Privacy Policy
What we collect, why we collect it, and what you can tell us to do with it. Written to be read, not skimmed past.
- Last updated
- 21 August 2026
1. Who we are
Prentice is a platform that helps people in the UK prepare for and find tech apprenticeships. This policy covers prenticehq.com and everything you do while signed in.
For data protection law, the “data controller” — the party responsible for your personal data — is:
- Dominic Tigreros-Bosini, trading as Prentice
- Contact for anything about your data: privacy@prenticehq.com
- If you need a postal address for a formal request, email us and we’ll provide one.
Our community server runs on Discord, and Discord is a separate company with its own privacy policy. Joining it is optional and your Discord account is not linked to your Prentice account.
2. What we collect
This is the complete list. If something isn’t here, we don’t collect it.
Things you tell us
| What | When | Why we need it |
|---|---|---|
| Email address | Sign-up | It identifies your account, and it’s how we send you a confirmation link and security alerts. |
| Password | Sign-up | Stored only as a cryptographic hash. Nobody at Prentice can read it, including us. |
| First name | Setting up your account | So the app and our emails can address you properly. |
| Date of birth | Setting up your account | To check you're at least 13, and to design the service appropriately for under-18s. See section 4. |
| The career path you pick | Setting up your account | To shape your roadmap and what we show you. |
| Employers you star, and apprenticeships you save | While using the app | To build your shortlist and flag when applications open. |
| Messages you send in a live event chat | During a live session | So the room works. Everyone watching sees your message next to your full name — see “Live event chats” below before you type anything you would not want the room to read. |
| Reports you make about someone else’s message | When you press the report flag | So we can look at what was said and act on it. We keep a copy of the message you reported. |
| A CV, if you send one in for a live session | When you submit it for a CV review | So the host can read it during the session. It goes in private storage only you and the session’s hosts can open, and it’s deleted a week later — see section 7. |
Live event chats
This is the one part of Prentice where other people see something you wrote, so it’s worth being blunt about it.
- Your full name appears next to every message you send. Not a nickname or a handle. That is deliberate: it is what keeps the room civil, because what you say is attached to who you are.
- Everyone signed in and watching that session can read it. There is no private messaging, and nobody can click your name to find out anything else about you.
- The chat is never shown on the stream itself and is never part of the recording we publish afterwards. What you write stays on the Prentice page and disappears with it.
- We delete chat messages 48 hours after they are sent. If somebody reports a message, we keep a copy of that one for longer — see section 7.
- We can hide a message and stop an account posting. If we do, the message is hidden from everyone but we keep our own record of it, so there is evidence of what happened if it is ever needed.
Things we generate or observe
| What | Detail |
|---|---|
| Sign-in device records | When you sign in with a password we store a one-way hash of your user ID, browser identifier, and part of your network address; a readable label such as “Chrome on Windows”; and an approximate city such as “Manchester, GB”. We deliberately do not store your full IP address or full browser identifier. This exists so we can email you if someone signs in from somewhere new. |
| Product analytics | Which pages you open, which buttons you press, how long a setup step took, and whether something errored. These are our own records on our own database, from a fixed list of events. They never contain your name, your email, your date of birth, or anything you typed as free text — including anything you type into the employer search box. |
| Email confirmation tokens | Stored as a hash, single-use, and expiring after 24 hours. |
| Consent timestamps | The moment you accepted these terms, kept so we can show when and what you agreed to. |
| Technical request data | Like any website, our host receives your IP address in order to deliver pages and block abuse. Our own database never stores it. |
What we never collect
We do not ask for or store your school, your address, your phone number, your exam results, your National Insurance number, or any payment details. There are no paid features yet. We do not use third-party advertising or tracking scripts, and we do not run cross-site trackers.
3. Why we use it, and our legal basis
UK GDPR requires us to have a specific lawful reason for each use. Ours:
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account | You asked us to provide the service. | Performance of a contract |
| Confirm your email address | To prove the address is yours before unlocking anything sensitive. | Performance of a contract |
| Email you when a new device signs in | So you find out quickly if someone else gets into your account. | Legitimate interests — account security |
| Check your age and enforce the minimum | Legal obligation to run an age-appropriate service, and our own duty of care. | Legal obligation, and legitimate interests — child safety |
| Show you relevant apprenticeships and roadmaps | It’s the service you signed up for. | Performance of a contract |
| Measure how the product is used, in aggregate | To find where people get stuck and fix it. | Legitimate interests — improving the service |
| Keep the service secure and prevent abuse | To protect users, most of whom are children. | Legitimate interests — security |
| Show your messages, with your name, in a live event chat | It’s how a live chat works, and you chose to post. | Performance of a contract |
| Keep a copy of a reported message, and act on it | So we can look into what was said, protect whoever was affected, and show what we did about it. This is why a reported message outlives the ordinary 48-hour deletion. | Legitimate interests — child safety and moderation |
Where we rely on legitimate interests, we’ve weighed our interest against your privacy, and taken the more private option each time it was available: our analytics are first-party, they hold no persistent device identifier, and our device records hold hashes and a coarse location rather than your IP address. You can object to any legitimate interests processing — see section 8.
4. Young people and age checks
Most of the people using Prentice are between 13 and 18. We designed the service around that, following the ICO’s Age Appropriate Design Code.
The minimum age is 13
That’s the age at which you can consent to online services yourself in the UK. We ask for your date of birth while you set up your account, and we check it.
If you’re under 13
We can’t give you an account yet, and we’re honest about what happens next. We keep a deliberately minimal record so the block actually works: your email address, and the date you turn 13. We do not keep your date of birth.
