Privacy & UK GDPR
Fellow Privacy Notice
Last updated: 4 October 2026
The short version
Fellow is an admissions-preparation service. We use the personal information needed to create and secure your account, remember your preparation progress, provide practice and feedback, run optional AI or voice features, manage subscriptions and support School-plan features. We do not sell your personal data. We aim to collect only what is reasonably needed for these purposes and apply high-privacy defaults for young users.
If you are under 18
Fellow is designed to be usable by teenagers. Your account starts with high-privacy settings. We ask for an age band rather than your full date of birth. There are no public student profiles or student-to-student messages. You do not need to share unnecessary sensitive information to use the core service. Optional AI, voice or third-party features only process the information needed when you choose to use them. You can use the Privacy Centre to download available account data, make a privacy request or request account deletion.
1. Who is responsible for your data?
ScholarBridge is responsible for Fellow personal data where Fellow decides why and how the information is used. A school or other organisation may instead be the controller for some school-managed activities, with Fellow acting as its processor or in another documented role.
Operating location: Cheshire, North West England, United Kingdom (full service address must be confirmed before paid launch)
Privacy contact: msgray95@hotmail.com
Fellow is the operator name supplied for the service. If Fellow is a trading name rather than a separate incorporated legal entity, the underlying legal person or entity must also be identified in the legal records and disclosures that require it. The regional location above is not being treated as a complete geographic service address for paid launch.
2. Information we collect or receive
- Account details such as name, email address and authentication information.
- A broad age band, such as 13–15, 16–17 or 18+, so age-appropriate protections can be applied without collecting a full date of birth.
- Versioned acknowledgement of the Terms and this Privacy Notice.
- Target university, course, application year and preparation preferences.
- Practice answers, scores, feedback, progress, reflections, study plans and revision activity.
- Written work, personal-statement text, files or other content you choose to submit for analysis.
- Interview transcripts and audio when you actively use a feature that needs them.
- School, cohort, assignment and authorised membership information where School-plan features are used.
- Subscription, entitlement and payment-status information. Full payment-card details are handled by Stripe rather than stored directly by Fellow.
- Technical, security and usage information reasonably needed for authentication, rate limiting, fraud or abuse prevention and service reliability.
- Privacy-rights requests, support messages and safeguarding reports that you choose to submit.
3. Why we use personal information
We use personal information to:
- create, authenticate and protect accounts;
- provide practice, marking, progress tracking, interview preparation and personalised learning features;
- provide optional AI and voice features when requested;
- manage subscriptions, entitlements and customer support;
- provide authorised School-plan dashboards and assignments;
- respond to privacy-rights requests and safeguarding concerns;
- prevent misuse, investigate security problems and keep the service reliable; and
- meet legal, accounting and regulatory obligations where they apply.
4. Our lawful bases
The lawful basis depends on the purpose. Core account and service processing may be necessary to provide a service requested by the user or to take steps requested before entering a contract. Security and limited service-protection processing may rely on legitimate interests where those interests do not override the rights and interests of users, especially children. Billing and record-keeping may also be required by law. Consent is used where it is the appropriate basis for genuinely optional processing. Where we rely on consent, it can be withdrawn without affecting processing that was already lawful before withdrawal.
School-managed processing is assessed separately because the school may determine the purpose and lawful basis for pupil data. Fellow and the school must document their respective roles before pupil information is imported or shared at scale.
5. AI, voice and service providers
Depending on the feature, Fellow may use Supabase for authentication/database services, Vercel for hosting/server execution, Stripe for billing, and AI or voice providers such as Google Gemini, OpenAI and ElevenLabs. A provider should receive only the information reasonably required to deliver the feature being used.
Do not include health information, passwords, financial details or other highly sensitive personal information in essays, prompts, interview responses or uploads unless it is genuinely necessary for the feature and you understand why it is being provided.
6. International transfers
Some service providers may process information outside the United Kingdom. Where UK data-protection law requires safeguards for an international transfer, Fellow must use an applicable UK adequacy arrangement, approved contractual safeguard or other lawful transfer mechanism and keep the provider arrangement under review.
7. Children and young people
Fellow is likely to be accessed by people under 18 and is designed with the ICO Children's Code in mind. Direct self-sign-up is intended for users aged 13 or over. We use an age band instead of a full date of birth and apply high-privacy defaults. Core use does not require geolocation, public profiles or student-to-student messaging. Personalisation is intended to support educational preparation rather than infer sensitive characteristics. If you are under 13, do not create a direct self-sign-up account; use an appropriate school-managed or parent/guardian-supported route if one is offered.
8. How long we keep information
Account and learning information is kept while reasonably needed to provide the account and associated service. When an account is deleted, user-linked data is designed to be removed through the deletion workflow, subject to lawful exceptions. Privacy-request and safeguarding records may be retained for a proportionate period where necessary for accountability, safety or legal obligations. Stripe and other payment providers may retain transaction records where financial or tax law requires them. Security and rate-limit records should be kept for the shortest operational period reasonably necessary.
9. Your data-protection rights
Depending on the circumstances, UK data-protection law may give you rights to access your information, correct inaccurate information, request deletion, restrict processing, object to some processing, receive certain information in a portable format and withdraw consent where consent is the lawful basis. These rights are not absolute in every situation.
Fellow provides a Privacy Centre for available data export, privacy requests and account deletion. You can also email msgray95@hotmail.com. You may complain to the UK Information Commissioner's Office if you are unhappy with how your information is handled.
10. Automated and AI feedback
AI-generated feedback, classifications, readiness indicators and practice scores are educational support tools. They are not official Oxford, Cambridge, school or admissions-test decisions and must not be used as the sole basis for a significant decision about a learner. Fellow does not intend to infer sensitive traits such as health, ethnicity, religion or sexuality from voice, writing or interview behaviour.
11. School-plan use
Before a school imports pupil data, the school and Fellow must identify their data-protection roles, document the purpose and lawful basis for the processing, agree appropriate data-processing terms where required and limit access to authorised staff and pupils. Schools remain responsible for information they choose to upload and for ensuring they have authority to use Fellow for their pupils.
12. Cookies and device storage
Essential storage may be used for authentication, account security, plan access and privacy preferences. Non-essential cookies or similar technologies must not be enabled merely because a user visits Fellow where consent is required. See the Cookie & Storage Notice for more information.
13. Security and data breaches
Fellow uses technical and organisational safeguards intended to protect personal information, including access controls, server-side authorisation and account-security controls. No online service can guarantee absolute security. Suspected personal-data breaches must be recorded and assessed, and reportable breaches must be handled in accordance with UK data-protection law.
14. Safeguarding and complaints
Safety concerns can be raised through the Safeguarding page. Privacy questions or complaints can be sent to msgray95@hotmail.com. AI is not used as the sole decision-maker for whether a safeguarding concern is valid or requires action.
15. Changes to this notice
We may update this notice when features, providers, business arrangements or laws change. Material changes should be highlighted to users, and a new acknowledgement may be requested where appropriate. The date at the top shows the current version.