Privacy Policy
Last updated: 1 May 2026
UCAT Genius ("we", "our", "us") is committed to protecting your privacy. This policy explains what data we collect, how we use it, the third parties we share it with, and your rights under UK GDPR and other applicable data protection laws.
UCAT Genius is an independent study tool. We are not affiliated with, endorsed by, or connected to the UCAT Consortium, Pearson VUE, the official UCAT exam, or any university or admissions body. We do not have access to or claim knowledge of the official UCAT mark scheme. All practice questions, explanations, and analytics are produced independently as a preparation aid only. For the official exam information, visit https://www.ucat.ac.uk.
UCAT Genius is operated as a sole trader trading under the name "UCAT Genius", based in the United Kingdom. The data controller for the purposes of UK GDPR is UCAT Genius. You can contact us at [email protected] for any privacy-related queries, including subject access requests, data deletion, or to exercise any of the rights set out in this policy.
1. Information We Collect
We keep data collection limited to what is needed for the app to work:
- Email address — used only to create and manage your account, send essential service emails (such as password resets and security notices), and identify you when you contact support.
- Test and practice performance data — including your answers, scores, timings, and analytics summaries from timed mock tests, so your results can be retrieved and we can help you analyse your progress.
- AI Tutor messages — questions and messages you send to the AI tutor are stored so we can monitor for abuse, prevent misuse of the service, investigate complaints, and improve the app's quality. AI Tutor messages are sent to OpenAI without your email or account identifier attached so OpenAI cannot link them to you.
- Subscription and purchase data — when you purchase a subscription, RevenueCat and Apple/Google process the transaction. We receive purchase metadata such as the product purchased, transaction ID, and subscription status. We never see, receive, or store your payment card details.
- Device identifiers — RevenueCat and Supabase generate anonymous identifiers (such as a user UUID and an app user ID) used to link your account to your subscription and progress data.
- Crash and error logs — when the app crashes or hits an error, Sentry receives diagnostic information including device model, operating system version, app version, anonymised user identifiers, and a stack trace of the error. This is used solely to fix bugs and improve stability.
- Authentication metadata — our authentication provider (Supabase) automatically logs technical information when you sign in or sign up, including your IP address, the time of the event, and your device's user agent. This is used for security, fraud prevention, and to protect your account from unauthorised access.
We do not collect: your real name, address, phone number, payment card details, location data, contacts, photos, microphone or camera input, push notification tokens, or any data we have not described above.
2. How We Use Your Information
We use your information only for the following limited purposes:
- To create, secure, and manage your account
- To save and display your test performance and analytics