← Back to Prentice

Privacy Policy

What we collect, why we collect it, and what you can tell us to do with it. Written to be read, not skimmed past.

Last updated
21 August 2026

1. Who we are

Prentice is a platform that helps people in the UK prepare for and find tech apprenticeships. This policy covers prenticehq.com and everything you do while signed in.

For data protection law, the “data controller” — the party responsible for your personal data — is:

  • Dominic Tigreros-Bosini, trading as Prentice
  • Contact for anything about your data: privacy@prenticehq.com
  • If you need a postal address for a formal request, email us and we’ll provide one.

Our community server runs on Discord, and Discord is a separate company with its own privacy policy. Joining it is optional and your Discord account is not linked to your Prentice account.

2. What we collect

This is the complete list. If something isn’t here, we don’t collect it.

Things you tell us

Personal data you provide directly
WhatWhenWhy we need it
Email addressSign-upIt identifies your account, and it’s how we send you a confirmation link and security alerts.
PasswordSign-upStored only as a cryptographic hash. Nobody at Prentice can read it, including us.
First nameSetting up your accountSo the app and our emails can address you properly.
Date of birthSetting up your accountTo check you're at least 13, and to design the service appropriately for under-18s. See section 4.
The career path you pickSetting up your accountTo shape your roadmap and what we show you.
Employers you star, and apprenticeships you saveWhile using the appTo build your shortlist and flag when applications open.
Messages you send in a live event chatDuring a live sessionSo the room works. Everyone watching sees your message next to your full name — see “Live event chats” below before you type anything you would not want the room to read.
Reports you make about someone else’s messageWhen you press the report flagSo we can look at what was said and act on it. We keep a copy of the message you reported.
A CV, if you send one in for a live sessionWhen you submit it for a CV reviewSo the host can read it during the session. It goes in private storage only you and the session’s hosts can open, and it’s deleted a week later — see section 7.

Live event chats

This is the one part of Prentice where other people see something you wrote, so it’s worth being blunt about it.

  • Your full name appears next to every message you send. Not a nickname or a handle. That is deliberate: it is what keeps the room civil, because what you say is attached to who you are.
  • Everyone signed in and watching that session can read it. There is no private messaging, and nobody can click your name to find out anything else about you.
  • The chat is never shown on the stream itself and is never part of the recording we publish afterwards. What you write stays on the Prentice page and disappears with it.
  • We delete chat messages 48 hours after they are sent. If somebody reports a message, we keep a copy of that one for longer — see section 7.
  • We can hide a message and stop an account posting. If we do, the message is hidden from everyone but we keep our own record of it, so there is evidence of what happened if it is ever needed.

Things we generate or observe

Personal data we create or observe
WhatDetail
Sign-in device recordsWhen you sign in with a password we store a one-way hash of your user ID, browser identifier, and part of your network address; a readable label such as “Chrome on Windows”; and an approximate city such as “Manchester, GB”. We deliberately do not store your full IP address or full browser identifier. This exists so we can email you if someone signs in from somewhere new.
Product analyticsWhich pages you open, which buttons you press, how long a setup step took, and whether something errored. These are our own records on our own database, from a fixed list of events. They never contain your name, your email, your date of birth, or anything you typed as free text — including anything you type into the employer search box.
Email confirmation tokensStored as a hash, single-use, and expiring after 24 hours.
Consent timestampsThe moment you accepted these terms, kept so we can show when and what you agreed to.
Technical request dataLike any website, our host receives your IP address in order to deliver pages and block abuse. Our own database never stores it.

What we never collect

We do not ask for or store your school, your address, your phone number, your exam results, your National Insurance number, or any payment details. There are no paid features yet. We do not use third-party advertising or tracking scripts, and we do not run cross-site trackers.

3. Why we use it, and our legal basis

UK GDPR requires us to have a specific lawful reason for each use. Ours:

Purposes and lawful bases
What we doWhyLegal basis
Create and run your accountYou asked us to provide the service.Performance of a contract
Confirm your email addressTo prove the address is yours before unlocking anything sensitive.Performance of a contract
Email you when a new device signs inSo you find out quickly if someone else gets into your account.Legitimate interests — account security
Check your age and enforce the minimumLegal obligation to run an age-appropriate service, and our own duty of care.Legal obligation, and legitimate interests — child safety
Show you relevant apprenticeships and roadmapsIt’s the service you signed up for.Performance of a contract
Measure how the product is used, in aggregateTo find where people get stuck and fix it.Legitimate interests — improving the service
Keep the service secure and prevent abuseTo protect users, most of whom are children.Legitimate interests — security
Show your messages, with your name, in a live event chatIt’s how a live chat works, and you chose to post.Performance of a contract
Keep a copy of a reported message, and act on itSo we can look into what was said, protect whoever was affected, and show what we did about it. This is why a reported message outlives the ordinary 48-hour deletion.Legitimate interests — child safety and moderation

Where we rely on legitimate interests, we’ve weighed our interest against your privacy, and taken the more private option each time it was available: our analytics are first-party, they hold no persistent device identifier, and our device records hold hashes and a coarse location rather than your IP address. You can object to any legitimate interests processing — see section 8.

