Privacy Policy

BandUp ("we", "our", "us") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how you can control it. We will never sell your personal data to third parties.

1. Who We Are

BandUp is an IELTS preparation platform operated by Quest Labs. If you have any questions about this policy, contact us at [email protected].

2. Data We Collect

Account data

When you create an account we collect your email address and the password hash generated by our authentication provider (Supabase). We never store plaintext passwords.

Usage data

We collect information about how you use the app, including:

Device and technical data

We automatically collect standard technical information when you use BandUp:

Audio and written responses

If you use Speaking or Writing practice features, your responses are processed by our AI scoring engine. Audio recordings are processed in real time and are not stored beyond the active session unless you explicitly save a result. Written responses are stored with your session history so you can review feedback later.

Payment data

Payments are processed by Stripe. We do not store card numbers or payment credentials. We receive only a transaction reference, subscription status, and plan type.

3. How We Use Your Data

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area, our legal bases for processing your data are:

5. Data Sharing

We share data only with the following categories of third-party service providers, and only to the extent necessary to operate BandUp:

All providers are bound by data processing agreements and are prohibited from using your data for their own purposes.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where retention is required by law (e.g., billing records for 7 years in some jurisdictions).

7. Your Rights

Depending on your location, you may have the right to:

To exercise any of these rights, email [email protected]. We will respond within 30 days.

8. Cookies

BandUp uses the following cookies and local storage entries:

We do not use advertising or tracking cookies.

9. Children's Privacy

BandUp is intended for users aged 13 and older. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with data without parental consent, contact us and we will delete it promptly.

10. Security

We implement industry-standard security measures including HTTPS encryption in transit, hashed passwords, row-level security on our database, and regular security reviews. No system is 100% secure, and we cannot guarantee absolute security.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by email or by displaying a notice in the app. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of BandUp after changes take effect constitutes acceptance.

12. Contact

Questions or requests regarding this Privacy Policy: