Privacy Policy

Last updated 6 August 2026

If you’re under 18: please read this with a parent or guardian before creating an account, and ask them to handle payment if you upgrade to Premium.

Who we are

MarkMatch (“we”, “us”) is operated by Alex Drizen, a sole trader based in the UK. This policy explains what personal data we collect through the MarkMatch website and app, why, and what rights you have over it. Contact: dan.drizen@gmail.com.

What we collect

  • Account details: your email address, first name (optional), password (stored securely by our authentication provider — we never see it in plain text), and an exam date if you choose to set one.
  • Your learning data: the subjects and topics you practise, the answers you write, the marks and feedback you receive, and your progress and streak history. This is the core data the app needs to mark your work and track your revision.
  • A device identifier: a cookie used only to stop the same person claiming multiple free trials (see Cookies below).
  • Payment status:whether you’re subscribed and to which plan. Your card details are handled entirely by Stripe — we never see or store them.

We do not use any analytics or advertising trackers — no Google Analytics, no ad pixels, nothing that profiles you for marketing.

Why we collect it

To create your account and provide the service you’ve asked for — marking your answers, tracking your progress, and remembering your streak. The device cookie is used on the basis of our legitimate interest in keeping the free trial fair for everyone. We do not use your data for any purpose beyond running MarkMatch — we don’t sell it, and we don’t use it for ad targeting.

Who we share it with

  • OpenAI— to generate practice questions and mark your answers, the text of your answer is sent to OpenAI’s API. As of writing, OpenAI’s API terms state that data submitted via the API is not used to train their models by default. OpenAI only receives your answer text and the topic it relates to — not your name, email, or account details.
  • Stripe — to process payments if you upgrade to Premium.
  • Supabase — hosts our database and handles account login.

Where your data is processed

Our database is hosted by Supabase; OpenAI and Stripe may process data outside the UK/EEA (including in the US) under their own standard contractual safeguards. None of these providers are used for anything beyond running the service described above.

How long we keep it

For as long as your account is active. If you ask us to delete your account, we’ll delete your personal data, keeping only what we’re legally required to (for example, payment records for accounting purposes).

Your rights

Under UK GDPR you have the right to access, correct, or delete your personal data, to receive a copy of it, and to object to or restrict how we use it. Your account page has self-service tools for the two most common requests — “Download my data” and “Delete my account”, both under Your data in Profile. For anything else, email dan.drizen@gmail.com and we’ll action your request promptly. You can also complain to the UK Information Commissioner’s Office (ico.org.uk) if you believe we’ve mishandled your data.

Cookies

  • A session cookie that keeps you logged in.
  • gcse_device_id — a random identifier lasting up to a year, used only to detect repeat free-trial signups.

No advertising or analytics cookies. Your light/dark theme preference is stored locally in your browser (not a cookie) and never leaves your device.

Security

We rely on Supabase and Stripe’s security infrastructure and follow reasonable practices to protect your data, but no method of transmission or storage is completely secure.

Changes to this policy

We’ll update the date at the top of this page whenever we make changes, and highlight anything significant.

Contact

Questions about this policy? dan.drizen@gmail.com

See also our Terms of Service.