4. Young people and age checks

Most of the people using Prentice are between 13 and 18. We designed the service around that, following the ICO’s Age Appropriate Design Code.

The minimum age is 13

That’s the age at which you can consent to online services yourself in the UK. We ask for your date of birth while you set up your account, and we check it.

If you’re under 13

We can’t give you an account yet, and we’re honest about what happens next. We keep a deliberately minimal record so the block actually works: your email address, and the date you turn 13. We do not keep your date of birth.

We keep that record until the day you turn 13, then delete it, and you’re welcome to sign up. We’re keeping a small amount of information about a child in order to keep them out of a service that isn’t for them yet — if we deleted everything, you could sign up again a minute later with a different birthday, and the protection would be worthless.

If we’ve blocked you by mistake, email privacy@prenticehq.com and we’ll fix it.

What we do because our users are young

  • No advertising, no ad targeting, and no selling of data.
  • No third-party tracking scripts. Our analytics are first-party and never leave our own database.
  • No profiling that makes decisions about you, and no recommendation system built from your behaviour.
  • No public profiles. Nothing you save or pick is visible to other users.
  • No nudges to share more than you need to, and no “dark patterns” that make the private option harder to choose.
  • No private messaging between adults and young people on Prentice. Our Discord community rules say staff never message you first.

For parents and carers

If you’re a parent or guardian and want to know what we hold about your child, ask them to email us from their account address, or contact us at privacy@prenticehq.com. We’ll need to be reasonably sure who we’re talking to before sharing anything, and where the young person is old enough to decide for themselves we’ll usually involve them in the request.

5. Who we share it with

We do not sell your personal data and we never will. We share it only with the suppliers below, who process it on our instructions and cannot use it for their own purposes.

Processors
SupplierWhat they doWhat reaches them
SupabaseDatabase, authentication, and file storageYour email address, password (stored only as a hash), date of birth, first name, chosen track, saved employers and programmes, sign-in device records, and product analytics events.
VercelWebsite hosting and content deliveryTechnical request data including IP address, which Vercel processes to serve the site, to protect against abuse, and to resolve an approximate city for sign-in alerts.
ResendSending our emailsYour email address and the contents of the emails we send you — which include your first name, and for sign-in alerts your device type and approximate city.
GoogleOptional “Continue with Google” sign-inOnly if you choose it. Google tells us your email address and name; we never receive your Google password. Google’s own privacy policy governs what Google does.
YouTube (Google)Playing the live stream on our events pagesWhen a live session page loads, your browser requests the video player from Google, which means Google receives your IP address and basic request information. We use the no-cookie version of the player, so it does not set advertising or tracking cookies unless you press play. We do not send Google your name, email, or anything else about your account.
DiscordOur community server (optional)Nothing is sent by us. If you choose to join, Discord processes your data under its own terms, and your Discord account is not linked to your Prentice account.

We may also disclose data if the law requires it, to protect someone from harm, or as part of investigating a safeguarding concern. If we ever transfer the business, we’d tell you before your data moved.

6. Cookies and browser storage

We use no advertising cookies and no analytics cookies, which is why you haven’t been asked to dismiss a cookie banner. Everything below is strictly necessary to make the site work or is stored only in your own browser.

Cookies and browser storage
NameTypePurposeLifetime
sb-…-auth-tokenCookieKeeps you signed in. Set by Supabase, our authentication provider. Strictly necessary — without it you would be signed out on every page.Until you sign out or it expires
prentice.analytics.sidSession storageA random ID that groups one visit’s events together. Not a cookie, never sent to other sites.Deleted when you close the tab
prentice.analytics.seenLocal storageA single yes/no flag so we can count new versus returning visitors. It is not an identifier and cannot single you out.Until you clear your browser data
prentice.onboarding.draftSession storageHolds your half-finished setup answers — including your first name and date of birth — so a refresh doesn’t lose them. It stays in your browser and is not sent to us until you finish.Cleared when you finish, or after 12 hours

You can clear browser storage at any time through your browser settings. Clearing the sign-in cookie will simply sign you out.

