PharmRevise privacy notice
Last updated: 25 September 2026
PharmRevise is a free revision tool for people preparing for the GPhC registration assessment. Anyone can try the PharmRevise 150 without an account, and anyone can create an account. The full question bank opens once we have reviewed the account. It is not affiliated with the General Pharmaceutical Council. This notice explains what personal data the tool holds about you, why, who else handles it, how long it is kept and what you can do about it.
1. Who is responsible for your data
The controller of your data is PharmRevise, the trading name of the individual who runs it. PharmRevise is not yet a company; if that changes, this notice will be updated to name it.
Contact: hello@pharmrevise.co.uk.
We have not appointed a data protection officer.
2. What we hold, and where it comes from
Everything below comes from you, or from your use of the app.
| What | Details | Where it is stored |
|---|---|---|
| Your account | Your email address. If you use a password, a scrambled (hashed) copy of it; we cannot read your password. The date the account was created, and when you last signed in | Supabase (our database and sign-in provider) |
| Your display name | The part of your email address before the "@", created automatically | Supabase |
| Your answers | For every question you answer: which question, whether you got it right, how many seconds you took, which mode you were in, and when. This includes answers you gave in the PharmRevise 150 before you had an account: they move to your account when you create it | Supabase |
| Your review schedule | For each question: how many times you have answered it and got it right, when it is next due, and whether you flagged it | Supabase |
| Your study sessions | For each session: its title, how many questions, how many right or skipped, and the time taken | Supabase |
| Your access | Whether your account can open the question bank, when access was granted, and when it ends | Supabase |
| Your unlock request | Whether your account is waiting for the full bank, has been given it, or has been refused, and when | Supabase |
| Your exam sitting | The June or November sitting you tell us you are aiming for, used to set your countdown. You can change it at any time | Supabase |
| Sign-up and sign-in emails | Your email address and the emails we send you to confirm your account, sign you in by link, or reset your password | Resend (our email sender) |
| Question reports | If you report a question: which question, the bank version, your note, and when | Supabase |
| Download record | Each time your device downloads the question bank: when, how many questions, and which version | Supabase |
| Sign-in records | Sign-in, sign-out, password-reset and similar events, with the IP address and browser details they came from | Supabase's logs |
| Website request logs | When you load a page, our host records the request, which includes your IP address and browser details | Netlify (our website host) |
| Emails you send us | Anything you write to hello@, and your email address | Zoho Mail (our mailbox) |
We do not collect your name (unless it is part of your email address), your phone number, your location, payment details, or anything about your health. The only thing you can type into the app is the optional note on a question report.
If you use the PharmRevise 150 without an account. We collect nothing from you. Your answers stay in your browser's storage on your device and are not sent to us. Our website host, Netlify, records each page request, including your IP address and browser details, as it does for every visitor. If you then create an account, the answers on that device move to it. To remove them without creating an account, clear this site's data in your browser.
3. What we use it for, and our lawful basis
We rely on legitimate interests (UK GDPR Article 6(1)(f)) for all of the processing below. Our interests, and why we think they do not override yours, are:
- Running the tool you signed up for. Keeping your account, answers, review schedule and sessions is the tool: without them there is nothing to revise from and nothing to sync between your devices.
- Deciding whether to open the full bank to your account. We look at the email address, when the account was created and how it has been used. A person makes this decision, not software. We may say no, for example to keep numbers manageable while we test, or where an account looks like it is being used to copy content.
- Protecting the question bank from bulk copying. The download record lets us see who downloaded the bank and when. Much of the question content belongs to other people and is shared only for private study, so we have to be able to show who had it. The record holds no answers and is not used to judge you.
- Keeping the service secure. Sign-in records and request logs are kept by our providers to detect misuse and fix faults.
- Seeing how people are doing. The person who runs PharmRevise can see each account's answer history and scores, listed by display name, and totals for the group as a whole, in an admin view. It is used to find weak topics and wrong questions.
- Answering you when you email us.
You can object to any of this (see section 7). Because the tool cannot work without your account and answer history, objecting to those in practice means closing your account.
You must give an email address to have an account. You do not need an account to try the PharmRevise 150. You need one to save your progress and to ask for the full bank.
We do not make any automated decisions about you that have legal or similarly significant effects. The review schedule only decides which question the app shows you next.
