Privacy
Your practice stays in the browser or app on your device. An account is optional and changes only what is named below. This page says exactly what that means, and where the exceptions are.
Last updated 8 August 2026
The short version
- An account is optional. Signed out — which is the default, and how the app ships today — nothing identifies you and nothing is held about you.
- Signed out, your progress lives only in the tab you have open and is gone when you close it. Signed in, it is kept on your account so it follows you between devices.
- No cookies, no analytics, no advertising and no third-party trackers.
- Your writing and your speaking transcript are sent for marking when you ask for it, and are not stored afterwards.
- BandUp never uploads audio from your microphone and never saves it as a file.
- On the web you can choose to have your speech transcribed on your own device, so the audio never leaves it at all. The recogniser built into your browser or phone is still the default.
What is stored, and where
Signed out, everything BandUp remembers about you lives in the tab you are using and nowhere else. Close the tab or the browser and it is gone; open BandUp again and you start fresh. Nothing is left behind on the machine, which matters most on a shared or borrowed one. Signed in, the same five entries are kept on your account instead, so they follow you between devices. Either way, this is the whole of it:
ielts-prep-v1
Your placement result, target band, study plan and test scores.
bandup.drills.v1
Which grammar and vocabulary drills you have finished, and how you did.
bandup.lookups.v1
Words you have tapped to look up, so you can revise them later.
bandup.theme
Whether you chose the warm, light or dark theme.
bandup.speech.v1
Which speech recogniser you chose for the speaking test, and which model size.
One further thing can be stored, and only if you ask for it: if you turn on on-device transcription in the speaking test, the speech model it needs (about 75 or 145 MB, depending on which you pick) is downloaded once and kept in your browser’s cache so it works offline afterwards. It holds no data about you — it is the same file every user downloads — and the speaking test offers a button to delete it.
Because this lives on the device and nowhere else, your progress does not follow you to a new phone or a different browser, and we cannot recover it for you if it is lost.
What leaves your device
Four features need a model to think about your English, and those are the only times anything you write is sent anywhere. Each one goes to BandUp’s server, which passes it to Anthropic’s API for the answer and sends that answer back to you. BandUp writes none of it to a database or a log.
Writing marking /api/grade/writing
The essay you wrote and the task prompt it answers.
Speaking marking /api/grade/speaking
The written transcript of your interview — the text, never the audio.
New practice tests /api/generate
The topic and difficulty you picked. Nothing about you.
Word lookup /api/define
The word you selected and the sentence it appeared in.
Ask a tutor /api/chat
The question you typed, and the recent messages of that conversation so the answer follows on. The conversation lives in the tab you are reading it in and is gone when you close it.
Your placement result, your study plan and your test scores are never among them. Anthropic handles what it receives under its own terms; BandUp sends no name, no email and no identifier alongside it, because it holds none.
One other request leaves your device, and it carries nothing of yours: if you turn on on-device transcription, the speech model is downloaded once from Hugging Face. It is described in full under the microphone below.
Placement, the study plan, the bundled practice tests, the grammar and vocabulary drills and the marking of reading and listening answers all run entirely on your device, and work with no connection at all.
The microphone, in full
The speaking test asks for microphone access so it can hear your answers. This is the part worth reading carefully, because the speaking test now offers two ways of turning speech into text and they differ in exactly this respect. You choose on the screen before the interview starts.
Your device’s recogniser — the default
- Your speech is turned into text by the recogniser built into the device or browser you are using — Apple’s speech recognition in the iOS app, the browser’s own Web Speech API on the web. BandUp receives only the words it returns.
- Those recognisers are not ours, and some of them send audio to their own servers to transcribe it — Chrome’s uploads to Google. Apple and the makers of Chrome, Safari and Edge each decide whether recognition happens on the device or in their cloud, and that is governed by their privacy policies, not this one. We would rather tell you this plainly than claim your voice never leaves the phone when we cannot guarantee it.
On-device transcription — if you turn it on
- With this on, your audio never leaves your device. A speech model called Whisper runs inside your own browser and does the transcription there. Nothing is sent to BandUp, to us, or to anyone else, and no recogniser outside your device hears it.
- Your answer is held in memory while you speak, because this model needs the whole answer before it can transcribe it. It is never written to a file and it is discarded as soon as the text comes back.
- There is one exception worth being exact about, and it is not audio. The model itself has to be downloaded before it can run, and it comes from Hugging Face, who host it. That request happens once, then the file is cached and used offline. Hugging Face therefore sees that some device asked for the file, along with the IP address any download reveals. It carries no audio, no transcript, no identifier, and nothing about you or your practice.