We keep that record until the day you turn 13, then delete it, and you’re welcome to sign up. We’re keeping a small amount of information about a child in order to keep them out of a service that isn’t for them yet — if we deleted everything, you could sign up again a minute later with a different birthday, and the protection would be worthless.
If we’ve blocked you by mistake, email privacy@prenticehq.com and we’ll fix it.
What we do because our users are young
- No advertising, no ad targeting, and no selling of data.
- No third-party tracking scripts. Our analytics are first-party and never leave our own database.
- No profiling that makes decisions about you, and no recommendation system built from your behaviour.
- No public profiles. Nothing you save or pick is visible to other users.
- No nudges to share more than you need to, and no “dark patterns” that make the private option harder to choose.
- No private messaging between adults and young people on Prentice. Our Discord community rules say staff never message you first.
For parents and carers
If you’re a parent or guardian and want to know what we hold about your child, ask them to email us from their account address, or contact us at privacy@prenticehq.com. We’ll need to be reasonably sure who we’re talking to before sharing anything, and where the young person is old enough to decide for themselves we’ll usually involve them in the request.
7. How long we keep it
| What | How long |
|---|---|
| Your account and everything in it | until you delete it. |
| A sign-up that never finished setting up | 30 days, then deleted. |
| An under-13 block | until the day you turn 13, then deleted. |
| Email confirmation links | 24 hours. |
| Product analytics | 24 months, then deleted. |
| Sign-in device records | For as long as your account exists, so we can tell a familiar device from a new one. |
| Live event chat messages | 48 hours, then deleted permanently. They are never added to the published recording. |
| A CV you send in for a live session | 7 days, then the file and our record of it are both deleted. You can withdraw it yourself any time before it's read out. |
| A message somebody reported | We keep a copy of the message, who sent it, and the report — 6 months after we have dealt with it. This is longer than the 48 hours above on purpose: if a report were deleted with the chat, the record of what was said would be gone before we had dealt with it. A report nobody has dealt with yet is never deleted. |
When you delete your account, we delete your profile, your date of birth, your saved employers and apprenticeships, your device records, your confirmation tokens, and your analytics events. It is immediate and irreversible — there’s no grace period and no backup copy we can restore from, so please be sure.
Two records survive deletion, and neither is linked to you: the bare fact that an account was deleted, and the bare fact that someone was blocked for being under 13. They carry no user ID. We keep them because we can’t otherwise count how often either happens.
One more thing survives, and it’s worth stating plainly rather than leaving you to find out: if a message you sent was reported before you deleted your account, our copy of that report stays for the period above. Deleting your account cannot erase a safeguarding record about something you said to someone else — that would make the report useless to the person who made it. Everything else about you goes.
8. Your rights
Under UK data protection law you have the rights below, free of charge. We respond within one month.
- Access. Get a copy of what we hold about you.
- Correction. Fix anything wrong. Some details can’t yet be edited in the app, so email us and we’ll change them.
- Deletion.Have your data erased. You can do this yourself: Account → Security → Delete account.
- Portability. Receive your data in a machine-readable format, or have us send it somewhere else.
- Restriction. Ask us to pause using your data while a dispute is sorted out.
- Objection. Object to anything we do on the basis of legitimate interests, including our analytics.
- Withdraw consent. Where we rely on consent, withdraw it at any time.
To use any of these, email privacy@prenticehq.com from the address on your account. We may ask a question or two to check it’s really you — we’re not being awkward, we just won’t hand your data to someone pretending to be you.
9. Profiling and advertising
We do not make automated decisions about you that have a legal or similarly significant effect. Nothing on Prentice scores you, ranks you, or decides what you’re capable of.
We use the career track and the employers you choose to decide which apprenticeships to show you. That’s you telling us your preferences, not us inferring things about you from your behaviour, and you can change it whenever you like.
We do not advertise on Prentice, we do not allow third parties to advertise to you here, and we do not build audience segments or share data for marketing.
10. How we protect it
- Everything travels over HTTPS, and your password is stored only as a hash. We can never see it.
- Our database enforces row-level security, so one account cannot read another’s data even if something else goes wrong.
- Sensitive tables — device records, confirmation tokens, analytics — are not reachable from the browser at all. Only our server can touch them.
- Confirmation links and password resets are single-use and expire.
- You can sign out of every device at once from Account → Security.
No system is perfectly secure. If a breach ever puts you at risk, we’ll tell you, and we’ll report it to the ICO within 72 hours as the law requires.
11. Where your data goes
We prefer UK and EU hosting, and choose it where our suppliers offer it — our email provider processes data in Ireland for that reason.
Some of our suppliers are based in the United States. Where personal data leaves the UK, we rely on the safeguards UK law recognises — either the UK extension to the EU–US Data Privacy Framework, or an International Data Transfer Agreement with the supplier. We don’t transfer data anywhere without one of those in place.
If you want to know exactly where a specific piece of your data is stored, email privacy@prenticehq.com and we’ll tell you.
12. Changes to this policy
When we change this policy we’ll update the date at the top. If a change materially affects you — new kinds of data, a new purpose, a new supplier receiving your information — we’ll email you before it takes effect, and we’ll explain it in plain language rather than pointing you at a diff.
13. Contact and complaints
For anything about your data, email privacy@prenticehq.com. For everything else, hello@prenticehq.com.
If we get it wrong, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk or on 0303 123 1113. Complaining to them doesn’t cost anything and you don’t have to come to us first.