, you have the right to:

  • Get a copy of the personal data we hold about you.
  • Have inaccurate or incomplete data corrected.
  • Have your data deleted.
  • Ask us to restrict how we use your data.
  • Object to how we use your data, including for any marketing.
  • Receive your data in a portable format.
  • Withdraw your consent at any time, where we rely on consent.

You can update your details and delete your account in Settings. For anything else, email support@sqe-practice.com or use the Support page. We will reply within one month. We may need to confirm your identity first.

Children and eligibility

The Service is for people preparing for a professional legal exam. It is not aimed at children, and you must be at least 16 years old to use it. If you believe someone under 16 has given us personal data, please contact us so we can delete it.

Changes to this policy

We may update this Privacy Policy from time to time. The date at the top of this page shows when it last changed. If we make a significant change, we will tell you in the Service or by email.

Contact and complaints

If you have a question about this policy or how we handle your data, email support@sqe-practice.com or use the Support page.

If you are unhappy with how we have handled your data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator, at ico.org.uk or on 0303 123 1113.