Privacy Policy
A Note Before You Read
Your privacy matters. This policy explains, in plain language, what data we collect, how we use it, and what rights you have. We have tried to avoid jargon, and where we have had to use a technical term, we explain it.
If something is not clear, email us at legal@fe1madesimple.ie.
This policy covers our Study Platform at fe1madesimple.ie and Study Notes purchases at notes.fe1madesimple.ie. The FE-1 Made Simple podcast is hosted on Spotify, and their privacy policy governs your data when you are on Spotify.
01 Who is responsible for your data?
Data Controller
FE-1 Made Simple Limited, a company registered in Ireland (Company No. 815400)
Contact via the email opposite for any data-protection matter.
Contact
legal@fe1madesimple.ieUnder GDPR (the General Data Protection Regulation), we are the "controller" of your personal data, meaning we decide how and why it is used.
02 What data we collect
We only collect data that we actually need. Here is what we collect and why:
2.1 Account Information (when you register)
| Data | Why we collect it |
|---|---|
| Your name | To personalise your experience and address you correctly |
| Email address | To log you in, send important account emails, and respond to support requests |
| Password | Stored securely as a hash, never in plain text, to authenticate your account |
| Google account info | Name and email from Google to create/match your account |
2.2 Profile Information (what you fill in after registering)
| FE-1 subjects | To personalise your dashboard and show relevant content first |
| Exam sitting date | To show you an accurate countdown and send timely study reminders |
| Academic background | Optional. To tailor explanations (e.g., flagging legal fundamentals for non-law graduates) |
2.3 Usage Data (collected automatically)
| Lessons completed | To track your progress and show you what to study next |
| Answers & history | To show your history, power AI feedback, and help you identify weak areas |
| Mock exam records | To let you review your performance over time |
| AI feedback counts | To apply your monthly usage limits and save feedback history |
| Study streaks | To power the streak feature and send study reminders |
2.4 Private Notes and Study Groups
If you use reader annotations, we store your subject, page number, note or bookmark, and saved dates so you can return to them on any device. These annotations are private unless you deliberately share one with a study group.
If you create or join a private study group, we store the group name, membership, role, messages and any selected annotation you share. Group posts are visible to that group's members. Do not include confidential, sensitive or third-party personal information. Your annotations, memberships and posts are included in your account data export and are removed when your account is deleted.
2.5 Payment Information
We do not store your card details. All payment processing is handled by Stripe, a PCI-DSS certified payment processor. We receive a token from Stripe confirming successful payment, and we store:
- Stripe customer ID
- Current subscription plan
- Subscription status
- Billing history (amount, date)
- Notes Shop product, order reference and purchase email
- Purchased-notes access and download count
2.6 Technical Data (collected automatically)
| IP address | Security and fraud detection, not for tracking |
| Browser type | To diagnose technical issues |
| Device type | To ensure the right layout is served |
| Notes device identifier and access time | To apply the three-device limit and protect purchased notes from unauthorised sharing |
| Error logs | To identify and fix bugs |
03 How we use your data
To provide the service
Keeping you logged in, tracking progress, delivering AI feedback, and showing relevant content.
To improve the platform
We may use aggregated or de-identified usage patterns to understand performance and improve content. Identifiable answers are used only for the purposes and sharing described in this policy; we do not use them for advertising.
To send important emails
Security updates, payment receipts, password resets, and renewal reminders.
To educate uniquely
Personalising content recommendations based on your subject choices.
For AI Feedback
When you submit a practice essay for AI feedback, your essay text and the question it answers are sent to Anthropic via the Claude API (Commercial tier).
What Anthropic does
- Processes the essay to generate the marker output
- Does not use API inputs or outputs to train models, under Anthropic's Commercial Terms of Service
- Operates Zero Data Retention for API traffic where available
- EU→US transfers covered by Standard Contractual Clauses
What we store
- Essay text linked to your account for review
- Marker output, score, band and the cited authorities
- History deleted if your account is deleted
Automated decision-making
The AI marker is an automated process. Its output is informational and educational only. It is not a decision that produces legal effects on you and is not your actual exam result. You can request human review of any AI mark by emailing legal@fe1madesimple.ie.
