Legal
Kraemon is operated by Thomas Feather ("we", "us"). If you have any questions about this policy, or want to exercise your privacy rights, contact us at kraemon.app@gmail.com.
We are registered as a data controller with the UK Information Commissioner's Office (ICO), registration reference ZC220466.
We collect the minimum data needed to run the revision service. The table below lists every piece of information we may store, depending on how you use the app.
| Data | What it is | Why we need it |
|---|---|---|
| Anonymous user ID | A random identifier generated by Firebase when you first open the app, before any sign-in. It carries no personal information on its own. If you later create a durable account, this ID is linked to your sign-in credential. | Ties your revision data to your device so it persists between sessions, even without a named account. |
| Account email address (only if you create a durable account) |
If you sign in with a magic link, we send a one-time link to the email address you provide and store that address in Firebase Authentication. If you sign in with Apple or Google, we receive the email address associated with your Apple ID or Google account (Apple may provide a relay address instead of your real one if you choose "Hide My Email"). | Identifies your account so your progress can be restored on any device, and enables us to send the sign-in link. |
| Age confirmation record (only if you create a durable account) |
When you start to create a durable account, we ask you to confirm you are aged 13 or over. If you confirm, we store a small record against your account: the fact that you confirmed you are 13+, the date and time you confirmed, which sign-in method you used, and the version of this policy in force at the time. We do not collect or store your date of birth. | UK data-protection law lets a child aged 13 or over consent to an online service without a parent. Recording your confirmation is how we evidence that account holders have self-declared they meet this age and agreed to this policy. |
| Subject enrolments | The GCSE subjects you have chosen, including tier (Foundation / Higher), option branches (e.g. History period study choice), your self-reported confidence level (1–5), how far through the course you are, and your preferred study block length. | Filters and personalises your revision queue to the topics you actually need to revise. |
| Revision progress | For each topic: your last review date, next scheduled review date, how many times you have reviewed it, your recall score (ease factor), and actual minutes studied. | Powers the spaced-repetition algorithm that decides what to show you next and when. |
| Topic status flags | "Not covered yet" or "Didn't do this session" — set when you tap those options during a session. | Temporarily removes topics from your queue that you have not yet been taught. |
| Daily study minutes | Total minutes studied per calendar day. | Powers the daily progress bar on your dashboard. |
| Revision windows | The days and times you prefer to study (e.g. Monday 6 pm). | Used only to schedule local study reminders on your device. Not transmitted to any external service. |
| Waitlist email address (website only, if you sign up) |
The email address you provide on the website "Notify me" form, if you choose to join the waitlist. Collected via Formspree and stored in their secure system. | To notify you when Kraemon is publicly available. Used for no other purpose. |
We do not collect your name, phone number, date of birth, location, contacts, photos, browsing history, or any information beyond what is listed above. The app works fully without creating a durable account — the account email is only collected if you actively choose to sign in.
Under UK GDPR we process your data on more than one lawful basis, depending on the type of data:
We use your data exclusively to:
We do not use your data for advertising, profiling, or any purpose unrelated to delivering the revision service.
Your revision data is stored in Google Firebase (Firestore database and Firebase Authentication), a service provided by Google LLC. Firebase servers are located in the United States and the European Union. Google participates in the EU–US Data Privacy Framework and processes data under Google's standard data processing terms.
Magic-link sign-in: if you use email sign-in, your email address is stored in Firebase Authentication (Google LLC) and a one-time sign-in link is delivered via Firebase's email infrastructure. The link expires after one use.
Apple Sign-In: if you sign in with Apple, your sign-in request is handled by Apple Inc. Apple may share your real email address or a private relay address, depending on your Apple privacy settings. Apple's handling of your data is governed by Apple's Privacy Policy. We receive only the identifier and email (or relay address) needed to create or match your account — no other Apple account data is shared with us.
Google Sign-In: if you sign in with Google, your sign-in request is handled by Google LLC under Google's Privacy Policy. We receive only your Google account email address and a unique Google user identifier — no other Google account data is shared with us.
Website waitlist: if you joined our waitlist, your email is processed by Formspree, Inc. (formspree.io), a US-based form handling service governed by its own privacy policy. We use Formspree solely for waitlist signups and do not share your email with any further party.
We do not use advertising networks or any other third-party services beyond those described above.
Crash reporting and product analytics: to keep the app reliable, we use two privacy-protective tools, both hosted in the EU. Crash reporting (via Sentry) records technical details of any app crash — such as the error and the screen it occurred on — tagged only with your anonymous ID, with personal information and IP-address storage switched off. Product analytics (via PostHog) records anonymous, aggregated usage counts — for example how many people finish onboarding or complete a study session — to show us where the app can be improved, also tagged only with your anonymous ID. Neither tool stores your email, your name, the content of your revision, or anything you type, and neither is used for advertising.
We retain your data for as long as your account exists. If you delete your account via Settings → Delete Account, all Firestore data (revision progress, enrolments, study stats) and your Firebase Authentication credential (including any linked email address) are permanently erased within seconds. There is no recovery after deletion.
Anonymous accounts: if you have not signed in and you uninstall or reset your device, the anonymous session cannot be recovered and your progress will be lost. We recommend creating a durable account if you want to safeguard your progress.
Durable accounts (email, Apple, or Google sign-in): uninstalling the app does not delete your account. You can reinstall and sign in again to restore your progress. Your data will remain on our servers until you explicitly delete your account.
Inactive anonymous accounts: to avoid holding data longer than we need to, an anonymous account (one that has never been linked to an email, Apple, or Google sign-in) that has had no activity for 24 months is automatically and permanently deleted from our servers, along with all its revision data. Any activity resets the clock. Durable accounts are kept until you delete them.
Waitlist emails are retained until the app launches publicly, at which point we will send a single launch notification and give you the option to unsubscribe.
Under UK GDPR you have the following rights:
To exercise any of these rights, email kraemon.app@gmail.com. We will respond within one calendar month.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the ICO at ico.org.uk or by calling 0303 123 1113.
Kraemon is designed for GCSE students, who are typically aged 14–16. We take the ICO's Children's Code (Age Appropriate Design Code) seriously and have built the app accordingly:
We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, please contact us and we will delete it promptly.
Access to your Firestore data is controlled by Firebase Security Rules. Each user's data is only readable and writable by their own authenticated session — other users and unauthenticated requests cannot access it. The revision topic library (subjects, specs, exam dates) is read-only for all users.
Magic-link sign-in links are single-use and expire after one click. We do not store passwords. Apple Sign-In and Google Sign-In use industry-standard OAuth 2.0 flows — we never see your Apple or Google password. All data is transmitted over HTTPS.
If we make material changes to this policy we will update the "Last updated" date above. For significant changes we will add an in-app notice. Continued use of the app after a change constitutes acceptance of the updated policy.
Thomas Feather
kraemon.app@gmail.com