- This option is available on the web. The iOS app does not offer it yet: the on-device model there is written but not yet built into a released version, so in the app the speaking test still uses Apple’s recogniser. When that changes, this page changes with it.
Both ways share the rest: BandUp never uploads your audio and never saves it as a file. Only the finished transcript — text — is sent for marking, and only when you ask for feedback. The microphone is used during the speaking test and at no other time. You can also skip the microphone entirely and type your answers.
The speaking examiner also reads its questions aloud using the voice built into your device. That is playback only; nothing is captured.
If you sign in
BandUp can be used entirely signed out, and is by default. The placement test, your study plan, every practice test and both sets of drills work without an account and always will. An account exists to carry that work between your phone and your laptop, and to raise the daily limit on AI feedback.
Signing in uses Google or Apple. BandUp never sees your password — the provider confirms it is you and passes on your email address and nothing else. There is no password here to lose or to leak, because there is none to set.
If you do sign in, we hold:
- Your email address, so the account can be recovered if you lose access to Google or Apple.
- A count of AI requests over the last 24 hours, so the daily allowance can be applied. It records that a request happened and to which feature — never what you wrote, said or were told.
- A copy of your study progress, if you choose to sync it, so a new device can pick up where the last one left off.
- Anything you choose to put on your account page: a display name, a profile picture, and optionally your date of birth. All of it is optional, all of it can be cleared, and the account works exactly the same if you leave it empty.
Your date of birth is used for exactly one thing: confirming you are 13 or over. This app is not intended for younger children, and a date of birth is the only way that can be checked rather than assumed. Nothing else reads it — it does not affect your plan, your band or anything you see.
We previously asked for your gender. It has been removed, because nothing in BandUp ever used it and holding personal information with no purpose is not something we want to do. Any gender already stored has been deleted along with the field.
Your profile picture is stored privately and is never public. BandUp has no profile pages, no leaderboards and no way for other learners to find you, so the only person who ever sees it is you. It is served through a link that expires after an hour rather than from a permanent address.
Account data is stored with Supabase, who host the database on our behalf. Their servers may be in a different country from yours, which is true of almost any hosted service and is worth saying rather than leaving you to assume otherwise.
Questions about any of this, or a request about your data, go to hello@bandup.study.
Signing out ends the session on that device and deletes nothing. To close the account altogether, use Delete your account on your account page: it removes your email address, your details, your picture and any synced practice, immediately and permanently. The copy in your own browser stays, because it was never ours to delete — clear that from your browser’s settings whenever you like.
Sessions are kept in your device’s own storage rather than in a cookie, which is why signing in still sets none.
Cookies and tracking
There are none. BandUp sets no cookies, includes no analytics or advertising scripts, and loads nothing from a third party that could watch you across sites. There is no consent banner here because there is nothing to consent to. Signing in does not change this: the session is held in your device’s own storage, not in a cookie.
One honest edge: if you subscribe, the payment page is Stripe’s own, on Stripe’s domain, and it sets its own cookies under its own policy — as any payment page does. You are on their site for those two minutes, and back here after.
The web version is served by a hosting provider that, like any web host, records ordinary server request logs. BandUp does not use those logs to build any picture of you.
If you subscribe
Your card details never reach BandUp. Paying takes you to Stripe, the payment company, and the card is typed on their page and stored by them. Nothing here ever sees a card number, an expiry date or a security code, which means there is no version of this app being breached that exposes your card.
Stripe tells us only what is needed to know what you have bought: that a subscription started, renewed or ended, which plan it is, and an identifier that links it to your account. That is what the app stores — the plan, the dates, and the identifier.
Stripe is a separate company and handles your payment information under its own privacy policy. It needs your name, email and card to process a payment, and it uses that information to detect fraud, which is the reason payment works at all.
If you never subscribe, none of this applies to you and no payment company is involved in your account at all.
Deleting your data
Everything is on your device, so deleting it is entirely in your hands and takes effect immediately:
- In the app: delete BandUp from your device. Its storage goes with it.
- On the web: clear site data for this site in your browser’s settings.
Signed out there is no request to send us and no account to close, because nothing is held on our side to delete. That deletion is final — your progress cannot be restored afterwards. If you have an account, see below for what it holds and how to close it.
Children
BandUp is a study tool for people preparing for an English exam and is not aimed at children under 13. It collects nothing that would identify anyone of any age.
Changes to this policy
If what BandUp stores or sends ever changes, this page changes with it and the date at the top is updated. The version you are reading ships inside the app you have installed, so it always describes that version.
That is the whole policy. Back to the practice: