AI and data

Last updated August 27, 2026

Where your data goes, who handles it, and how long it is kept.

Illustration representing how Aicademy handles and stores data

This page explains in plain terms what happens to data inside Aicademy. It is not a legal document and is not intended to constitute a compliance certification. For data protection questions from schools or IT leads, contact privacy@useaicademy.com.

Who runs Aicademy

Aicademy is run by Diba Malikzadeh, a sole trader based in the United Kingdom, who is the data controller for everything described on this page.

Aicademy is a small operation rather than a company with a support desk. One named person is accountable for it, and the features listed at the end of this page do not exist yet.

Who Aicademy is for

Accounts require confirming that you are 13 or older. The material covers GCSE and A-level, so most users are between 13 and 17, and the service is designed on that basis rather than treating younger users as an edge case.

A school running a pilot with pupils under 13 would not be a good fit for the current product.

What AI service does Aicademy use?

Aicademy uses Azure OpenAI — Microsoft's enterprise AI service. This is a separate product from the consumer ChatGPT service offered directly by OpenAI. They are different services with different data handling terms.

Azure OpenAI runs on Microsoft Azure infrastructure and is governed by Microsoft's enterprise data handling terms, not OpenAI's consumer product terms.

The models used are GPT-5, GPT-4o and GPT-4o-mini, accessed through the Azure OpenAI API.

Where does AI processing happen?

Aicademy's Azure OpenAI resource sits in Microsoft's Sweden Central data centre, and anything Microsoft stores at rest stays in that region.

The processing itself runs on Data Zone deployments, which means a prompt is handled somewhere within Microsoft's EU data zone — Sweden, or another EU country, depending on where there is capacity at that moment. It does not leave the EU.

In short: your data is stored in Sweden, and processed across the EU.

Is data used to train AI models?

According to Microsoft's published Azure OpenAI Service Data, Privacy, and Security documentation, prompts, completions, and customer data are not used to train or improve foundation models without explicit permission, and are not shared with OpenAI (the company). Aicademy has not granted any such permission, and has not opted into fine-tuning or any additional retention programme.

Microsoft does run automated abuse monitoring across the service. If content is flagged as potentially breaking Microsoft's rules, it may be stored separately and checked — usually by automated systems, and in some cases read by authorised Microsoft staff. Because the resource sits in the European Economic Area, any staff who review it are located there too.

Microsoft no longer publishes how long flagged content is kept. There is an exemption from abuse monitoring that customers can apply for, which Aicademy has not applied for, so the default applies. This part is governed by Microsoft's terms rather than Aicademy's.

Where is application data stored?

Accounts, lessons, quizzes, flashcards, notes, tutor conversation history, progress and sign-in sessions all live in a single Supabase PostgreSQL database hosted on AWS in London (eu-west-2). AWS is Supabase's own infrastructure provider rather than a service Aicademy contracts with directly.

Supabase is a US company, so although the data is held in the UK, its staff can reach it to support and maintain the service. That is covered by our data processing agreement with them, which incorporates the International Data Transfer Addendum approved by the UK Information Commissioner.

What happens when I upload a document?

When you upload a PDF, Word document (.docx), plain text (.txt) or Markdown (.md) file:

  • The file is parsed on Aicademy's servers to extract its text content.
  • That text is sent to Azure OpenAI to produce a structured representation of the material.
  • The structured content is saved to your account as study material.
  • The original file is discarded, but the extracted text and the file name are stored on your account until you delete them.

So the document itself is gone, but what it said is kept. Only upload study materials. Do not upload documents containing personal information, student names, addresses, identification numbers, medical records, safeguarding information, or confidential school records.

What happens if sensitive information is entered?

Aica, the AI tutor, is instructed not to repeat back personal information about real people, and to ask users to remove or anonymise it and rephrase the question without it.

That instruction shapes the reply; it does not stop the processing. Any message sent to Aica is still sent to Azure OpenAI to generate a response, and tutor conversation history is stored on the user's account. It is not visible to other users.

The same applies to the free-text personalisation settings, where users describe how they like to be taught. Those are stored and sent to the AI service with every request, so they should describe a learning preference rather than a health condition.

For a school context, usage guidelines should make clear to pupils that they should not enter personal information about themselves or others, school records, safeguarding details, names of students or staff, or any confidential material into Aicademy.

Analytics and session recording

Aicademy uses PostHog, processed in the European Union, to understand how the product is used — page views and in-product actions such as generating a lesson or finishing a quiz, tied to the account that did them. PostHog stores a small identifier on the device to tell one visit from another.

