This Privacy Policy explains how 11+ Daily ("we", "us", "our") collects, uses and protects your personal information when you use our service. We are committed to protecting privacy and complying with the UK General Data Protection Regulation and the Data Protection Act 2018.
1. Who we are
11+ Daily is operated by 11+ Daily. For questions about this policy or your data, please use our contact form.
2. What data we collect
We collect the following information when you use 11+ Daily:
- Account information: username, email address and hashed password
- Usage data: study sessions completed, scores, streaks, bookmarks and project activity
- Subscription data: whether you hold a Pro subscription and its expiry date. Payment card details are handled entirely by Stripe and are never stored by us
- Communications: public contact form submissions and emails you send to us for support, including your name, email address, selected reason, message content and limited anti-abuse data
We do not collect your postal address or phone number. We do not use cookies for tracking or advertising.
3. How we use your data
We use your data to:
- Provide and maintain the 11+ Daily service
- Track study progress and show personalised statistics
- Process subscriptions and send receipts or renewal reminders
- Send transactional emails such as password resets and email verification codes
- Respond to support queries
- Review and respond to contact enquiries submitted through our public website
- Prevent abuse of the public contact form
- Comply with legal obligations
Our lawful basis for processing is contract performance, which covers providing the service you signed up for, and legitimate interests, which covers improving the service and preventing fraud.
4. Children's data
11+ Daily is designed for children aged 8 to 11. In line with UK GDPR and the Children's Code, accounts must be created by a parent or guardian aged 18 or over. The email address registered with the account must belong to the parent or guardian, not the child.
We collect only the minimum data needed to provide the service. We do not show advertising, and we do not sell or share children's data with third parties for marketing purposes.
If you believe we have collected data about a child without appropriate parental consent, please get in touch via our contact form and we will delete it promptly.
5. Third parties
We use a small number of trusted third-party services to operate 11+ Daily:
- Neon, database hosting. Data is stored in the US East 1 region under appropriate transfer safeguards
- Cloudflare, hosting and content delivery
- Cloudflare Turnstile, bot and abuse prevention on the public contact form
- Stripe, payment processing. Stripe handles card data and we receive subscription status only
- RevenueCat, subscription management
- Resend, transactional email delivery
We do not sell personal data to any third party.
6. Data retention
We retain account data for as long as the account is active. If you request deletion, we will delete personal data within 30 days unless we are required to keep some records for legal or accounting reasons, for example subscription payment records that must be retained for seven years.
Public contact form submissions are retained for up to 24 months so we can respond to enquiries, spot repeated abuse patterns and maintain a clear support record.
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data
- Restrict or object to certain processing
- Data portability, which means receiving your data in a machine-readable format
To exercise any of these rights, send a request via our contact form. We will respond within 30 days. You also have the right to complain to the Information Commissioner's Office.
8. Security
Passwords are hashed using bcrypt and never stored in plain text. All data is transmitted over HTTPS. We take reasonable technical and organisational measures to protect your data, but no system is completely secure. Please use a strong, unique password.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via the app. Continued use of the service after changes take effect constitutes acceptance of the revised policy.
10. Contact
For any questions about this Privacy Policy or your data, please use our contact form.