ExamRizz Campfire
Privacy Policy
Stream Learning Ltd ("we", "us", "our") operates the ExamRizz Campfire mobile application ("the app"). This policy explains what information we collect, how we use it, who we share it with, and the rights you have over it.
Effective date: 12 May 2026. Last updated: 12 May 2026.
1. Information We Collect
Account information
When you create an account using your email address, we collect your email and the password hash stored by our authentication provider, Supabase. When you sign in with Google, we receive your Google account email, display name, and profile picture URL from Google.
Profile information
During onboarding and in Settings, you provide a display name, region, class year, and role, such as student, teacher, or parent. This information is stored in your user profile.
Learning data
As you use the app, we collect:
- Lesson progress and completion history
- Mastery scores and knowledge state estimates
- Evidence events recorded during lessons and practice
- Exam practice attempts and answers, including supercurricular and admissions practice sessions
- Daily briefing interactions and study session records
Voice recordings
If you use the mock interview feature, the app will request microphone permission and record your spoken answers. Each recording is uploaded to our Supabase backend and forwarded to OpenAI's transcription API to produce a text transcript. We do not retain the raw audio after transcription completes. The text transcript is stored against your account so you can review your interview history.
Push notification token
If you grant notification permission, we store a device push token issued by Apple Push Notification service on iOS and Firebase Cloud Messaging on Android, via Expo Push. We use this token to send study reminders and other notifications you have opted in to.
Diagnostics and device information
We use Sentry to collect crash reports, error stack traces, and device information, including device model, operating system version, app version, locale, and anonymous installation ID. We use this information to diagnose crashes and stability issues.
Information we do not collect
We do not collect precise location, contacts, photos, calendar data, payment information, or advertising identifiers. We do not currently use a third-party product analytics service.
2. How We Use Your Information
- To provide and maintain the app's learning features and personalise your study experience
- To track your progress, mastery, and study history
- To transcribe mock interview answers so you can review them
- To send notifications you have opted in to
- To diagnose crashes and improve app stability
- To respond to your support and privacy requests
- To comply with our legal obligations
We do not sell your personal information. We do not use your data to train AI models. We do not use your data for advertising.
3. Legal Basis for Processing (UK / EU users)
If you are in the United Kingdom or the European Economic Area, the UK GDPR and EU GDPR apply. We rely on the following legal bases:
- Contract: to provide the app's core learning features once you create an account.
- Consent: for microphone access, push notifications, and optional features you turn on. You can withdraw consent at any time.
- Legitimate interests: for crash diagnostics and abuse prevention, balanced against your rights.
- Legal obligation: where retention is required by law.
4. Third-Party Services
We use the following processors. Each operates under its own privacy policy.
- Supabase: authentication, database hosting, and edge functions. Supabase stores your account, profile, and learning data.
- Google: sign-in with Google. Google shares your email, display name, and profile picture URL with us when you choose to sign in.
- OpenAI: transcription of mock interview audio via the OpenAI API. Under OpenAI's published API data controls, OpenAI does not use API inputs to train models by default and may retain abuse-monitoring logs for up to 30 days, unless longer retention is legally required.
- Firebase Cloud Messaging (Google): delivery of push notifications on Android devices.
- Apple Push Notification service: delivery of push notifications on iOS devices.
- Sentry: crash reporting and error tracking.
- Expo / EAS (Expo, Inc.): over-the-air app updates, build infrastructure, and the Expo Push relay used to forward notifications to APNs and FCM.
We do not sell your personal information to any third party.
5. Where Your Data Is Stored
Your data is stored on servers operated by the processors listed above. Supabase data is currently hosted in EU regions. Other processors may transfer data outside the UK or EEA. For example, OpenAI and Sentry operate primarily from the United States.
Where data is transferred outside the UK or EEA, we rely on the relevant transfer safeguards, such as the UK International Data Transfer Addendum and EU Standard Contractual Clauses made available by those processors.
6. Data Retention
We retain your account and learning data for as long as your account is active. If you request deletion of your account, we will permanently delete your personal data within 30 days, except where we are required to retain certain records by law, such as financial or tax records, or where data has been irreversibly anonymised for aggregate analytics.
Crash reports in Sentry are retained according to Sentry's standard retention, currently 90 days for events. Push tokens are deleted when you sign out or revoke notification permission.
7. Data Security
We use industry-standard measures to protect your data, including encryption in transit (TLS) and at rest, access controls on our backend, and row-level security policies in our database. No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Children's Privacy
ExamRizz Campfire is intended for users aged 13 and over. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at team@examrizz.com and we will delete it.
9. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, also called the right to be forgotten
- Restrict or object to certain processing
- Withdraw consent for processing based on consent
- Receive your data in a portable format
- Lodge a complaint with your local data protection authority. In the UK, that is the Information Commissioner's Office, available at ico.org.uk.
To exercise any of these rights, contact us at team@examrizz.com. To delete your account, see our Account Deletion page.
10. California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the CPRA, including the right to know what personal information we collect about you, the right to delete it, the right to correct it, and the right to opt out of the sale or sharing of personal information.
We do not sell or share personal information as defined by the CCPA. To exercise your rights, contact us at team@examrizz.com.
11. Account Deletion
You can request deletion of your account and associated personal data at any time by visiting our Account Deletion page or by emailing team@examrizz.com with the subject line "Account Deletion Request".
12. Changes to This Policy
We may update this policy from time to time. We will update the Last updated date above and, for material changes, notify you in the app or by email before they take effect.
13. Contact Us
If you have questions about this privacy policy or want to exercise any of the rights above, contact:
Email: team@examrizz.com
Stream Learning Ltd
71-75 Shelton Street
London WC2H 9JQ
United Kingdom