Legal

Privacy Policy

Last updated: 15 April 2026

1. Data Controller

StudySEM is operated by Protero Ltd. We are the data controller responsible for your personal data. If you have any questions about this policy or how we handle your data, you can contact us at studysem@protero.io.

2. What Data We Collect

We collect the following types of personal data when you use StudySEM:

  • Name and email address - provided when you create an account.
  • Account credentials - authentication is handled by Supabase Auth. We never see or store your raw password.
  • Payment information - processed entirely by Stripe. We do not store your card details on our servers.
  • Usage data - pages visited, questions attempted, scores, and time spent on the platform.
  • Device and browser information - collected through PostHog analytics to help us understand how the site is used.

3. Why We Collect It

We use your data to:

  • Provide and improve the StudySEM platform and courses.
  • Process payments and manage subscriptions.
  • Track your learning progress and provide performance analytics so you can see how you're doing.
  • Communicate service updates and important account information.
  • Monitor and improve site performance and reliability.

We do not sell your data to third parties.

4. Third-Party Services

We share data with the following trusted third-party services, each of which has its own privacy policy:

  • Supabase - database and authentication (hosted in the EU).
  • Stripe - payment processing.
  • Vercel - website hosting.
  • PostHog - analytics (hosted in the EU).
  • Mailchimp - email communications.

5. Cookies

We use essential cookies that are required for authentication and basic site functionality. These cannot be disabled as the site would not work without them.

We also use analytics cookies (via PostHog) to understand how the site is used. These are only set with your consent. You will see a cookie consent banner on your first visit, and you can change your preferences at any time.

6. Data Retention

We retain your personal data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days.

Anonymised, aggregated data (such as overall usage statistics) may be retained for analytics purposes after account deletion. This data cannot be used to identify you.

7. Your Rights Under UK GDPR

Under the UK General Data Protection Regulation, you have the right to:

  • Access - request a copy of the personal data we hold about you.
  • Rectification - ask us to correct any inaccurate data.
  • Erasure - ask us to delete your personal data.
  • Restrict processing - ask us to limit how we use your data.
  • Data portability - request your data in a portable format.
  • Object - object to certain types of processing.

To exercise any of these rights, email us at studysem@protero.io. We will respond within 30 days.

8. Children

StudySEM is designed for medical professionals and trainees. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us at studysem@protero.io and we will remove it promptly.

9. Changes to This Policy

We may update this privacy policy from time to time. The date at the top of this page reflects the most recent revision. We encourage you to review this page periodically. If we make significant changes, we will notify you by email or through a notice on the platform.