7. How long we keep it

Retention periods
WhatHow long
Your account and everything in ituntil you delete it.
A sign-up that never finished setting up30 days, then deleted.
An under-13 blockuntil the day you turn 13, then deleted.
Email confirmation links24 hours.
Product analytics24 months, then deleted.
Sign-in device recordsFor as long as your account exists, so we can tell a familiar device from a new one.
Live event chat messages48 hours, then deleted permanently. They are never added to the published recording.
A CV you send in for a live session7 days, then the file and our record of it are both deleted. You can withdraw it yourself any time before it's read out.
A message somebody reportedWe keep a copy of the message, who sent it, and the report — 6 months after we have dealt with it. This is longer than the 48 hours above on purpose: if a report were deleted with the chat, the record of what was said would be gone before we had dealt with it. A report nobody has dealt with yet is never deleted.

When you delete your account, we delete your profile, your date of birth, your saved employers and apprenticeships, your device records, your confirmation tokens, and your analytics events. It is immediate and irreversible — there’s no grace period and no backup copy we can restore from, so please be sure.

Two records survive deletion, and neither is linked to you: the bare fact that an account was deleted, and the bare fact that someone was blocked for being under 13. They carry no user ID. We keep them because we can’t otherwise count how often either happens.

One more thing survives, and it’s worth stating plainly rather than leaving you to find out: if a message you sent was reported before you deleted your account, our copy of that report stays for the period above. Deleting your account cannot erase a safeguarding record about something you said to someone else — that would make the report useless to the person who made it. Everything else about you goes.

8. Your rights

Under UK data protection law you have the rights below, free of charge. We respond within one month.

  • Access. Get a copy of what we hold about you.
  • Correction. Fix anything wrong. Some details can’t yet be edited in the app, so email us and we’ll change them.
  • Deletion.Have your data erased. You can do this yourself: Account → Security → Delete account.
  • Portability. Receive your data in a machine-readable format, or have us send it somewhere else.
  • Restriction. Ask us to pause using your data while a dispute is sorted out.
  • Objection. Object to anything we do on the basis of legitimate interests, including our analytics.
  • Withdraw consent. Where we rely on consent, withdraw it at any time.

To use any of these, email privacy@prenticehq.com from the address on your account. We may ask a question or two to check it’s really you — we’re not being awkward, we just won’t hand your data to someone pretending to be you.

9. Profiling and advertising

We do not make automated decisions about you that have a legal or similarly significant effect. Nothing on Prentice scores you, ranks you, or decides what you’re capable of.

We use the career track and the employers you choose to decide which apprenticeships to show you. That’s you telling us your preferences, not us inferring things about you from your behaviour, and you can change it whenever you like.

We do not advertise on Prentice, we do not allow third parties to advertise to you here, and we do not build audience segments or share data for marketing.

10. How we protect it

  • Everything travels over HTTPS, and your password is stored only as a hash. We can never see it.
  • Our database enforces row-level security, so one account cannot read another’s data even if something else goes wrong.
  • Sensitive tables — device records, confirmation tokens, analytics — are not reachable from the browser at all. Only our server can touch them.
  • Confirmation links and password resets are single-use and expire.
  • You can sign out of every device at once from Account → Security.

No system is perfectly secure. If a breach ever puts you at risk, we’ll tell you, and we’ll report it to the ICO within 72 hours as the law requires.

11. Where your data goes

We prefer UK and EU hosting, and choose it where our suppliers offer it — our email provider processes data in Ireland for that reason.

Some of our suppliers are based in the United States. Where personal data leaves the UK, we rely on the safeguards UK law recognises — either the UK extension to the EU–US Data Privacy Framework, or an International Data Transfer Agreement with the supplier. We don’t transfer data anywhere without one of those in place.

If you want to know exactly where a specific piece of your data is stored, email privacy@prenticehq.com and we’ll tell you.

12. Changes to this policy

When we change this policy we’ll update the date at the top. If a change materially affects you — new kinds of data, a new purpose, a new supplier receiving your information — we’ll email you before it takes effect, and we’ll explain it in plain language rather than pointing you at a diff.

13. Contact and complaints

For anything about your data, email privacy@prenticehq.com. For everything else, hello@prenticehq.com.

If we get it wrong, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk or on 0303 123 1113. Complaining to them doesn’t cost anything and you don’t have to come to us first.