Legal

Privacy

QEBoys.com is operated by Lightcube. This page explains what the product stores and why.

Who controls the data?

Lightcube is the controller for data collected on this site. Contact ops@lightcube.app for privacy questions or requests. For product support, email ops@lightcube.app.

Accounts and purchases

When you create an account, we store your email address, the account timestamps and the exam surface where you signed up. If you set a password, we store a one-way password hash rather than the password. If you use Google sign-in, we also store the Google account identifier and any name or profile-photo URL Google provides. A signed-in session is represented by an HttpOnly cookie.

If you buy access, we store the purchase, product, amount, currency, status, buyer email and the Stripe checkout, payment and customer identifiers needed to grant access, handle refunds and support the transaction. Checkout may also collect your billing address and VAT ID so Stripe can determine the tax treatment and put it on your receipt. Stripe processes payment details; UniGenius does not receive your full card number.

Learning and saved results

Anonymous learning uses a signed session cookie. A diagnostic run can store its platform, selected modules, questions, responses, timing and computed result before an account is required. If you choose to save an ESAT result, the run is linked to your account and its associated attempts are linked to the same account.

Saving a result uses a short-lived, HttpOnly claim cookie. It expires after 10 minutes, is restricted to the ESAT API path, and is cleared after the handoff. The server stores a hash of the receipt rather than the receipt value. Optional product measurement is recorded only after you accept its consent prompt; that record contains the consent version and time plus an activation event with no direct contact fields, but it can be linked to the diagnostic run.

Reminders, cookies and analytics

If you request a deadline reminder, we store your email address, the reminder requested, the consent wording version and signup time in private storage. Deadline-reminder messages are not currently sent. The UCAT and LNAT programme-interest forms additionally store the role and £199 price-interest response you select, alongside the consent version and signup time; they do not create an account, charge you or grant course access. The application-programme enquiry additionally stores the selected role, exam route and proposed tier with the email, consent version and signup time, and creates one private customer-service follow-up for an operator to review within one hour; no automatic customer message is sent by that route. It does not create an account, charge you or grant programme access. If you opt in to ESAT prep updates after the diagnostic, your address is added to the UniGenius Resend list for occasional updates. You can unsubscribe from those updates at any time. We do not sell personal data.

Guest and standard signed-in account session cookies expire after 180 days. A checkout-created authenticated session expires after 30 days. Learning diagnostic session cookies expire after 30 days, and the Google sign-in state cookie expires after 10 minutes. Expiry stops a cookie being accepted. Session and claim records are not currently removed by an automatic cleanup job. UCAT calibration attempt records are a separate ephemeral store: they expire within 30 minutes and are purged opportunistically when that route is used; consented UCAT measurement events are retained for up to 90 days and then purged by the same cleanup. Account, purchase, diagnostic and reminder records do not currently have an automatic deletion schedule. Vercel Analytics is separate from the consent-gated product measurement described above and may process analytics data when enabled on the deployment.

Service providers

Vercel hosts the site, may process request and analytics data, and stores reminder leads in private blob storage. Supabase hosts the application database, including support messages received at our published support address. Google handles optional sign-in and returns the verified account identity. Stripe handles checkout and payment processing. Resend sends ESAT updates, password-reset and paid-course welcome email when those features are enabled, and receives support email sent to the live UniGenius support address for routing into our support inbox.

Access and deletion

There is no self-service account deletion control today. You can ask us to access, correct or delete account, learning, reminder or other personal data, and you can withdraw reminder or measurement consent. Email ops@lightcube.app and include the address concerned and the request you want us to handle. Requests are handled manually; payment, security, provider or other records may need to be retained where applicable, and we will explain the scope.