Privacy Policy

FE-1 Made Simple
Effective date: 12 August 2026

A Note Before You Read

Your privacy matters. This policy explains, in plain language, what data we collect, how we use it, and what rights you have. We have tried to avoid jargon, and where we have had to use a technical term, we explain it.

If something is not clear, email us at legal@fe1madesimple.ie.

This policy covers our Study Platform at fe1madesimple.ie and Study Notes purchases at notes.fe1madesimple.ie. The FE-1 Made Simple podcast is hosted on Spotify, and their privacy policy governs your data when you are on Spotify.

01 Who is responsible for your data?

Data Controller

FE-1 Made Simple Limited, a company registered in Ireland (Company No. 815400)

Contact via the email opposite for any data-protection matter.

Under GDPR (the General Data Protection Regulation), we are the "controller" of your personal data, meaning we decide how and why it is used.

02 What data we collect

We only collect data that we actually need. Here is what we collect and why:

2.1 Account Information (when you register)

Data Why we collect it
Your nameTo personalise your experience and address you correctly
Email addressTo log you in, send important account emails, and respond to support requests
PasswordStored securely as a hash, never in plain text, to authenticate your account
Google account infoName and email from Google to create/match your account

2.2 Profile Information (what you fill in after registering)

FE-1 subjectsTo personalise your dashboard and show relevant content first
Exam sitting dateTo show you an accurate countdown and send timely study reminders
Academic backgroundOptional. To tailor explanations (e.g., flagging legal fundamentals for non-law graduates)

2.3 Usage Data (collected automatically)

Lessons completedTo track your progress and show you what to study next
Answers & historyTo show your history, power AI feedback, and help you identify weak areas
Mock exam recordsTo let you review your performance over time
AI feedback countsTo apply your monthly usage limits and save feedback history
Study streaksTo power the streak feature and send study reminders

2.4 Private Notes and Study Groups

If you use reader annotations, we store your subject, page number, note or bookmark, and saved dates so you can return to them on any device. These annotations are private unless you deliberately share one with a study group.

If you create or join a private study group, we store the group name, membership, role, messages and any selected annotation you share. Group posts are visible to that group's members. Do not include confidential, sensitive or third-party personal information. Your annotations, memberships and posts are included in your account data export and are removed when your account is deleted.

2.5 Payment Information

We do not store your card details. All payment processing is handled by Stripe, a PCI-DSS certified payment processor. We receive a token from Stripe confirming successful payment, and we store:

  • Stripe customer ID
  • Current subscription plan
  • Subscription status
  • Billing history (amount, date)
  • Notes Shop product, order reference and purchase email
  • Purchased-notes access and download count

2.6 Technical Data (collected automatically)

IP addressSecurity and fraud detection, not for tracking
Browser typeTo diagnose technical issues
Device typeTo ensure the right layout is served
Notes device identifier and access timeTo apply the three-device limit and protect purchased notes from unauthorised sharing
Error logsTo identify and fix bugs
We do not sell personal data. Advertising or analytics technologies, if introduced, will be described here and used only with any consent required by law.

03 How we use your data

To provide the service

Keeping you logged in, tracking progress, delivering AI feedback, and showing relevant content.

To improve the platform

We may use aggregated or de-identified usage patterns to understand performance and improve content. Identifiable answers are used only for the purposes and sharing described in this policy; we do not use them for advertising.

To send important emails

Security updates, payment receipts, password resets, and renewal reminders.

To educate uniquely

Personalising content recommendations based on your subject choices.

For AI Feedback

When you submit a practice essay for AI feedback, your essay text and the question it answers are sent to Anthropic via the Claude API (Commercial tier).

What Anthropic does

  • Processes the essay to generate the marker output
  • Does not use API inputs or outputs to train models, under Anthropic's Commercial Terms of Service
  • Operates Zero Data Retention for API traffic where available
  • EU→US transfers covered by Standard Contractual Clauses

What we store

  • Essay text linked to your account for review
  • Marker output, score, band and the cited authorities
  • History deleted if your account is deleted

Automated decision-making

The AI marker is an automated process. Its output is informational and educational only. It is not a decision that produces legal effects on you and is not your actual exam result. You can request human review of any AI mark by emailing legal@fe1madesimple.ie.

04 Who we share your data with

ServiceWhat they doWhat they receive
RailwayApplication hosting for the API, admin console and managed Postgres databaseAccount, progress and payment-record data; request logs
Cloudflare (Global)CDN, caching and DDoS protection in front of every pageIP addresses, request metadata, a small set of operational cookies
StripePayment processing (PCI-DSS Level 1 certified)Name, email, billing address, card token (we never see card numbers)
AnthropicAI feedback processing on essays you submit (via the Claude API)Practice essay text and the question prompt
BrevoTransactional and notification email (account, billing, study reminders)Name and email address
CloudinaryStorage and delivery of media assets (podcast thumbnails, illustrations)No personal data; only public course media
GoogleOAuth sign-in for users who choose "Continue with Google"Google account email + basic profile fields you consent to at sign-in

We do not sell your data. We do not share your data with the Law Society of Ireland or any other exam body.

05 Where is data stored?

Our service providers may process data in Ireland, elsewhere in the European Economic Area, and in other countries. Where personal data is transferred outside the EEA, we use a lawful transfer mechanism where required, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with appropriate supplementary measures. Contact us if you would like information about the safeguard relevant to your data.

06 How long we keep it

Account dataWhile the account is active, then deleted or anonymised after closure unless needed for legal claims, security or another stated legal obligation
Answers and AI-feedback historyWhile the account is active; removed or anonymised following a valid deletion request unless an exception under law applies
Payment recordsKept for the period required by Irish tax, accounting and company law, normally at least six years after the relevant accounting period
Technical and security logsKept only as long as reasonably required for security, troubleshooting and legal claims; periods vary by log and provider
Purchased-notes device recordsUntil removed by you or the associated account is deleted

07 Your Rights

Under GDPR, you have the following rights. These are real rights, not marketing language.

To Know

Request a copy of all personal data we hold about you.

To Correct

Update inaccurate information via your settings or by asking us.

To Delete

The right to be forgotten. Delete account and data (except tax records).

Portability

Request an export of your data in CSV or JSON format.

To Object

Object to unfair or unlawful processing.

To Restrict

Pause data usage while a dispute is being resolved.

To exercise any of these rights:

Email us with "Data Request" in the subject line. We respond within one calendar month.

legal@fe1madesimple.ie

You also have the right to lodge a complaint with the Data Protection Commission of Ireland if you believe we have handled your data unlawfully.

09 Children, Breaches & Data Protection Officer

Children

FE-1 Made Simple is intended for users aged 18 or over. We do not knowingly collect personal data from anyone under 16. If you believe a child has registered an account, contact us and we will delete the data.

Breach notification

If we suffer a personal-data breach likely to result in a risk to your rights, we will notify the Data Protection Commission within 72 hours of becoming aware of it, and notify you directly where the risk is high, as required by Articles 33 and 34 GDPR.

Data Protection Officer

We are a small operation that is not legally required to appoint a DPO. Data-protection enquiries are handled directly by the operator at legal@fe1madesimple.ie.

08 Cookies

We use essential cookies and similar storage to provide security, authentication and remembered preferences. Any non-essential analytics or advertising technology will be off until you make the cookie choice required by law, and can be changed below.

CookiePurpose
Session / auth Keeps you logged in between pages and visits
Cloudflare Operational cookies (e.g. __cf_bm) set by Cloudflare to keep the CDN running and block bot traffic. No advertising or tracking.
Stripe Required for Stripe payment checkout to work

Change your cookie choice

Re-open the cookie banner if you would like to update what you previously accepted.

10 Security

Hashed passwords (bcrypt)
HTTPS encryption in transit (TLS 1.2+)
Encryption at rest on Google Cloud SQL
Private VPC, no direct database internet access
Role-scoped database credentials, least privilege
No stored card details (Stripe tokens only)

FE-1 Made Simple Limited

FE-1 Made Simple Limited, a company registered in Ireland (Company No. 815400).
Complaints can be directed to the Data Protection Commission of Ireland at dataprotection.ie

Last updated: 12 August 2026