Privacy Policy

FE-1 Made Simple
Effective date: May 2026

A Note Before You Read

Your privacy matters. This policy explains, in plain language, what data we collect, how we use it, and what rights you have. We have tried to avoid jargon, and where we have had to use a technical term, we explain it.

If something is not clear, email us at legal@fe1madesimple.ie.

This policy covers our Study Platform at fe1madesimple.ie and Study Notes purchases at notes.fe1madesimple.ie. The FE-1 Made Simple podcast is hosted on Spotify, and their privacy policy governs your data when you are on Spotify.

01 Who is responsible for your data?

Data Controller

FE-1 Made Simple Limited, a company registered in Ireland (Company No. 815400)

Contact via the email opposite for any data-protection matter.

Under GDPR (the General Data Protection Regulation), we are the "controller" of your personal data, meaning we decide how and why it is used.

02 What data we collect

We only collect data that we actually need. Here is what we collect and why:

2.1 Account Information (when you register)

Data Why we collect it
Your nameTo personalise your experience and address you correctly
Email addressTo log you in, send important account emails, and respond to support requests
PasswordStored securely as a hash, never in plain text, to authenticate your account
Google account infoName and email from Google to create/match your account

2.2 Profile Information (what you fill in after registering)

FE-1 subjectsTo personalise your dashboard and show relevant content first
Exam sitting dateTo show you an accurate countdown and send timely study reminders
Academic backgroundOptional. To tailor explanations (e.g., flagging legal fundamentals for non-law graduates)

2.3 Usage Data (collected automatically)

Lessons completedTo track your progress and show you what to study next
Answers & historyTo show your history, power AI feedback, and help you identify weak areas
Mock exam recordsTo let you review your performance over time
AI feedback countsTo apply your monthly usage limits and save feedback history
Study streaksTo power the streak feature and send study reminders

2.4 Payment Information

We do not store your card details. All payment processing is handled by Stripe, a PCI-DSS certified payment processor. We receive a token from Stripe confirming successful payment, and we store:

  • Stripe customer ID
  • Current subscription plan
  • Subscription status
  • Billing history (amount, date)

2.5 Technical Data (collected automatically)

IP addressSecurity and fraud detection, not for tracking
Browser typeTo diagnose technical issues
Device typeTo ensure the right layout is served
Error logsTo identify and fix bugs
We do not use cookies for advertising. We do not sell or share your data with advertisers.

03 How we use your data

To provide the service

Keeping you logged in, tracking progress, delivering AI feedback, and showing relevant content.

To improve the platform

We use anonymised, aggregated patterns from student answers, marks, and study behaviour to improve the marker accuracy and prioritise the content we produce next. Your individual answers are never shared outside the platform.

To send important emails

Security updates, payment receipts, password resets, and renewal reminders.

To educate uniquely

Personalising content recommendations based on your subject choices.

For AI Feedback

When you submit a practice essay for AI feedback, your essay text and the question it answers are sent to Anthropic via the Claude API (Commercial tier).

What Anthropic does

  • Processes the essay to generate the marker output
  • Does not use API inputs or outputs to train models, under Anthropic's Commercial Terms of Service
  • Operates Zero Data Retention for API traffic where available
  • EU→US transfers covered by Standard Contractual Clauses

What we store

  • Essay text linked to your account for review
  • Marker output, score, band and the cited authorities
  • History deleted if your account is deleted

Automated decision-making

The AI marker is an automated process. Its output is informational and educational only. It is not a decision that produces legal effects on you and is not your actual exam result. You can request human review of any AI mark by emailing legal@fe1madesimple.ie.

04 Who we share your data with

ServiceWhat they doWhat they receive
Railway (United States)Application hosting for the API, admin console and managed Postgres databaseAccount, progress and payment-record data; request logs
Cloudflare (Global)CDN, caching and DDoS protection in front of every pageIP addresses, request metadata, a small set of operational cookies
Stripe (Ireland / United States)Payment processing (PCI-DSS Level 1 certified)Name, email, billing address, card token (we never see card numbers)
Anthropic (United States)AI feedback processing on essays you submit (via the Claude API)Practice essay text and the question prompt
Brevo (France)Transactional and notification email (account, billing, study reminders)Name and email address
Cloudinary (United States)Storage and delivery of media assets (podcast thumbnails, illustrations)No personal data — only public course media
Google (United States)OAuth sign-in for users who choose "Continue with Google"Google account email + basic profile fields you consent to at sign-in

We do not sell your data. We do not share your data with the Law Society of Ireland or any other exam body.

05 Where is data stored?

Application servers and primary database (Postgres on Google Cloud SQL) are hosted in the European Union, Google's europe-west1 region (St. Ghislain, Belgium). Cloudflare sits in front of the site as CDN. AI processing via Anthropic may occur on infrastructure outside the EU (typically the US); transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) together with Anthropic's Commercial Terms of Service, including their Zero Data Retention commitment for API customers.

06 How long we keep it

Account DataUntil account deletion
AI Feedback HistoryUntil account deletion
Payment records7 years from the transaction (required under Irish tax law and survives account deletion in anonymised form)
Technical logs90 days

07 Your Rights

Under GDPR, you have the following rights. These are real rights, not marketing language.

To Know

Request a copy of all personal data we hold about you.

To Correct

Update inaccurate information via your settings or by asking us.

To Delete

The right to be forgotten. Delete account and data (except tax records).

Portability

Request an export of your data in CSV or JSON format.

To Object

Object to unfair or unlawful processing.

To Restrict

Pause data usage while a dispute is being resolved.

To exercise any of these rights:

Email us with "Data Request" in the subject line. We respond within one calendar month.

legal@fe1madesimple.ie

You also have the right to lodge a complaint with the Data Protection Commission of Ireland if you believe we have handled your data unlawfully.

09 Children, Breaches & Data Protection Officer

Children

FE-1 Made Simple is intended for users aged 18 or over. We do not knowingly collect personal data from anyone under 16. If you believe a child has registered an account, contact us and we will delete the data.

Breach notification

If we suffer a personal-data breach likely to result in a risk to your rights, we will notify the Data Protection Commission within 72 hours of becoming aware of it, and notify you directly where the risk is high, as required by Articles 33 and 34 GDPR.

Data Protection Officer

We are a small operation that is not legally required to appoint a DPO. Data-protection enquiries are handled directly by the operator at legal@fe1madesimple.ie.

08 Cookies

We use a small number of essential cookies to make the platform work. We do not use tracking or advertising cookies.

CookiePurpose
Session / auth Keeps you logged in between pages and visits
Cloudflare Operational cookies (e.g. __cf_bm) set by Cloudflare to keep the CDN running and block bot traffic. No advertising or tracking.
Stripe Required for Stripe payment checkout to work

Change your cookie choice

Re-open the cookie banner if you would like to update what you previously accepted.

10 Security

Hashed passwords (bcrypt)
HTTPS encryption in transit (TLS 1.2+)
Encryption at rest on Google Cloud SQL
Private VPC, no direct database internet access
Role-scoped database credentials, least privilege
No stored card details (Stripe tokens only)

FE-1 Made Simple Limited

FE-1 Made Simple Limited, a company registered in Ireland (Company No. 815400).
Complaints can be directed to the Data Protection Commission of Ireland at dataprotection.ie

Last updated: July 2026