4. Who else handles it
We use these providers to run the service. Each acts on our instructions under a data processing agreement.
| Provider | What it does | Where your data is |
|---|---|---|
| Supabase Pte. Ltd (Singapore) | Database and sign-in | Stored on Amazon Web Services in Ireland (EU). Supabase staff and its own sub-processors may access it from other countries under the UK's approved contract clauses |
| Netlify, Inc. (USA) | Website hosting and request logs | USA and Netlify's global network |
| Zoho Corporation B.V. (Netherlands) | The hello@ mailbox | Zoho's EU data centre; Zoho may transfer within its group, including to the USA |
| Resend (Plus Five Five, Inc., USA) | Sends our sign-up, sign-in and password emails | USA |
We do not sell your data, share it with advertisers, or use analytics or advertising trackers. We do not send your data to AI services.
We may disclose data where the law requires it.
5. Transfers outside the UK
- Ireland (EU): the UK treats EEA countries as providing adequate protection, so no extra safeguard is needed.
- USA (Netlify): it states that it is certified under the UK Extension to the EU-US Data Privacy Framework, which UK regulations recognise.
- USA (Resend): protected by the standard contractual clauses with the UK Addendum issued by the Information Commissioner.
- Supabase (a Singapore company) and Zoho group transfers: protected by the standard contractual clauses with the UK Addendum issued by the Information Commissioner. You can ask us for a copy of the safeguards at hello@.
6. How long we keep it
Deletion after a period without sign-in is not automated yet; until it is, we carry it out by hand.
| Data | Kept for |
|---|---|
| Account, answers, review schedule, sessions, access | While your account is open. Deleted when you ask, or automatically after 12 months with no sign-in. All member data is deleted by 30 June 2028, twelve months after the June 2027 assessment, unless we tell you beforehand that the service is continuing |
| Download record | 12 months from each download, and always deleted with your account |
| Accounts never confirmed | Deleted 7 days after sign-up |
| Accounts waiting for, or refused, the full bank | While you use them for the PharmRevise 150. Deleted after 6 months with no sign-in. If we refuse the full bank we email you, and delete the account 30 days later unless you reply that you want to keep it for the 150 |
| Sign-in records (Supabase) | Supabase's own log period: currently 1 hour for sign-in audit logs and 1 day for other logs on our plan. |
| Website request logs (Netlify) | Netlify's own log period |
| Emails to hello@ | 12 months after the matter is closed. If you ask us to delete your account, we keep a short record that we did (date and what was deleted, not your answers) for 24 months, to show we did it |
7. Your rights
You have the right to:
- see the data we hold about you and get a copy;
- correct it if it is wrong;
- delete it;
- restrict how we use it while a problem is sorted out;
- object to our using it; and
- complain to us, and to the Information Commissioner's Office.
To use any of these, email hello@pharmrevise.co.uk from the address on your account. We reply within one month. We can extend that by up to two more months for a complex request, and if we do we tell you why within the first month.
Deleting your account removes your account, answers, review schedule, sessions, access record and download record from our database. This works the same whether or not the full bank was ever opened to your account, and it includes answers that came from the PharmRevise 150. You can delete your account yourself from the Account screen, or email us and we will do it for you. What it does not remove straight away: copies in our providers' short-lived logs (section 6), which expire on their own schedule; any emails you sent us; and the progress stored on your own devices, which you remove by signing out and clearing the site's data in your browser.
Complaints. If you are unhappy with how we have handled your data, email hello@ first. We will acknowledge your complaint within 30 days and tell you the outcome. You can also complain to the Information Commissioner's Office: ico.org.uk, or 0303 123 1113.
8. What the app stores on your device
The app uses your browser's local storage and IndexedDB, not cookies. Everything listed is needed for the service you asked for:
| Name | What it is for |
|---|---|
sb-nlfgmdoaoaiptchtplgv-auth-token | Keeps you signed in (Supabase) |
qbank_progress_v1 | Your progress, so the app works offline |
qbank_outbox_v1 | Answers waiting to sync to your account |
qbank_live | The paper you are part-way through, so a reload does not lose it |
qbank_guest_progress_v1 | Your answers in the PharmRevise 150 without an account, kept on your device only |
qbank_guest_live | The question you are on in the 150, so a reload does not lose it |
qbank_sitting | The exam sitting you chose, so the countdown shows before you sign in |
qbank_auth_method | Remembers whether you sign in by password or email link |
qbank_bank (IndexedDB) | A copy of the question bank for your account, so it loads quickly and offline. The app stops using it after 14 days without reaching our server, and deletes it when your access ends |
nl-hud:public:v1 | Set by Netlify's site badge |
qbank_pass | Older versions only: a saved passphrase from before accounts. |
9. Changes to this notice
If we change this notice we will update the date at the top and email account holders about any change that affects them before it takes effect.