Privacy Notice

What Aptly saves, why it saves it, and what you can do about it.

Last updated 30 September 2026

The short version

  • Aptly saves your account, submitted work and feedback so you can use History and see what to practise next.
  • OpenAI processes work you submit for AI feedback, handwriting extraction and diagram analysis. Aptly does not save the photo files, but extracted text and diagram observations can be saved.
  • Your work is private from other students and is not sent to your school or teachers. The operator and authorised internal administrators can access information for the purposes below.
  • There are no ads and Aptly does not sell your information. Optional interaction analytics is off unless you allow it in Your data.
  • You can delete saved answers or your account, and email contactaptly@gmail.com for a copy, a correction or a privacy complaint.

Who runs Aptly

Aptly is a free, non-commercial study project run by Joao Perracini, not a company. For data protection law, Joao Perracini is the “controller”: the person responsible for how your information is used.

For questions, rights requests or complaints, email contactaptly@gmail.com.

What Aptly saves

Your account. Your email, Supabase account ID, account timestamps, name or nickname, SL or HL course level, sign-in session and privacy choices. An email, a name or nickname and a course level are needed to set up the account; a real name is not needed.

Your work. Questions, written answers, source text, revisions and selected or generated Practice questions. Feedback includes estimated marks, strengths, mistakes, topics and diagnostic information. Aptly also saves assessment evidence, content hashes, question provenance and assessment/model versions so results can be understood and checked. Diagram evidence is explained below.

Optional ratings, comments and original marks. You can rate feedback, leave a comment or enter an earlier mark. These are linked to your account and answer. An original mark is student-reported, even if you say it came from a teacher; Aptly does not verify it or change its own estimate to match it. You can edit or remove these entries. Authorised internal administrators can read comments and review ratings and original marks to assess feedback quality. Keep personal or sensitive details out of comments.

Operational records. Account-linked usage reservations, request fingerprints, statuses, failure categories and timestamps enforce limits, prevent duplicate AI requests and help diagnose failures. These are separate from saved work and optional interaction logs. They do not contain answer text or photo files.

Contact messages. If you email Aptly, it receives your email address, message and any attachments. Please send only what is needed to explain the issue.

Why Aptly uses it

Data protection law requires a reason, called a “lawful basis”, for each use:

  • Providing your study tools — legitimate interests. Aptly uses your account, work and results to sign you in, assess answers, save History, generate Practice and personalise Current Focus. The interest is providing the private study help you request. This is necessary to provide the service you asked for; Aptly does not assume every teenager can enter a legally binding contract.
  • Operating, securing and improving Aptly — legitimate interests. The interests are preventing abuse, keeping the service reliable and understanding whether it is useful. Aptly uses operational records and limited facts from saved work, such as topic, marks, revision links and activity dates, for internal usage, return-visit and quality measures. Optional ratings, comments and original marks help investigate feedback quality. Routine reports do not include your full answer text.
  • Optional interaction analytics — consent. Only if you allow it, Aptly records opening feedback, History or Current Focus, starting Practice or a revision, clicking a suggested next step, completing onboarding and adding or removing a diagram. Records contain your account ID, relevant work ID, event, time and a limited source/action label. These are identifiable internal records, not anonymous statistics. No session recording, answer text or photos are included. You can withdraw consent and clear these logs in Your data without losing study features. Withdrawal does not undo the lawfulness of processing already carried out with valid consent.
  • Support — legitimate interests. Aptly uses messages and relevant records to answer your questions and resolve problems. Legal obligations cover handling data-protection rights, complaints and records needed to demonstrate that Aptly has dealt with them.

Aptly weighs these interests against your privacy, giving extra weight to children's interests. Core study processing does not rely on consent. Work is required for the feature you ask to use; photos, ratings, comments, original marks and interaction analytics are optional.

AI, and what OpenAI receives

Aptly uses the OpenAI API to assess answers and diagrams, read handwriting and sometimes create Practice questions. Other Practice questions come from Aptly's question bank. AI requests include the relevant question, answer, source material, photo or observations and assessment instructions; Practice requests can include your course level, target topic and skill.

Aptly does not add your profile name, email address or account ID to these requests. Anything identifying you that you put in the work itself will still be sent, so avoid names, faces and private details.

Every AI request sets store: false to disable stored response state. Under OpenAI's API policies, API content is not used to train its models by default. This is API processing, separate from using the consumer ChatGPT service.

That does not mean OpenAI keeps nothing. Its security and abuse-monitoring logs may include prompts, responses and images and are normally retained for up to 30 days, with possible longer retention for legal or safety reasons. Aptly has not confirmed special zero-data-retention arrangements. See OpenAI's API data policies.

Photos

Scan. Selecting a photo sends it through Aptly's server to OpenAI to read the handwriting. Your browser first resizes and re-encodes it, removing the original file metadata, such as GPS information. You can check and edit the extracted text. That text can remain in a browser draft and becomes saved work if you submit it for grading.

Diagrams. An assessed diagram is sent when you choose Grade; a separate diagram review sends it when you request review. Aptly can save visible observations, a content hash, assessment decisions and evidence with the answer. These can affect the estimated mark in diagram-aware assessments. Historical feedback-only reviews keep their original marking behaviour.

Photo bytes pass through temporary browser and server memory and OpenAI processing. Aptly does not write them to its Supabase database or a photo/file store on Supabase or Vercel. The current page may keep a photo in memory for a revision; reloading or switching accounts removes that copy. Photos are not saved in browser draft storage. After reopening an answer, you need to attach the photo again. OpenAI's retention above still applies to what it receives.

How Aptly personalises your practice

Aptly automatically analyses saved marks, topics, mistakes and revisions to estimate strengths and gaps, show Current Focus and suggest Practice. This kind of analysis is called profiling. Current Focus is recalculated from saved work; the focus used for a Practice question can be saved with that question.

These are study suggestions and practice estimates. Aptly does not use them to decide school grades, admissions or access to education, and does not send them to schools, teachers, parents or other students. AI can get things wrong: check feedback alongside your teacher and course materials. Email Aptly to question a result or request a review of your information.

Deleting an answer removes it from future calculations. Separately saved revisions or Practice questions can still contain related information; delete those too if you want to remove that history.

Who else is involved

The operator and authorised internal administrators can access information when needed for support, security, rights requests and the internal quality/usage review described above. The internal analytics view includes account-linked activity and attempt details, optional comments and original marks; an account can be located by email. Other students have no access to this information.

  • Supabase hosts the account database, saved work and authentication.
  • Resend delivers sign-in emails through Supabase's custom email service, processing your address, email content and delivery records.
  • OpenAI provides the AI processing described above.
  • Vercel, Aptly's hosting provider, serves the site and runs server requests.
  • Google Gmail handles messages sent to Aptly's contact address.

These services and their infrastructure suppliers process relevant information to provide their services. They can also handle service/security information for purposes described in their own policies. Aptly may disclose information where required by law. Aptly does not sell information or share it for advertising, and has no separate third-party website analytics service.

Processing outside the UK

Aptly's Supabase project is hosted in Frankfurt, Germany. Hosting, AI, email delivery, support and provider operations can also involve processing outside the UK, including in the United States; the database region does not mean all processing stays there.

OpenAI, Supabase, Vercel and Resend publish data-processing terms containing contractual safeguards for UK transfers, including the UK Addendum to standard contractual clauses. Aptly is still checking the applicable agreements and transfer arrangements for its accounts, including its contact mailbox, and cannot yet confirm that every arrangement is covered. Email contactaptly@gmail.com for the current details or to request a copy of applicable safeguards.

How long things are kept

  • Accounts and saved work: kept until you delete them; there is no automatic deletion just because an account is inactive. Deleting an answer also deletes its assessment snapshot, ratings, comments, original mark and linked events. Revisions remain separate. Unused linked Practice questions are removed where possible; any remaining ones are removed with the account.
  • Account deletion: Your data deletes your Auth account and its linked work, Practice, reports, privacy choices and operational/interaction records from Aptly's active database. This cannot be undone.
  • AI usage records: records dated more than 30 days ago are removed when you next make a request for the same AI feature. There is no background deletion timer, so inactive accounts can retain these records longer, until another request or account deletion.
  • Optional interaction logs: reports use at most 90 days of events collected after your current opt-in. Older records are deleted when another permitted event is recorded for that account, so inactive accounts may retain them longer. Turning analytics off clears all your interaction logs. Logs collected before this choice was introduced are excluded from routine reports and can also be cleared using that control.
  • Support and complaints: correspondence is kept while the issue is being handled, then reviewed for deletion normally within 12 months of closure. A necessary record may be kept longer for an unresolved dispute or legal obligation. Deleting an account does not automatically delete email correspondence.

Photo handling and browser draft limits are described in their own sections. Provider security logs, delivery records and backups have separate retention schedules; deleting your account does not immediately erase every provider copy. Exact periods depend on the service and settings and have not all been verified for Aptly's accounts. OpenAI's usual API period is explained above.