04 Who we share your data with
| Service | What they do | What they receive |
|---|---|---|
| Railway | Application hosting for the API, admin console and managed Postgres database | Account, progress and payment-record data; request logs |
| Cloudflare (Global) | CDN, caching and DDoS protection in front of every page | IP addresses, request metadata, a small set of operational cookies |
| Stripe | Payment processing (PCI-DSS Level 1 certified) | Name, email, billing address, card token (we never see card numbers) |
| Anthropic | AI feedback processing on essays you submit (via the Claude API) | Practice essay text and the question prompt |
| Brevo | Transactional and notification email (account, billing, study reminders) | Name and email address |
| Cloudinary | Storage and delivery of media assets (podcast thumbnails, illustrations) | No personal data; only public course media |
| OAuth sign-in for users who choose "Continue with Google" | Google account email + basic profile fields you consent to at sign-in |
We do not sell your data. We do not share your data with the Law Society of Ireland or any other exam body.
05 Where is data stored?
Our service providers may process data in Ireland, elsewhere in the European Economic Area, and in other countries. Where personal data is transferred outside the EEA, we use a lawful transfer mechanism where required, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with appropriate supplementary measures. Contact us if you would like information about the safeguard relevant to your data.
06 How long we keep it
| Account data | While the account is active, then deleted or anonymised after closure unless needed for legal claims, security or another stated legal obligation |
| Answers and AI-feedback history | While the account is active; removed or anonymised following a valid deletion request unless an exception under law applies |
| Payment records | Kept for the period required by Irish tax, accounting and company law, normally at least six years after the relevant accounting period |
| Technical and security logs | Kept only as long as reasonably required for security, troubleshooting and legal claims; periods vary by log and provider |
| Purchased-notes device records | Until removed by you or the associated account is deleted |
07 Your Rights
Under GDPR, you have the following rights. These are real rights, not marketing language.
To Know
Request a copy of all personal data we hold about you.
To Correct
Update inaccurate information via your settings or by asking us.
To Delete
The right to be forgotten. Delete account and data (except tax records).
Portability
Request an export of your data in CSV or JSON format.
To Object
Object to unfair or unlawful processing.
To Restrict
Pause data usage while a dispute is being resolved.
To exercise any of these rights:
Email us with "Data Request" in the subject line. We respond within one calendar month.
You also have the right to lodge a complaint with the Data Protection Commission of Ireland if you believe we have handled your data unlawfully.
09 Children, Breaches & Data Protection Officer
Children
FE-1 Made Simple is intended for users aged 18 or over. We do not knowingly collect personal data from anyone under 16. If you believe a child has registered an account, contact us and we will delete the data.
Breach notification
If we suffer a personal-data breach likely to result in a risk to your rights, we will notify the Data Protection Commission within 72 hours of becoming aware of it, and notify you directly where the risk is high, as required by Articles 33 and 34 GDPR.
Data Protection Officer
We are a small operation that is not legally required to appoint a DPO. Data-protection enquiries are handled directly by the operator at legal@fe1madesimple.ie.
08 Cookies
We use essential cookies and similar storage to provide security, authentication and remembered preferences. Any non-essential analytics or advertising technology will be off until you make the cookie choice required by law, and can be changed below.
| Cookie | Purpose |
|---|---|
| Session / auth | Keeps you logged in between pages and visits |
| Cloudflare | Operational cookies (e.g. __cf_bm) set by Cloudflare to keep the CDN running and block bot traffic. No advertising or tracking. |
| Stripe | Required for Stripe payment checkout to work |
Change your cookie choice
Re-open the cookie banner if you would like to update what you previously accepted.