For a sample of sessions it also records what happens on screen. What a user types into a box, and the contents of their notes, are blanked out before the recording is saved. Everything else on the page is captured as displayed — including a lesson, a quiz, or a tutor conversation once the reply appears on screen.

Recordings are deleted after 30 days, no AI is used to analyse them, and none of this is sold or used for advertising. Anyone who would rather it was not collected can email privacy@useaicademy.com and we will delete the analytics data held against their account. A setting to switch it off directly is on our list.

Vercel also provides basic page analytics, which count visits without cookies and without storing anything on the device.

Third-party services

These services handle data as part of running Aicademy. Processors act only on our instructions, under a data processing agreement. Independent controllers decide some things for themselves, under their own privacy policies.

ServicePurposeRoleLocation
Azure OpenAI (Microsoft)AI generation and tutor features — processes prompts and returns completionsProcessorProcessed in the EU; stored in Sweden Central
SupabaseApplication database and sign-in sessions — accounts, lessons, quizzes, notes, tutor history, progressProcessorLondon, UK (AWS eu-west-2)
VercelHosting, deployment, and cookieless page analyticsProcessorUS-based (global edge)
PostHogProduct analytics and sampled session recording — see “Analytics and session recording” aboveProcessorEuropean Union
CloudinaryNote editor images, profile avatars, and content cover imagesProcessorUS-based CDN
ResendEmail delivery — verification, password reset, billing, updatesProcessorUS-based
StripeSubscription and payment processing, and its own fraud and record-keeping decisionsIndependent controllerUS-based
GoogleOptional Google Sign-In — returns a name and email address on sign-inIndependent controllerUS-based
Microsoft Entra IDOptional Microsoft Sign-In — personal accounts and work or school accountsIndependent controllerMicrosoft global identity infrastructure
DiceBearDefault profile pictures — the browser calls it directly, so it receives the username and the user's IP addressIndependent controllerGermany (Hetzner); CDN via Bunny (Slovenia)

Not listed: Next.js and Auth.js are software frameworks and libraries, not third-party data processors. AWS appears through Supabase rather than as a direct arrangement. IndexNow is used to notify search engines of new public page URLs — no personal data is included. The image cleanup job that removes deleted media from Cloudinary is an internal scheduled task.

How long is data kept, and how is it deleted?

  • Accounts, study content, tutor history and the text taken from uploaded documents — until the user deletes them, or deletes their account
  • Session recordings — 30 days
  • Analytics events — the retention period set on our PostHog plan, then deleted automatically
  • Billing and subscription records — around six years after the tax year they relate to, because HMRC requires it

Users can permanently delete their account from Settings. That removes the account, profile, study content, tutor conversation history, progress, uploaded document text, media and authentication records from the database in one operation.

Two things sit outside that one action: PostHog still holds the usage data recorded beforehand, and Stripe keeps the payment records it is legally required to keep. Email us and we will delete the PostHog data too.

For specific requests — deleting a particular record, requesting a copy of data, or making a school-level deletion request — contact privacy@useaicademy.com.

If something goes wrong

If there is a personal data breach that puts people's rights at risk, we will report it to the Information Commissioner's Office as soon as we can and within 72 hours of finding out, and tell the people affected where the risk to them is high.

Complaints can be made to us directly at privacy@useaicademy.com. We acknowledge them within 30 days and tell you the outcome. You do not have to come to us first, and you can go to the Information Commissioner's Office whether or not you do.

The Privacy Policy sets out the full list of rights — access, correction, deletion, restriction, objection and portability — and how to use them.

What Aicademy does not currently provide

The following are not available in the current product:

  • A teacher or administrator dashboard — staff do not have platform-level visibility into pupil accounts or generated content
  • School-managed account provisioning, licensing, or staff-controlled access
  • A data processing agreement offered to schools. Aicademy holds one with each of its own providers, but there is no school-facing agreement appointing Aicademy as a processor for a school.
  • Cohort or group activity reporting
  • Guaranteed EU/UK-only data residency across all subprocessors — the table above shows which services are US-based

These are features intended for future development, shaped with schools that run supervised pilots.

Full privacy policy: useaicademy.com/privacy

Terms of service: useaicademy.com/terms

Schools enquiries: useaicademy.com/schools

Top students don’t revise more. They revise what counts.

Start revising free

Free to start. No card needed.