Your rights

You can ask for access to your information, correction of inaccurate information, erasure or restriction of processing. You can object to processing based on legitimate interests, including personalisation or internal analytics based on saved records. Aptly must consider your situation and stop unless it has the legal grounds to continue. Objecting to processing necessary for a feature may mean it cannot provide that feature.

You can withdraw optional analytics consent in Your data. Where the legal conditions apply, portability lets you receive information you provided in a reusable format and send it to another service; this applies to automated processing based on consent or contract. An access request is available for other personal information too. These rights have conditions and exceptions, which Aptly will explain if they affect your request.

You can delete individual answers in History, edit or remove ratings and original marks, and delete your account yourself. For a copy/export, other corrections, an objection or a restriction, email contactaptly@gmail.com, preferably from your account address. There is no automatic export button. Aptly may need proportionate identity checks and normally responds within one month; if the law permits extra time, Aptly will explain why.

Complaints

To make a data-protection complaint to Aptly, email contactaptly@gmail.com and explain what happened and what you would like put right. No special form or legal wording is needed. Aptly will acknowledge it within 30 days, investigate, keep you informed of progress and explain the outcome without undue delay.

You also have the right to complain to the Information Commissioner's Office, the UK regulator, through the ICO complaint service. The ICO normally asks you to raise the issue with the organisation first.

Your privacy if you are under 18

Aptly is designed for students. Accounts are private, there are no public profiles or advertising, and optional interaction analytics starts off for everyone. Learning recommendations are used to support your studying. You can ask a trusted adult to help you understand this notice or exercise your rights.

You must be at least 13 to have an account. This is Aptly's eligibility rule, not a claim that UK law bans all services for younger children. Aptly does not collect a date of birth or identity documents to check age; it applies these protections to everyone. If Aptly learns that an account belongs to someone under 13, it will arrange deletion.

Cookies and what Aptly stores on your device

Storage rules cover browser storage and device settings as well as cookies. Aptly uses:

  • Sign-in cookies: Supabase session cookies and a temporary sign-in verification cookie. They are necessary for secure sign-in, refresh and account access. Session cookies have a rolling library expiry of up to 400 days; session validity can end sooner. Sign-out clears the local session, and the verification cookie is removed after the sign-in exchange.
  • Appearance: the device's light/dark setting and a theme choice in local storage, without a fixed expiry, to adapt the display. This uses the appearance/functionality exception to the storage consent rule. The control below lets you object simply, including while signed out.
  • Practice mark total: your last selection in session storage for the browser session, so the requested Practice flow remembers your input.
  • Temporary typed drafts: account-specific question, answer and source text in the tab's session storage, with timestamps and retry identifiers, to recover unfinished input. Drafts expire after 24 hours; Aptly checks this cutoff when it next accesses draft storage, without a background deletion timer. When storage is accessible, Aptly clears the matching draft after a confirmed save or discard, and account drafts when you sign out, switch accounts or delete your account. If the browser blocks storage access, removal of stored drafts cannot be guaranteed. Pending cleanup is retried before the next draft access or account event in the same loaded page; these pending retries do not survive reloading or closing it. Photos are not included. This is not cloud saving or cross-device sync, and recovery after closing the browser is not guaranteed.

Sign-in, preserving requested inputs/drafts and remembering privacy choices use the strictly necessary exception. Optional interaction analytics uses scripts and only runs with your consent, stored with your account. Aptly uses no advertising cookies or advertising pixels. You can also clear this site data through your browser settings; doing so can sign you out and remove drafts and preferences.

Appearance on this device

Aptly normally follows your device's light or dark setting and remembers your theme choice. Turn this off to stop using those stored preferences and the device setting. You can still change appearance for the current page. Aptly saves your objection so it can respect it.

Keeping your information safe

Database access rules separate students' records, and privileged internal access is restricted. Connections use encryption. Application error handling is designed to log failure categories and technical details without raw work or photos. Hosting, authentication and email providers may separately keep request, delivery and security information, such as IP addresses and browser details. Aptly cannot promise that infrastructure never logs personal information or that any service has perfect security.

Changes to this notice

This review clarifies internal access, providers and retention, explains legitimate interests for the study service and adds separate choices for interaction analytics and appearance. Previous wording relied generally on a contract; this notice does not treat that as automatically valid for every child.

The date at the top shows the latest review. Aptly will explain material changes in the app or by email before starting a new use of your information, and seek a new choice where consent is required.