Privacy policy
Last updated 15 September 2026
PrepGrid 11+ is used by children, so the short version matters most: we never ask a child for their name, email address, date of birth or anything else that identifies them. A child is a nickname and a PIN chosen by their parent or teacher, and nothing more.
Who we are
This service is run by Nadeem Ahmad, trading as PrepGrid. We are the data controller for everything described here.
For anything in this policy — including a request to see, correct or delete your data — write to prep11.uk@gmail.com. We aim to answer within a few days, and are required to answer within one month.
What we collect from adults
- Your email address and password, when you create a parent or teacher account. Passwords are stored only as a hash by our authentication provider; we never see them.
- Your sign-in activity — when you last signed in, and whether your email is confirmed.
- Billing details, if you subscribe. Card numbers are handled entirely by Stripe and never reach our servers; we store only Stripe’s customer and subscription identifiers, the status of the subscription, and its renewal date.
- For teachers, the school or tutoring organisation your account belongs to, the classes you create, and the tasks you set.
What we collect about children
This is deliberately as little as we can operate on.
- A nickname, chosen by the parent or entered by the teacher from their class register. We ask for a nickname rather than a real name precisely so that the record need not identify anybody.
- A four-digit PIN, stored as a hash, used only to open practice mode on a shared device.
- Their practice history: which questions were shown, which answer was chosen, whether it was right, when it was answered, and the topic and difficulty of each question. This is what produces the progress dashboard and the teacher’s class view, and it is the reason the service exists.
We do not collect a child’s real name, email address, date of birth, photograph, location, or school year, and children are never asked to create an account or to enter anything about themselves.
Reporting a problem with a question
Anyone can flag a question that looks wrong, including visitors who are not signed in. When that happens we store the question, what was reported, and any description written — plus a one-way hash of the reporter’s IP address, used solely to stop one person flooding the queue. We never store the IP address itself, and the hash cannot be reversed back into one.
Cookies and analytics
We set a small number of cookies that the service cannot work without: one that keeps you signed in, and one that remembers a child is through the PIN gate on that device. These cannot be turned off without breaking sign-in.
We would also like to use Google Analytics to understand which parts of the site are used. It sets its own cookies and records the pages visited and approximate location. It only runs if you say yes — we ask the first time you visit, and nothing analytics-related loads until you have. You can change your mind by clearing this site’s data in your browser, which makes us ask again.
Saying no costs you nothing: the site works exactly the same either way, and we do not ask again on that device.
Who else sees the data
We do not sell anything to anybody. We use these providers to run the service:
- Supabase — the database and sign-in system that stores everything described above.
- Vercel — hosting; it processes requests and keeps short-lived server logs.
- Stripe — payments, for subscribers only.
- Google Analytics — usage measurement.
Your data is stored in the United Kingdom. Our database is hosted in London (Supabase region eu-west-2), so accounts, child profiles and practice history do not leave the UK.
Our hosting, payment and analytics providers are international companies and may process some information — such as the technical details of a request, or a payment — outside the UK, under the transfer safeguards they each publish.
A teacher can see the practice history of the pupils in their own class, and nobody else’s. A parent can see their own child’s, and nobody else’s.
How long we keep it
Account and practice records are kept while the account is open. When an account is closed we delete it, its child profiles and their practice history within 30 days.
Reports about a question are kept as long as the question is in the bank, because the point of them is to notice a question going wrong repeatedly. They carry no name, no email and no IP address — only the one-way hash described above. Our hosting and database providers also keep their own short-lived technical logs, under their retention policies rather than ours.
Your rights
You can ask to see the data held about you or your child, have it corrected, or have it deleted, by writing to the address above. Deleting a parent account removes its child profiles and their practice history. A teacher removing a pupil from a class removes that pupil’s record.
If you are unhappy with how we have handled your information you can complain to the Information Commissioner’s Office at ico.org.uk.
Changes
If this policy changes in a way that affects what we collect or who sees it, we will say so here and update the date at the top.